Data Retention and Disposal Policy
Last updated: September 27, 2026
1. Purpose and scope
This policy defines how long Filebox Bookkeeping LLC keeps client and consumer data, when that data is deleted, and how deletion is performed. It covers bookkeeping records, documents uploaded to the receipt inbox, transaction data received through bank integrations such as Plaid, website inquiries, and backup copies of any of the above.
2. Retention periods
Client bookkeeping records are retained for the duration of the client relationship and for seven years after the relationship ends, matching standard business recordkeeping obligations, then deleted. Website inquiries and leads are retained while relevant to providing service, up to twelve months. Transaction data received through bank integrations is stored only as long as needed to perform the bookkeeping and is included in the same seven-year client retention window.
3. Bank integration data
Bank data is received read-only through client-approved integrations. When a client relationship ends or a bank connection is removed, the access token for that connection is revoked immediately, and stored transaction data follows the client retention window above.
4. Backups
Backups run on a scheduled basis for disaster recovery and follow a rotating retention schedule. Client data inside backups is covered by the same retention window; expired backup generations are destroyed as part of the rotation.
5. Disposal
At the end of the retention period, client data is disposed of by deletion from production systems and by allowing expired backup generations to rotate out. Disposal is documented when performed. Legal holds suspend deletion for records subject to them.
6. Client requests
Clients may request access to, correction of, or deletion of their personal information by emailing dave@fileboxbookkeeping.com. Requests are honored within a reasonable time, subject to legal recordkeeping obligations described in this policy and the Privacy Policy.
7. Review
This policy is reviewed at least annually and after any material change to systems or applicable law, in line with the Security Policy.