Data Retention and Disposal Policy

Last updated: June 3, 2026

1. Scope

This policy applies to all consumer and business data processed by the RinseRight CRM, including data received from Plaid Inc., Google Business Profile, Stripe, Twilio, and Cloudflare R2.

2. Categories of data and retention windows

Data categoryRetentionReason
Plaid access tokensUntil user disconnectsBank API credential; revoked the moment the user disconnects.
Bank transactions imported via Plaid7 years from postingIRS retention requirement for Schedule C expense substantiation.
OAuth tokens (Google Business Profile)Until user disconnectsRevoked on disconnect.
Customer PII (name, address, phone, email)Life of business + 3 yrsActive customer relationship; tax/legal records.
Invoice + payment records7 yearsIRS retention requirement.
SMS conversations7 yearsA2P 10DLC compliance + dispute records.
Audit logs2 yearsOperational security review.
Receipt photos (Cloudflare R2)7 yearsTax substantiation requirement.
Employee/contractor records7 years after terminationTax and labor-law retention.
Session cookies / login state30 days maxRe-authentication enforced.

3. Triggers for deletion

Data is irreversibly deleted upon any of the following events:

4. Method of disposal

5. Special handling for Plaid-sourced data

6. Policy review

This policy is reviewed at least annually by the business owner and updated as data-handling practices change. Material changes are reflected in the “Last updated” date above.

7. Contact

Questions about this policy, requests to access or delete your data, or compliance inquiries: cameron@rinserightservices.com.

See also: our Information Security Policy, Privacy Policy, and SMS Terms & Conditions.