Skip to main content
Cresora Commerce
Compliance

Data Retention

How long Cresora retains data and your data retention obligations.

Cresora data retention schedule

Data typeRetention periodNotes
Payment records7 yearsPCI DSS Requirement 10; required for dispute resolution
API request logs90 daysAvailable in audit log
Webhook delivery logs30 daysAvailable in Portal
Settlement reports7 yearsRequired for financial records
User activity logs1 yearPortal login and action history
ACH authorization records2 years after last entryNACHA requirement; stored by you, not Cresora

Your data retention obligations

DataYour retention obligation
ACH authorization records2 years after last debit (NACHA)
Customer consent recordsPer your privacy policy and applicable law
PCI SAQRetain each completed SAQ
NACHA authorization samples2 years

Data deletion requests

Cresora honors verified data deletion requests per GDPR, CCPA, and other applicable privacy laws. Payment records required by law (PCI, AML, tax) are exempt from deletion.

To submit a data deletion request on behalf of a customer:

  1. Verify the customer's identity
  2. Submit via Partner Portal → Compliance → Data Requests → New Request
  3. Specify the data subject and request type

Cresora processes deletion requests within 30 days and provides confirmation.

Data portability

Customers can request export of their personal data. Cresora provides:

  • Transaction history
  • Payment method details (masked)
  • Account activity

Submit portability requests via Partner Portal → Compliance → Data Requests → New Request → Type: Export.