G-312Legal
Planbase Data Retention and Deletion
Related: Privacy Policy §11–12 · Subprocessors · Data Processing Addendum §11 · Subscription and Refund Policy
Summary in plain language
- We keep your data while your account is open and for a short time after, then delete it or strip out what identifies you.
- The exception is the tester programme: if you test DimSum for us, your tester checklists, feedback, crash reports and the record that you accepted the tester agreement are kept indefinitely, as the history of how DimSum was tested. You can ask us to delete it at any time, and we will unless we must keep it, e.g. the record that you accepted the tester agreement.
- Your job files are on your computer; we don’t hold them unless you sent them in a diagnostic bundle or, later, synced them with DimSum Cloud.
- DimSum Cloud files are kept 3 months after you cancel, with a download email straight away and another 7 days before deletion.
- Some records must be kept longer by law (such as tax records) or to prove what happened (such as the license agreement you accepted). We keep only what’s needed.
- You can ask us to delete your data at any time: email privacy@planbaseestimating.com.
1. Definitions
- “Closed” means an Account was deleted (by you, through Clerk, or by us on request), or a Workspace was closed after its license lapsed and the lapse period in the Subscription and Refund Policy ended.
- “Delete” means removed from our live systems so it can’t be used. Copies in backups are removed when the backup expires (§5).
- “Anonymise” means changing a record so it no longer identifies anyone, for example replacing a name and email with a random ID.
- “Retention period” means the longest time we keep a kind of data, measured from the event in the table.
- Other terms have the meanings in the Privacy Policy §2.
2. Principles
2.1 We keep personal data only as long as needed for the purpose we collected it for, or as long as the law requires. Tester-programme records are kept indefinitely (row 29), because they are the record of how each version of DimSum was tested.
2.2 When a retention period ends, we delete or anonymise the data within 30 days.
2.3 Legal holds. If data is needed for a dispute, investigation or legal claim, we keep it until that ends, even past the period below.
2.4 Aggregated data that can’t identify anyone (such as how many Workspaces use the beta channel) isn’t covered by this schedule.
3. Retention schedule
“Status” says whether deletion at the end of the period already happens automatically in our systems, or still needs to be built (to build). Until it’s built, we delete manually on request and at least quarterly.
| # | Data | Where | Kept for | Then | Status |
|---|---|---|---|---|---|
| 1 | Account (name, email, Clerk ID, last seen) | D1 users; Clerk |
While the Account is open; then 90 days after it’s closed | Name and email anonymised; the ID kept so the audit log still makes sense. Zac deletes the sign-in in Clerk, and Clerk then deletes its copy | To build (today a deleted user’s row and email stay, marked deleted) |
| 2 | Workspace (name, plan, status, seats, Paddle and Keygen IDs, last 4 of the license key, notes) | D1 workspaces, notes |
While the Workspace is open; then 90 days after it’s closed | Deleted, except the billing fields in row 4 | To build |
| 3 | Memberships and invitations | D1 memberships, invitations |
Memberships: while the person is a member. Invitations: 90 days after accepted, revoked or unanswered | Deleted | To build (removing a member already deletes the membership) |
| 4 | Billing records we hold (Paddle customer and subscription IDs; each subscription, transaction, refund, credit and chargeback with its date, amount, tax, status and invoice link) | D1 workspaces, billing_subscriptions, billing_transactions, billing_adjustments; audit log |
7 years after the transaction, the period tax and accounting records must be kept | Deleted. Kept (not deleted or anonymised) when someone asks for deletion | To build |
| 5 | Paddle’s records (card, billing address, tax, invoices) | Held by Paddle, not us | Paddle’s own retention, as merchant of record | Per Paddle’s privacy policy | Paddle’s |
| 6 | License records | Keygen | While the Workspace is open; then 90 days | Deleted in Keygen | To build |
| 7 | Activated computers (name, fingerprint, OS, version, channel, check-ins) | D1 machines; Keygen |
Active: while activated. Deactivated: 12 months after deactivation (to show history and stop slot abuse) | Deleted. A computer named in a kept EULA acceptance (row 11) is anonymised, not deleted: its row stays without its name, fingerprint or Keygen ID. Keygen’s machine record is deleted at deactivation already | D1 to build; Keygen automatic |
| 8 | Device tokens (hashed) | D1 device_tokens |
Until revoked, or 180 days without use (then they stop working); the hash is deleted 30 days after that | Deleted | Expiry automatic; deletion to build |
| 9 | Sign-in hand-off codes (hashed) | D1 desktop_codes |
5 minutes to use; deleted about 1 day after expiry | Deleted | Automatic |
| 10 | Installer download links (hashed) | D1 download_links |
Short-lived; deleted about 1 day after expiry | Deleted | Automatic |
| 11 | EULA acceptances | D1 eula_acceptances |
While the Account is open, then for the limitation period for contract claims under Missouri law (up to 10 years) | Deleted. Kept when someone asks for deletion: it is the proof of what was agreed | To build |
| 12 | Audit log | D1 audit_log |
3 years, or longer for entries needed as billing records (row 4) | Deleted; entries about a closed Account are anonymised with it (row 1) | To build |
| 13 | Email records (which email went to whom and when: service emails, trial and offer emails, thank-you and feedback replies, release emails, newsletter issues and outreach; the provider’s message ID) | D1 email_log, release_email_sends, newsletter_sends, outreach_sends |
While the Workspace is open; then 90 days. Newsletter sends: row 18. Outreach sends: row 30 | Deleted | To build |
| 14 | Email choices (unsubscribe token, opt-out date) | D1 email_prefs |
While the Account exists. The fact that an address opted out is kept as long as needed to honour it | Deleted with the Account, except a suppression entry if needed | To build |
| 15 | Email delivery logs | Resend | Resend’s retention on our plan | Deleted by Resend | Resend’s |
| 16 | Diagnostic bundles (logs, note, email, versions; a job file only if you ticked it) | R2 dimsum-diagnostics; D1 diagnostics |
Until the issue is closed, then 90 days; never more than 12 months from receipt | The .zip and its row deleted | To build |
| 17 | Beta sign-ups | D1 planbase-site beta_signups |
Until the beta ends, then 12 months, or sooner if you ask | Deleted | To build |
| 18 | Newsletter sign-ups (weekly newsletter) | D1 newsletter_subscribers; which issue went to which address in newsletter_sends |
Pending, never confirmed: 30 days. Confirmed: until you unsubscribe (the send records with it). Unsubscribed: email and date kept as a suppression record so we don’t mail you again | Deleted or kept as suppression | To build |
| 19 | Support email | Our support mailbox (subprocessors.md) | 3 years from the last message in the conversation | Deleted | Manual |
| 20 | Webhook receipts (provider, event ID, type, times; no payload) | D1 webhook_events |
90 days | Deleted | To build |
| 21 | Release channel overrides (“move to Beta” for a user, computer or Workspace) | D1 channel_overrides |
Until removed, or the subject is deleted | Deleted | To build (with rows 1, 2, 7) |
| 22 | Platform error reports | Sentry | Sentry’s retention on our plan | Deleted by Sentry | Sentry’s |
| 23 | Application and request logs | Cloudflare (Workers Logs, network logs) | Cloudflare’s retention periods | Deleted by Cloudflare | Cloudflare’s |
| 24 | Sign-in sessions and security data | Clerk | While the Account exists, per Clerk’s retention | Deleted by Clerk with the Account | Clerk’s |
| 25 | Website visit counts | Cloudflare Web Analytics | Cloudflare’s retention; holds no identifiers | Deleted by Cloudflare | Cloudflare’s |
| 26 | DimSum Cloud content (coming) | R2 | While DimSum Cloud is active. After cancelling: 3 months, with a download email straight away and another 7 days before deletion. If the license lapses: a 2-month grace period, then the 3 months | Deleted | To build with Cloud |
| 27 | Remote Workstation records (coming: pairings, session start/end, devices) | Cloudflare (Durable Objects) | Pairings: until unpaired or the Account is closed. Session records: 90 days. The session’s picture and input are never stored | Deleted | To build with Cloud |
| 28 | Job files on your computer | Your computer | Your choice. We don’t hold them | Delete them yourself, or uninstall DimSum | n/a |
| 29 | Tester-programme records (only if we invite you to test): your tester checklists (task lists, marks, notes, screenshots and survey answers), the feedback and crash reports you send as a tester, and the record of which version of the Beta and Tester Agreement you accepted, and when | D1 testers, tester_agreement_acceptances, tester_surveys, tester_task_lists and its steps, marks and runs, feedback; R2 dimsum-diagnostics (screenshots) |
Indefinitely, including after your testing ends. You can ask us to delete it at any time, and we will unless we must keep it, e.g. the record that you accepted the tester agreement. A diagnostic bundle (logs, and a job file if you ticked it) attached to a tester’s report still follows row 16 | Kept | n/a |
| 30 | Prospect records (outreach: name, business email, company, trade, city, note, tags, emails sent, replies, bounces, opt-outs) | D1 outreach_contacts, outreach_sends, with its replies, notes and reminders (rows 34, 35) |
While useful for telling the prospect about DimSum; deleted when they ask | Deleted, except the do-not-email entry (row 31) | Manual |
| 31 | Do-not-email list (address, reason, source, date) | D1 email_suppressions |
Indefinitely, so we never email that address again | Kept | n/a |
| 32 | Terms of Service and Privacy Policy acceptances (the versions, time, where accepted (sign-up), country, browser user agent) | D1 terms_acceptances |
While the Account is open, then for the limitation period for contract claims under Missouri law (up to 10 years), as row 11 | Deleted. Kept when someone asks for deletion: it is the proof of what was agreed | To build |
| 33 | Email delivery events (our copy of Resend’s events for each email: sent, delivered, delayed, bounced, complained) | D1 email_events |
As the email record it belongs to (row 13) | Deleted. A bounce or spam complaint also puts the address on the do-not-email list (row 31) | To build |
| 34 | Correspondence in our CRM (the text of replies to our outreach, received at r+…@replies.planbaseestimating.com through Cloudflare Email Routing, logged, then forwarded to hello@; copies of emails Zac sends by hand with log@replies.planbaseestimating.com in Bcc) | D1 crm_messages; the forwarded copy in our mailbox (row 19) |
With the record it belongs to: a prospect’s per row 30; a customer’s 3 years from the last message, as support email (row 19) | Deleted | Manual |
| 35 | CRM notes and follow-up reminders (our notes on a contact or Workspace, and the date of the next follow-up) | D1 crm_notes, crm_reminders, notes |
With the contact or Workspace record they belong to (rows 2, 30) | Deleted with it | Manual |
| 36 | Feedback and crash reports from customers who aren’t testers (what you wrote, your details, screenshots, our notes and replies) | D1 feedback, feedback_notes, feedback_acks, feedback_attachments; R2 dimsum-diagnostics |
While the Account is open; then 90 days after it’s closed. Testers: row 29. An attached diagnostic bundle: row 16 | Deleted | To build |
| 37 | Company details and Locations (company details; each location’s contact and report details, logo, tax rate, suppliers, notes and members) | D1 workspace_profiles, locations; R2 dimsum-diagnostics (logos) |
While the Workspace is open; then 90 days after it’s closed (row 2) | Deleted with the Workspace. One person’s deletion only removes their email from it | To build |
4. Deleting your Account
4.1 How. A Close my account page in the portal, which checks your Workspace admin duties first, is on the way. Until it’s available, email privacy@planbaseestimating.com from the Account’s address and we’ll close the Account for you.
4.2 Before you delete.
- If you’re the only admin of a Workspace with other members, make someone else admin first, or close the Workspace.
- Deactivate your computers to free their seats (deleting the Account also signs DimSum out on them).
- Ask us for Download all my data (§6) to keep a copy of everything stored with us.
4.3 What happens. Zac deletes your sign-in in Clerk, and Clerk then deletes its copy. Your devices are signed out. Your personal data is deleted or anonymised under §3, except what the law or §2.3 requires us to keep. We’ll confirm by email when it’s done.
4.3A What a deletion keeps. When we delete or anonymise someone’s data, we keep three kinds of record: agreement records (the EULA, Terms of Service and Privacy Policy, and tester agreement acceptances), billing records (row 4) and the do-not-email entry (row 31). A computer named in a kept EULA acceptance is anonymised, not deleted: its row stays without its name, fingerprint or license ID (row 7).
4.4 A Workspace’s data (its name, members, licenses, and DimSum Cloud content) belongs to the Workspace. Deleting one member’s Account doesn’t delete the Workspace’s data.
4.5 Paddle. Deleting your Account doesn’t delete Paddle’s records. Ask Paddle directly (its privacy policy explains how), or ask us and we’ll pass your request on.
5. Backups
5.1 Our databases (Cloudflare D1) keep an automatic restore history (Time Travel) of up to 30 days. Deleted data stays in that history until it ages out, and is then gone.
5.2 Stored files (Cloudflare R2) aren’t versioned, so a deleted file is gone at once.
5.3 We don’t restore deleted personal data from a backup except to recover from an incident, and then we re-apply any deletions made since.
6. “Download all my data”
6.1 What it is. One download (a .zip) of everything we hold about you, or, for a Workspace Admin, about the Workspace: a machine-readable copy (JSON) of every record in §3, and the files we store for you (diagnostic bundles, feedback attachments, logos; DimSum Cloud content when it exists). It’s part of every license: your work is never held hostage.
6.2 How. It’s available now, on request: email support@planbaseestimating.com or privacy@planbaseestimating.com from the Account’s address. We send it within 30 days, usually much sooner. Your job files are already on your computers.
6.3 After closure. We can still send it for 90 days after an Account closes (the period in row 1).
6.4 Unlocking. Until a view-only viewer ships, the latest version of DimSum opens unlocked files read-only without a License (see the EULA).
7. Requests and questions
Email privacy@planbaseestimating.com. We’ll answer within the times in the Privacy Policy §12.3.
Change log
| Date | Version | Change |
|---|---|---|
| 2026-10-07 | 1.0 | Published. Same day: row 29, tester-programme records kept indefinitely, with the right to ask for deletion; the summary and §2.1 say so. |
| 2026-10-07 | 1.0 | Same day, added after attorney review (show at the next review): rows 30 and 31, prospect records (outreach) and the do-not-email list. |
| 2026-10-07 | 1.0 | Same day, added after attorney review (show at the next review): billing records spelled out (row 4); email records name every kind (row 13); rows 32-37 (Terms and Privacy acceptances, Resend delivery events, CRM correspondence, CRM notes and reminders, feedback from non-testers, company details and Locations); a kept EULA acceptance’s computer is anonymised, not deleted (row 7); what a deletion keeps (4.3A); Zac deletes the Clerk sign-in; Download all my data is available on request (§4.2, §6). |
Planbase Estimating LLC, 3418 East 104th Street, Kansas City, MO 64137, USA. Questions: legal@planbaseestimating.com.All legal documents.