Data Retention & Disposal Policy
How long BuddyWorkflow keeps each category of data, and how it is securely disposed of — including financial data accessed through Plaid and billing data processed through Stripe.
Version: 1.0Effective date: July 1, 2026Owner: Founder & Security LeadReview cadence: Annual + on change
1. Purpose & Scope
This policy defines how long BuddyWorkflow retains each category of customer and company data, and how that data is securely disposed of once it is no longer needed. It supports our commitment to data minimization: we keep data only as long as there is a clear business or legal reason to do so.
It applies to all data BuddyWorkflow stores, processes, or transmits across production and development environments, and to all personnel, contractors, and subprocessors handling that data.
2. Retention Principles
- Minimize: collect and keep only what is needed to operate the Service.
- Purpose limitation: retention periods are tied to the reason the data was collected.
- Honor deletion: customer-initiated disconnection and deletion requests are actioned promptly on defined timelines.
- Legal holds: data subject to a legal, tax, or regulatory obligation is retained for the required period before disposal.
3. Retention Schedule
Data categoryRetention periodTrigger to dispose
Financial data from Plaid (transactions, balances)While account is active; deleted within 30 days of disconnection or account deletionDisconnect, deletion request, or account closure
Plaid access tokensUntil disconnection or deletion; revoked at Plaid immediately on disconnectDisconnect or account closure
Customer-entered records (invoices, contacts, budgets, notes)While account is active; deleted within 30 days of account deletionAccount deletion request
Account & profile data (name, email)Life of the account; deleted within 30 days of closureAccount closure
Billing records (Stripe metadata, invoices)Retained up to 7 years to meet tax/accounting obligationsEnd of legal retention period
Authentication & security logsUp to 12 monthsRolling expiry
Application / server logsUp to 90 daysRolling expiry
Encrypted database backupsUp to 30 days on a rolling cycleBackup-cycle expiry
Support correspondenceUp to 24 monthsRolling expiry
Periods are defaults; a specific legal hold or regulatory requirement may extend retention for the affected records only.
4. Deletion & Disposal Procedures
- Disconnection: when a customer disconnects a linked account, we stop retrieving data and revoke the Plaid access token at Plaid immediately. Previously imported transactions follow the account-deletion timeline unless the customer also requests deletion.
- Account deletion: on a verified deletion request or account closure, financial data, customer records, and profile data are deleted from production systems within 30 days.
- Backups: data persists in encrypted backups until those backups expire on the normal rolling cycle (up to 30 days), after which it is unrecoverable. Backups are not restored to selectively resurrect deleted data.
- Method of disposal: electronic data is deleted from the managed database and object storage; cryptographic controls and provider media-sanitization practices ensure disposed data is not reconstructable. Secrets and tokens are revoked at the source provider.
- Physical media: BuddyWorkflow operates on managed cloud infrastructure and does not store customer data on local or removable media. Any decommissioned developer devices are wiped using full-disk-encryption key destruction.
5. Subprocessor Disposal
When data is deleted, we also rely on our subprocessors' deletion and retention practices: Plaid tokens are revoked and item data removed per Plaid's controls; Supabase deletes records and ages out backups; Stripe retains billing records per its own legal obligations. Subprocessor data-handling is reviewed before onboarding and periodically thereafter.
6. Exceptions & Legal Holds
Where BuddyWorkflow is legally required to retain data (e.g., tax records, response to lawful requests, or an active dispute), the affected records are placed under a legal hold and excluded from routine disposal until the obligation ends. Holds are documented and approved by the Security Lead.
7. Roles & Review
The Founder & Security Lead owns this policy, approves exceptions, and is responsible for ensuring retention periods are enforced and deletion requests are honored. This policy is reviewed at least annually and after any material change to systems, subprocessors, or legal obligations. Requests and questions: bryn@buddyworkflow.com.