KeyZup Data Retention & Deletion Policy
| Field | Value |
|---|---|
| Version | 1.0.0 |
| Audience | Internal (privacy/engineering/operations) and, in summary form, KeyZup users |
| Effective date | August 8, 2026 |
| Acceptance method | Internal governance document; user-facing summary reflected in the Privacy Policy |
| Change notice | Reviewed periodically; changes tracked by version |
| Governing law | the laws of the state in which KeyZup is organized, without regard to its conflict-of-laws principles |
1. Purpose and principles
This policy sets how long KeyZup retains categories of personal information and how deletion is handled. It reflects a data-minimization posture: collect what is needed, keep it only as long as needed, and delete or de-identify thereafter — subject to legal, accounting, fraud-prevention, and safety exceptions.
2. Retention schedule
| Category | Retention | Basis |
|---|---|---|
| Account data (profile, credentials, contact) | As long as necessary for the stated purpose and as required by law (life of account plus a wind-down window) | Provide the service; account recovery; security |
| Jobs (service requests, details, status) | As long as necessary for the stated purpose and as required by law | Service records; dispute resolution; safety |
| Messages | As long as necessary for the stated purpose and as required by law | Communication history; dispute/abuse investigation |
| Images (message images) | As long as necessary for the stated purpose and as required by law | Job evidence; dispute resolution |
| Portfolio | As long as necessary for the stated purpose and as required by law — while published + removal window | Provider-published content; removed on request/unpublish |
| Verification documents (identity, licence, insurance, business) | As long as necessary for the stated purpose and as required by law | Trust & safety; point-in-time verification proof |
| Expired / rejected documents | As long as necessary for the stated purpose and as required by law (short window, then purge) | Minimize retention of non-current or unaccepted docs |
| Background status / reference | As long as necessary for the stated purpose and as required by law | Eligibility signal; status/reference only — no report contents stored |
| Financial ledger (wallet, fees, subscriptions) | As long as necessary for the stated purpose and as required by law — likely extended statutory period | Accounting, tax, and financial-recordkeeping obligations |
| Stripe references (token/card summary) | As long as necessary for the stated purpose and as required by law | Billing continuity; reconciliation; no full card numbers stored |
| Admin audit logs | As long as necessary for the stated purpose and as required by law | Security, accountability, compliance |
| Incidents | As long as necessary for the stated purpose and as required by law | Safety investigations; legal defense |
| Support tickets | As long as necessary for the stated purpose and as required by law | Service continuity; quality; dispute history |
| Logs / backups | As long as necessary for the stated purpose and as required by law (short log TTL; backups on a rolling cycle) | Reliability, security; backups expire on their own cycle |
3. Account deletion flow
The account deletion flow is as follows:
- Request intake — user initiates deletion in-app or via privacy@keyzup.com; identity/authority verified.
- Eligibility and holds check — confirm no active jobs, open disputes, outstanding balances, or legal holds that require retention.
- Deletion / de-identification — remove or de-identify personal information not subject to a retention exception; disable authentication.
- Retained-data notice — inform the user which categories are retained and why (e.g., financial ledger, fraud/safety, legal hold).
- Vendor propagation — trigger deletion requests to processors where applicable (Section 5).
- Confirmation and record — log the action in admin audit logs; record completion.
Public content such as reviews and published portfolio items may be handled distinctly (removal, attribution changes, or retention) in accordance with this policy and applicable law.
4. Litigation / legal hold
When litigation, investigation, or a regulatory request is reasonably anticipated or active, affected data is placed on legal hold and is exempt from routine deletion and expiry until the hold is released. Hold scope, custodians, and release are managed under KeyZup's legal-hold procedures. A legal hold overrides the schedule in Section 2 and any pending deletion request.
5. Vendor deletion
Where personal information is held by processors, deletion requests are propagated as applicable:
- Firebase / Google — delete relevant Firestore records, Storage objects (including verification documents), and auth records; account for backup expiry cycles.
- Stripe — handle customer/payment-method objects per Stripe capabilities and any financial-record retention obligations.
- Background-screening provider (a service provider) — KeyZup holds only status/reference; report contents are held (if at all) by the provider under its own retention terms.
- Other processors (analytics, support, push) — propagate deletion where supported.
Vendor-side backups and legally required retention may persist beyond KeyZup's primary deletion; those timelines depend on each processor's own retention cycles.
6. Privacy minimization
- Store the minimum necessary: card summary/Stripe token (never full card numbers); background status/reference (never report contents).
- Verification documents restricted to owner/admin access in Firebase Storage; admin access via short-lived signed URLs; no public access.
- Purge expired/rejected documents on a short cycle.
- Keep log retention short and let backups expire on a rolling cycle.
- Prefer de-identification over indefinite retention where a record must persist for aggregate/statistical purposes.
7. Implementation
Retention and deletion are carried out through KeyZup's operational systems and controls in accordance with the standards set out in this policy.
