This policy explains how long PineappleOrangeJuice.com keeps data, what is deleted automatically, what is deleted only on request, and what is currently kept until an account is closed. It forms part of our Privacy Policy and is referenced by our Terms of Service.
| Marker | Meaning |
|---|---|
| Automatic | Deleted by the application without anyone asking. |
| On request | Deleted when a venue or individual asks and we act manually. |
| Retained | Kept until the workspace is closed and the wind-down period in Section 6 expires. No automatic deletion occurs before then. |
The following are deleted automatically by the application today.
| Data | Retention | Mechanism | Detail |
|---|---|---|---|
| Sign-in, signup and password-reset attempt records | 7 days | Automatic | Used for rate limiting and abuse prevention. The email address or IP address is stored only as a keyed cryptographic hash, never in readable form. Records older than seven days are purged on each new attempt. A successful sign-in immediately clears prior failed attempts for that identifier. |
| Staff password reset tokens | 30 minutes | Automatic | Stored only as a SHA-256 hash. Single use. Requesting a new reset invalidates all outstanding tokens for that account. Used and expired tokens are removed on the next reset request for that account. |
| Telephone booking verification codes | 10 minutes | Automatic | Six-digit codes sent by email or text to verify a caller. Stored only as a keyed hash bound to the specific call. Expire after ten minutes or five failed attempts, whichever comes first. |
| AI Phone Operator private call data | Venue-configured: 0–365 days, default 30 | Automatic | A scheduled job deletes private call data once the configured number of days has elapsed since the call ended. The deletion timestamp is recorded. Setting the value to 0 deletes private call data as soon as the job next runs after the call ends. See Section 4 for the scope of deletion. |
| In-call transcript length | Most recent 64 entries | Automatic | A cap applied while the call is in progress. On a long call the earliest turns are not retained even before the retention period elapses. |
| Guest waiver links | Until 24 hours after the booking ends | Automatic | The link stops working. The signed waiver record itself is retained — see Section 5. |
| Guest self-service booking links | 90 days | Automatic | The link expires and stops working. The link is a signed token, not a password. It is not individually revocable before expiry, so a forwarded booking email remains usable for the full period. |
| Staff and platform sessions | 8 hours / 4 hours | Automatic | Staff sessions expire after 8 hours, platform administrator sessions after 4. Sessions are additionally invalidated immediately when a user is deactivated or a password is reset. |
We retain non-private operational metadata needed to run, secure and bill for the Service, including call timing, status, duration and outcome; action type, status and latency; and metered usage records.
The following are retained for as long as the workspace exists. There is currently no automatic expiry.
| Data | Retention | Detail and reason |
|---|---|---|
| Bookings and booking history | Retained | Booking records, prices, discounts applied, status timeline, staff notes, check-in and no-show marks, cancellation reasons and reschedules. Retained as the operational and financial record of the transaction. |
| Customer records | Retained | Name, email address, telephone number, purchase history and booking answers. Retained so venues can recognise returning guests and honour their history. |
| Participant rosters and signed waivers | Retained | Participant names, adult or minor classification, guardian details where captured, typed signature, signing timestamp, and an immutable snapshot of the exact waiver text and version signed. Retained as evidence of the agreement. See Section 5.1. |
| Payment and refund records | Retained | Provider, amount, currency, status, provider reference identifiers, refunds and failure messages. Required for accounting, tax and dispute handling. Contains no card data. |
| Gift voucher ledger | Retained | Issue, redemption and restoration entries. An immutable financial ledger; entries are added, never altered. |
| Notification delivery records | Retained | Recipient address, subject, a snapshot of the message body as sent, attempt count, status and any provider error. Retained so venues can evidence what was sent to a guest and when. |
| Discount codes and groups | Retained | Including single-use code batches and their redemption counts. |
| Staff accounts | Retained | Deactivating a staff member disables access and invalidates sessions but retains the account so that historical actions attributed to that person remain intelligible. |
| Platform audit log | 7 years | Records of platform-level lifecycle actions, such as suspension or reactivation of a workspace, with the administrator identity, reason and timestamp. Retained for security, dispute and compliance purposes. |
| Subscription and billing event records | 7 years | Stripe customer and subscription identifiers, status, period dates and processed billing event identifiers. Retained for accounting and tax obligations and to prevent duplicate processing of payment events. |
Confirm the correct period with your insurer and your attorney, and note that it will usually be far longer than any other retention period in this policy. Because the Service does not currently expire waiver records automatically, retaining them is the default — but you should also export and archive them independently, so that closing your account does not destroy your evidence.
Cancelling your subscription stops future billing and ends access at the end of the paid period. It does not by itself delete your data.
A suspended workspace retains all data. Suspension blocks staff sign-in, public booking pages, availability endpoints, booking widgets and new bookings, while payment and subscription events continue to be received so that financial reconciliation is not interrupted.
| Stage | Timing | What happens |
|---|---|---|
| Access ends | End of the paid period | Staff can no longer sign in. Public booking pages stop serving. Data is retained. |
| Retrieval window | 30 days after access ends | You may request a full export of your Customer Data. Contact staff@pineappleorangejuice.com. We will provide it on a commercially reasonable basis. |
| Deletion | 90 days after access ends | We delete Customer Data from live systems, except records we are required or permitted to retain: financial and tax records, the platform audit log, aggregated and de-identified statistics, and anything subject to a legal hold. |
| Backups | Up to 35 days after deletion | Data persists in encrypted backups until they age out on their normal cycle. See Section 8. |
You may ask us to delete your workspace sooner than the schedule above. Email staff@pineappleorangejuice.com from the owner address. We will confirm before acting, because deletion is irreversible. Export first.
Where a guest asks a venue to delete their personal data, the venue directs the request to us and we act on the venue’s instruction. We will delete or de-identify the guest’s contact and identity data while retaining what we must for financial, legal and anti-fraud purposes — typically the transaction amount, date, booking reference and payment record in a form that no longer identifies the individual.
We may decline or partially fulfil a request where retention is required by law, necessary to establish or defend legal claims, or necessary to prevent fraud. We will explain our reasons.
Target response time: 30 days, extendable where a request is complex.
We maintain encrypted backups for disaster recovery. Backups are not a live copy and are not used for ordinary access.
When data is deleted from live systems it remains in existing backups until those backups expire. We do not restore deleted data into live systems except in a genuine disaster recovery event, and where a restoration would reintroduce deleted records we re-apply the deletion promptly afterwards.
Where we become aware of actual or reasonably anticipated litigation, an investigation, a regulatory request or a legal obligation to preserve data, we will suspend the deletion of relevant data for as long as necessary. A legal hold overrides every period in this policy. Where we are legally permitted, we will inform the affected venue.
| Setting | Range | Default | Effect |
|---|---|---|---|
| Private call data retention (days) | 0–365 | 30 | How long AI Phone Operator private call data is kept after a call ends. See Section 4 for scope. |
| Customer self-service | On / off | On | Whether guests receive expiring self-management links in booking emails. |
| Cancellation deadline (hours) | 0–8760 | 24 | How close to the start time a guest may cancel online. |
| Reschedule deadline (hours) | 0–8760 | 24 | How close to the start time a guest may reschedule online. |
We review this policy at least annually and whenever we materially change how the Service stores or deletes data. Material changes will be notified to venue owners at least 30 days in advance.
Retention and deletion enquiries: staff@pineappleorangejuice.com
Export requests: staff@pineappleorangejuice.com
Pineapple Orange Juice, LLC, 8 The Green STE A, Dover, Kent County, DE 19901, United States