Data Retention Policy
- Version
- 1.1
- Effective
- July 28, 2026
- Last updated
- September 2, 2026
1. Principles
TraIDCred practices data minimization: we retain personal information only as long as necessary for the purpose for which it was collected or as required by law, then delete or anonymize it. We keep the least sensitive data for the shortest defensible time, while preserving the minimal records we need to evidence agreements and verification history.
2. Retention schedule
| Data category | Retention period | Notes |
|---|---|---|
| Account & profile data | While the Account is active, and up to 12 months after closure | Then deleted or anonymized, except records under §3–§4. |
| Credential documents (licenses, COIs, W-9, OSHA, other) | While active/relevant, and up to 12 months after Account closure or replacement | Superseded or Rejected Credentials are minimized sooner (target 90 days) unless needed as evidence under §4. These windows are applied through periodic operator review rather than an automated schedule; backup copies are addressed in §3.3. You can request earlier deletion at any time (§5). |
| Sensitive Credential Data (e.g., SSN/EIN/ID numbers within a document) | Shortest period reasonably necessary; never longer than the underlying Credential | We discourage SSN submission (see Privacy Policy §2.1); any inadvertently received is access-restricted and never displayed. |
Privacy-minimal analytics (profile_view, qr_scan events) | Rolling, up to 24 months | No IP/user-agent/PII stored; salted per-day hash for dedup only. |
| Acceptance & consent records; verification history | Up to 7 years | Retained as minimal legal evidence (version, timestamp, and the limited acceptance metadata in Privacy Policy §2.3), even after Account deletion, where lawful. |
| Billing & transaction records (invoices, subscription status, Stripe customer/charge identifiers; no full card numbers) | Up to 7 years | Retained for tax, accounting, and dispute/chargeback purposes. Full card data is held by Stripe, not TraIDCred. |
| Document-access requests & access audit log (Profile Viewer name, email, optional phone and project description; grant/denial events) | Up to 24 months | Evidence of who was granted access to which document, and when. Access links themselves expire 48 hours after a grant. |
| Referral-program data (referral codes, attribution, referral events and rewards) | While the Account is active, and up to 12 months after closure | Retained to administer the program and honor earned credits; billing consequences fall under the billing row below. |
| Support & other communications | Up to 24 months | PII kept out of application logs; internal identifiers used where possible. |
| Database backups (disaster recovery) | Rolling — approximately 14 daily and 8 weekly copies, so about two months of history | Each copy is a point-in-time snapshot; older copies age out automatically as newer ones are taken. |
| Uploaded-file backups (disaster recovery) | Retained indefinitely — see §3.3 | Backup copies of uploaded documents and images are not deleted when the live file is deleted. This is a deliberate disaster-recovery design, disclosed here rather than implied away. |
3. Deletion and anonymization
3.1 On Account closure or a valid deletion request, we delete or anonymize personal information within a reasonable time and no later than the periods in §2, except for records we must retain under §4 and the backup copies described in §3.3.
3.2 Database backups. Deleted data may persist in a database backup copy until that copy ages out on the rolling cycle in §2 — approximately two months. We do not restore deleted data from backups except to meet a legal obligation or to recover from a genuine data-loss incident.
3.3 Uploaded-file backups are append-only, and we do not delete from them. ⚠️ TraIDCred maintains an off-site, encrypted backup of uploaded files (credential documents, representative photographs, business logos). That backup is append-only: when a file is deleted from our live systems, the backup copy is kept, not removed, and it is retained for as long as we operate the backup.
We do this on purpose. A file that vanishes from live storage is exactly what a backup exists to bring back — a deletion caused by a defect, a bad migration, or a mistaken click is indistinguishable, at the moment it happens, from an intended one. Treating the live system's silence as authority to erase the backup would defeat the only safeguard against those failures.
What this means for you, stated plainly:
- Deleting a document, replacing it, or closing your Account removes it from the live Services —
it stops being visible to anyone, stops being served, and stops being used.
- A copy may remain in the off-site backup indefinitely. That copy is **encrypted, private, accessible
only to TraIDCred operations personnel, and used only to restore the Services after data loss.** It is never served to any user, never published, and never used for any other purpose.
- If you need a backup copy destroyed rather than only removed from the live Services, contact
privacy@traidcred.com and tell us so; we will handle the request individually.
🔮 Future operational policy, not current behavior: TraIDCred intends to introduce scheduled pruning of backup copies of deleted files so that this category acquires a finite retention period. That work is not implemented today, and nothing in this Policy should be read as promising it.
4. Records we retain as evidence or by law
We retain the minimum records needed to (a) evidence your acceptance of the Terms and any consents, (b) evidence verification history and enforcement decisions, and (c) comply with law, resolve disputes, and enforce our agreements. This is consistent with the Privacy Policy's retention section and the acceptance-recording design. Where a deletion right applies, this evidentiary retention relies on the legal-obligation / establish-or-defend-legal-claims exception recognized by applicable privacy laws.
5. Legal holds
If TraIDCred reasonably anticipates or becomes subject to litigation, an investigation, or a legal hold, it will suspend deletion of the relevant data until the matter is resolved.
6. Sub-processors
We seek to align sub-processor retention with this Policy through our agreements with them (see Privacy Policy §5 for the current sub-processor list). The off-site backups described in §3.3 are stored with Cloudflare (Cloudflare R2). Identity verification data held by Stripe is retained under Stripe's own practices, not this Policy — see the Identity Verification Notice for how to have it deleted. Messages you send to our published @traidcred.com addresses are delivered to mailboxes we operate on Google Workspace; the "Support & other communications" period in §2 applies to them, and they are not removed by deletion of your Account — tell us if you would like your correspondence removed as well.
7. Changes
We may update this Policy; material changes are versioned and, where appropriate, notified.