Legal & Compliance

Updated Data Retention Policy & User Deletion Process

Transparent guidelines on how RaiseIt manages, stores, and permanently deletes your data.

Last Updated: October 24, 2025

1. Introduction & Commitment

At RaiseIt, we recognize that data privacy and user autonomy are fundamental to trust. This document outlines how long we retain different categories of information, why we retain it, and the exact process users can follow to request permanent account deletion and data erasure. This policy applies to all platform users, including campaign creators, backers, and administrative staff.

⚖️ Regulatory Compliance Our retention and deletion practices are aligned with GDPR (EU), CCPA/CPRA (California), and financial record-keeping regulations applicable to crowdfunding platforms. Where local laws require longer retention than user preferences allow, we will retain the minimum legally required data in a restricted-access state.

2. Data Retention Framework

We only retain data for as long as necessary to fulfill the purpose it was collected for, comply with legal obligations, resolve disputes, and enforce agreements. Below is our standard retention schedule:

Data Category Purpose Retention Period
Account & Profile Data User authentication, preferences, communication 24 months after account deletion/inactivity
Campaign & Backing Records Fulfillment tracking, dispute resolution, platform analytics 36 months post-campaign conclusion
Financial & Transaction Data Payment processing, tax reporting, anti-fraud compliance 7 years (legal/financial requirement)
Communications & Support Logs Customer service, security incidents, user requests 24 months after ticket resolution
Technical & Analytics Data Platform performance, security monitoring, crash logs 12 months (aggregated/anonymized thereafter)

Data retained beyond active use for legal, tax, or security purposes is stored in restricted, access-controlled environments and is never used for marketing or product development.

3. User Account & Data Deletion Process

RaiseIt provides a straightforward, self-service pathway for users who wish to close their account and request erasure of personal data. Please note that certain transactional and legal records may be retained in accordance with Section 2, but will be fully anonymized or isolated from active processing systems.

  1. Initiate Deletion Request Navigate to Settings → Account → Privacy & Data → Delete My Account. Alternatively, email privacy@raiseit.com with the subject line "Account Deletion Request" and verify your registered email.
  2. 30-Day Cooling Period Upon request, your account enters a "pending deletion" state. All public visibility is immediately removed. You may cancel the deletion and restore access at any time within this window.
  3. Permanent Erasure & Anonymization After 30 days, all personally identifiable information (PII) is permanently deleted from primary databases. Financial and campaign metadata required by law is stripped of identifiers and moved to secure archival storage.
  4. Confirmation & Documentation You will receive a final email confirmation containing a deletion certificate (request ID, timestamp, data categories processed). This serves as your audit trail.
🔒 Important Exceptions We may retain minimal data beyond your request if required to: (a) comply with lawful orders or legal processes, (b) detect/prevent fraud or security breaches, (c) resolve disputes, or (d) enforce our Terms of Service. Such data is never combined with other sources for profiling.

4. Your Rights & How to Exercise Them

Depending on your jurisdiction, you may have the right to:

  • Access, export, or correct your personal data
  • Request erasure or restriction of processing
  • Object to automated decision-making or profiling
  • Withdraw consent at any time (where processing is consent-based)

To exercise these rights, use our self-service dashboard or contact our Data Protection team. All requests are verified for security and processed within 30 calendar days, with possible extensions for complex requests as permitted by law.

5. Security & Data Minimization

RaiseIt employs industry-standard encryption (AES-256 at rest, TLS 1.3 in transit), strict access controls, and regular third-party security audits. We continuously review our data collection practices to minimize retention to what is strictly necessary. Any third-party processors (payment gateways, cloud hosting, analytics) are contractually bound to delete or return your data upon our instruction.

Questions About Your Data?

Our Privacy & Compliance team is available to assist with deletion requests, data exports, or policy clarifications.

Contact Data Protection Team