1. Purpose and Scope
This Data Retention and Deletion Policy describes how Storefront Labs, LLC (“Storefront”) retains, archives, deletes, and disposes of information processed through its websites, Storefront Business Manager and Places applications, connected devices, integrations, messaging tools, camera and audio features, analytics, artificial intelligence features, billing systems, and related services.
This policy supplements Storefront’s Terms of Use, Privacy Policy, Security Overview, and applicable customer agreements.
2. Retention Principles
Storefront generally retains information only for as long as reasonably necessary to provide and secure the Services, perform customer instructions, maintain business and legal records, prevent fraud and abuse, resolve disputes, comply with law, and protect Storefront, customers, users, and third parties.
3. Customer and Storefront Roles
Customers generally determine the purposes for which customer data is collected and how long it should be retained, subject to available product settings, legal requirements, and the applicable agreement.
Storefront determines retention for information processed for its own account administration, billing, fraud prevention, security, analytics, legal compliance, and service-improvement purposes.
4. Data Categories
- account, user, administrator, and business information;
- business listings, hours, status, content, and publication history;
- messages, attachments, check-ins, and communications metadata;
- images, video, audio, camera feeds, recordings, and media metadata;
- device, sensor, location, occupancy, headcount, ETA, and operational data;
- AI prompts, outputs, classifications, and automation events;
- integration, authentication, and application logs;
- billing, invoice, tax, and transaction records;
- support, feedback, beta, and research information;
- security, fraud, abuse, diagnostic, and incident records; and
- aggregated, de-identified, statistical, and derived information.
5. General Retention Schedule
| Data Category | General Retention Approach |
|---|---|
| Active account and business data | Retained while the account or service remains active and for a reasonable period afterward. |
| Customer content and operational data | Retained according to feature functionality, customer settings, contractual requirements, and operational needs. |
| Messages and attachments | Retained for a reasonable period to support communications, abuse prevention, dispute resolution, and lawful recordkeeping. |
| Camera, audio, and media | Retained according to configuration, feature design, storage capacity, legal obligations, and operational requirements. |
| Security and authentication logs | Retained for threat detection, investigations, audit, abuse prevention, and legal requirements. |
| Billing, tax, and accounting records | Retained for the period required or reasonably appropriate under tax, accounting, audit, and commercial laws. |
| Support and legal records | Retained as needed to resolve issues, document commitments, manage disputes, and establish or defend legal claims. |
| Backups | Retained until overwritten or expired through ordinary backup rotation and disaster-recovery processes. |
| Aggregated or de-identified data | May be retained indefinitely where it no longer identifies a customer or individual and is used lawfully. |
6. Messages and Communications
Messages, attachments, delivery records, timestamps, sender and recipient details, moderation signals, and related metadata may be retained for a reasonable period appropriate to the communication feature.
7. Camera, Audio, and Media
Video, images, audio, snapshots, live streams, recordings, and related metadata may be stored and relayed as part of configured Storefront features. Retention may depend on customer settings, subscription level, storage capacity, legal holds, security needs, third-party platform behavior, and applicable law.
Storefront does not guarantee that a recording will begin, continue, capture a particular event, remain available, or satisfy a legal retention requirement.
8. Analytics, AI, and Derived Data
Storefront may retain AI prompts, outputs, automation events, model interactions, occupancy estimates, headcount, queue length, ETA, opening-time predictions, and related metadata for a reasonable period to provide the feature, investigate errors, prevent abuse, support customers, and improve reliability.
Aggregated or de-identified analytics, benchmarks, telemetry, and statistical information may be retained for longer periods where permitted by law.
9. Accounts, Billing, and Transactions
Account records may be retained throughout the customer relationship and for a reasonable period after closure to support reactivation, disputes, fraud prevention, legal compliance, and administration.
Billing, invoice, transaction, tax, refund, and payment-status records may be retained as required by law and ordinary accounting practice.
10. Security and Diagnostic Logs
Storefront may retain logs concerning authentication, administrative access, device events, integrations, errors, abuse signals, security alerts, suspected fraud, and incidents. Retention periods are based on security risk, investigative usefulness, operational needs, applicable law, and storage considerations.
11. Backups and Disaster Recovery
Storefront may maintain backups, snapshots, replicas, archives, and disaster-recovery copies. Deleted data may remain in backup systems until overwritten or expired through ordinary cycles.
Backup copies are generally not actively used except for restoration, continuity, security, legal, or compliance purposes.
12. Termination and Account Closure
After termination or expiration, Storefront may provide a limited export period, disable account access, retain data for a reasonable wind-down period, delete or anonymize data, retain records required for legal or security purposes, and maintain residual copies in backups until overwritten.
13. Deletion Requests
Customers may request deletion through available product functionality or by contacting Storefront. Storefront may require verification of identity, account authority, scope, and legal entitlement before acting.
Deletion may be limited where retention is necessary to complete transactions, maintain security, comply with law, preserve legal claims, retain accounting records, protect rights or safety, or allow backup expiration.
14. Legal Holds and Exceptions
Storefront may suspend deletion or extend retention where information is subject to litigation, investigation, audit, subpoena, preservation request, regulatory inquiry, insurance matter, dispute, security incident, fraud review, or other legal or operational obligation.
15. Subprocessors and Third-Party Services
Storefront’s subprocessors and integration providers may maintain their own retention schedules. Information transmitted to independent third-party platforms may remain subject to that platform’s retention and deletion practices after Storefront transmits it.
16. Deletion and Disposal Methods
Depending on the system and data type, Storefront may use logical deletion, cryptographic deletion, secure overwrite, account deactivation, access revocation, media destruction, anonymization, aggregation, backup expiration, or provider-managed deletion processes.
Deletion is considered complete when data is no longer reasonably accessible through active Storefront systems, subject to backup retention, legal holds, and technical limitations.
17. Customer Responsibilities
| Area | Customer Responsibility |
|---|---|
| Retention settings | Configure available retention controls appropriate to the business and legal requirements. |
| Legal records | Maintain independent copies of information that must be preserved. |
| Privacy notices | Disclose retention practices to employees, customers, visitors, parents, guardians, and others where required. |
| Deletion requests | Verify requests and instruct Storefront accurately when Storefront acts as a processor. |
| Sensitive data | Avoid submitting regulated or unnecessary data and apply shorter retention where appropriate. |
| Account closure | Export needed information before access ends. |
18. Changes to This Policy
Storefront may update this policy to reflect changes in the Services, law, technology, vendor practices, and operational requirements. The current version will be identified by its effective date.
19. Contact Information
Storefront Labs, LLC
1642 Burgos Dr
Sarasota, FL 34238
United States
Email: hello@storefrontworks.com
Website: www.storefrontworks.com
Last Updated: August 26, 2026