Cancelled = subscription ended, but the subsite still exists and data is retained for 30 days. User can resubscribe to reactivate.
Deactivated = tenant flag set, login blocked at the subsite, but database rows still present. Triggered automatically by customer.subscription.deleted.
Deleted = manual super-admin action. Run after the 30-day grace period for non-resubscribed accounts. Use Network Admin → Sites → Delete.
Never delete a tenant without confirming the customer is past the grace period and has been emailed.
