Our approach
Dollflow keeps information only while needed to provide the service, protect accounts, follow merchant instructions, resolve disputes, and satisfy legal obligations. The Merchant remains responsible for its own retention duties and can request earlier deletion where applicable.
Retention schedule
| Record | Typical lifecycle | End-of-life action |
|---|---|---|
| Appointments and customer details | 24 months after the appointment date | Identity, contact, notes, intake, reminder, provider, and calendar references are removed or anonymized automatically. |
| Waitlist requests | 24 months after the requested date | Old personal waitlist records are deleted. |
| Temporary waitlist slot holds | 15 minutes | The private hold expires and the slot can be offered again. |
| Notification and delivery records | Linked to the operational booking lifecycle | Deleted with related booking data unless a shorter provider lifecycle applies. |
| Membership, payment, transaction, and refund references | While needed for entitlement, refunds, accounting, fraud prevention, or law | Deleted, anonymized, or retained only as legally required. |
| Verification and customer-management links | Until expiry, use, replacement, or related-record deletion | Expired operational records and hashed tokens are removed. |
| Google connection data | While connected and needed for synchronization | Credentials are deleted on disconnect or shop deletion; event references follow appointments. |
| Shopify sessions and configuration | While installed and needed for operation | Deleted through Shopify's shop-redaction process after uninstall, subject to law. |
| Security and operational logs | Only while an active security, support, or legal need exists | Rotated or deleted; protected-data logs are designed to be pseudonymous. |
Deletion and anonymization
Anonymization removes customer contact details, booking messages, intake answers, notification records, payment-provider references, and connected calendar-event references. Non-personal service, time, status, and amount facts may remain for merchant reporting where they can no longer identify the customer.
Shopify's customer-redaction process supports earlier deletion. After uninstall, Shopify sends a shop-redaction request and Dollflow removes shop personal data unless law requires retention.
Backups and infrastructure
Encrypted operational backups may contain data until they rotate out under the backup lifecycle. They are access restricted, used for disaster recovery, and not restored to avoid an applicable deletion. Infrastructure providers may keep short-lived security or recovery copies under their controls.
Merchants should configure booking questions conservatively and avoid copying appointment data into longer-lived free-text systems unless necessary.
Requests and changes
Customers should normally contact the merchant that collected their information. Merchants may contact dollflowapp@gmail.com for verified retention or deletion requests. We may update this schedule when features or legal requirements change.