Data Retention and Access Policy

Scope

This policy covers personal data processed by the Attribution platform, including hashed customer emails, anonymous visitor IDs, browsing events, conversion records, and integration credentials.

Retention periods

Data categoryRetentionMechanism
Browsing events (events table)13 months from event timestampTinybird TTL on timestamp column
Identity links (anonymous_id ↔ hashed_email)13 months from `identified_at`Tinybird TTL
Conversions (orders, deals, leads)13 months from `occurred_at`Tinybird TTL
Attributed journeys13 months from conversionTinybird TTL
Integration credentials (encrypted tokens)Until merchant uninstallsNeon deletion on uninstall
Project configurationUntil project deletionNeon deletion on request
Server logs30 daysVercel default retention

Data is automatically deleted when its retention period expires. No manual intervention is required.

Data minimization

Access controls

Staff access

Application access

Third-party access

Access logging

Deletion requests

Review

This policy is reviewed annually and updated as infrastructure or sub-processors change.