This Data Deletion and Retention Policy (“Policy”) defines how 456Labs Inc. (“456Labs”, “we”, “us”, “our”) retains, deletes, and anonymizes personal information collected through Invoicefinito (the “Services”), including our mobile applications and website. It is designed to align with applicable data protection laws, including the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and the Personal Information Protection and Electronic Documents Act (PIPEDA) where relevant to our users in Canada.
This Policy applies to:
This Policy supplements our Privacy Policy and user-facing account deletion instructions. If there is a conflict, this Policy governs retention and deletion practices; the Privacy Policy governs broader privacy disclosures.
The table below summarizes default retention periods for major categories of personal information while an account is active and after deletion is requested.
| Data category | While account is active | After deletion request |
|---|---|---|
| Account & authentication (email, profile, sign-in metadata) | Retained while the account exists | Deactivated immediately on in-app deletion; authentication record permanently deleted on hard purge (see Section 5) |
| Business data (clients, invoices, expenses, time entries, projects, settings) | Retained while the account exists | Retained during 30-day grace period; permanently deleted on hard purge |
| Files (invoice PDFs, receipt images) | Retained while the account exists | Retained during grace period; storage prefix deleted on hard purge |
| Bank connection summaries & imported transactions (Plaid, optional) | Retained while connected or until account deletion | Disconnect removes Plaid access and connection credentials; all bank data deleted on hard purge |
| Subscription / billing entitlement records | Retained while needed to provide the subscription | Deleted on hard purge; store receipts may remain with Apple/Google |
| Encrypted backups & replicas | Per cloud provider cycles | Residual copies may persist up to 90 days after primary deletion |
| Aggregated or de-identified analytics | May be retained indefinitely | Not reasonably identifiable; not subject to erasure requests |
| Records required by law (tax, fraud, disputes) | As required by applicable law | Retained only for the legally required period and limited to compliance purposes |
Account deletion is available only through the authenticated in-app flow described below. Users must sign in to delete their account.
status: deleted,
records the deletion reason (optional), and sets a
purgeAfter timestamp 30 calendar days
in the future.
On hard purge, we enforce deletion of:
users/{uid} (recursive
delete), including clients, invoices, expenses, time entries, bank
transactions, and related subcollections.
users/{uid}/.
Users with an optional Plaid bank connection may disconnect a bank at Settings → Bank connections → Disconnect without deleting their Invoicefinito account. This enforces:
Previously imported transactions remain until the user deletes their full account or those records are removed during hard purge.
Depending on jurisdiction, users may have rights to access, correct, delete, restrict, or port personal information. Account deletion is performed in the app as described in Section 5. For other privacy requests (for example, access or correction), contact hello@invoicefinito.com. We may request information to verify identity before acting on a request. If you need help signing in so you can use in-app deletion, contact us at the same address.
We do not sell personal information. We do not use Plaid data for purposes unrelated to providing the Services described in our Privacy Policy.
456Labs reviews this Policy at least annually and upon any material change to data practices, product features (including new integrations), or applicable law. The “Last updated” / review date is revised with each review. Owners: product and engineering leadership, with privacy inquiries directed to hello@invoicefinito.com.
Approved by: 456Labs Inc.
Contact: hello@invoicefinito.com
Public references: