eTechflow LLC · Supplement SafetyOps

Data Retention Policy

Last updated: 28 August 2026  ·  Version 1.0

1.Two kinds of data, two sets of rules

Personal data should not be kept longer than needed. But a merchant selling dietary supplements is legally required to keep safety records for six years — whether or not a report was ever sent to the FDA.

These two things are not in conflict, but they have to be handled separately. We hold data in two categories:

CategoryExamplesRule
Regulated safety recordComplaint narrative, seriousness decision, investigation, submission, audit trail, evidenceKept six years minimum while you are subscribed. After uninstall, see section 6
Ordinary copied commerce dataSynced product catalogue, imported order history with no linked complaintKept only while needed, then deleted on schedule

The difference is enforced in how data is stored, not just described in this policy. A deletion request that would destroy a regulated record goes to review. A deletion request touching only copied commerce data is carried out.

2.How long we keep things

InformationRetention periodReason
Regulated case and all its versionsSix years from receipt, while subscribedLegal recordkeeping requirement
Evidence and attachments on a caseSame as the casePart of the record
Audit trailSame as the case, minimumRecord integrity
Electronic signaturesSame as the caseMust stay linked to the version signed
Submission records and correspondenceSame as the caseEvidence of what was filed
Merchant account data after a deletion requestOrdinarily deleted within 30 daysNo legal basis to keep it
Imported order data not linked to a case24 months rollingApp functionality only
Product and catalogue dataWhile installed, plus any versions a case refers toVersioned product data is part of the record
Security and audit logs12–24 months, unless attached to a regulatory caseSecurity monitoring
Encrypted backups90 days rollingRecovery

Merchants can set a longer retention period. They cannot set a shorter one below the legal minimum, because that would put them in breach.

3.Holds

Deletion is blocked, whatever the schedule says, while any of these is in force: a legal hold, a regulatory hold, a case-specific hold, or an open investigation.

A hold is applied by an authorised user, recorded in the audit trail with a reason, and has to be lifted deliberately.

4.What happens when something is deleted

SituationWhat we do
Draft deleted before it becomes a real complaintSoft delete, with an audit entry
Case created by mistakeMarked as created in error — not destroyed
Duplicate caseLinked to the main case; the original is kept, never auto-merged
Consumer asks for deletionGoes to privacy review — see section 5
Merchant uninstallsExportable by you; then deleted as Shopify requires — see section 6
Retention period expiresControlled disposal with approval, then a destruction certificate

Never permitted: hard deletion from the interface · overwriting the database to tidy data · automatic deletion when a customer is deleted in Shopify · deleting anything before you have had the chance to export it.

Every disposal is approved, recorded, and evidenced by a destruction certificate kept in the audit trail.

5.Privacy requests and Shopify privacy webhooks

We handle all three of Shopify's required privacy webhooks — customer data request, customer redaction, and shop redaction.

The customer redaction handler does not delete an adverse-event case. A default "delete this customer's data" implementation would destroy records our merchants are legally required to hold.

Instead, we:

  1. Receive and verify the request
  2. Find all records relating to that person
  3. Separate ordinary copied Shopify data from regulated safety records
  4. Delete or export the copied commerce data — that part is done
  5. Put any regulated record into privacy review
  6. Restrict access to it and pseudonymise it as far as the law allows
  7. Document the recordkeeping reason for whatever is kept
  8. Tell the merchant what was kept, why, and what they need to do
  9. Record evidence that the request was completed

We honour verified deletion requests unless the information has to be kept for legal, regulatory, safety, fraud-prevention, dispute-resolution or legal-claims reasons. While a mandatory retention period applies, the information is restricted to authorised compliance, safety and legal purposes only. When the period ends, it is securely deleted or irreversibly anonymised, subject to normal backup cycles.

6.Uninstalling the app

The six-year recordkeeping duty belongs to the merchant — the supplement brand and its responsible person — not to eTechflow LLC. Our job is to make sure you can always take your records with you.

Shopify requires us to erase a store's data after the app is uninstalled, and sends that instruction (the shop/redact webhook) 48 hours after uninstall. We must act on it within 30 days.

So the model is export-first. The export functions below are Planned and will be in place before SafetyOps is available to any merchant — we will not take a subscription for a records system you cannot get your records out of. Current status is shown in our Trust Centre.

  1. A complete compliance archive will be downloadable at any time from your dashboard, throughout your subscription — not only at the end. Uninstall cannot always be detected before it happens, so the export never depends on catching that moment.
  2. We will warn you before uninstall wherever technically possible: "Export your six-year compliance archive before uninstalling."
  3. When we detect an uninstall we will automatically send a secure export link to the account owner.
  4. The link stays live only for the period Shopify's requirements permit, bounded by the deletion obligation above.
  5. We process the shop/redact webhook and delete Shopify-derived store and customer data as required.

We do not offer a paid archive tier. Shopify App Store apps bill through Shopify, and Shopify billing ends at uninstall — so we cannot charge for storage after you leave, and we will not pretend otherwise.

Export your records before you go. That is the arrangement, and it is stated plainly in our Terms of Service.

7.Imported historical complaints

When old complaints are imported, we keep their original receipt, decision and submission dates alongside the date they were imported. The import date is never quietly treated as the date the complaint was received.

Where the history is incomplete, that limitation is recorded on the record rather than hidden.

8.Backups and logs

Retention applies to backups, logs and derived data too, not just the live database.

Records removed under section 4 drop out of backups on the normal 90-day backup cycle rather than sitting there indefinitely. The disposal record notes the date that backup expiry finishes.

9.Review

This policy is reviewed every year, and whenever legal retention requirements, our subprocessor list, or the app's data model change.

Questions: etechflow0@gmail.com