Trust & Compliance
Data Retention Schedule
Transparency about how long we keep your data and why
Transparent Retention
Right to Erasure
Automated Deletion
FoxtInn retains data only as long as necessary for legitimate business and legal purposes. This schedule applies to all data processed by FoxtInn as both data controller and processor.
1. Customer Account Data
| Data Type | Retention Period | Legal Basis | Notes |
|---|---|---|---|
| Account registration (name, email, phone) | Duration of account + 30 days post-termination | Contract performance | Exported within 30-day window |
| Billing & payment records | 7 years after last transaction | Legal obligation (IRS, SOX) | Required for tax/audit compliance |
| Subscription history | Duration of account + 7 years | Legal obligation | Includes plan changes, invoices |
| Support tickets & communications | 3 years after resolution | Legitimate interest | Quality assurance, dispute resolution |
| Login & authentication logs | 180 days | Legitimate interest / Security | Fraud detection, access auditing |
| Account preferences & settings | Duration of account | Contract performance | Deleted with account |
2. Staff/Employee Data (Processed as Processor)
| Data Type | Retention Period | Legal Basis | Notes |
|---|---|---|---|
| Employee profiles (name, role, contact) | Duration of employment + Customer-configured retention | Customer instruction (processor) | Customer controls retention settings |
| Scheduling records | 24 months rolling default | Customer instruction | Configurable by Customer |
| Time & attendance logs | 36 months rolling default | Customer instruction / Legal obligation | Labor law compliance varies by jurisdiction |
| Performance notes | Duration of employment | Customer instruction | Customer may configure shorter period |
| Training records | Duration of employment + 12 months | Customer instruction / Legal obligation | Regulatory compliance documentation |
3. Guest Data (Processed as Processor)
| Data Type | Retention Period | Legal Basis | Notes |
|---|---|---|---|
| Guest profiles (name, email, phone) | 12 months after last stay (default) | Customer instruction | Customer configurable: 6/12/24 months |
| Check-in/check-out records | 24 months | Customer instruction / Legal obligation | Tax, hospitality regulation compliance |
| Guest preferences & requests | 12 months after last stay | Customer instruction | Deleted with guest profile |
| ID verification data | 30 days after checkout | Customer instruction / Legal obligation | Local ID laws may require longer |
| Guest feedback & reviews | Duration of Customer account | Customer instruction | Anonymized on guest profile deletion |
| Payment card data | NOT STORED by FoxtInn | N/A | Processed directly by Stripe (PCI DSS) |
4. Operational & AI Data
| Data Type | Retention Period | Legal Basis | Notes |
|---|---|---|---|
| AI query logs (LALA interactions) | 90 days | Legitimate interest | Service improvement, debugging. No model training. |
| AI-generated outputs (reports, summaries) | Duration of Customer account | Contract performance | Customer-owned content |
| Audit logs (admin actions) | 180 days | Security / Legal obligation | Compliance monitoring |
| System performance logs | 90 days | Legitimate interest | Infrastructure monitoring |
| Error & crash reports | 90 days | Legitimate interest | Bug fixing, stability |
5. Marketing & Analytics Data
| Data Type | Retention Period | Legal Basis | Notes |
|---|---|---|---|
| Website analytics (GA4) | 14 months (Google default) | Consent | Aggregated, IP-anonymized |
| Cookie consent records | 12 months | Legal obligation (GDPR Art. 7) | Proof of consent |
| Marketing email interactions | 24 months after last interaction | Consent / Legitimate interest | Unsubscribe honored immediately |
| Marketing pixel data (Meta, LinkedIn) | Per platform retention policy | Consent | Opt-out available via cookie settings |
| Lead/contact form submissions | 24 months | Legitimate interest | Business development |
6. Post-Termination Data Handling
- 30-day export window: Customer may export all data via platform tools or request via support
- 30 days post-termination: All Customer data deleted from production systems
- 90 days post-termination: All Customer data purged from backups
- Destruction certificate: Available on request confirming complete data deletion
- Exceptions: Data required by law (tax records, audit logs) retained per legal minimums
7. Automated Deletion Processes
FoxtInn implements automated data lifecycle management:
- Guest data automatic purge based on Customer-configured retention window
- Session data automatic expiry (15-minute JWT tokens, session cookies)
- Temporary files purged within 24 hours
- Failed upload data purged within 7 days
- Soft-deleted records hard-deleted after 30-day grace period
8. Your Rights Regarding Data Retention
- Right to Erasure: Request deletion under GDPR Art. 17, CCPA, LGPD, or other applicable law
- Right to Restriction: Request we limit processing while retaining data (GDPR Art. 18)
- Right to Object: Object to processing based on legitimate interest (GDPR Art. 21)
- Data Portability: Export data in machine-readable format before deletion
- Contact: privacy@foxtcon.com
- See also: International Privacy Rights for jurisdiction-specific timelines
9. Legal Hold & Exceptions
Data may be retained beyond standard periods when:
- Subject to active legal proceedings
- Required by court order or regulatory investigation
- Necessary for fraud prevention in ongoing investigation
- Required by tax/financial audit
Customers are notified when legal hold affects their data (unless prohibited by law).
10. Updates
Last updated: April 13, 2026. Reviewed quarterly.