Data retention and disposal policy

Last updated on: March 5th, 2026

1. Purpose

This policy explains how UpFlip retains and disposes of data collected or generated through our internal financial tracking system, including data received through third-party providers such as Plaid.


2. Scope

This policy applies to data stored in the internal financial tracking system and related databases, logs, backups, and file storage, as well as company personnel and contractors with approved access. This system is used for internal company operations and is not consumer-facing.


3. Data we retain

We may retain the following categories of data:

  • Transaction data (date, amount, description/merchant, category, account reference)
  • Account metadata (institution name, account type, masked account identifiers)
  • Internal user access and audit logs (login history, actions taken, system events)
  • System configuration and integration metadata needed to maintain connectivity

We do not intentionally store bank login credentials. Where access tokens are used, they are stored securely and only for the purpose of maintaining the connection.


4. Retention periods

Unless a longer period is required for accounting, tax, legal, or audit needs, we retain data as follows:

  • Financial records (transactions, reconciliations, reports): retained for 7 years to support accounting and tax requirements
  • Integration data (access tokens, connection identifiers): retained as long as the connection is active, and deleted within 30 days after disconnection unless needed for troubleshooting or audit purposes
  • Application logs (non-audit): retained for 30–90 days depending on operational need
  • Security and audit logs: retained for 12 months
  • Backups: retained for 30–45 days, then automatically expired

5. Data access and minimization

  • Access is limited to authorized personnel who require it for finance and operations
  • We follow least-privilege access where practical
  • We retain only the data needed to operate the system and meet compliance/accounting obligations

6. Disposal and deletion

When data reaches the end of its retention period, it is disposed of by one or more of the following methods:

  • Secure deletion of database records
  • Expiration and deletion of backups under the backup retention schedule
  • Removal of files from storage and deletion from trash/recycle where applicable

If an integration is disconnected, associated tokens and integration identifiers are deleted within the timeframes listed above.


7. Legal holds and exceptions

If we are required to preserve data due to legal obligations (for example, litigation, investigation, audit, or regulatory request), deletion may be suspended until the hold is lifted.


8. Policy review and updates

We review this policy at least annually and update it as our systems and operational requirements evolve.


9. Contact

Questions about this policy can be directed to Nikita Leonovets (CTO) at support@upflip.com.