Data Retention Policy
Introduction
This Data Retention Policy explains how long Automate America ("we", "us", "our") keeps the different kinds of data collected through the Automate America platform and related services, what happens to your data when you delete your account, and how to contact us about it.
Where this policy gives a time period, something we run changes or deletes the data when that period ends. Where it says we keep something and gives no period, nothing deletes that data automatically today.
For questions about data retention or to request data deletion, contact info@automateamerica.com.
1. User Account Data
What We Retain:
- Profile information (name, email, phone, address, professional details)
- Account settings and preferences
- Verification and identity documents
- Contacts you import from your address book (each contact's name and email address)
Retention Period:
- Your account: Kept until you delete it or we remove it. We do not delete accounts for inactivity, and we do not send inactivity notices.
- Account deletion requests: A deletion request starts a 30-day grace period. During the grace period your profile is hidden from our public listings and you can cancel the request from your account settings. The deletion is carried out automatically in the nightly run after the 30-day grace period ends. Section 3 describes what the deletion removes.
- Backup copies: Remain only in backup copies until those copies are deleted (see Section 10)
- After deletion — the retired-identity code: When an account deletion is carried out, we keep a one-way code (a SHA-256 hash) made from the account's email address and phone number, instead of the address and number themselves, so that they cannot be used to register again. Kept; nothing deletes these codes.
- Contacts you import: each contact's name and email address, kept until you remove it or your account is deleted. Contacts you did not choose to keep are deleted within 25 hours of the import. We do not keep your Google or Microsoft sign-in.
Legal Basis: Contract performance (GDPR Art. 6(1)(b)), legitimate interest (GDPR Art. 6(1)(f))
2. Financial Records
What We Retain:
- Contracts and work orders
- Timesheets and attendance records
- Invoices and payment records
- Tax documents (W-9, 1099 forms)
Retention Period:
- All financial records: Retained for 7 years from the date of the transaction
- Tax documents: Retained for 7 years (IRS requirement under 26 USC 6501)
- Payment method details: Tokenized through Stripe — we do not store full card numbers
Legal Basis: Legal obligation (GDPR Art. 6(1)(c)) — IRS record-keeping requirements, state tax compliance
Note: Users cannot request deletion of financial records during the 7-year retention period due to legal compliance obligations.
3. Messages and Communications
What We Retain:
- Direct messages between users
- System notifications and alerts
- Support ticket communications
Retention Period:
- Messages: Kept. Nothing deletes messages automatically.
- System notifications: Kept. Nothing deletes them automatically.
- Support tickets: Kept. Nothing deletes them automatically.
Account Deletion Behavior:
- When your account deletion is carried out, your name, email addresses, phone numbers, photos, website links and profile text are removed from your account record, and your profile is no longer shown to anyone (a one-way code of your email address and phone number is kept — Section 1).
- Messages you sent stay in the conversations of the people you sent them to. If you requested deletion from the Privacy & Data Settings page, the text of the messages you sent is also replaced with a deletion notice.
- A conversation is not deleted when both people in it have deleted their accounts.
- The contacts you imported from your address book are deleted.
- Other records connected to your account, such as notifications, activity records and work history, are not all deleted when your account is deleted (see Sections 5, 6 and 8).
Legal Basis: Contract performance (GDPR Art. 6(1)(b)), legitimate interest (GDPR Art. 6(1)(f))
4. Error and Security Logs
What We Retain:
- Error records (time, the address requested, status code, error message, and — for up to 30 days — your user ID, IP address, browser details and the request details logged with the error)
- Security records (for example sign-in attempts, password changes and suspicious activity), which can include your user ID and IP address
Retention Period:
- Error records: Deleted after 90 days. After 30 days, we remove your user ID, IP address, browser details and the request details from each error record.
- Rate limiting data: Held in server memory only, and discarded when the limit's time window ends (windows run from one minute to 24 hours). When a limit is exceeded, the refusal may be kept as a security record.
- Security records: Kept. Nothing deletes them automatically today.
Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)) — system reliability, security monitoring, fraud prevention
Right to Erasure: You may request early deletion of your error log data by contacting info@automateamerica.com. We act on a verified request without undue delay.
5. Notification Data
What We Retain:
- Notification history (type, title, message, read status, timestamps)
- Push notification subscription data (browser endpoint URL, encryption keys)
Retention Period:
- Notification history: Kept. Nothing deletes it automatically.
- Push subscriptions: Kept while the subscription is active. When a browser unsubscribes from our push notifications, we delete that browser's subscription.
Account Deletion Behavior:
- Push subscription data is not deleted by an account deletion.
- If you requested deletion from the Privacy & Data Settings page, the notifications you received are deleted when the deletion is carried out; otherwise they are kept.
Legal Basis: Contract performance (GDPR Art. 6(1)(b)), consent (GDPR Art. 6(1)(a)) for push notifications
6. Feed Engagement Data
What We Retain:
- Feed card impressions (which cards were shown to which users)
- Click events (which cards were clicked)
- Engagement signals (saves, shares, applies, time spent)
- Search queries and result interactions
Retention Period:
- Engagement data: Kept with your account. Nothing removes your user ID from it automatically today.
- Search queries: Kept with your account. Nothing anonymizes them automatically today.
Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)) — platform improvement, algorithm optimization
7. Authentication and Session Data
What We Retain:
- Sign-in tokens
- Renewal tokens, with the IP address and browser they were issued to
- Cookie consent preferences
Retention Period:
- Sign-in tokens: Last up to 30 days.
- Renewal tokens: Last up to 30 days. We store them so that they can be revoked, and we delete each one about a day after it expires.
- Cookie consent records: Your choice is kept on your device, and we ask again after 12 months. If you are signed in, the date and version of your choice are also kept with your account.
Legal Basis: Contract performance (GDPR Art. 6(1)(b))
8. Trade and Classification Data
What We Retain:
- Trade selections and specializations
- Sector classifications
- Skills and certifications
- Completed work portfolio entries
Retention Period:
- Trade/classification data: Kept while your account exists. When your account is deleted your profile is no longer shown, but these records are not all deleted (see Section 3).
- Completed work records: Retained indefinitely as part of the professional's portfolio record. Financial aspects of completed work follow the 7-year financial records retention.
- Verification status: Retained while account is active
Legal Basis: Contract performance (GDPR Art. 6(1)(b)), legitimate interest (GDPR Art. 6(1)(f))
9. Affiliate Program Data
Automate America does not operate an affiliate program, so it holds no affiliate data.
10. Backup and Archival Data
What We Retain:
- Database backups
- File system backups
Retention Period:
- Server copies: Daily database backups are kept on the server for 7 days
- Off-site copies: Backup copies are also stored with Amazon Web Services (S3)
Deletion from Backups:
When data is deleted from the live system, it remains only in backup copies until those copies are deleted; server copies are deleted after 7 days.
Legal Basis: Legitimate interest (GDPR Art. 6(1)(f)) — disaster recovery, business continuity
11. Your Rights
Right to Access: You can request a copy of all data we hold about you.
Right to Erasure: You can request deletion of your personal data, subject to legal retention requirements (e.g., 7-year financial records cannot be deleted early).
Right to Rectification: You can request correction of inaccurate personal data.
Right to Data Portability: You can request your data in a machine-readable format.
Right to Object: You can object to processing based on legitimate interest.
How to Exercise Your Rights:
- In your account: Privacy & Data Settings lets you download your data ("Export My Data") and request deletion of your account
- Email: info@automateamerica.com
- Mail: Automate America, Inc., PO BOX 1638, Greer, SC 29652
- Phone: 586-770-8083
We respond to all data requests within 30 days (45 days for complex requests, with notice).
Verification: We verify your identity before processing data requests to prevent unauthorized access.
12. Changes to This Policy
We may update this Data Retention Policy to reflect changes in our practices, legal requirements, or platform features. Each update is posted on this page with a new version number and effective date.
We encourage you to review this policy periodically.
Acknowledgment
This Data Retention Policy is part of Automate America's commitment to transparency and compliance with GDPR, CCPA, and other applicable data protection laws.
Questions? Contact info@automateamerica.com or call 586-770-8083.
Automate America, Inc.
PO BOX 1638, Greer, SC 29652
A South Carolina Corporation
