Compliance
Data Retention
How long Cresora retains data and your data retention obligations.
Cresora data retention schedule
| Data type | Retention | Notes |
|---|---|---|
| Payment records & audit trail | Not pruned | Rows are soft-deleted at most, never removed; no published fixed horizon |
| Platform request logs (internal) | 90 days in production | CloudWatch; not partner-visible — the audit trail is the partner-facing record |
| Webhook delivery history | 90 days | The delivery log in the Portal and on the API |
| ACH authorization records | 2 years after last entry | NACHA requirement; the platform stores the per-debit consent evidence, and you retain your own records too |
Where a compliance obligation needs a guaranteed window (PCI 12 months, SOX 7 years), export and archive on your side — see Audit logging.
Your data retention obligations
| Data | Your retention obligation |
|---|---|
| ACH authorization records | 2 years after last debit (NACHA) |
| Customer consent records | Per your privacy policy and applicable law |
| PCI SAQ | Retain each completed SAQ |
| NACHA authorization samples | 2 years |
Data deletion requests
Cresora honors verified data deletion requests per GDPR, CCPA, and other applicable privacy laws. Payment records required by law (PCI, AML, tax) are exempt from deletion.
To submit a data deletion request on behalf of a customer:
- Verify the customer's identity
- Contact your Cresora account manager with the data subject and request type — there is no self-service portal surface for data requests yet
Data portability
Customers can request export of their personal data (transaction history, masked payment method details, account activity). Route portability requests through your Cresora account manager as well.