eTechflow LLC · Supplement SafetyOps
Personal data should not be kept longer than needed. But a merchant selling dietary supplements is legally required to keep safety records for six years — whether or not a report was ever sent to the FDA.
These two things are not in conflict, but they have to be handled separately. We hold data in two categories:
| Category | Examples | Rule |
|---|---|---|
| Regulated safety record | Complaint narrative, seriousness decision, investigation, submission, audit trail, evidence | Kept six years minimum while you are subscribed. After uninstall, see section 6 |
| Ordinary copied commerce data | Synced product catalogue, imported order history with no linked complaint | Kept only while needed, then deleted on schedule |
The difference is enforced in how data is stored, not just described in this policy. A deletion request that would destroy a regulated record goes to review. A deletion request touching only copied commerce data is carried out.
| Information | Retention period | Reason |
|---|---|---|
| Regulated case and all its versions | Six years from receipt, while subscribed | Legal recordkeeping requirement |
| Evidence and attachments on a case | Same as the case | Part of the record |
| Audit trail | Same as the case, minimum | Record integrity |
| Electronic signatures | Same as the case | Must stay linked to the version signed |
| Submission records and correspondence | Same as the case | Evidence of what was filed |
| Merchant account data after a deletion request | Ordinarily deleted within 30 days | No legal basis to keep it |
| Imported order data not linked to a case | 24 months rolling | App functionality only |
| Product and catalogue data | While installed, plus any versions a case refers to | Versioned product data is part of the record |
| Security and audit logs | 12–24 months, unless attached to a regulatory case | Security monitoring |
| Encrypted backups | 90 days rolling | Recovery |
Merchants can set a longer retention period. They cannot set a shorter one below the legal minimum, because that would put them in breach.
Deletion is blocked, whatever the schedule says, while any of these is in force: a legal hold, a regulatory hold, a case-specific hold, or an open investigation.
A hold is applied by an authorised user, recorded in the audit trail with a reason, and has to be lifted deliberately.
| Situation | What we do |
|---|---|
| Draft deleted before it becomes a real complaint | Soft delete, with an audit entry |
| Case created by mistake | Marked as created in error — not destroyed |
| Duplicate case | Linked to the main case; the original is kept, never auto-merged |
| Consumer asks for deletion | Goes to privacy review — see section 5 |
| Merchant uninstalls | Exportable by you; then deleted as Shopify requires — see section 6 |
| Retention period expires | Controlled disposal with approval, then a destruction certificate |
Never permitted: hard deletion from the interface · overwriting the database to tidy data · automatic deletion when a customer is deleted in Shopify · deleting anything before you have had the chance to export it.
Every disposal is approved, recorded, and evidenced by a destruction certificate kept in the audit trail.
We handle all three of Shopify's required privacy webhooks — customer data request, customer redaction, and shop redaction.
The customer redaction handler does not delete an adverse-event case. A default "delete this customer's data" implementation would destroy records our merchants are legally required to hold.
Instead, we:
We honour verified deletion requests unless the information has to be kept for legal, regulatory, safety, fraud-prevention, dispute-resolution or legal-claims reasons. While a mandatory retention period applies, the information is restricted to authorised compliance, safety and legal purposes only. When the period ends, it is securely deleted or irreversibly anonymised, subject to normal backup cycles.
The six-year recordkeeping duty belongs to the merchant — the supplement brand and its responsible person — not to eTechflow LLC. Our job is to make sure you can always take your records with you.
Shopify requires us to erase a store's data after the app is uninstalled, and sends that instruction (the shop/redact webhook) 48 hours after uninstall. We must act on it within 30 days.
So the model is export-first. The export functions below are Planned and will be in place before SafetyOps is available to any merchant — we will not take a subscription for a records system you cannot get your records out of. Current status is shown in our Trust Centre.
We do not offer a paid archive tier. Shopify App Store apps bill through Shopify, and Shopify billing ends at uninstall — so we cannot charge for storage after you leave, and we will not pretend otherwise.
Export your records before you go. That is the arrangement, and it is stated plainly in our Terms of Service.
When old complaints are imported, we keep their original receipt, decision and submission dates alongside the date they were imported. The import date is never quietly treated as the date the complaint was received.
Where the history is incomplete, that limitation is recorded on the record rather than hidden.
Retention applies to backups, logs and derived data too, not just the live database.
Records removed under section 4 drop out of backups on the normal 90-day backup cycle rather than sitting there indefinitely. The disposal record notes the date that backup expiry finishes.
This policy is reviewed every year, and whenever legal retention requirements, our subprocessor list, or the app's data model change.
Questions: etechflow0@gmail.com