Data Retention Policy

Last updated: May 9, 2026

ApexPitCore retains different categories of data for different periods based on operational need, legal requirements, and contractual obligations. This schedule governs how long we retain data by default. Shop accounts may have different retention needs and should consult with legal counsel regarding their specific state and industry requirements.

Data CategoryDefault RetentionNotes
Shop account profileSubscription duration + 3 yearsAnonymized on account deletion
Employee accountsSubscription duration + 3 yearsDeactivated accounts retained for audit trail
Customer PII (name, contact)7 years from last serviceCan be anonymized on valid deletion request; financial records retained
Vehicle records (VIN, plate)7 years from last serviceAssociated with repair records for liability purposes
Repair orders7 yearsState laws vary; some require longer retention
Estimates7 years
Invoices and payments7 yearsRequired for tax compliance; personal data may be anonymized while record structure is retained
SMS and email logs2 yearsDelivery metadata, not full message body for marketing
Consent records (SMS opt-in/out)5 years from last eventTCPA compliance evidence
Inspection records and photos5 yearsMay be subject to vehicle warranty claims
Audit logs (activity_logs)3 yearsSecurity event logs: 2 years
Application logs90 daysAutomated rotation
Backup snapshotsPer backup policy (default 30 days rolling)Configurable per organization
Privacy request records5 yearsCompliance evidence
Security events2 years
Incident records5 yearsBreach records may require longer retention

Financial Record Retention Note

Invoices and payment records are retained for a minimum of 7 years to satisfy IRS guidelines for business record retention. When a customer requests deletion of their personal information, their identifiable contact details are anonymized, but the financial record structure (amounts, dates, service descriptions, tax) is retained to fulfill these legal obligations.

Requesting Deletion

To request deletion of personal data, visit /privacy/request. We will process your request within 45 days and notify you of which data can be deleted and which must be retained under applicable law.