Data Retention Policy

Data Retention Policy — JITPOS Platform

Entity: AppSquire Consulting Ltd. Effective Date: 2026-05-29 Version: 1.1 Applies to: All JITPOS platforms (Storefront, iPad POS, SaaS Platform)


1. Introduction

This Data Retention Policy describes how AppSquire Consulting Ltd. ("we," "us," or "our") retains and disposes of data across the JITPOS Platform ecosystem. This policy applies to all data processed through the Storefront, iPad POS, and SaaS Platform.

Proper data retention is essential for regulatory compliance (including the Cannabis Act, PIPEDA, and provincial cannabis legislation), operational needs, and privacy protection.

2. Principles

  • Purpose Limitation: Data is retained only as long as necessary for the purpose for which it was collected
  • Legal Compliance: Minimum retention periods are observed as required by law
  • Data Minimization: We do not retain data longer than necessary
  • Secure Disposal: Data is securely deleted when no longer required

3. Retention Schedules

3.1 Customer Data (Storefront & iPad POS)

Data CategoryRetention PeriodJustification
Customer account informationDuration of account + 2 years after closureService provision, legal compliance
Date of birth / age verificationDuration of account + 2 yearsCannabis regulatory compliance
Transaction / order records7 years from transaction dateTax, regulatory, and audit requirements
Payment records (transaction confirmations)7 years from transaction dateFinancial record-keeping, dispute resolution
Shipping / delivery records7 years from delivery dateDispute resolution, regulatory compliance
Customer communications3 years from last communicationCustomer service, dispute resolution
Loyalty program dataDuration of enrollment + 24 monthsProgram administration
Marketing consent recordsDuration of consent + 36 yearsProof of consent under PIPEDA

3.2 Tenant Data (SaaS Platform)

Data CategoryRetention PeriodJustification
Tenant business informationDuration of subscription + 7 yearsContractual, legal compliance
Authorized User accountsDuration of subscription + 30 daysService provision
Subscription and billing records7 years from last paymentTax, accounting, audit
Support tickets3 years from resolutionService quality, dispute resolution
Tenant configuration dataDuration of subscription + 90 day export windowService provision

3.3 Platform Operations Data

Data CategoryRetention PeriodJustification
Application logs6 monthsDebugging, security monitoring
Access / authentication logs12 monthsSecurity, compliance auditing
API logs12 monthsPerformance monitoring, debugging
Error logs6 monthsDebugging, quality assurance
Security event logs2 yearsSecurity investigation, compliance

3.4 Analytics and Cookies

Data CategoryRetention PeriodJustification
Website analytics (raw)14 monthsPerformance optimization
Website analytics (aggregated)5 yearsTrend analysis
Session cookiesEnd of browser sessionStorefront functionality
Persistent cookiesSee Cookie PolicyPer cookie purpose

3.5 Backups

Backup TypeRetention PeriodNotes
Daily backups35 daysRolling deletion
Weekly backups12 weeksRolling deletion
Monthly backups6 monthsRolling deletion

4. Regulatory Minimum Retention

Certain records must be retained for minimum periods under applicable law:

RegulationData TypeMinimum Period
Cannabis Act / Provincial Cannabis LegislationTransaction records, age verification records[VERIFY WITH LEGAL — varies by province]
Income Tax ActFinancial and transaction records6 years from end of fiscal year
PIPEDAConsent recordsDuration of consent relationship + reasonable period
Provincial Employment StandardsEmployee-related records (if applicable)[VERIFY — varies by province]

Note: Where regulatory minimums exceed the periods in Section 3, the regulatory minimum applies.

5. Data Disposal

5.1 Secure Deletion

When data reaches the end of its retention period, it will be securely deleted using:

  • Cryptographic erasure for encrypted data stores
  • Secure overwrite or destruction for other storage media
  • API-based deletion for third-party services (e.g., payment processors)

5.2 Backup Disposal

Data in backups will be purged according to the backup retention schedule in Section 3.5. Data may persist in backups beyond its primary retention period until the backup is purged.

5.3 Exception: Legal Holds

Data subject to a legal hold (e.g., litigation, regulatory investigation) must not be deleted until the hold is released, regardless of the standard retention period.

6. Tenant Data on Termination

When a Tenant's subscription ends:

  1. Export Window: Tenant Data is available for export for 30 days
  2. Deletion: After the export window, Tenant Data is deleted from active systems within 90 days
  3. Backups: Tenant Data is purged from backups within 180 days of deletion
  4. Certification: Upon request, we provide written certification of deletion
  5. Exceptions: Data required by law (e.g., transaction records, age verification) is retained for the applicable regulatory period

7. Customer Data Deletion Requests

7.1 Storefront Customers

Customers may request deletion of their account and personal information. Upon receiving a valid request:

  • Account and profile data are deleted within 30 business days
  • Transaction records are retained for the regulatory minimum period (anonymized where possible)
  • Age verification records are retained as required by law

7.2 iPad POS Customers

Customers who provided personal information at point of sale may request deletion by contacting the Retailer or us directly.

8. Responsibilities

RoleResponsibility
AppSquire Consulting Ltd.Implementing and enforcing retention schedules, secure disposal
TenantsCooperating with retention obligations, not requesting retention beyond legal requirements
Privacy OfficerOverseeing compliance, reviewing retention schedules annually

9. Review and Updates

This policy will be reviewed at least annually and updated as necessary to reflect changes in:

  • Applicable laws and regulations
  • Business requirements
  • Platform capabilities
  • Industry best practices

10. Contact Information

Privacy Officer AppSquire Consulting Ltd. 7313 Roper Rd NW info@jitpos.net 888-481-3323


Revision History

VersionDateChanges
1.02026-05-29Initial Document Creation
1.12026-05-29Updated templating structure