exactly - under GDPR it would be fine to retain specific data for a limited period of time to prevent fraud (which is what this is, really).
Also, this type of user is not making deletion requests - they are deleting and then immediately reinstalling the app to appear "fresh".