Data Retention Policy

Effective Date: January 1, 2025
Last Updated: November 15, 2025
Version: 1.0

📋 Table of Contents

  1. INTRODUCTION
  2. PURPOSE AND SCOPE
  3. GENERAL RETENTION PRINCIPLES
  4. ACCOUNT DATA
  5. TRANSACTION AND FINANCIAL DATA
  6. BANKING AND INVESTMENT DATA
  7. COMMUNICATION RECORDS
  8. ANALYTICS AND USAGE DATA
  9. SECURITY AND AUDIT LOGS
  10. AI CONVERSATION DATA
  11. PAYMENT AND TAX RECORDS
  12. SUPPORT AND CRM DATA
  13. MARKETING AND REFERRAL DATA
  14. BACKUP AND DISASTER RECOVERY
  15. LEGAL HOLDS AND EXCEPTIONS
  16. USER DELETION REQUESTS
  17. DATA SUBJECT RIGHTS REQUESTS
  18. RETENTION SCHEDULE SUMMARY
  19. COMPLIANCE AND LEGAL REQUIREMENTS
  20. CONTACT INFORMATION
  1. Introduction
  1. Purpose and Scope
  1. General Retention Principles
  1. Account Data
  1. Transaction and Financial Data
  1. Banking and Investment Data
  1. Communication Records
  1. Analytics and Usage Data
  1. Security and Audit Logs
  1. AI Conversation Data
  1. Payment and Tax Records
  1. Support and CRM Data
  1. Marketing and Referral Data
  1. Backup and Disaster Recovery
  1. Legal Holds and Exceptions
  1. User Deletion Requests
  1. Data Subject Rights Requests
  1. Retention Schedule Summary
  1. Compliance and Legal Requirements
  1. Contact Information

INTRODUCTION

INTRODUCTION

INTRODUCTION

INTRODUCTION


PURPOSE AND SCOPE

Purpose:

PURPOSE AND SCOPE

Scope:

Protect against litigation risks

All user types (active, inactive, deleted accounts)


GENERAL RETENTION PRINCIPLES

Data Minimization:

GENERAL RETENTION PRINCIPLES

  1. Service Delivery: Providing requested services to users
  1. Legal Obligations: Compliance with tax, financial, and regulatory requirements
  1. Legitimate Interests: Fraud prevention, security, dispute resolution
  1. Consent Duration: As long as consent remains valid (for consent-based processing)

Retention Criteria:

Consent Duration: As long as consent remains valid (for consent-based processing)

Automatic Deletion:

Secure Deletion:

Manual review for exceptions (legal holds, active disputes)


ACCOUNT DATA

Active Account Data:

ACCOUNT DATA

ACCOUNT DATA

ACCOUNT DATA

30-day grace period allows account recovery if closure was accidental

Account status (active, suspended, closed)


Inactive Account Data:

Account status (active, suspended, closed)

Account status (active, suspended, closed)

After Closure Notice: 90 days to respond before automatic closure and data deletion

Inactive accounts without balances are low-value and increase security risk

  1. After 24 months of inactivity (zero balance accounts):
  1. If no response after 90 days:

Deleted Account Data:

Data deleted per standard deletion schedule (30 days after closure)

Data deleted per standard deletion schedule (30 days after closure)

Data deleted per standard deletion schedule (30 days after closure)

Data subject to legal hold: Duration of hold

Fraud investigation window


TRANSACTION AND FINANCIAL DATA

Transaction History:

TRANSACTION AND FINANCIAL DATA

TRANSACTION AND FINANCIAL DATA

TRANSACTION AND FINANCIAL DATA

Legal Disputes: Statute of limitations for financial disputes

Related user account (anonymized after account deletion)


Referral Commission Records:

Personal names and contact information removed

Personal names and contact information removed

Personal names and contact information removed

Fraud detection and prevention


Subscription and Billing Records:

Commission adjustments and reversals

Commission adjustments and reversals

Commission adjustments and reversals

Refund and dispute resolution


BANKING AND INVESTMENT DATA

Bank Account Connection Data (Plaid - Coming Soon):

BANKING AND INVESTMENT DATA

BANKING AND INVESTMENT DATA

Transaction History: Imported transactions treated as user-generated data (retained until account deletion + 30 days)

Imported transactions belong to user and follow account data retention

Imported transaction data (user's financial transactions)


Investment Portfolio Data:

User-imported transactions remain until account deletion

User-imported transactions remain until account deletion

After Account Deletion: 30 days (grace period), then deletion

No legal retention requirement (not actual brokerage accounts)

Watchlists and alerts


COMMUNICATION RECORDS

Email Communications:

COMMUNICATION RECORDS

COMMUNICATION RECORDS

Support Emails: 3 years (see Support Data section)

Compliance with email regulations (CAN-SPAM, GDPR)

Open and click tracking data (if enabled)

Open and click tracking data (if enabled)


SMS Records:

Open and click tracking data (if enabled)

Open and click tracking data (if enabled)

Open and click tracking data (if enabled)

Compliance with telecommunications regulations

Carrier information

Carrier information


Push Notifications:

Carrier information

Carrier information

Carrier information

No long-term retention need

Engagement metrics (opened, dismissed)

Engagement metrics (opened, dismissed)


ANALYTICS AND USAGE DATA

Usage Analytics:

ANALYTICS AND USAGE DATA

ANALYTICS AND USAGE DATA

ANALYTICS AND USAGE DATA

GDPR Article 89 (research and statistics)

IP addresses (anonymized to city-level)

IP addresses (anonymized to city-level)

User IDs pseudonymized (not directly linked to accounts without access controls)


Cookie Data:

User IDs pseudonymized (not directly linked to accounts without access controls)

User IDs pseudonymized (not directly linked to accounts without access controls)

User IDs pseudonymized (not directly linked to accounts without access controls)

Marketing Cookies: Not currently used

Preference cookies enhance user experience


SECURITY AND AUDIT LOGS

Security Logs:

SECURITY AND AUDIT LOGS

SECURITY AND AUDIT LOGS

SECURITY AND AUDIT LOGS

Compliance audits

Suspicious activity alerts

Tamper-proof logging


Audit Logs:

Tamper-proof logging

Tamper-proof logging

Tamper-proof logging

Accountability and transparency

API access logs (admin endpoints)


AI CONVERSATION DATA

AI Assistant Conversations:

AI CONVERSATION DATA

AI CONVERSATION DATA

AI CONVERSATION DATA

Minimize sensitive data retention

User ID (for conversation threading)

Financial data is anonymized or generalized before processing

OpenAI (API requests, 30-day retention per OpenAI policy)


PAYMENT AND TAX RECORDS

Payment Method Information:

PAYMENT AND TAX RECORDS

PAYMENT AND TAX RECORDS

After Removal/Expiration: Immediate deletion from our database (Stripe retains per their policy)

Stripe is PCI DSS compliant and handles secure storage

Payment method tokens (Stripe IDs)

Payment method tokens (Stripe IDs)


Tax Reporting Records:

Payment method tokens (Stripe IDs)

Payment method tokens (Stripe IDs)

Payment method tokens (Stripe IDs)

Amended return support

Filed forms and submission confirmations

Regular security audits


Chargeback and Dispute Records:

Regular security audits

Regular security audits

Regular security audits

Risk management

Fraud investigation notes


SUPPORT AND CRM DATA

Customer Support Tickets:

SUPPORT AND CRM DATA

SUPPORT AND CRM DATA

SUPPORT AND CRM DATA

Accountability and transparency

Communication timestamps


CRM Data (Customer Relationship Management):

Communication timestamps

Communication timestamps

After Account Deletion: 90 days, then deletion

Moderate retention after account deletion for potential re-activation support

Relationship stage and status


MARKETING AND REFERRAL DATA

Referral Program Data:

MARKETING AND REFERRAL DATA

MARKETING AND REFERRAL DATA

Commission Records: 7 years (see Transaction Data section)

Tax reporting (commissions paid)

Conversion dates and status

Relationship structure retained for analytics (no personal data)


Marketing Campaign Data:

Relationship structure retained for analytics (no personal data)

Relationship structure retained for analytics (no personal data)

Opt-Out Records: Permanent (indefinite retention)

Prevent re-addition to marketing lists

Even after account deletion, opt-out status is retained


BACKUP AND DISASTER RECOVERY

Backup Retention:

BACKUP AND DISASTER RECOVERY

BACKUP AND DISASTER RECOVERY

Monthly Backups: 12 months

Compliance with backup best practices

Includes data that may have been deleted from production since backup

Maximum: 12 months for deleted data to be purged from all backups

All backups containing data are fully purged by January next year


Legal Hold Definition:

LEGAL HOLDS AND EXCEPTIONS

Legal Hold Process:

Internal investigations (fraud, policy violations)

  1. Legal or compliance team identifies need for hold
  1. Specific user accounts or data categories flagged
  1. Automated deletion processes suspended for flagged data
  1. Hold documented with reason and date
  1. Regular review to determine if hold can be lifted

Regular review to determine if hold can be lifted

Until internal investigation is complete and all appeals exhausted

Where legally permissible, users are informed of holds affecting their data


Exceptions to Deletion:

If retention period has expired during hold, immediate deletion (after brief review period)

  1. Active Legal Dispute: User is party to lawsuit or arbitration with XPlus Finance
  1. Fraud Investigation: Account is under investigation for fraud or abuse
  1. Outstanding Debt: User owes money to XPlus Finance (e.g., chargeback debt)
  1. Regulatory Request: Government or regulator has requested data preservation

Regulatory Request: Government or regulator has requested data preservation


USER DELETION REQUESTS

Right to Deletion (GDPR Article 17, CCPA):

USER DELETION REQUESTS

Deletion Request Process:

USER DELETION REQUESTS

  1. Email [email protected] with subject "Data Deletion Request"
  1. Verify identity (for security)
  1. Specify scope (full account deletion or specific data)
  1. Acknowledge understanding of consequences (account closure, data loss)

Acknowledge understanding of consequences (account closure, data loss)

OR login to account and submit deletion request via Account Settings

What Gets Deleted:

Confirmation: Email sent upon completion

Cached data and sessions

Aggregated analytics (no personal identifiers)

30-Day Grace Period:


DATA SUBJECT RIGHTS REQUESTS

GDPR and CCPA Requests:

DATA SUBJECT RIGHTS REQUESTS

Restriction Request: Limit how we process data

  1. Submit request to [email protected]
  1. Verify identity
  1. We respond within 30 days (GDPR) or 45 days (CCPA)
  1. Provide requested data or explanation if request is denied

Documentation Retention:

Provide requested data or explanation if request is denied

Purpose: Demonstrate compliance, audit trail, dispute resolution

Denial reasons (if applicable)


RETENTION SCHEDULE SUMMARY


Regulatory Framework:

COMPLIANCE AND LEGAL REQUIREMENTS

Regular Review:

State Laws: Data breach notification and retention laws


CONTACT INFORMATION

CONTACT INFORMATION

Subject Line: "Data Retention Inquiry"

Subject Line: "Data Deletion Request"

See Privacy Policy for comprehensive information

See Privacy Policy for comprehensive information

See Privacy Policy for comprehensive information

See Privacy Policy for comprehensive information


See Privacy Policy for comprehensive information

See Privacy Policy for comprehensive information

See Privacy Policy for comprehensive information


Security Policy