Retention and deletion policy
Policy version 1.0. No indefinite retention is permitted.
Approved retention schedule
- An imported order not linked to an open dispute is retained for 30 days after its last import.
- An order linked to an open dispute is retained while the dispute is open, then for 90 days after closure.
- A dispute record is retained while open, then for 90 days after closure.
- A privacy export is available for at most 7 days or until its first successful retrieval, whichever occurs first. The current response is generated once in memory and is not retained after successful retrieval.
- Operational logs are retained for no more than 30 days.
- Content-free webhook and audit identifiers are retained for 180 days.
- A general 365-day hard cap applies unless an active dispute or documented legal obligation justifies continued retention.
Deletion paths
- sessions and tokens are deleted immediately on uninstall;
- verified customer redaction deletes matching normalized orders;
- verified shop redaction deletes the complete tenant;
- merchants can delete imported data from App Home;
- expired records are removed in bounded, idempotent purge batches.
Legal obligations
Any retention beyond the general cap must be tied to an active dispute or a documented legal obligation. When that justification ends, the applicable post-closure period resumes and the purge process removes the record.