Principles and governance
Retention runs from a defined trigger, never from indefinite collection. The schedule below restates the Privacy Policy's retention section, which governs; the two are kept in step. The retention sweep runs monthly and reports what it removes, category by category. Anonymisation is irreversible in the reasonably available environment; pseudonymised data is still personal data and is treated as such.
Retention schedule
| Record | Trigger and period | Notes |
|---|---|---|
| Account and registration details | Life of the account; deleted straight away when the holder confirms deletion by email | Reviews are anonymised, not removed |
| Published reviews and replies | While published; a self-deleted review is purged 24 months after deletion | A review removed for breaking the rules is kept as the record of that decision, anonymised if the account is later deleted |
| Verification order details | Decision + 24 months, then the details are removed; sooner if the review is purged first | The outcome of the check stays with the review; pending details are kept until the decision |
| Review flags | Decision + 24 months | Appeals and their outcomes are kept as the record of the decision; the internal staff-action log is kept for the life of the platform |
| Review invitations | Sending + 24 months, then the address is removed | The counts remain |
| Sign-in sessions and logs | Sessions 7 days, with expired records cleared; the platform's mail log 90 days; visit-counting tokens destroyed within 26 hours | The Cookie Policy lists what lives on your device |
| Consent decision | Held on your own device only; a notice-version change asks again | Nothing is held on our servers |
| Billing | Linking identifiers for the life of the page; invoices and payment details sit with our payment processor | Accounting records at least six years, per UK tax and company law |
| Support and complaints | While the matter is open, then as the record of how it was handled | The platform's own mail log expires after 90 days |
Account-deletion workflow
Deletion is confirmed by a link emailed to the address on file. It is refused while the account still runs an open provider page, or a closed page whose paid plan is still running; otherwise it completes straight away.
On confirmation: the account record and registration details are deleted, notifications are deleted, votes are withdrawn and the counts corrected, team links are removed, managed Discord roles are cleared, and reviews are anonymised - attributed to "Former member", country "Not stated", with the account link cut everywhere and the change recorded.
Verification order details are kept under the fraud-defence retention above; the Privacy Policy states that basis.
An erasure request sent by email instead is answered normally within one month, subject to lawful extension.
Holds and exceptions
An open appeal, an active investigation or a legal claim suspends deletion for the records it concerns, for as long as that matter needs; the retention sweep skips them automatically. Rights may be refused only on a specific legal basis, with reasons and complaint information.
Secure disposal and assurance
Deletion uses the database's own removal and expiry mechanisms; keys and tokens are revoked when access ends. The sweep reports what it removes per category, clears orphaned rows, and fails loudly when a step cannot run.