Data Retention Policy
Version 1.0
Last Updated: July 19, 2026
Purpose
This Data Retention Policy describes how SetRoasFlow retains, deletes and anonymizes information processed through the Services.
Retention periods are designed to balance operational requirements, legal obligations, security considerations and data minimization principles.
Where the Merchant controls the retention of Merchant Customer Data, SetRoasFlow acts according to the Merchant's documented instructions.
Retention Principles
SetRoasFlow follows these principles:
- retain data only as long as necessary;
- minimize stored personal data;
- support Merchant-controlled deletion where available;
- securely delete or anonymize data when no longer required;
- retain operational records only for legitimate business or legal purposes.
Standard Retention Periods
| Data Category | Default Retention |
|---|---|
| Merchant Account Information | Until account deletion, plus legally required retention periods |
| Authentication Records | As necessary for account security |
| Customer Profiles | Until deleted by the Merchant or account termination |
| Events | According to Merchant configuration where supported |
| Identity Resolution Records | Until no longer required to maintain Customer Profiles |
| Operational Logs | Limited retention based on operational and security requirements |
| Security Logs | Retained only as long as necessary for security investigations |
| Backup Data | Automatically rotated according to infrastructure policies |
| Warehouse Export Queue | Until delivered to the Merchant's destination, then 3 days |
| Warehouse Export History | 30 days (batch outcome records: destination, row count, status) |
Account Deletion
Upon account termination, SetRoasFlow will initiate deletion or anonymization of Merchant Customer Data within a commercially reasonable period unless retention is required by:
- applicable law;
- ongoing disputes;
- fraud prevention;
- security investigations;
- backup restoration cycles.
Backups
Backups are maintained exclusively for disaster recovery and business continuity.
Where deletion from active systems occurs, corresponding backup copies will expire according to the normal backup rotation schedule and will not be restored except where operationally necessary.
Warehouse Export
Where a Merchant enables warehouse export, event records are queued on SetRoasFlow infrastructure only for as long as needed to deliver them in batches to the Merchant's own destination.
Records are deleted three days after successful delivery. Records that cannot be delivered after repeated attempts are retained for the same period so the Merchant can investigate, then deleted.
Once delivered, retention of the exported data is determined solely by the Merchant within their own systems.
Legal Retention
Certain records, including invoices, tax documentation and security-related information, may be retained for periods required by applicable law.
Such records are retained only for the legally required purposes.
Policy Updates
This policy may be updated to reflect changes in:
- applicable law;
- infrastructure;
- product functionality;
- security requirements.
Contact
Questions regarding this policy may be directed to:
End of Data Retention Policy