themassis.com
Data Retention and Disposal Policy
Customer financial information is not kept longer than needed, is not kept in backups after it is deleted from production, and is not “soft-deleted” in a recoverable form unless a closed-list legal hold applies. Diligence copy: data-retention-and-disposal-policy.pdf.
1. Principles (no loopholes)
- Purpose limitation. No “might be useful later.”
- Minimization. Least data that will match a payout, draft a balanced journal, and operate the account.
- No bank credentials — they are never stored, so they have no retention period.
- Closed-list exceptions only (Section 4).
- Deletion means disposal. A status flag with recoverable ciphertext is not disposal.
- Backups follow production. Primary deletion starts a backup-expiry clock of not more than 90 days.
- Tokens die with the connection (24 hours).
2. Retention schedule
| Data class | Trigger / period | Disposal |
|---|---|---|
| Bank / card login credentials | Never collected | If inadvertently received, delete within 24 hours |
| Plaid access_token, item_id | While connected; 24 hours after disconnect | Plaid item/remove, then delete encrypted fields |
| Plaid transactions used to match deposits | 90 days after match or disconnect; unmatched max 12 months | Delete primary; backups ≤ 90 days |
| Shopify and QBO OAuth tokens | While connected; 24 hours after disconnect | Revoke at provider; delete encrypted fields |
| Account profile | Account lifetime; 30 days after verified erasure except Section 4 | Delete user and sessions |
| Payouts, journals, mappings, exceptions | Account lifetime; after closure 7 years unless earlier erasure and no hold | Secure delete. Posted entries already in QBO stay in the customer’s company |
| Posting audit log | 7 years from the event | Secure delete |
| Sessions, CSRF, reset tokens | Until expiry | Delete |
| Server logs | 90 days; incident logs 3 years | Rotation and overwrite |
| Support email | 3 years, or 30 days after erasure if requested and no hold | Delete copies we control |
| Stripe billing identifiers | 7 years after last invoice. Cards not stored by themassis | Delete our copies |
| Backups | Rolling 30-day files; production deletions purged within 90 days | Encrypted; expired media overwritten or cryptographically erased |
3. Disposal
Aligned with NIST SP 800-88: hard-delete database rows including token columns; provider secure delete for objects; crypto-shred where designed; disaster-recovery restore is followed by re-application of outstanding deletion requests; paper is cross-cut shredded.
4. Legal holds — closed list
- A statute, regulation, or court order requires it.
- Reasonable anticipation of litigation, regulatory inquiry, or a dispute about a posted journal — limited to relevant records.
- Investigation of fraud, a security incident, or abuse.
- Enforcing our Terms or collecting amounts owed — billing and identity only.
- Your active written request that we preserve a copy.
A hold is not a license to keep Plaid access tokens live.
5. Deletion requests
Disconnect or write to [email protected]. Tokens are revoked and deleted within 24 hours. A verified erasure request deletes account data, tokens, Plaid payloads, and support threads we control, subject to Section 4. We confirm or explain any keep within 30 days. You do not need to call or buy a plan to exercise deletion.
6. Contact
themassis · themassis.com · [email protected] · [email protected]