Pace Data Retention and Deletion Policy

Version: 1.0
Effective date: June 30, 2026
Contact: patrickrgloria@gmail.com

Purpose

This policy defines how Pace retains, disconnects, deletes, and restores consumer financial data. It supports the privacy, user-control, and security requirements for the personal budgeting application and Plaid production diligence.

Scope

This policy applies to user profile data, settings, budgets, accounts, balances, transactions, bills, imports, Plaid/provider access tokens, consent records, sessions, application logs, and backups.

Retention Rules

Active application data is retained while a user account is active and while needed to provide budgeting, transaction history, cash-flow, and support features.

Provider access tokens are retained only while a user keeps the associated account connected. Tokens must be removed when the account is disconnected or when a verified deletion request is completed.

Operational logs are retained according to the configured cloud logging retention period and must not intentionally include cookies, request bodies, response bodies, provider tokens, API keys, bank credentials, or full financial payloads.

Database backups are retained according to the Cloud SQL backup configuration. Backup copies may contain data deleted from the live database until those backups expire according to the configured retention window.

Account Disconnect

Delete Account Data

When a user requests deletion of account data, Pace removes linked accounts, encrypted provider tokens, transactions, budgets, bills, settings, consents, imports, and active sessions from active application storage.

The user profile and authentication record may be retained only as needed to preserve login, security, legal, fraud-prevention, or operational requirements unless full account deletion is separately requested and verified.

Backups

Deleted data may remain in encrypted backups until the backup retention period expires. Backups are used for disaster recovery and are not used to restore deleted user data except where required for security, legal, or incident response purposes.

Current Implementation

The application provides server-side APIs to disconnect linked accounts and delete user financial data. The delete-data action removes linked accounts, encrypted provider tokens, transactions, budgets, bills, settings, consents, imports, and active sessions from active storage, then signs the user out.

Contact

Patrick Gloria
patrickrgloria@gmail.com