Legal & policies
Data Retention & Deletion
Effective date: 9 June 2026
This policy describes how long Tradie Texts keeps personal information and how access, correction, deletion and de-identification requests are handled. It supports APP 11, APP 12 and APP 13.
1. Retention principles
We keep personal information only for as long as reasonably needed to provide the Service, support Customers, maintain security, meet legal obligations, resolve disputes and keep required business records. When information is no longer needed, we take reasonable steps to delete it or de-identify it unless we are required or permitted by law to keep it.
2. Retention schedule
| Data category | Examples | Target retention |
|---|---|---|
| Caller leads and lead metadata | phone number, job type, suburb/address, urgency, status, AI summary | Up to 24 months after last activity, then delete or de-identify |
| SMS conversations | inbound and outbound message bodies, Twilio message SID, segments, timestamps | Up to 24 months after last message, then delete or de-identify |
| Missed-call and call-event records | call SID, status, time, number metadata | Up to 24 months unless needed for security, billing or dispute handling |
| Opt-out and opt-in records | STOP/START status, phone number, timestamp, business | As long as needed to honour the preference and demonstrate compliance |
| Webhook payloads | raw Twilio/Stripe webhook payloads used for audit and idempotency | Minimise; target 90 days for raw message/call payloads unless needed for a dispute, security incident or billing audit |
| Account profile and business configuration | account email, business details, routing settings, AI settings | Life of the account, then delete or de-identify unless retained for legal/business records |
| Billing and tax records | invoices, subscription IDs, payment records, usage billing records | 7 years after the relevant transaction or longer if required by law |
| Application/security logs | operational logs, error logs, access/security events | Up to 12 months, with phone numbers and message bodies redacted where practicable |
| Audit records | account changes, permission changes, important operational actions | Up to 7 years where needed for legal, security or dispute reasons |
These periods are maximum targets, not promises to keep information for the full period. We may delete or de-identify information earlier where it is no longer needed.
3. Current implementation status
A scheduled retention job now runs daily and enforces the core of this schedule automatically:
- Caller leads and their SMS conversations that have had no activity for 24 months are
deleted. Deleting the lead cascades to its conversations, messages and AI jobs, so caller phone numbers, message bodies and lead details are removed together in one atomic operation.
- Raw webhook payloads (un-redacted Twilio/Stripe bodies kept for short-term idempotency
and audit) are deleted after 90 days.
- Billing and tax records (usage records, subscriptions) and the audit log are deliberately
preserved, so required financial records remain intact while unnecessary caller personal information is removed.
The destructive logic runs server-side as a single reviewed database function (purge_expired_personal_data), invoked by an authenticated daily cron job (/api/jobs/retention). The default windows are 730 days for caller leads and 90 days for webhook payloads.
Remaining backlog (handled manually until built):
- Per-message de-identification of very old messages that sit on a still-active lead (rare;
the lead-level purge covers the common case);
- A one-click account-closure workflow for Customers; and
- A structured, auditable request-tracking log for individual Caller access, correction and
deletion requests (the process itself is now documented — see below; there is no dedicated tracking table yet, so requests are logged manually).
Individual deletion and de-identification requests outside the scheduled job are handled following the process in docs/RUNBOOK_DATA_DELETION.md, which covers how a request comes in, how identity is verified before anything is changed, which tables are touched, and how the deletion or de-identification is performed.
4. Account deletion
When a Customer requests account deletion, we will delete or de-identify business configuration, Caller leads, conversations and related operational records unless we need to retain limited records for billing, tax, legal, security, fraud prevention, dispute resolution or compliance.
Deleting a Customer account may not immediately remove records held by third-party providers such as Twilio, Stripe, OpenAI, Supabase, Vercel or backups. We will take reasonable steps available to us to action deletion or de-identification with providers where required and practicable.
5. Caller requests
Callers should first contact the trade business they called. We will assist that business to locate, access, correct, delete or de-identify relevant records. Callers may also contact hello@tradietexts.com.au directly, and we will route or action the request as appropriate.
We may need to verify identity and confirm the relevant business before disclosing or changing records. If we refuse or limit a request, we will explain the reason where reasonable and lawful.
6. Backups and residual copies
Deleted information may remain in encrypted backups or provider logs for a limited period until those backups or logs expire. We will not actively restore deleted personal information except where required for security, business continuity, legal compliance or dispute handling.
7. Contact
Privacy and deletion enquiries: hello@tradietexts.com.au