← Return to DFA demo store
Dollflow

Data lifecycle

Data Retention Policy

How long Dollflow keeps appointment information and what happens when it is no longer needed.Effective October 2, 2026
01

Our approach

Dollflow keeps information only while needed to provide the service, protect accounts, follow merchant instructions, resolve disputes, and satisfy legal obligations. The Merchant remains responsible for its own retention duties and can request earlier deletion where applicable.

02

Retention schedule

RecordTypical lifecycleEnd-of-life action
Appointments and customer details24 months after the appointment dateIdentity, contact, notes, intake, reminder, provider, and calendar references are removed or anonymized automatically.
Waitlist requests24 months after the requested dateOld personal waitlist records are deleted.
Temporary waitlist slot holds15 minutesThe private hold expires and the slot can be offered again.
Notification and delivery recordsLinked to the operational booking lifecycleDeleted with related booking data unless a shorter provider lifecycle applies.
Membership, payment, transaction, and refund referencesWhile needed for entitlement, refunds, accounting, fraud prevention, or lawDeleted, anonymized, or retained only as legally required.
Verification and customer-management linksUntil expiry, use, replacement, or related-record deletionExpired operational records and hashed tokens are removed.
Google connection dataWhile connected and needed for synchronizationCredentials are deleted on disconnect or shop deletion; event references follow appointments.
Shopify sessions and configurationWhile installed and needed for operationDeleted through Shopify's shop-redaction process after uninstall, subject to law.
Security and operational logsOnly while an active security, support, or legal need existsRotated or deleted; protected-data logs are designed to be pseudonymous.
03

Deletion and anonymization

Anonymization removes customer contact details, booking messages, intake answers, notification records, payment-provider references, and connected calendar-event references. Non-personal service, time, status, and amount facts may remain for merchant reporting where they can no longer identify the customer.

Shopify's customer-redaction process supports earlier deletion. After uninstall, Shopify sends a shop-redaction request and Dollflow removes shop personal data unless law requires retention.

04

Backups and infrastructure

Encrypted operational backups may contain data until they rotate out under the backup lifecycle. They are access restricted, used for disaster recovery, and not restored to avoid an applicable deletion. Infrastructure providers may keep short-lived security or recovery copies under their controls.

Merchant action

Merchants should configure booking questions conservatively and avoid copying appointment data into longer-lived free-text systems unless necessary.

05

Requests and changes

Customers should normally contact the merchant that collected their information. Merchants may contact dollflowapp@gmail.com for verified retention or deletion requests. We may update this schedule when features or legal requirements change.