Data Retention Policy
Proposed schedule · Last updated: 7 October 2026
These are target periods, not currently automated deletion guarantees. A database maintenance function is defined but is not scheduled; it archives eligible unpublished listings, deletes old viewing requests, and anonymizes old interactions. It does not purge Storage photos or inactive accounts. Account export is available, while deletion requests require manual handling. The operator must implement, test, and monitor the cleanup process before collecting production data.
| Data category | Target period | Action after expiry |
|---|---|---|
| Inactive profiles | 2 years after last login | Delete or anonymize, subject to legal requirements and a tested account-deletion workflow. |
| Draft or expired listings | 90 days after expiry | Target: delete listing records and photos after a tested Storage cleanup process exists. Current database cleanup only archives eligible unpublished records. |
| Viewing requests | 6 months after the preferred viewing date | Delete request details, subject to unresolved disputes or legal obligations. |
| Interaction logs | 90 days | Remove direct account identifiers and retain only aggregate statistics if needed. |
| Policy acknowledgement records | While the account is active | Review for deletion or anonymization when the account is closed, unless a legal obligation or claim requires retention. |
Where a legal obligation, security investigation, or unresolved dispute requires longer retention, access should be restricted and the reason documented. Photos removed from a listing must also be deleted from the private Supabase Storage bucket and any configured backups according to the provider’s backup lifecycle.