Skip to main content
Cresora Commerce
Compliance

Data Retention

How long Cresora retains data and your data retention obligations.

Cresora data retention schedule

Data typeRetentionNotes
Payment records & audit trailNot prunedRows are soft-deleted at most, never removed; no published fixed horizon
Platform request logs (internal)90 days in productionCloudWatch; not partner-visible — the audit trail is the partner-facing record
Webhook delivery history90 daysThe delivery log in the Portal and on the API
ACH authorization records2 years after last entryNACHA requirement; the platform stores the per-debit consent evidence, and you retain your own records too

Where a compliance obligation needs a guaranteed window (PCI 12 months, SOX 7 years), export and archive on your side — see Audit logging.

Your data retention obligations

DataYour retention obligation
ACH authorization records2 years after last debit (NACHA)
Customer consent recordsPer your privacy policy and applicable law
PCI SAQRetain each completed SAQ
NACHA authorization samples2 years

Data deletion requests

Cresora honors verified data deletion requests per GDPR, CCPA, and other applicable privacy laws. Payment records required by law (PCI, AML, tax) are exempt from deletion.

To submit a data deletion request on behalf of a customer:

  1. Verify the customer's identity
  2. Contact your Cresora account manager with the data subject and request type — there is no self-service portal surface for data requests yet

Data portability

Customers can request export of their personal data (transaction history, masked payment method details, account activity). Route portability requests through your Cresora account manager as well.