Data Retention and Disposal Policy

Data Retention and Disposal Policy · Version 1.0 · Effective 4 September 2026 · themassis.com

Customer financial information is not kept longer than needed, is not kept in backups after it is deleted from production, and is not “soft-deleted” in a recoverable form unless a closed-list legal hold applies. This policy satisfies FTC Safeguards Rule disposal expectations, Plaid MSA proper disposal of End User Data, NIST SP 800-88 sanitization, and ordinary US books-and-records practice. Diligence copy: data-retention-and-disposal-policy.pdf.

1. Purpose

themassis retains information only to provide reconciliation, keep a reconstructable audit trail of posting, bill, secure the service, and meet law. When the purpose ends, we dispose of the information so it cannot be read or reconstructed by an unauthorized person. If a class is not listed, the default is: do not collect; if already collected, delete within 30 days of discovery unless a legal hold applies.

2. Scope

Production, staging, laptops, tickets, email, exports, logs, backups, and subprocessors. Covers Plaid End User Data, Shopify payouts, QuickBooks tokens and workpapers, account data, and operational logs. Copies inside Shopify or QuickBooks remain the customer's; disconnecting themassis does not wipe Intuit or Shopify.

3. Principles (no loopholes)

4. Roles

The Qualified Individual owns this policy. Engineering implements deletion, token revocation, and backup expiry. Support accepts requests at privacy@themassis.com and authenticates the requester.

5. Retention schedule

Where two periods could apply, the shorter applies unless Section 8 requires a keep. Storage is in the United States unless the Privacy Policy states otherwise.

Data classTrigger / periodDisposal
Bank / card login credentials, OTP, institution cookiesNever collectedIf inadvertently received, delete within 24 hours and notify security@themassis.com
Plaid access_token, item_id, selected account idsWhile connected; 24 hours after disconnect, deletion, or irreparable item errorPlaid item/remove, then delete encrypted token fields. Never log the token.
Plaid transactions used to match deposits90 days after match or disconnect, whichever first; unmatched max 12 monthsDelete primary; backups ≤ 90 days
Shopify and QBO OAuth tokensWhile connected; 24 hours after disconnect or deletionRevoke at provider where possible; delete encrypted fields
Account email, name, role, password hash, store domainAccount lifetime; 30 days after verified erasure or closure except Section 8Delete user and sessions. Hashes are not recovered.
Payouts, components, mappings, draft/posted journals, exceptionsAccount lifetime; after closure 7 years unless earlier erasure and no holdSecure delete. Posted entries already in QBO stay in the customer's company.
Audit log of approve / reject / post / connect / disconnect7 years from the event, including after closureSecure delete at 7 years unless a hold. Not used for marketing.
Sessions, CSRF, reset tokens, OAuth stateUntil expiry; expired rows deleted on sight and dailyDelete. Used reset tokens gone within 7 days.
Server and security logs90 days; incident logs 3 yearsRotation and overwrite. Secrets filtered before write.
Support email and chat3 years from last message, or 30 days after erasure if requested and no holdDelete copies we control. Do not paste tokens into tickets.
Stripe billing identifiers and invoices7 years after last invoice (tax). Cards not stored by themassis.Delete our copies; Stripe keeps what it must.
BackupsRolling 30-day backup files; production deletions purged from backups within 90 daysEncrypted; expired media overwritten or cryptographically erased

6. Plaid End User Data

Retained only while needed to provide the bank-match you asked for, to debug that match, or to meet a Section 8 hold — not to enrich a profile, sell insights, or train models. On disconnect we revoke the item at Plaid and delete our copies on the 24-hour clock. If Plaid invalidates an item, we delete our token even if you have not clicked disconnect. End User Data is not stored in analytics, error trackers, or support desks unless redacted. Accidental debug captures are purged within 24 hours.

7. How we dispose (NIST 800-88 aligned)

8. Legal holds — closed list

We may retain a specified record past its schedule only if one of the following applies. The hold is documented (what, why, owner, review date) and released when the reason ends.

A hold is not a license to keep Plaid access tokens live. Historical rows may be preserved while live access is still revoked, unless the hold is exceptional and customer-directed.

9. Deletion, disconnect, closure

Disconnect Shopify, QuickBooks, or Plaid in the product or by writing to support@themassis.com or privacy@themassis.com. Tokens are revoked and deleted within 24 hours; new collection stops. Historical workpapers remain on the 7-year clock unless you also request erasure.

A verified erasure request deletes account data, tokens, Plaid payloads, and support threads we control, subject to Section 8. We confirm or explain any keep within 30 days of verification. You do not need to call or buy a plan to exercise deletion. We will not reactivate a Plaid item without a new Link session and your intent.

10. Exports

Files you download are your records. themassis cannot dispose of files on your disk. Accountants should handle exports under the merchant's own retention program.

11. Verification

Deletion jobs are logged (tenant, class, time, actor). The Qualified Individual reviews a sample of disconnects and erasure requests at least quarterly. Failures are incidents. Partners with a contractual audit right may review this policy and, under NDA, evidence of a sample deletion.

12. Review and contact

Reviewed at least annually and after material change. Requests: privacy@themassis.com. Incidents: security@themassis.com. themassis · themassis.com