Data Retention and Disposal Policy
Customer financial information is not kept longer than needed, is not kept in backups after it is deleted from production, and is not “soft-deleted” in a recoverable form unless a closed-list legal hold applies. This policy satisfies FTC Safeguards Rule disposal expectations, Plaid MSA proper disposal of End User Data, NIST SP 800-88 sanitization, and ordinary US books-and-records practice. Diligence copy: data-retention-and-disposal-policy.pdf.
1. Purpose
themassis retains information only to provide reconciliation, keep a reconstructable audit trail of posting, bill, secure the service, and meet law. When the purpose ends, we dispose of the information so it cannot be read or reconstructed by an unauthorized person. If a class is not listed, the default is: do not collect; if already collected, delete within 30 days of discovery unless a legal hold applies.
2. Scope
Production, staging, laptops, tickets, email, exports, logs, backups, and subprocessors. Covers Plaid End User Data, Shopify payouts, QuickBooks tokens and workpapers, account data, and operational logs. Copies inside Shopify or QuickBooks remain the customer's; disconnecting themassis does not wipe Intuit or Shopify.
3. Principles (no loopholes)
- Purpose limitation. No “might be useful later” or unspecified analytics.
- Minimization. Least data that will match a payout, draft a balanced journal, and operate the account.
- No bank credentials. Usernames, passwords, PINs, and MFA codes are never stored, so they have no retention period.
- Closed-list exceptions only (Section 8). No implied exception for research or model training.
- Deletion means disposal. A status flag with recoverable ciphertext is not disposal.
- Backups follow production. Primary deletion starts a backup-expiry clock of not more than 90 days.
- Tokens die with the connection. Disconnect or closure revokes and deletes secrets within 24 hours.
- Legal holds freeze specified records; they do not authorize new collection.
- Erasure requests are honored except where Section 8 requires a keep. Refusals are explained in writing.
- Anonymization is not a bypass for End User Data reuse.
4. Roles
The Qualified Individual owns this policy. Engineering implements deletion, token revocation, and backup expiry. Support accepts requests at privacy@themassis.com and authenticates the requester.
5. Retention schedule
Where two periods could apply, the shorter applies unless Section 8 requires a keep. Storage is in the United States unless the Privacy Policy states otherwise.
| Data class | Trigger / period | Disposal |
|---|---|---|
| Bank / card login credentials, OTP, institution cookies | Never collected | If inadvertently received, delete within 24 hours and notify security@themassis.com |
| Plaid access_token, item_id, selected account ids | While connected; 24 hours after disconnect, deletion, or irreparable item error | Plaid item/remove, then delete encrypted token fields. Never log the token. |
| Plaid transactions used to match deposits | 90 days after match or disconnect, whichever first; unmatched max 12 months | Delete primary; backups ≤ 90 days |
| Shopify and QBO OAuth tokens | While connected; 24 hours after disconnect or deletion | Revoke at provider where possible; delete encrypted fields |
| Account email, name, role, password hash, store domain | Account lifetime; 30 days after verified erasure or closure except Section 8 | Delete user and sessions. Hashes are not recovered. |
| Payouts, components, mappings, draft/posted journals, exceptions | Account lifetime; after closure 7 years unless earlier erasure and no hold | Secure delete. Posted entries already in QBO stay in the customer's company. |
| Audit log of approve / reject / post / connect / disconnect | 7 years from the event, including after closure | Secure delete at 7 years unless a hold. Not used for marketing. |
| Sessions, CSRF, reset tokens, OAuth state | Until expiry; expired rows deleted on sight and daily | Delete. Used reset tokens gone within 7 days. |
| Server and security logs | 90 days; incident logs 3 years | Rotation and overwrite. Secrets filtered before write. |
| Support email and chat | 3 years from last message, or 30 days after erasure if requested and no hold | Delete copies we control. Do not paste tokens into tickets. |
| Stripe billing identifiers and invoices | 7 years after last invoice (tax). Cards not stored by themassis. | Delete our copies; Stripe keeps what it must. |
| Backups | Rolling 30-day backup files; production deletions purged from backups within 90 days | Encrypted; expired media overwritten or cryptographically erased |
6. Plaid End User Data
Retained only while needed to provide the bank-match you asked for, to debug that match, or to meet a Section 8 hold — not to enrich a profile, sell insights, or train models. On disconnect we revoke the item at Plaid and delete our copies on the 24-hour clock. If Plaid invalidates an item, we delete our token even if you have not clicked disconnect. End User Data is not stored in analytics, error trackers, or support desks unless redacted. Accidental debug captures are purged within 24 hours.
7. How we dispose (NIST 800-88 aligned)
- Database: hard delete of the record, including encrypted token columns. Soft-delete flags are not used for tokens or End User Data.
- Object storage: overwrite or provider secure delete; versioning that would resurrect token objects is included in the 90-day expiry.
- Keys: rotated so old Restricted ciphertext cannot be read where crypto-shredding is the designed control.
- Backups: time-expire. Disaster-recovery restore is followed by re-application of outstanding deletion requests.
- Laptops: full-disk encryption in use; cryptographic erase or destruction on retirement. Lost devices are incidents.
- Paper: cross-cut shred. Vendors must return or destroy data at end of service, with written confirmation on request.
8. Legal holds — closed list
We may retain a specified record past its schedule only if one of the following applies. The hold is documented (what, why, owner, review date) and released when the reason ends.
- A statute, regulation, or court order requires it.
- Reasonable anticipation of litigation, regulatory inquiry, or a dispute about a posted journal — limited to relevant records.
- Investigation of fraud, a security incident, or abuse — limited to what the investigation and notice need.
- Enforcing our Terms or collecting amounts owed — billing and identity records only.
- Your active written request that we preserve a copy (for example your CPA asked for a seven-year archive).
A hold is not a license to keep Plaid access tokens live. Historical rows may be preserved while live access is still revoked, unless the hold is exceptional and customer-directed.
9. Deletion, disconnect, closure
Disconnect Shopify, QuickBooks, or Plaid in the product or by writing to support@themassis.com or privacy@themassis.com. Tokens are revoked and deleted within 24 hours; new collection stops. Historical workpapers remain on the 7-year clock unless you also request erasure.
A verified erasure request deletes account data, tokens, Plaid payloads, and support threads we control, subject to Section 8. We confirm or explain any keep within 30 days of verification. You do not need to call or buy a plan to exercise deletion. We will not reactivate a Plaid item without a new Link session and your intent.
10. Exports
Files you download are your records. themassis cannot dispose of files on your disk. Accountants should handle exports under the merchant's own retention program.
11. Verification
Deletion jobs are logged (tenant, class, time, actor). The Qualified Individual reviews a sample of disconnects and erasure requests at least quarterly. Failures are incidents. Partners with a contractual audit right may review this policy and, under NDA, evidence of a sample deletion.
12. Review and contact
Reviewed at least annually and after material change. Requests: privacy@themassis.com. Incidents: security@themassis.com. themassis · themassis.com
themassis