Managing digital certificates requires accurate account records, secure validation history, and reliable audit trails. In some cases, you may no longer need an SSL.com account, may have created a duplicate account by mistake, or may want to remove stored information from an account.
Because SSL.com is a publicly trusted Certificate Authority (CA), some account and certificate-related records must be retained for security, compliance, audit, and legal purposes. This means an SSL.com account cannot always be permanently deleted in the same way as a typical consumer website account. Instead, SSL.com provides a secure account deactivation and privacy request process that helps protect your information while maintaining required CA compliance obligations.
This guide explains how SSL.com handles account deactivation and data deletion requests, what information may need to be retained, and how to submit a request.
Who This Guide Is For
This guide is intended for SSL.com customers who want to:- Deactivate an unused SSL.com account.
- Disable a duplicate SSL.com account.
- Remove stored payment information.
- Submit a privacy or data deletion request.
- Understand why some Certificate Authority records may need to be retained.
Why SSL.com May Need to Retain Some Account Data
SSL.com issues publicly trusted digital certificates. As part of that role, SSL.com must maintain certain records related to certificate issuance, validation, certificate lifecycle events, customer transactions, and security activity. These records support:- Certificate Authority compliance.
- Security auditing.
- Fraud prevention.
- Certificate lifecycle management.
- Legal and regulatory obligations.
- Investigation of certificate issuance, revocation, or validation events.
Account Deactivation vs. Data Deletion
Account deactivation and data deletion are related, but they are not always the same. Account deactivation disables future use of the account. Once deactivated, the account can no longer be used to place orders, manage certificates, or access customer portal functions. Data deletion refers to the removal of eligible personal data or account-related records, subject to applicable legal, regulatory, security, and Certificate Authority retention obligations. In some cases, SSL.com may be able to delete certain records. In other cases, SSL.com may need to retain, archive, or place data beyond active use until the applicable retention period has been satisfied.What Happens When an SSL.com Account Is Deactivated?
Once an SSL.com account is deactivated:- The account can no longer be used to place orders.
- The account can no longer be used to manage certificates.
- Stored payment methods can be removed.
- Billing activity associated with the disabled account stops.
- Required account and certificate records may remain in SSL.com systems for audit, compliance, legal, or security purposes.
- Inactive account data may later be archived or purged according to SSL.com’s applicable data retention policies.
Before You Request Account Deactivation
Before contacting SSL.com Support, review the following items to avoid delays or accidental loss of access.1. Remove Stored Payment Information
If you have a saved credit card or billing profile, remove it before requesting account deactivation. To remove a stored payment method:- Log in to your SSL.com account.
- Go to Dashboard.
- Navigate to Manage Billing Profiles.
- Locate the saved payment method.
- Select Delete.
2. Review Active Certificates
Before requesting deactivation, check whether the account contains certificates you still need to manage. Do not request account deactivation if you still need to:- Download, reissue, renew, revoke, or manage active certificates.
- Access validation records.
- Manage certificate contacts or order details.
- Maintain access for your organization’s IT or security team.
3. Confirm the Correct Account
If you created multiple SSL.com accounts, confirm which account should be deactivated. This is especially important if one account is still in use and another account is a duplicate. Providing the correct email address helps SSL.com Support prevent accidental deactivation of the wrong account.How to Request Account Deactivation or Data Deletion
If you want to submit a data deletion request or another data subject rights request, email privacy@ssl.com or support@ssl.com and clearly state that you are requesting deletion of your personal data. You can also reach our privacy team through the live chat on ssl.com. To protect your account, SSL.com will need to verify your identity before processing the request. You will be asked to provide two of the following:- The email address associated with your SSL.com account.
- Your SSL.com Account ID.
- An Order ID for a certificate purchased through the account.
How SSL.com Reviews Account Deactivation and Data Deletion Requests
SSL.com generally reviews data deletion requests using the following process.Phase 1: Request Received
SSL.com receives your privacy or data deletion request and routes it to the appropriate team for review.Phase 2: Acknowledgment
SSL.com acknowledges the request and provides next steps. You may be asked to wait for further instructions before sending additional details.Phase 3: Identity Verification
SSL.com verifies that the requester is authorized to act on the account. This protects customer accounts, certificates, billing records, and validation data from unauthorized changes.Phase 4: Certificate and Account Review
SSL.com reviews the account to determine whether it contains:- Active certificates.
- Recently expired certificates.
- Recently revoked certificates.
- Validation records subject to retention requirements.
- Billing, support, or legal records that may need to be retained.
Phase 5: Eligible Data Processing
For data that is eligible for deletion, SSL.com processes the request according to applicable privacy, security, legal, and compliance requirements.Phase 6: Retained or Archived Data Review
If some data cannot yet be deleted, SSL.com may retain it in accordance with applicable CA, legal, security, or audit obligations. Where appropriate, data may be removed from public-facing systems and placed into protected internal systems until retention obligations have been fulfilled.Phase 7: Completion Notification
After the review is complete, SSL.com will notify you of the outcome. The response may explain:- What data was deleted.
- What data, if any, had to be retained.
- Why retained data could not be deleted immediately.
- Whether retained data has been archived or placed beyond active use.
- How to contact SSL.com with additional questions.
Why a Data Deletion Request May Not Be Completed Immediately
SSL.com may be unable to immediately complete a full deletion request if the account contains active certificates or certificate records that remain subject to retention requirements. This may include records related to:- Certificate orders.
- Certificate validation.
- Identity verification.
- Domain, organization, or individual validation.
- Certificate issuance.
- Certificate revocation.
- Certificate expiration.
- Audit logs.
- Security events.
- Support or transaction history.
Deactivating a Duplicate SSL.com Account
If you accidentally created a second SSL.com account, you can request deactivation of the duplicate account while keeping your primary account active. When contacting SSL.com Support, provide:- The email address of the duplicate account.
- Confirmation that this is the account you want deactivated.
- Confirmation that the duplicate account does not contain certificates, subscriptions, or records you still need.
- The email address of your primary account, if helpful for clarification.