Data Retention Policy
Booking records
Kept for as long as the shop's account is active. These are the shop's own appointment and revenue records, so they aren't deleted automatically just because time has passed - a shop needs its full appointment history for its own accounting and to look up past customers.
Guest/customer personal details (name, email, phone)
Kept attached to a booking until the shop's account is deleted, or until the person the details belong to requests removal (see delete my data). On request, we replace the name/email/phone on every matching booking with an anonymized placeholder. We keep the booking row itself (date, time, service, price, status) rather than deleting it outright, since the shop has a legitimate business/accounting reason to keep a record that an appointment happened - what's removed is specifically the data that identifies who it was for.
Customer accounts
A registered customer account (name, email, password hash) is kept until the account holder requests deletion, or the account has had no activity for an extended period (currently not automatically enforced - deletion is on request only, via the same delete-my-data flow).
Business owner / staff accounts
Kept for as long as the account is active on the platform. Deleting a shop or owner account is a manual, platform-admin-assisted process today (not self-service), since it needs to account for any bookings, billing history, and connected calendar tokens tied to it.
Google Calendar tokens
Kept only while a staff member's calendar connection is active, encrypted at rest (see docs/runbook.md in the codebase for the encryption/key details). Disconnecting a calendar, or removing a staff member, deletes the stored tokens.
Payment data
We store payment status and amount, not card details. Once real payment processing is enabled, card details are handled entirely by Stripe under its own retention policy.
Clinical / patient records
Shops in regulated health fields (clinics, physiotherapists, therapists) can optionally keep clinical records - a patient profile and treatment notes. This is sensitive health data and is treated separately from ordinary contact details: it is only ever visible to the shop that recorded it, and is never included in client-list exports.
Because keeping these records is a legal duty for the practitioner, they are subject to a statutory retention period - in Cyprus, 15 years from the patient's last visit. During that period a clinical record is excluded from the “delete my data” erasure flow: the right to erasure does not override a legal obligation to retain medical records. Once the retention period has elapsed the record can be removed like any other data. Patients retain their right of access - the practice can provide a copy of the record on request.
This is an operational policy describing what the software actually does today, written to be accurate rather than exhaustive. Have it reviewed alongside the privacy policy before publishing it as your official policy.