← Back
Data Retention Policy — Pareto B2B Quotes
Last updated: 2026-08-19
Contact: nikola@pareto-labs.com
We keep personal data only as long as necessary for the purposes for which it was collected.
Retention periods
| Data | Retention | Then |
|---|---|---|
| Quote request data (customer name, email, phone, company, address, requested items) | 24 months after the last activity on the request | Deleted automatically |
| Attached files submitted with a quote request | Same as the quote request they belong to | Deleted with the request |
| Access log (non-nominative: action, resource id, counters — never personal data) | 90 days | Deleted automatically |
| Product analytics events (store domain, store attributes and technical counters — never customer personal data) | 12 months | Deleted automatically by the analytics provider |
| Store-level profile held by the analytics provider (store domain, plan, country, currency) | Until the store profile is deleted on request | Deleted on request |
| Merchant account data & access token | For the duration of the installation | Deleted on uninstall |
| Email delivery logs (via Resend) | Per Resend's retention (short-term) | Deleted by provider |
| Encrypted database backups | Rolling point-in-time-recovery window provided by our database provider | Rotated / overwritten automatically |
Deletion triggers (before the period ends)
- Merchant uninstalls the App → we delete or anonymise the personal data processed on that merchant's behalf.
shop/redactwebhook (Shopify, ~48h after uninstall) → shop and related personal data deleted. Product analytics events are deliberately retained until the period above, since they contain no customer personal data; a merchant may request their deletion at any time (see below).customers/redactwebhook (Shopify) → the specified customer's personal data deleted.- Direct request to nikola@pareto-labs.com → handled without undue delay.
How deletion works
Deletion removes records from the production database. Any copies remaining in short-term encrypted backups are purged when those backups rotate out (within the backup window above). Backups are never restored selectively to re-introduce deleted data.
Review
This policy is reviewed at least annually and when processing changes materially.