Data Retention Policy

Effective Date: 8th June 2026Last Updated: 7th June 2026
Version 1.0GhanaGDPR Compliant

1. Introduction

This Data Retention Policy outlines how Pickseat Transport Services ("Pickseat", "we", "our", or "us") manages the retention and deletion of personal and business data collected through our platform. This policy is designed to:

  • Ensure compliance with applicable laws and regulations
  • Protect the privacy and security of user data
  • Balance operational needs with data minimization principles
  • Provide transparency about our data retention practices

This policy applies to all data collected by Pickseat from users, drivers, vehicle operators, advertisers, and other stakeholders who interact with our platform.

2. Scope

This policy covers all categories of data collected by Pickseat, including:

  • Personal information (names, contact details, identification)
  • Account information and credentials
  • Location and route data
  • Usage and analytics data
  • Transaction and payment information
  • Driver and vehicle information
  • Communication records
  • System logs and technical data

This policy applies to all data processing activities, whether automated or manual, and covers data stored in active systems, backups, archives, and third-party services.

3. Retention Principles

Our data retention practices are guided by the following principles:

  • Data Minimization - We collect and retain only the data necessary for legitimate purposes
  • Purpose Limitation - Data is retained only as long as needed for the purposes for which it was collected
  • Legal Compliance - We comply with all applicable legal and regulatory retention requirements
  • Security - Data is securely stored and protected throughout its lifecycle
  • Transparency - Users are informed about how long their data is retained
  • Accountability - We maintain records of our retention practices and regularly review them

We retain data for no longer than is necessary for the purposes described in this policy, unless a longer retention period is required by law.

4. Retention Periods

The following are our standard retention periods for different categories of data. Actual retention periods may vary based on specific circumstances and legal requirements.

4.1 Account Data

Data TypeRetention PeriodPurpose
User account informationWhile account is active + 30 daysService provision and account management
Login credentialsWhile account is active + 30 daysAuthentication and security
Account preferencesWhile account is active + 30 daysPersonalization
Authentication logs2 yearsSecurity auditing

4.2 Personal Information

Data TypeRetention PeriodPurpose
Full name and contact detailsWhile account is active + 3 yearsCommunication and verification
Email addressWhile account is active + 3 yearsCommunication and account recovery
Phone numberWhile account is active + 3 yearsVerification and communication
Profile photographWhile account is active + 30 daysUser identification
Date of birthWhile account is active + 3 yearsAge verification and compliance

4.3 Driver and Vehicle Data

Data TypeRetention PeriodPurpose
Driver license informationWhile driver is active + 5 yearsVerification and legal compliance
Vehicle registration documentsWhile vehicle is active + 5 yearsVerification and legal compliance
Insurance certificatesWhile active + 7 yearsLegal and liability purposes
Vehicle inspection records3 yearsSafety and quality assurance
Driver background checks5 yearsSafety and legal compliance

4.4 Location and Route Data

Data TypeRetention PeriodPurpose
Real-time location data30 days (anonymized after)Service provision and route optimization
Route history90 daysUsage analytics and improvement
Anonymized location data2 yearsResearch and analytics
Location permissions consentWhile account is active + 3 yearsConsent documentation

4.5 Transaction and Payment Data

Data TypeRetention PeriodPurpose
Transaction records7 yearsLegal compliance and accounting
Payment references7 yearsAudit and dispute resolution
Payment processor dataAs per processor's policyPayment processing
Billing information7 yearsAccounting and legal compliance
Refund records7 yearsFinancial record-keeping

4.6 Communication Data

Data TypeRetention PeriodPurpose
Support tickets and chats3 yearsCustomer service and quality
Email communications3 yearsRecord-keeping and service
In-app messages90 daysCommunication facilitation
Survey responses2 yearsService improvement

4.7 Usage and Analytics Data

Data TypeRetention PeriodPurpose
App usage logs2 yearsAnalytics and improvement
Feature usage data2 yearsProduct development
Performance metrics2 yearsService optimization
Crash reports1 yearTechnical debugging
Anonymized analyticsIndefiniteResearch and business intelligence

4.8 System and Technical Data

Data TypeRetention PeriodPurpose
Server logs90 daysSystem monitoring and security
IP addresses90 daysSecurity and fraud prevention
Device informationWhile account is activeDevice management and compatibility
System backups30 daysDisaster recovery

4.9 Marketing Data

Data TypeRetention PeriodPurpose
Marketing consent recordsWhile consent is valid + 3 yearsConsent documentation
Advertising interaction data2 yearsMarketing optimization
Newsletter subscriptionsWhile subscribed + 3 yearsMarketing communication

5. Data Deletion Process

When data reaches the end of its retention period, we take the following steps:

5.1 Deletion Methods

  • Permanent Deletion - Data is securely deleted from active systems
  • Anonymization - Identifying information is removed so data can no longer be linked to specific individuals
  • Aggregation - Data is combined with other data for statistical purposes without identifying individuals
  • Archiving - Data may be moved to secure archives for legal or compliance purposes

5.2 Deletion Triggers

Data deletion may be triggered by:

  • Expiration of retention period
  • User account deletion request
  • User request to delete specific data
  • Withdrawal of consent
  • Legal obligation to delete
  • Security or integrity concerns

5.3 Deletion Verification

  • Automated verification - Systems verify that deletion processes have been completed successfully
  • Audit trails - Deletion activities are logged for accountability
  • Regular audits - We conduct periodic audits to ensure data is being retained and deleted properly

6. Data Archiving

Some data may be archived for long-term storage when required for legal, compliance, or business purposes.

6.1 Archive Criteria

Data may be archived if it is:

  • Required by law or regulation to be retained
  • Needed for ongoing legal proceedings
  • Relevant to dispute resolution
  • Essential for historical research or statistical purposes
  • Required for business continuity

6.2 Archive Security

  • Archived data is stored in secure, encrypted systems
  • Access to archives is restricted to authorized personnel
  • Archives are subject to the same security controls as active data
  • Archives are reviewed periodically for continued necessity

7. User Rights and Data Retention

Users have the following rights regarding their data and retention:

  • Right to Access - Request information about what data we hold and how long it will be retained
  • Right to Correction - Request correction of inaccurate data
  • Right to Deletion - Request deletion of data, subject to legal retention requirements
  • Right to Restriction - Request restriction of processing
  • Right to Object - Object to processing based on legitimate interests
  • Right to Data Portability - Request transfer of data to another organization

To exercise any of these rights, contact us at: makosagroups@gmail.com

8. Data Security During Retention

Throughout the retention period, data is protected by:

  • Encryption - Data is encrypted at rest and in transit
  • Access Controls - Role-based access controls limit who can access retained data
  • Monitoring - Systems are monitored for unauthorized access
  • Regular Security Assessments - We conduct regular security reviews and vulnerability assessments
  • Data Minimization - We only retain data that is necessary
  • Staff Training - Employees are trained on data protection and security practices

9. Data Retention Review

We regularly review our data retention practices to ensure they remain appropriate and effective.

9.1 Review Frequency

  • Annual Review - Comprehensive review of retention periods and practices
  • Quarterly Review - Review of data deletion logs and compliance
  • Ad-hoc Review - When new laws or regulations are introduced

9.2 Review Criteria

During reviews, we consider:

  • Changes in legal and regulatory requirements
  • Changes in our business practices
  • New technology or processing methods
  • User feedback and complaints
  • Security incidents or breaches
  • Changes in industry standards

10. Special Circumstances

In some circumstances, we may need to retain data beyond standard retention periods:

10.1 Legal Proceedings

  • Data may be retained longer when relevant to ongoing or anticipated legal proceedings
  • Data subject to a legal hold or preservation order will be retained as required

10.2 Investigations

  • Data may be retained during investigations of fraud, abuse, or misconduct
  • Data may be retained when requested by law enforcement

10.3 Security Incidents

  • Data related to security incidents may be retained for investigation and prevention

10.4 Technical Limitations

  • Some data may persist in backups for a limited period after deletion from active systems
  • We make reasonable efforts to remove data from backups, but some residual data may remain

11. Compliance and Enforcement

We are committed to complying with this policy and applicable data protection laws.

11.1 Monitoring

  • Data retention practices are regularly monitored
  • Automated systems track retention periods
  • Manual reviews are conducted for non-automated data

11.2 Reporting

  • Data retention compliance reports are prepared for management
  • Non-compliance is escalated and addressed promptly

11.3 Training

  • Staff receive training on data retention requirements
  • Training is updated when policies change

Failure to comply with this policy may result in disciplinary action, up to and including termination of employment for staff and termination of contracts for vendors.

12. Data Breach Procedures

In the event of a data breach involving retained data, we have procedures in place:

  • Immediate Response - Suspend affected systems and investigate the breach
  • Assessment - Determine the scope and impact of the breach
  • Notification - Notify affected users and relevant authorities as required by law
  • Remediation - Take corrective actions to prevent recurrence
  • Documentation - Document the breach and response for future reference

13. Policy Updates

This Data Retention Policy may be updated periodically to reflect changes in our practices, technology, or legal requirements.

Changes will be communicated through:

  • Email notifications to registered users
  • In-app notifications
  • Website announcements

Continued use of Pickseat after policy updates constitutes acceptance of the revised Data Retention Policy.

14. Contact Information

For questions about this Data Retention Policy, please contact us:

Pickseat Data Protection Team

Company: Pickseat Transport Services

Email: makosagroups@gmail.com

Address: Spintex Road, Accra-Ghana

© 2026 Pickseat Transport Services. All rights reserved.

This Data Retention Policy is for informational purposes only and does not constitute legal advice.