Legal · Version 2026-09-01

Data Retention Policy

This policy describes how long Promotlr keeps different records, what makes a record eligible for deletion, and which limited records may remain after an account closes.

Effective date
September 1, 2026

1. Retention principles

Promotlr keeps personal data only while it is needed to provide the service, secure it, meet a legal obligation, resolve a dispute, or establish and defend legal claims. Retention is based on record purpose, account status, plan, user controls, statutory periods, and any active investigation or legal hold. Access is restricted when a record must be preserved but is no longer needed for ordinary service delivery.

2. Current operational schedule

Record categoryNormal retention or deletion criterion
Account, profile, workspace membership, and configurationFor the active account and the seven-day confirmed-deletion grace period; then deleted or anonymized unless an exception below applies.
Active authentication sessions12 hours from creation by default. When “Remember for 30 days” is selected, up to 30 days from creation. Sessions end earlier on sign-out, password reset, security revocation, suspension, or confirmed deletion.
Email verification and recovery secretsVerification secrets expire after the short period shown in the email; password-reset secrets expire after 30 minutes. Used, locked, invalidated, and expired secrets cannot authenticate a user and may be retained briefly as abuse-prevention evidence before cleanup.
Authentication rate-limit bucketsActive window plus a short abuse-prevention period; stale buckets are eligible for deletion after 24 hours.
Forum credentials, API tokens, proxy secrets, and browser sessionsWhile the connected account or workspace needs them; revoked on removal and deleted with the owning record or confirmed account deletion, subject to a security hold.
Debug job logs and worker log events30 days. Cleanup is applied as new logs are ingested.
Standard jobs, results, usage, schedules, and activity historyWhile the workspace remains active or until an available user or administrator deletion control is used. Records required for plan enforcement, incident investigation, or a billing dispute are kept until that purpose ends.
Screenshots and other artifactsUntil the artifact retention date where one is assigned, an available manual deletion, or deletion of the owning workspace. Failure evidence may be kept while a support or security case remains open.
Email campaign recipients and delivery eventsWhile the campaign or workspace remains active. Unsubscribe, complaint, and suppression records are retained for as long as reasonably necessary to ensure the person is not contacted again and may be minimized or hashed.
Support messages and administrative audit recordsFor the support relationship and then as needed for security, accountability, and the applicable legal-claims period. Unnecessary attachments and sensitive content should be removed earlier.
Invoices, payments, refunds, payouts, and tax recordsFor the statutory accounting, tax, anti-fraud, and dispute period applicable to the service operator. These records can remain after account deletion with access restricted and unnecessary profile data removed.
Legal-document assentWhile the account exists and as needed to prove the applicable contract or notice. It is restricted to authorized staff and is not used for marketing.

3. Account deletion

A self-service deletion request requires confirmation. Once confirmed, sign-in sessions are revoked and deletion is scheduled after a seven-day grace period shown to the user. The user can cancel during that period. When the request becomes due, Promotlr’s deletion process cancels or ends service access, removes active authentication material, handles owned workspaces and dependent records, and records completion. Data that must be retained for law, fraud prevention, payment disputes, or legal claims is separated from ordinary product use and minimized.

4. Backups and distributed systems

Deletion from the live service does not always remove every encrypted backup copy immediately. Backups remain isolated, are not restored for ordinary use, and expire under the infrastructure backup rotation. If a backup is restored for disaster recovery, deletion and suppression records must be reapplied. Provider-specific backup schedules are reviewed as part of vendor management and can be requested from the legal contact where disclosure does not create a security risk.

5. Legal holds and exceptions

A record may be retained longer when required by law, a court or authority, a payment or fraud investigation, a security incident, an unresolved complaint, or the establishment, exercise, or defense of legal claims. The hold is limited to relevant data, access is restricted, and deletion resumes when the hold ends. Promotlr does not retain customer content indefinitely merely because storage is technically available.

6. Workspace responsibility

Workspace owners control much of the customer data placed into Promotlr and should delete obsolete credentials, recipients, messages, exports, and artifacts promptly. Owners must define retention appropriate to their own legal basis and inform their recipients. An account-deletion request by one member may not authorize deletion of records owned by another legal entity; ownership and transfer issues are resolved before the workspace is removed.

7. Requests

You may request deletion, restriction, or information about a retention criterion through account settings or the Contact page. Promotlr may retain a minimal record of the request and response to demonstrate compliance. Mandatory exceptions and the rights described in the Privacy Policy still apply.