Data Retention Standard
Version 2026-08-04.1 · Last updated 2026-08-04
How we apply this standard
- Keep personal information only as long as reasonably needed for its disclosed purpose or a documented legal requirement.
- Use the shortest operational period that still supports the service, security, disputes, and lawful obligations.
- Apply legal holds only to the narrowest affected records and review them on a documented schedule.
- Keep deletion receipts as counts and status metadata, never as copies of deleted content.
- Treat provider backups as temporary recovery copies that age out and are not restored to reactivate deleted accounts.
A wedding owner's deletion request starts a 30-day recoverable grace period. Narrow legal holds, fraud or safety investigations, payment disputes, and statutory duties may pause disposal only for affected records.
Retention schedule
Wedding workspace and private files
- What it covers
- Wedding, events, tasks, budgets, guests, private documents, extracted text, AI conversations, and approved proposals.
- Maximum period
- While the workspace is active, then a 30-day recoverable deletion grace period.
- Disposal
- Permanently purge in-scope relational records and private objects after the grace period unless a narrow legal hold applies.
Privacy export files
- What it covers
- Private generated export objects and their storage pointers.
- Maximum period
- 7 days after generation.
- Disposal
- Delete the private object, clear the pointer, and retain only minimized completion metadata.
Storyboard photos and virtual try-on results
- What it covers
- User-authorized fitting photo, outfit reference, generated result, event link, and minimized processing metadata.
- Maximum period
- Until the creator deletes Storyboard data or the wedding workspace is permanently purged after its grace period.
- Disposal
- Delete private profile, garment, and result objects before cascading the related metadata; provider base64 output follows its short processing window.
Wedding and partner invitations
- What it covers
- Invitation record and one-time token digest.
- Maximum period
- Delete within 30 days after expiry, acceptance, revocation, or cancellation.
- Disposal
- Permanently delete the invitation record and token digest unless held.
Support and privacy correspondence
- What it covers
- Support tickets, operational notes, and necessary attachments.
- Maximum period
- 24 months after resolution or closure.
- Disposal
- Permanently delete unless a complaint, security investigation, dispute, or legal hold remains active.
Wedding activity and operational audit records
- What it covers
- Minimized wedding activity and administrative evidence required for security or dispute handling.
- Maximum period
- 24 months, unless a shorter workspace purge or a narrow legal hold applies.
- Disposal
- Delete or irreversibly aggregate; never retain deleted content in a run receipt.
Vendor profiles and verification evidence
- What it covers
- Business profile, portfolio, verification submissions, moderation record, and complaint evidence.
- Maximum period
- While active; delist immediately on closure; retain minimized moderation and dispute evidence for up to 24 months.
- Disposal
- Remove the public listing immediately and delete non-required profile content after the operational period.
Marketplace leads, inquiries, and quotes
- What it covers
- Lead, inquiry, quote, shortlist, and booking-linked marketplace records.
- Maximum period
- Active relationship plus 24 months after closure.
- Disposal
- Delete the closed lead and cascading quote records unless held for a scoped dispute.
Billing, tax, and payment evidence
- What it covers
- Invoices, refunds, subscription events, tax evidence, and minimized payment-provider identifiers; no full card data.
- Maximum period
- 7 years after the transaction or applicable fiscal period.
- Disposal
- Delete platform copies at expiry; provider records follow the configured Stripe account policy and legal requirements.
Consent, policy acceptance, and email suppression evidence
- What it covers
- Policy version acceptance and HMAC-only email suppression records.
- Maximum period
- While relied upon plus 3 years; active delivery suppressions remain while needed to honour the opt-out or protect delivery.
- Disposal
- Delete released evidence after expiry; keep no message body or plaintext recipient in suppression rows.
Transactional email delivery records
- What it covers
- Minimized webhook receipts, delivery state, provider message identifier, and recipient digest.
- Maximum period
- 24 months after the final delivery event.
- Disposal
- Delete the receipt and webhook event; never retain the message body in the operations tables.
Product analytics
- What it covers
- Consent-gated, privacy-sanitized product events identified by internal UUID.
- Maximum period
- 12 months at identifiable event level; aggregate only thereafter.
- Disposal
- Delete identifiable event history and retain only non-identifying aggregates.
Error and security monitoring
- What it covers
- Redacted client, server, and operational error events.
- Maximum period
- 90 days.
- Disposal
- Provider expiry or earlier deletion; do not export expired event payloads into long-lived evidence.
Inactive accounts
- What it covers
- Accounts with no login or workspace activity for 24 months.
- Maximum period
- Manual review at 24 months of inactivity, with at least 30 days' notice before closure.
- Disposal
- Offer export, close the account after notice, and use the standard workspace deletion process. No automatic closure occurs without notice.
Encrypted database backups
- What it covers
- Provider-managed database recovery copies; Supabase Storage objects are not included in database backups.
- Maximum period
- Provider plan recovery window, targeted at no more than 30 days and documented before launch.
- Disposal
- Provider rotation ages the copy out. A restore must reapply post-backup deletion requests before normal service resumes.
AI provider request data
- What it covers
- The minimum wedding context and tool result needed to answer an authorized request; secrets are excluded.
- Maximum period
- Application copies follow the wedding-workspace period; provider handling must satisfy the production AI gate before real customer use.
- Disposal
- Purge application records with the workspace and rely on the approved provider's contracted retention controls.
Retention receipts and legal holds
- What it covers
- Counts-only sweep receipts and narrow legal-hold metadata.
- Maximum period
- Sweep receipts for 24 months; legal holds until release, with a scheduled review date.
- Disposal
- Delete the receipt or released hold metadata; never store deleted content or subject details in receipts.
Backups and restoration
Database backups are recovery copies, not active customer records. They age out under the configured provider recovery window. A restore runbook must reapply deletion requests made after the restore point before normal service resumes. Private Storage objects are managed separately from database backups.
Questions and requests
Use Privacy settings in RokaOS to request an export or deletion. For access, correction, retention, or complaint questions, contact privacy@rokaos.com. We may verify identity and authority before acting.