Data Retention & Deletion Policy
How long RW Business Services keeps data, when and how it is deleted, and how deletion is carried out at Plaid and in RWBS OS.
Purpose & principles
Retain data only as long as there is a legitimate business or legal need, then delete it. Minimize what we collect — only what is required to deliver the service, as authorized. This policy governs End User Financial Data obtained via Plaid and the derived accounting records in RWBS OS.
Retention schedule
| Data | Retention | Rationale |
|---|---|---|
| Plaid access tokens / item IDs (encrypted) | Only while the bank connection is active. Deleted immediately on disconnect, account closure, or verified deletion request. | Credentials and secrets — no reason to keep past the active connection. |
| Bank transactions, balances, statements, receipts (books of record) | Kept as part of the accounting records for as long as required by tax and accounting law (generally up to 7 years), then deleted; deleted sooner on a valid request where no legal hold applies. | Bookkeeping and tax substantiation. |
| Audit log | Retained for a defined security and compliance window (currently 2 years), immutable. | Security investigations and integrity. |
| CRM records (companies, contacts, deals, activities) | Business relationship lifecycle; removed on request where no legal need remains. | Separate from Plaid data. |
Deletion triggers
- Disconnect a bank (user action) — immediate token deletion plus Plaid-side deletion.
- Account or relationship closure, or customer off-boarding (multi-tenant) — export if requested, then delete that party's data subject to legal holds.
- Verified deletion request — honored per applicable privacy law, subject to records we are legally required to retain; we delete everything not under a retention obligation.
- Vendor or subprocessor change — deprovision and delete as appropriate.
How deletion works
- At Plaid: call
/item/removefor the connection — this removes the Item and triggers Plaid's deletion of the associated End User Data on their side. - In RWBS OS: delete the encrypted
access_tokenand thebank_connection/bank_accountrows for that Item; purge or anonymize the associatedbank_transactionsthat are not part of a legally-required accounting record; delete linked Drive documents when the record is deleted. - Confirm & log: record the deletion in the audit log, without storing the deleted secrets.
- Rotation on exposure: if a token is suspected exposed rather than being deleted for retention, invalidate via
/item/access_token/invalidateand rotateFINANCE_ENCRYPTION_KEY.
Retention versus deletion
Some accounting records must be retained for tax and audit purposes even if a deletion is requested. We resolve this by separating:
- Live Plaid connection secrets — always deleted on disconnect, never subject to a retention hold;
- Already-posted accounting records — retained only for the minimum legally-required period, de-linked from any live Plaid connection, then deleted.
We delete everything not covered by a specific legal retention obligation, and we tell requesters what (if anything) we must keep and for how long.
Multi-tenant note
When RWBS OS is offered to external customers, each customer owns their data. On off-boarding we provide an export and delete that tenant's data, subject to legal holds, enforced by per-tenant isolation (org_id plus Postgres row-level security).
Review
The Owner reviews this policy and the retention schedule at least annually, and after any change in applicable law or in the service.
security@rw-businessservices.com
South Lake Tahoe, California 96150