Data Retention & Deletion Policy

Version 1.0 · May 28, 2026 · Reviewed annually by the Privacy Officer.

1. Principles

BillSlash keeps personal data only as long as necessary for the purpose it was collected, applicable legal obligations, or legitimate business interests. Data minimization is enforced at collection time.

2. Retention windows

CategoryRetentionBasis
Account profileLife of account + 30 daysContract performance
Bills, receipts, transactionsLife of account + 30 daysContract performance
Plaid access_token / item_idUntil disconnect or account deletion (revoked via /item/remove)Contract / consent
Payment & tax records7 yearsIRS / state tax law
Security audit logs13 monthsSecurity, fraud prevention
Email delivery logs90 daysDeliverability troubleshooting
Encrypted backups90 days rollingDisaster recovery
Marketing email subscribersUntil unsubscribe + 30 daysConsent

3. Account deletion

4. Verification

We verify deletion requests using your account email. Authorized agents are accepted with signed authorization.

5. Review

This policy is reviewed at least annually and after any material change to the service or applicable law. See also our Privacy Policy and Security Overview.