SwiftSku’s Data Retention & Deletion Policy
Last updated: March 17, 2026
SwiftSku, Inc. (“SwiftSku,” “Company,” “we,” “our,” or “us”) is committed to retaining and handling data responsibly and in accordance with applicable legal, contractual, and operational requirements. This Data Retention & Deletion Policy (the “Policy”) describes how we retain, manage, and delete data collected in connection with our websites, applications, software platforms, and related digital services (collectively, the “Services”). We retain personal and operational data only for as long as reasonably necessary to support our business operations, comply with legal and contractual obligations, and protect the security and integrity of the Services.
Scope and Applicability of This Data Retention & Deletion Policy.
This Policy applies to data collected, generated, or received by us through our operation of the Services, including data relating to consumers, end users, retailers, and other business users who interact with the Services through websites, applications, integrations, or support channels. We retain personal data only for periods that are reasonably necessary and proportionate to the disclosed purposes for which the data was collected. Additional information about how we collect, use, and disclose personal information through the Services is described in our Privacy Policy, available at www.swiftsku.com/privacy-policy.
This Policy primarily covers end‑user data associated with:
•consumer interactions with SwiftSku‑enabled platforms or storefronts;
•retailer or partner use of our software, analytics, and integrations; and
•payment‑enabled, ordering, delivery, settlement, and support workflows.
This Policy does not apply to:
•employee or workforce data;
•job applicant or recruiting data; and
•internal corporate records unrelated to end‑user interactions.
Those categories are governed by separate internal policies.
In certain circumstances, SwiftSku processes data on behalf of retailers or other business customers that use the Services. In those cases, the applicable business customer may determine the purposes and retention periods applicable to certain data associated with their end users, subject to applicable law and contractual obligations.
Categories of Data Retained.
Depending on how the Services are used, we may retain the following categories of data:
Account and Profile Information. Information associated with user or customer accounts, which may include names, contact details, login credentials, and account preferences.
Transaction and Order Data. Records relating to orders, payments, settlements, refunds, chargebacks, adjustments, and related transactional metadata.
Financial and Banking Information. Limited financial information necessary to support payment‑enabled features, such as bank account identifiers, settlement details, transaction identifiers, and compliance‑related information. We do not store full payment card numbers.
Customer Support and Communications. Emails, chat messages, support tickets, feedback, and other communications between users and us.
Device, Usage, and Technical Data. Information about devices, browsers, IP addresses, logs, timestamps, error reports, and usage patterns generated through interaction with the Services.
Marketing and Preference Data. Communication preferences, subscription settings, and engagement data related to marketing or informational communications.
Security, Fraud, and Compliance Data. Data used to detect, prevent, investigate, or respond to fraud, security incidents, regulatory inquiries, audits, or legal claims.
Privacy Rights and Request Records. Records relating to privacy‑related requests and interactions, including access, deletion, correction, or other rights requests submitted by individuals, our responses to such requests, and related verification or compliance documentation.
Data Retention Periods.
We retain data for periods that are reasonable and proportionate to the purposes for which the data was collected, as summarized below. We determine appropriate retention periods based on several factors, including the nature of the data, the purposes for which it was collected, applicable legal requirements, contractual obligations, and operational needs such as security monitoring and dispute resolution.
Data Category | Examples | Purpose of Retention | General Retention Period |
|---|---|---|---|
Account and Profile Information | User account details, contact information | Account management, service delivery, support | Duration of the account relationship, plus a reasonable period thereafter |
Transaction and Order Data | Orders, settlements, refunds, chargebacks | Accounting, tax, dispute resolution, audits | Generally retained for up to seven (7) years, consistent with accounting, tax, and dispute resolution requirements |
Financial and Banking Information | Bank account identifiers, settlement records | Payment processing, compliance, fraud prevention | Generally retained for up to seven (7) years, consistent with contractual and legal obligations |
Customer Support Communications | Emails, chats, support tickets | Customer service, issue resolution, training | Duration of support need, plus a reasonable archival period |
Device and Usage Data | Logs, IP addresses, usage metrics | Security, performance, analytics | Short to moderate periods, subject to log rotation and operational needs |
Marketing and Preference Data | Opt‑in status, communication preferences | Marketing compliance, preference management | Until preferences change or communications are no longer relevant |
Security and Compliance Records | Fraud reviews, investigation records | Legal compliance, risk management | As long as required to resolve issues or meet legal obligations |
Privacy Rights Request Records | Access, deletion, correction requests and responses | Legal compliance, auditability | At least 24 months, or longer if required by law |
Privacy rights request records are retained solely to document request handling, demonstrate compliance with applicable privacy and data protection requirements, and review or improve our internal compliance processes. Such records may be maintained in a ticketing system, log, or similar format.
These records are not used for any other business purpose and are not disclosed to third parties except as required by applicable law or a lawful regulatory or judicial request. Individuals responsible for handling privacy‑related inquiries or requests receive appropriate training regarding our information‑handling practices and are instructed on how to direct individuals to available mechanisms for exercising applicable privacy and data rights.
Retention periods may be extended where necessary to comply with applicable law, contractual requirements, or valid legal holds.
Certain financial and banking information may be processed by third-party payment service providers or financial partners that support payment functionality within the Services. Those providers maintain their own data retention practices.
Data Deletion and Disposal.
We delete, de‑identify, or anonymize data when it is no longer reasonably necessary for the purposes described above, subject to applicable exceptions.
Deletion practices may include:
•permanent deletion from active systems;
•de‑identification or anonymization;
•aggregation into non‑identifiable datasets; and
•automated log rotation and data lifecycle management.
Deletion may occur:
•upon account closure or termination;
•after expiration of applicable retention periods; and
•in response to valid data deletion requests, where required by law and subject to applicable exceptions.
Data stored in system backups or disaster recovery systems may persist for limited periods until those backups are overwritten or expire according to routine backup cycles. Backup data is protected by appropriate safeguards and is not actively used except for restoration or continuity purposes.
We may retain data for longer periods where necessary to:
•comply with legal, regulatory, or tax obligations;
•preserve records relevant to litigation, investigations, or disputes; and
•maintain security, fraud prevention, or system integrity.
De-identified or aggregated data that no longer reasonably identifies an individual may be retained for longer periods for analytics, research, or service improvement purposes.
We maintain reasonable records or logs of deletion activities and applicable exceptions to support accountability, compliance, and audit requirements.
Security Safeguards.
We maintain commercially reasonable administrative, technical, and organizational safeguards consistent with industry standards designed to protect retained data against unauthorized access, loss, misuse, or disclosure. These safeguards may include:
•access controls and role‑based permissions;
•encryption of data in transit and, where appropriate, at rest;
•monitoring and logging of system activity;
•secure vendor and third‑party management practices; and
•secure deletion and disposal procedures.
While no system can be guaranteed to be completely secure, we regularly review and update our safeguards to address evolving risks.
Policy Review and Updates.
We may update this Policy from time to time to reflect changes in our business practices, legal requirements, or technological developments. When we make changes, we will update the “Last updated” date at the top of this Policy and post the revised version on the Services. Our data retention and deletion practices are periodically reviewed to ensure they remain appropriate, compliant, and aligned with our operational needs.
How to Contact Us.
If you have questions about this Policy or our privacy practices, or if you wish to exercise your rights or submit a request regarding your personal information, you may contact us at:
SwiftSku, Inc.

