Livy never sends communications to a customer who didn’t accept them. Every email goes through a consent check before going out. Someone who didn’t give permission can still collect points and be part of the program, but doesn’t receive marketing emails.
Livy stores what’s needed for the program to work: the customer’s identification (to assign their points and history), their consent and their activity in the program (points earned, redeemed and purchases).
If a customer asks you to delete their data, the request is processed following Shopify’s flows. Shopify is the origin of those requests and Livy responds accordingly.
All of this helps make your program trustworthy: your customers receive only what they accepted, and their data is used to give them their benefit, nothing else.