Data Retention And Deletion

This policy explains how Prizm Services LLC retains, reviews, deletes, or anonymizes customer, invoice, payment, and bank-connection records.

Retention Schedule

Data TypeRetention PeriodReason
Customer contact recordsUp to 3 years after last activity, unless deletion is requested earlier and no legal exception applies.Customer support, project history, and dispute resolution.
Invoices, orders, and payment recordsUp to 7 years.Accounting, tax, chargeback, and legal recordkeeping.
Admin audit logsAt least 2 years where operationally available.Security review, fraud prevention, and operational accountability.
Plaid bank-link metadataOnly as long as needed for payment verification, payment status, fraud prevention, and support.Payment processing and reconciliation.
Marketing analyticsAggregated or anonymized data may be retained longer.Website performance and business reporting.

Deletion Requests

Customers may request access, correction, deletion, or limitation of personal data by contacting info@prizmservices.com. We respond within legally required timelines and may retain records where necessary for accounting, fraud prevention, legal claims, or compliance obligations.

Secure Disposal

When data reaches the end of its retention period, Prizm Services deletes, anonymizes, or archives it using reasonable safeguards. Sensitive credentials and production secrets must not be stored in public files or client-side code.

Review

This policy is reviewed at least annually or when material changes are made to payment processing, customer data handling, or legal requirements.