| Bookkeeping records: transactions, categories, splits, rules, chart of accounts, reports | Life of the account, then 30 days after account closure unless the customer asks for immediate deletion | The customer needs their books available, and tax records commonly must be reproducible for prior years. |
| Uploaded statements, CSV imports, and receipt images | Life of the account, deletable by the customer at any time | Supporting documentation for entries the customer has posted. |
| Financial account data from an aggregator: transactions, balances, account ownership | Deleted with the connection, immediately on disconnect | Access ends when the customer withdraws permission. |
| Aggregator access tokens | Deleted immediately on disconnect or account closure | A token has no purpose once the connection ends, and holding one is a standing risk. |
| Account and profile records: name, work email, role, workspace membership | Life of the account, then 30 days | Needed to operate access control, and briefly afterward to complete offboarding. |
| Authentication records: password hashes, passkey public keys, factor enrollments | Deleted with the account | No purpose once the login is removed. Passwords are stored only as salted hashes and are never recoverable. |
| Security and access logs: sign-ins, failures, administrative actions | 12 months | Investigation, incident response, and access review evidence. |
| Application error and performance logs | 90 days | Debugging and reliability. Scrubbed of financial detail. |
| Cookie-free site analytics: page path, timestamp, referrer domain, device type, daily-rotating anonymous hash | 25 months, aggregated monthly | Year-over-year traffic comparison. No cookies, no IP storage, no personal data. |
| Quote requests and sales inquiries | 24 months from last contact, or immediately on request | Following up on an active inquiry, and honoring opt-outs. |
| Email delivery records and marketing suppression list | Delivery records 12 months; suppression entries retained indefinitely | Deliverability troubleshooting, and a permanent record so an unsubscribed address is never emailed again. |
| Security program evidence: risk register, access reviews, policy acknowledgments, incident records | 3 years minimum | Governance and diligence evidence. |
| Encrypted database backups | Rolling 30 days, then automatically expired | Recovery from failure or error, without becoming a shadow archive. |
| Contracts, invoices, and accounting records of the business itself | 7 years | Tax and corporate recordkeeping obligations. |