Corporate Policy

Data Retention & Deletion Policy

How long RW Business Services keeps data, when and how it is deleted, and how deletion is carried out at Plaid and in RWBS OS.

Purpose & principles

Retain data only as long as there is a legitimate business or legal need, then delete it. Minimize what we collect — only what is required to deliver the service, as authorized. This policy governs End User Financial Data obtained via Plaid and the derived accounting records in RWBS OS.

Retention schedule

Data Retention Rationale
Plaid access tokens / item IDs (encrypted) Only while the bank connection is active. Deleted immediately on disconnect, account closure, or verified deletion request. Credentials and secrets — no reason to keep past the active connection.
Bank transactions, balances, statements, receipts (books of record) Kept as part of the accounting records for as long as required by tax and accounting law (generally up to 7 years), then deleted; deleted sooner on a valid request where no legal hold applies. Bookkeeping and tax substantiation.
Audit log Retained for a defined security and compliance window (currently 2 years), immutable. Security investigations and integrity.
CRM records (companies, contacts, deals, activities) Business relationship lifecycle; removed on request where no legal need remains. Separate from Plaid data.

Deletion triggers

  • Disconnect a bank (user action) — immediate token deletion plus Plaid-side deletion.
  • Account or relationship closure, or customer off-boarding (multi-tenant) — export if requested, then delete that party's data subject to legal holds.
  • Verified deletion request — honored per applicable privacy law, subject to records we are legally required to retain; we delete everything not under a retention obligation.
  • Vendor or subprocessor change — deprovision and delete as appropriate.

How deletion works

  1. At Plaid: call /item/remove for the connection — this removes the Item and triggers Plaid's deletion of the associated End User Data on their side.
  2. In RWBS OS: delete the encrypted access_token and the bank_connection / bank_account rows for that Item; purge or anonymize the associated bank_transactions that are not part of a legally-required accounting record; delete linked Drive documents when the record is deleted.
  3. Confirm & log: record the deletion in the audit log, without storing the deleted secrets.
  4. Rotation on exposure: if a token is suspected exposed rather than being deleted for retention, invalidate via /item/access_token/invalidate and rotate FINANCE_ENCRYPTION_KEY.

Retention versus deletion

Some accounting records must be retained for tax and audit purposes even if a deletion is requested. We resolve this by separating:

  • Live Plaid connection secrets — always deleted on disconnect, never subject to a retention hold;
  • Already-posted accounting records — retained only for the minimum legally-required period, de-linked from any live Plaid connection, then deleted.

We delete everything not covered by a specific legal retention obligation, and we tell requesters what (if anything) we must keep and for how long.

Multi-tenant note

When RWBS OS is offered to external customers, each customer owns their data. On off-boarding we provide an export and delete that tenant's data, subject to legal holds, enforced by per-tenant isolation (org_id plus Postgres row-level security).

Review

The Owner reviews this policy and the retention schedule at least annually, and after any change in applicable law or in the service.

ContactRW Business Services, LLC
security@rw-businessservices.com
South Lake Tahoe, California 96150
RW Business Services, LLCData Retention & Deletion PolicyVersion 1.0 · Effective July 30, 2026