PineappleOrangeJuice.com

Data Retention Policy

Effective date: July 26, 2026  ·  Version: 1.0  ·  Applies to: Pineapple Orange Juice, LLC and the PineappleOrangeJuice.com service

This policy explains how long PineappleOrangeJuice.com keeps data, what is deleted automatically, what is deleted only on request, and what is currently kept until an account is closed. It forms part of our Privacy Policy and is referenced by our Terms of Service.

1. Principles

2. Key to the schedule

MarkerMeaning
AutomaticDeleted by the application without anyone asking.
On requestDeleted when a venue or individual asks and we act manually.
RetainedKept until the workspace is closed and the wind-down period in Section 6 expires. No automatic deletion occurs before then.

3. Retention schedule — automatic deletion

The following are deleted automatically by the application today.

DataRetentionMechanismDetail
Sign-in, signup and password-reset attempt records 7 days Automatic Used for rate limiting and abuse prevention. The email address or IP address is stored only as a keyed cryptographic hash, never in readable form. Records older than seven days are purged on each new attempt. A successful sign-in immediately clears prior failed attempts for that identifier.
Staff password reset tokens 30 minutes Automatic Stored only as a SHA-256 hash. Single use. Requesting a new reset invalidates all outstanding tokens for that account. Used and expired tokens are removed on the next reset request for that account.
Telephone booking verification codes 10 minutes Automatic Six-digit codes sent by email or text to verify a caller. Stored only as a keyed hash bound to the specific call. Expire after ten minutes or five failed attempts, whichever comes first.
AI Phone Operator private call data Venue-configured: 0–365 days, default 30 Automatic A scheduled job deletes private call data once the configured number of days has elapsed since the call ended. The deletion timestamp is recorded. Setting the value to 0 deletes private call data as soon as the job next runs after the call ends. See Section 4 for the scope of deletion.
In-call transcript length Most recent 64 entries Automatic A cap applied while the call is in progress. On a long call the earliest turns are not retained even before the retention period elapses.
Guest waiver links Until 24 hours after the booking ends Automatic The link stops working. The signed waiver record itself is retained — see Section 5.
Guest self-service booking links 90 days Automatic The link expires and stops working. The link is a signed token, not a password. It is not individually revocable before expiry, so a forwarded booking email remains usable for the full period.
Staff and platform sessions 8 hours / 4 hours Automatic Staff sessions expire after 8 hours, platform administrator sessions after 4. Sessions are additionally invalidated immediately when a user is deactivated or a password is reset.

4. Scope of AI Phone Operator retention

Private call data deletion. At the end of the venue-configured retention period, the scheduled deletion process removes:

We retain non-private operational metadata needed to run, secure and bill for the Service, including call timing, status, duration and outcome; action type, status and latency; and metered usage records.

5. Retention schedule — data kept while your workspace is active

The following are retained for as long as the workspace exists. There is currently no automatic expiry.

DataRetentionDetail and reason
Bookings and booking historyRetained Booking records, prices, discounts applied, status timeline, staff notes, check-in and no-show marks, cancellation reasons and reschedules. Retained as the operational and financial record of the transaction.
Customer recordsRetained Name, email address, telephone number, purchase history and booking answers. Retained so venues can recognise returning guests and honour their history.
Participant rosters and signed waiversRetained Participant names, adult or minor classification, guardian details where captured, typed signature, signing timestamp, and an immutable snapshot of the exact waiver text and version signed. Retained as evidence of the agreement. See Section 5.1.
Payment and refund recordsRetained Provider, amount, currency, status, provider reference identifiers, refunds and failure messages. Required for accounting, tax and dispute handling. Contains no card data.
Gift voucher ledgerRetained Issue, redemption and restoration entries. An immutable financial ledger; entries are added, never altered.
Notification delivery recordsRetained Recipient address, subject, a snapshot of the message body as sent, attempt count, status and any provider error. Retained so venues can evidence what was sent to a guest and when.
Discount codes and groupsRetained Including single-use code batches and their redemption counts.
Staff accountsRetained Deactivating a staff member disables access and invalidates sessions but retains the account so that historical actions attributed to that person remain intelligible.
Platform audit log7 years Records of platform-level lifecycle actions, such as suspension or reactivation of a workspace, with the administrator identity, reason and timestamp. Retained for security, dispute and compliance purposes.
Subscription and billing event records7 years Stripe customer and subscription identifiers, status, period dates and processed billing event identifiers. Retained for accounting and tax obligations and to prevent duplicate processing of payment events.

5.1 Waiver records deserve a deliberate decision

For venue operators. A signed liability waiver is only useful if you still hold it when a claim is brought. Personal injury limitation periods commonly run for several years, and where a minor participated, many jurisdictions suspend the limitation period until the minor reaches the age of majority — meaning a waiver signed for a 9-year-old may need to be retained for well over a decade.

Confirm the correct period with your insurer and your attorney, and note that it will usually be far longer than any other retention period in this policy. Because the Service does not currently expire waiver records automatically, retaining them is the default — but you should also export and archive them independently, so that closing your account does not destroy your evidence.

6. Account closure and wind-down

6.1 Cancellation

Cancelling your subscription stops future billing and ends access at the end of the paid period. It does not by itself delete your data.

6.2 Suspension

A suspended workspace retains all data. Suspension blocks staff sign-in, public booking pages, availability endpoints, booking widgets and new bookings, while payment and subscription events continue to be received so that financial reconciliation is not interrupted.

6.3 Wind-down and deletion

StageTimingWhat happens
Access endsEnd of the paid periodStaff can no longer sign in. Public booking pages stop serving. Data is retained.
Retrieval window30 days after access endsYou may request a full export of your Customer Data. Contact staff@pineappleorangejuice.com. We will provide it on a commercially reasonable basis.
Deletion90 days after access endsWe delete Customer Data from live systems, except records we are required or permitted to retain: financial and tax records, the platform audit log, aggregated and de-identified statistics, and anything subject to a legal hold.
BackupsUp to 35 days after deletionData persists in encrypted backups until they age out on their normal cycle. See Section 8.

6.4 Immediate deletion on request

You may ask us to delete your workspace sooner than the schedule above. Email staff@pineappleorangejuice.com from the owner address. We will confirm before acting, because deletion is irreversible. Export first.

7. Individual deletion requests

Where a guest asks a venue to delete their personal data, the venue directs the request to us and we act on the venue’s instruction. We will delete or de-identify the guest’s contact and identity data while retaining what we must for financial, legal and anti-fraud purposes — typically the transaction amount, date, booking reference and payment record in a form that no longer identifies the individual.

We may decline or partially fulfil a request where retention is required by law, necessary to establish or defend legal claims, or necessary to prevent fraud. We will explain our reasons.

Target response time: 30 days, extendable where a request is complex.

8. Backups

We maintain encrypted backups for disaster recovery. Backups are not a live copy and are not used for ordinary access.

When data is deleted from live systems it remains in existing backups until those backups expire. We do not restore deleted data into live systems except in a genuine disaster recovery event, and where a restoration would reintroduce deleted records we re-apply the deletion promptly afterwards.

9. Legal holds

Where we become aware of actual or reasonably anticipated litigation, an investigation, a regulatory request or a legal obligation to preserve data, we will suspend the deletion of relevant data for as long as necessary. A legal hold overrides every period in this policy. Where we are legally permitted, we will inform the affected venue.

10. Venue-configurable settings

SettingRangeDefaultEffect
Private call data retention (days)0–36530How long AI Phone Operator private call data is kept after a call ends. See Section 4 for scope.
Customer self-serviceOn / offOnWhether guests receive expiring self-management links in booking emails.
Cancellation deadline (hours)0–876024How close to the start time a guest may cancel online.
Reschedule deadline (hours)0–876024How close to the start time a guest may reschedule online.

11. Review of this policy

We review this policy at least annually and whenever we materially change how the Service stores or deletes data. Material changes will be notified to venue owners at least 30 days in advance.

12. Contact

Retention and deletion enquiries: staff@pineappleorangejuice.com
Export requests: staff@pineappleorangejuice.com
Pineapple Orange Juice, LLC, 8 The Green STE A, Dover, Kent County, DE 19901, United States