Data retention and disposal policy
Last updated on: March 5th, 2026
Last updated on: March 5th, 2026
1. Purpose
This policy explains how UpFlip retains and disposes of data collected or generated through our internal financial tracking system, including data received through third-party providers such as Plaid.
2. Scope
This policy applies to data stored in the internal financial tracking system and related databases, logs, backups, and file storage, as well as company personnel and contractors with approved access. This system is used for internal company operations and is not consumer-facing.
3. Data we retain
We may retain the following categories of data:
We do not intentionally store bank login credentials. Where access tokens are used, they are stored securely and only for the purpose of maintaining the connection.
4. Retention periods
Unless a longer period is required for accounting, tax, legal, or audit needs, we retain data as follows:
5. Data access and minimization
6. Disposal and deletion
When data reaches the end of its retention period, it is disposed of by one or more of the following methods:
If an integration is disconnected, associated tokens and integration identifiers are deleted within the timeframes listed above.
7. Legal holds and exceptions
If we are required to preserve data due to legal obligations (for example, litigation, investigation, audit, or regulatory request), deletion may be suspended until the hold is lifted.
8. Policy review and updates
We review this policy at least annually and update it as our systems and operational requirements evolve.
9. Contact
Questions about this policy can be directed to Nikita Leonovets (CTO) at support@upflip.com.