Data Deletion and Retention Policy

456Labs Inc. (Invoicefinito)
Effective date: June 20, 2026  |  Version 1.0  |  Next scheduled review: June 2027

1. Purpose

This Data Deletion and Retention Policy (“Policy”) defines how 456Labs Inc. (“456Labs”, “we”, “us”, “our”) retains, deletes, and anonymizes personal information collected through Invoicefinito (the “Services”), including our mobile applications and website. It is designed to align with applicable data protection laws, including the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and the Personal Information Protection and Electronic Documents Act (PIPEDA) where relevant to our users in Canada.

2. Scope

This Policy applies to:

This Policy supplements our Privacy Policy and user-facing account deletion instructions. If there is a conflict, this Policy governs retention and deletion practices; the Privacy Policy governs broader privacy disclosures.

3. Principles

4. Retention schedule

The table below summarizes default retention periods for major categories of personal information while an account is active and after deletion is requested.

Data category While account is active After deletion request
Account & authentication (email, profile, sign-in metadata) Retained while the account exists Deactivated immediately on in-app deletion; authentication record permanently deleted on hard purge (see Section 5)
Business data (clients, invoices, expenses, time entries, projects, settings) Retained while the account exists Retained during 30-day grace period; permanently deleted on hard purge
Files (invoice PDFs, receipt images) Retained while the account exists Retained during grace period; storage prefix deleted on hard purge
Bank connection summaries & imported transactions (Plaid, optional) Retained while connected or until account deletion Disconnect removes Plaid access and connection credentials; all bank data deleted on hard purge
Subscription / billing entitlement records Retained while needed to provide the subscription Deleted on hard purge; store receipts may remain with Apple/Google
Encrypted backups & replicas Per cloud provider cycles Residual copies may persist up to 90 days after primary deletion
Aggregated or de-identified analytics May be retained indefinitely Not reasonably identifiable; not subject to erasure requests
Records required by law (tax, fraud, disputes) As required by applicable law Retained only for the legally required period and limited to compliance purposes

5. Account deletion process (enforced)

Account deletion is available only through the authenticated in-app flow described below. Users must sign in to delete their account.

5.1 In-app deletion

  1. An authenticated user initiates deletion at Settings → Account → Delete account.
  2. Our backend marks the user document with status: deleted, records the deletion reason (optional), and sets a purgeAfter timestamp 30 calendar days in the future.
  3. The user is signed out. Access to app data is blocked during the grace period except to restore the account or sign out.
  4. If the user signs in within 30 days, they may tap Restore account, which clears the deletion marker.
  5. A scheduled server job runs daily and permanently deletes accounts whose grace period has elapsed (“hard purge”).

5.2 Hard purge (permanent deletion)

On hard purge, we enforce deletion of:

6. Partial deletion — bank connections

Users with an optional Plaid bank connection may disconnect a bank at Settings → Bank connections → Disconnect without deleting their Invoicefinito account. This enforces:

Previously imported transactions remain until the user deletes their full account or those records are removed during hard purge.

7. Legal bases and user rights

Depending on jurisdiction, users may have rights to access, correct, delete, restrict, or port personal information. Account deletion is performed in the app as described in Section 5. For other privacy requests (for example, access or correction), contact hello@invoicefinito.com. We may request information to verify identity before acting on a request. If you need help signing in so you can use in-app deletion, contact us at the same address.

We do not sell personal information. We do not use Plaid data for purposes unrelated to providing the Services described in our Privacy Policy.

8. Exceptions and limitations

9. Governance and enforcement

10. Policy review

456Labs reviews this Policy at least annually and upon any material change to data practices, product features (including new integrations), or applicable law. The “Last updated” / review date is revised with each review. Owners: product and engineering leadership, with privacy inquiries directed to hello@invoicefinito.com.

Approved by: 456Labs Inc.

Contact: hello@invoicefinito.com

Public references: