Help us improve Paymarka

Allow anonymous usage analytics so we can understand which pages and actions are useful.

Data Retention Policy

Last updated 15 July 2026

Purpose and scope

This policy explains how long Paymarka keeps the categories of data used by its current account, workspace, client-portal, document, payment, notification, AI and security features. Retention is not a promise to keep records for a particular commercial or statutory period: the correct period depends on the controller, jurisdiction, contract, dispute status and legal obligation.

Paymarka is generally a controller for its own account, billing, security, support and service-management records. A workspace customer normally controls the retention of its client and commercial records, with Paymarka acting as processor or service provider under the relevant agreement. The workspace customer must give Paymarka retention and deletion instructions that are lawful and consistent with evidence, accounting and dispute requirements.

Retention principles

  • Keep personal data only for as long as it is needed for the stated purpose, a contract, a legal obligation, a dispute, fraud or abuse investigation, security, or a defensible evidence trail.
  • Apply deletion, anonymisation or access restriction when the purpose ends. Separate records that must survive from records that can be removed.
  • Preserve the integrity of accepted proposals, signed contracts, payment evidence, receipts, snapshots and audit events where a controller has a lawful need to preserve evidence. A correction or access restriction may be used instead of silently rewriting an evidence trail.
  • Keep provider and backup copies under the provider's documented retention and deletion controls; Paymarka cannot delete a copy it does not control until the relevant provider process permits it.
  • Review retention schedules when a purpose, provider, law, product feature or security risk changes. The operator must maintain a written records-of-processing and vendor-retention register.

Current product retention map

Accounts and sessions

User, membership and workspace records remain while the account or workspace is active, or until deletion is requested and no lawful hold or continuing relationship requires them. Access tokens are currently short-lived (15 minutes); refresh sessions are designed to expire after 30 days and are revoked or deleted on logout, password reset and account deletion. Verification links expire after 24 hours, password-reset links after 1 hour, team invitations after 7 days, and workspace-selection tokens after 5 minutes.

Drafts

A Public One-Off draft is stored in the browser that created it, under the key paymarka.oneOffDraft.v1, until it is cleared or imported. Clearing browser storage removes that local copy. Once imported, the resulting workspace data follows the commercial-record rules below.

Commercial records

Client contacts, deals, proposals, negotiation messages, contracts, signatures, invoices, milestones, payments, receipts, generated PDFs, payment proof, snapshots and audit records remain while the workspace is active and afterwards for the period reasonably required by the workspace customer for contract performance, accounting, tax, dispute resolution, fraud prevention, security, legal claims and reliable evidence. The current code does not impose one universal age-based deletion period; the workspace customer and counsel must approve the exact period for each jurisdiction and record class.

Notifications and support

Email and WhatsApp delivery records include recipients, subjects, provider IDs, status and failure information. Sales-lead and support records may be retained for follow-up, abuse prevention, service administration and legal accountability. Exact periods are not configured in this repository and must be set in the approved schedule.

Analytics, logs and security records

Request logs, audit events, platform audit logs, security events, error records and conditional PostHog events are retained only as long as needed for security, reliability, fraud prevention, service improvement and legal accountability. No complete time-based purge schedule for these records is present in the repository; the operator must confirm it for each log system and provider.

Provider copies and backups

Resend, Twilio, Paystack, Google, OpenAI, PostHog, Cloudinary, database, cache, hosting and backup providers may retain copies under their own contracts, settings and policies. Their actual locations, backup windows, deletion SLAs and sub-processors must be confirmed in the vendor register; they are not invented here.

Account deletion and the 30-day asset purge

The current product lets the workspace owner open Settings → Workspace, select a deletion reason and type “DELETE MY ACCOUNT”. The deletion transaction removes the workspace's core database records, revokes sessions and removes the user account when no other active workspace membership remains. It also attempts to cancel an active Paystack subscription before the workspace is removed.

Paymarka-owned Cloudinary assets are collected into a deletion manifest and scheduled for purge 30 days after the request. This delay supports recurring-billing cancellation retries and cleanup of externally stored assets. Failed deletion attempts are retried. A deletion manifest intentionally survives the workspace deletion so that billing and asset cleanup can finish; the current code does not assign an expiry to that manifest. Its final retention period, contents, access controls and disposal must be approved and implemented by the operator.

Platform audit records of the deletion and some shared records (for example, platform-managed clause packs or sales leads) may be detached from the deleted workspace rather than deleted immediately. Legal holds, regulatory duties, unresolved disputes, fraud or abuse investigations, accounting records, third-party copies and the rights of other data subjects can limit or delay erasure. We will restrict access and delete when the reason to retain ends.

Portal links, files and evidence

Client portal tokens stop authorising access after their recorded expiry. The associated portal-token row, generated files and notification logs may still remain until the applicable commercial, security or provider-retention period ends. Uploaded logos, signatures, contracts, receipts and payment proofs are separate assets and require both database-reference deletion and provider-side asset deletion.

Retaining an evidence record does not authorise using it for a new, incompatible purpose. If a record is retained to meet a legal, accounting or evidence obligation, processing should be limited to that purpose and access should be restricted.

Requests, holds and controller instructions

To request deletion, access, correction, portability, restriction or objection, contact the workspace customer for client and commercial records. Workspace owners can use the in-product account-deletion flow. For Paymarka's own processing, use [PRIVACY CONTACT EMAIL] or the Paymarka contact route. Requests may require identity verification and may be limited to protect another person's rights or a lawful evidence obligation.

A legal hold suspends ordinary deletion for the affected data only. The owner or workspace customer must document the scope, reason, approving person, start date and release date, and must remove the hold promptly when it is no longer needed.

Required operator confirmations

Before this policy is treated as final, the operator and privacy counsel must confirm: the legal entity and controller allocation; the DPO and privacy/security contacts; each statutory and contractual retention period; log, backup and deletion schedules; vendor names, sub-processors, processing countries and cross-border safeguards; whether Paymarka is a controller or processor for each AI and analytics flow; and any EEA or UK targeting that would activate GDPR or UK GDPR duties. Nothing in this policy should be read as waiving those checks or guaranteeing immunity from liability.