Alta VistaData Retention and Disposal Policy
Version 1.0 · Effective September 2, 2026
Purpose and scope
Alta Vista (“the Company”) — the operator of the Alta Vista client-reporting product at myaltavista.com and The Alta Vista Way personal budgeting service at thealtavistaway.com.
This policy defines how long the Company retains each category of data, how it is deleted when no longer needed or when a user asks, and how it satisfies requests from individuals about their data. It applies to all production data, backups, and logs.
The Company is a small, founder-operated business. The Security Owner is the founder, who is also the sole engineer with production access. Where a policy refers to a governing body, that body is the Company’s ownership, which reviews the security program on the cadence stated in the Information Security Policy. Policies are written so that they apply unchanged as staff are added: every clause that says “personnel” binds any future employee or contractor from their first day.
Principles
- Data is kept only as long as it serves the purpose it was collected for, or as long as the law requires.
- Deletion is real: records are removed from the production database, vendor-side access is revoked, and provider backups age out on their fixed schedule.
- Consumers and clients can ask for their data to be accessed, corrected, or deleted at any time, and the Company answers within thirty days.
Retention schedule
- Personal product (The Alta Vista Way) household data (email, monthly figures, plans, derived metrics): for the life of the household. Deleted within thirty days of the user’s request, or after twenty-four months of no sign-in following a notice email.
- Bank data obtained through Plaid (account descriptors, transactions): while the bank connection is active. Disconnecting a bank immediately removes the item at Plaid (revoking the Company’s access token) and marks the connection disconnected; the transaction history already incorporated into the household’s monthly numbers is retained with the household and is deleted with it. A user may request deletion of bank transaction history independently of the household.
- Business product (Alta Vista) client data (metrics, commentary, statements, questioned transactions, notes, accounting-sync data): for the life of the firm’s engagement with that client. Purged within twelve months after the engagement ends, or sooner on the firm’s request.
- Accounting connection tokens (QuickBooks): revoked and deleted when the firm disconnects or the client is removed.
- Authentication records (sign-in events, sessions): sessions expire per the auth provider’s configuration; the auth account itself is deleted when the address holds no remaining membership.
- Application audit tables (AI questions, answers and notes, write ledger, sync history): for the life of the tenant; deleted with it by database cascade.
- Public demo sessions and their chat history: purged automatically every day.
- Platform logs: the provider’s standard retention for the Company’s plan tier (see the Logging and Monitoring Policy).
- Database backups: kept by the database provider on a rolling schedule (daily backups retained for the plan’s standard window); deleted production records leave the backups as that window rolls forward.
- Business records (contracts, invoices, correspondence): seven years, per accounting and tax requirements.
Deletion procedure
- Household deletion (personal product): on request to hello@myaltavista.com, or under the inactivity rule, the Security Owner runs the household-deletion procedure: every active bank connection is removed at Plaid, the household record is deleted, which cascades to all bank data, metrics, targets, and audit rows through the database’s foreign-key rules, and the auth account is deleted if it holds no other membership. The user is told when it is done.
- Client deletion (business product): a firm administrator removes the client in the admin console, or asks the Company to; the same cascade applies, and accounting tokens are revoked first.
- Member removal: removing an email from a tenant deletes its membership row immediately; the auth account follows if orphaned, ending every session.
- Every deletion is recorded (who asked, when, what was removed, when confirmed) in the Company’s request log, which itself holds no financial data.
Data subject requests
Requests for access, correction, deletion, or a copy of personal data are accepted at hello@myaltavista.com and, for business-product users, through their accounting firm. The Company verifies the requester controls the email address on the account (by replying to it or by a signed-in action), fulfils the request within thirty days, and answers in writing. Access requests are answered with an export of the household’s or client’s records; corrections are applied in the product; deletions follow the procedure above.
Disposal of media
The Company holds no production media of its own; disposal of storage underlying the managed platforms is performed by those providers under their attested procedures. Company workstations are full-disk encrypted and are securely erased before disposal, resale, or transfer.
Review
Reviewed at least annually and on any material change. Retention periods are re-checked against applicable law at each review.