Data retention
Last updated: October 9, 2026
Keep what is needed. Review what is no longer needed.
This notice describes Book & Redeem’s current retention behavior during development and the process for handling requests. Retention depends on outstanding sessions, unresolved transactions, security needs, disputes and applicable law. Subscription cancellation, sign-out and data deletion are different actions.
How different records are handled
- Sign-in codes and sessions
- A sign-in challenge is valid for ten minutes; an issued app session lasts five minutes. Access can end earlier through use, sign-out, failed attempts or revocation. Authentication cleanup selects challenge and rate-limit records older than one hour in bounded batches. Cleanup depends on work running; these access periods are not promises that every stored copy is erased at that exact time.
- Connection credentials
- Credentials are kept encrypted while required for an authorized connection or guarded recovery. Disconnecting revokes app access and removes the active location credentials. Historical connection metadata and separate agency custody can remain; disconnecting one business does not authorize deleting another business’s connection.
- Credits, purchases and appointments
- These records preserve balances, fulfillment and financial history. They are retained after cancellation or disconnect so that unused credits and uncertain bookings are not silently lost. There is no automatic deletion of the financial ledger today. A verified request requires a scoped review of outstanding work, legal requirements and a safe deletion or de-identification method.
- Exports
- Authorized reports are returned privately. A downloaded file remains under the recipient’s control. Deleting data in the app does not delete copies a business has downloaded or supplied to another service.
- Support and incident records
- We keep the information needed to answer the request, track a recovery or resolve a dispute. Closed requests are reviewed for unnecessary personal information; incident evidence or legal holds may need longer retention. Ordinary email is not a permanent store for customer records.
- Provider records and recovery copies
- Hosting, security, email and CRM providers have their own retention and backup behavior. A deletion from active storage is not immediate removal from every backup. We confirm the relevant recovery window and any independent provider records when handling a request; we do not promise a universal deletion deadline.
Request access, export or deletion
- Email [email protected]. Identify the business and what you want us to review. Do not send passwords, codes or a full customer database.
- We verify your identity and authority. Customer-record requests are coordinated with the business responsible for those records.
- We identify the relevant data and any unresolved bookings, unused credits, refund questions or legal hold. Export or arrange fulfillment before closing access.
- We explain the action taken, information that must remain and why, and any provider or backup limits. We apply the response deadline required by applicable law. If a safe deletion method still needs preparation, we say so rather than report completion.
There is currently no self-service delete button or guaranteed post-cancellation export period. Do not disconnect first and assume the app can still read your CRM. Contact support to plan an orderly exit.
Safeguards during retention and recovery
We restrict retained information to authorized uses. An unresolved hold is investigated, not erased to make a balance appear correct. A retention exception must have a reason and a review date; it is not permission to keep everything forever. Recovery must preserve access revocations and approved deletion decisions rather than silently bringing removed access back.
The Enjoyable Work support team owns request handling and retention review. This notice is read together with the privacy notice and terms of service. The English text is the current version.