Data Retention and Disposal Policy

Effective: August 28, 2026 · Last reviewed: August 28, 2026 · Applies to services offered through ezcstore-us.com and related ezCstore Accounting systems. This policy supplements our Privacy Policy.

1. Purpose

This policy describes how long ezCstore Accounting (“ezCstore,” “we,” “us”) keeps personal information and business data, including bank connection data received through Plaid, and how that data is disposed of when it is no longer needed. We retain data only as long as required to operate the Services, meet legal, tax, and accounting obligations, resolve disputes, and enforce our agreements.

2. Scope and owner

This policy applies to production systems that store customer, employee-user, and financial data (application database, application logs, and related backups). The security owner is responsible for this policy and for reviewing it at least annually, or after a material change to products, vendors, or law.

3. Retention schedule

Default periods below apply unless a longer period is required by law, a customer contract, or a legal hold. “Active account” means the company still has a subscription, trial, or login access to the Services.

  • Account and profile data (name, email, phone, roles): kept while the user or company account is active, then up to 12 months after closure unless a deletion request is fulfilled sooner or a legal hold applies.
  • Bookkeeping and operational records (transactions, sales, purchases, reports, imported bank-feed lines used as accounting records): kept while the account is active and for 7 years after the relevant records are created or the account is closed, whichever supports tax and accounting obligations in the United States. Customers may export or request earlier deletion of data we are not required to keep.
  • Plaid connection tokens (access tokens, item IDs, sync cursors): kept only while the bank remains linked. Unlinking a bank in Settings → Bank removes the local token and requests Plaid to remove the Item so we stop receiving new transactions.
  • Bank connection data from Plaid (account identifiers, balances, transaction history already written to the bank feed): treated as bookkeeping records under the 7-year schedule above unless the customer requests deletion and no legal hold or tax-retention duty applies. Unlinking does not by itself erase historical feed rows, so existing reconciliations stay intact.
  • Integration credentials (for example Modisoft): kept only while the integration is enabled; removed or rotated when the integration is disconnected.
  • Support communications: kept as needed to resolve the request, then up to 24 months unless tied to an active dispute or legal hold.
  • Technical logs (IP, device, diagnostics): typically up to 12 months, or shorter if the hosting provider’s default log retention is less, unless needed for security investigation.
  • Backups: encrypted backups of the production database follow our cloud provider’s backup rotation (generally 30 days or less) and then expire. Deleted live data may remain in an encrypted backup until that backup ages out.

4. Disposal

When data reaches the end of its retention period or a valid deletion request is approved:

  • Production records are deleted or irreversibly de-identified in the application database.
  • Plaid Items are removed via Plaid’s Item-remove process when a user unlinks, so Plaid stops delivering new data to us.
  • Access that is no longer required (user accounts, API tokens, vendor keys) is revoked.
  • Paper copies, if any, are shredded or securely destroyed. We do not keep consumer bank data on removable media as a normal practice.

Disposal is not delayed for convenience. It may be delayed only for a documented legal hold, an unresolved security investigation, or a retention duty we cannot waive.

5. Customer and consumer requests

Users may unlink a bank in the product at any time. Users may request access, correction, or deletion of personal information and bank connection data we store through the support channels on Help. We will verify the requester’s identity and authority (for company data, an authorized administrator) before acting. We will complete valid deletion requests without undue delay, except where we must retain records for law, tax, accounting, or dispute resolution. Data held only by Plaid must be requested from Plaid (for example via my.plaid.com); unlinking or deleting in Plaid Portal does not automatically erase copies already in ezCstore.

6. Legal holds

If we reasonably believe data is needed for litigation, a government inquiry, or a security incident, we will suspend ordinary deletion for the affected records until the hold is released. Holds are limited in scope and documented.

7. Vendors

Hosting, database, and Plaid process data as service providers for the purposes described in our Privacy Policy. We do not sell retained data. When a vendor relationship ends, we require return or deletion of our customer data except for copies the vendor must keep by law.

8. Review

This policy is reviewed at least annually and when we add or change products that handle consumer financial data (including Plaid). The “Last reviewed” date on this page will be updated after each review.