Data policy
What we store, for how long and who can see it. The periods below are not a declaration: automatic deletion runs on these same numbers.
Retention periods
| What | How long | Why |
|---|---|---|
| Messages | 183 days | Six months is how long a message can still be wanted when something is being sorted out. After that it is deleted automatically, the ones you hid included. |
| Profile operations | 90 days after it finishes | Installing, enabling and deleting a profile. An unfinished operation is not deleted: while it is still open, it needs looking into. |
| Raw data from the payment provider | 365 days | The provider's response is what a dispute with it rests on. The payment itself and its amount stay in your history forever. |
| Profiles deleted from the chip | 183 days after deletion | The same as messages. A profile that sits in a cell is not deleted at all. |
| Log of staff actions | 1095 days | Which staff member opened or exported your messages, when and for what reason. The period is longer than the rest: this is a record of access to your data, and it is what a complaint against us is examined on. |
| History of payments and charges | no time limit | Accounting. Movements of money are not deleted on a timer. |
What we know about you
- Your email address. That is all: we require no KYC and ask for no documents.
- Your rentals, payments and balance.
- Incoming messages on the slots you rent — text, sender, time. Message text is not encrypted in the database: it is there to be shown back to you.
- The activation code is encrypted. It is a single-use secret, and once the install operation finishes it is wiped from our working data.
We do not collect the IP addresses you log in from: there is no such data model in the system.
Which of our staff can see your messages
A client's messages can be opened in exactly one place in the staff interface, and three rules apply there:
- A reason is required before anything is shown, not after. Without one the search finds nothing.
- What gets logged is not that a page was opened but what was actually shown: the query, the number of rows, the message ids, the time, the staff member and their address.
- An export to a file is a separate record from a plain view: the file leaves our system and lives on outside it, and that difference matters.
Entries in this log are immutable and are kept longer than your own data: a record of access to your messages has to outlive the messages.
Hiding and deletion
You can hide a message on your side — it leaves the feed and comes back whenever you want it. It does not leave the database until the retention period runs out: hiding is reversible, deletion is not, and we do not offer a button that destroys data you may need back when a dispute is being sorted out.
Once the retention period is up, a message is deleted automatically, hidden ones included. Every such run is logged: what was deleted, for which period and how many rows.
Exporting your own data
You can export your messages yourself from your account — CSV or JSON, for any period. It is the same mechanism support uses: the contents are identical, only the file format differs.
Every export carries a fingerprint of the file and of each message in it, so its contents can be checked without taking our database on trust.