Data Retention Policy
1. Introduction
This Data Retention Policy outlines how Pickseat Transport Services ("Pickseat", "we", "our", or "us") manages the retention and deletion of personal and business data collected through our platform. This policy is designed to:
- Ensure compliance with applicable laws and regulations
- Protect the privacy and security of user data
- Balance operational needs with data minimization principles
- Provide transparency about our data retention practices
This policy applies to all data collected by Pickseat from users, drivers, vehicle operators, advertisers, and other stakeholders who interact with our platform.
2. Scope
This policy covers all categories of data collected by Pickseat, including:
- Personal information (names, contact details, identification)
- Account information and credentials
- Location and route data
- Usage and analytics data
- Transaction and payment information
- Driver and vehicle information
- Communication records
- System logs and technical data
This policy applies to all data processing activities, whether automated or manual, and covers data stored in active systems, backups, archives, and third-party services.
3. Retention Principles
Our data retention practices are guided by the following principles:
- Data Minimization - We collect and retain only the data necessary for legitimate purposes
- Purpose Limitation - Data is retained only as long as needed for the purposes for which it was collected
- Legal Compliance - We comply with all applicable legal and regulatory retention requirements
- Security - Data is securely stored and protected throughout its lifecycle
- Transparency - Users are informed about how long their data is retained
- Accountability - We maintain records of our retention practices and regularly review them
We retain data for no longer than is necessary for the purposes described in this policy, unless a longer retention period is required by law.
4. Retention Periods
The following are our standard retention periods for different categories of data. Actual retention periods may vary based on specific circumstances and legal requirements.
4.1 Account Data
| Data Type | Retention Period | Purpose |
|---|---|---|
| User account information | While account is active + 30 days | Service provision and account management |
| Login credentials | While account is active + 30 days | Authentication and security |
| Account preferences | While account is active + 30 days | Personalization |
| Authentication logs | 2 years | Security auditing |
4.2 Personal Information
| Data Type | Retention Period | Purpose |
|---|---|---|
| Full name and contact details | While account is active + 3 years | Communication and verification |
| Email address | While account is active + 3 years | Communication and account recovery |
| Phone number | While account is active + 3 years | Verification and communication |
| Profile photograph | While account is active + 30 days | User identification |
| Date of birth | While account is active + 3 years | Age verification and compliance |
4.3 Driver and Vehicle Data
| Data Type | Retention Period | Purpose |
|---|---|---|
| Driver license information | While driver is active + 5 years | Verification and legal compliance |
| Vehicle registration documents | While vehicle is active + 5 years | Verification and legal compliance |
| Insurance certificates | While active + 7 years | Legal and liability purposes |
| Vehicle inspection records | 3 years | Safety and quality assurance |
| Driver background checks | 5 years | Safety and legal compliance |
4.4 Location and Route Data
| Data Type | Retention Period | Purpose |
|---|---|---|
| Real-time location data | 30 days (anonymized after) | Service provision and route optimization |
| Route history | 90 days | Usage analytics and improvement |
| Anonymized location data | 2 years | Research and analytics |
| Location permissions consent | While account is active + 3 years | Consent documentation |
4.5 Transaction and Payment Data
| Data Type | Retention Period | Purpose |
|---|---|---|
| Transaction records | 7 years | Legal compliance and accounting |
| Payment references | 7 years | Audit and dispute resolution |
| Payment processor data | As per processor's policy | Payment processing |
| Billing information | 7 years | Accounting and legal compliance |
| Refund records | 7 years | Financial record-keeping |
4.6 Communication Data
| Data Type | Retention Period | Purpose |
|---|---|---|
| Support tickets and chats | 3 years | Customer service and quality |
| Email communications | 3 years | Record-keeping and service |
| In-app messages | 90 days | Communication facilitation |
| Survey responses | 2 years | Service improvement |
4.7 Usage and Analytics Data
| Data Type | Retention Period | Purpose |
|---|---|---|
| App usage logs | 2 years | Analytics and improvement |
| Feature usage data | 2 years | Product development |
| Performance metrics | 2 years | Service optimization |
| Crash reports | 1 year | Technical debugging |
| Anonymized analytics | Indefinite | Research and business intelligence |
4.8 System and Technical Data
| Data Type | Retention Period | Purpose |
|---|---|---|
| Server logs | 90 days | System monitoring and security |
| IP addresses | 90 days | Security and fraud prevention |
| Device information | While account is active | Device management and compatibility |
| System backups | 30 days | Disaster recovery |
4.9 Marketing Data
| Data Type | Retention Period | Purpose |
|---|---|---|
| Marketing consent records | While consent is valid + 3 years | Consent documentation |
| Advertising interaction data | 2 years | Marketing optimization |
| Newsletter subscriptions | While subscribed + 3 years | Marketing communication |
5. Data Deletion Process
When data reaches the end of its retention period, we take the following steps:
5.1 Deletion Methods
- Permanent Deletion - Data is securely deleted from active systems
- Anonymization - Identifying information is removed so data can no longer be linked to specific individuals
- Aggregation - Data is combined with other data for statistical purposes without identifying individuals
- Archiving - Data may be moved to secure archives for legal or compliance purposes
5.2 Deletion Triggers
Data deletion may be triggered by:
- Expiration of retention period
- User account deletion request
- User request to delete specific data
- Withdrawal of consent
- Legal obligation to delete
- Security or integrity concerns
5.3 Deletion Verification
- Automated verification - Systems verify that deletion processes have been completed successfully
- Audit trails - Deletion activities are logged for accountability
- Regular audits - We conduct periodic audits to ensure data is being retained and deleted properly
6. Data Archiving
Some data may be archived for long-term storage when required for legal, compliance, or business purposes.
6.1 Archive Criteria
Data may be archived if it is:
- Required by law or regulation to be retained
- Needed for ongoing legal proceedings
- Relevant to dispute resolution
- Essential for historical research or statistical purposes
- Required for business continuity
6.2 Archive Security
- Archived data is stored in secure, encrypted systems
- Access to archives is restricted to authorized personnel
- Archives are subject to the same security controls as active data
- Archives are reviewed periodically for continued necessity
7. User Rights and Data Retention
Users have the following rights regarding their data and retention:
- Right to Access - Request information about what data we hold and how long it will be retained
- Right to Correction - Request correction of inaccurate data
- Right to Deletion - Request deletion of data, subject to legal retention requirements
- Right to Restriction - Request restriction of processing
- Right to Object - Object to processing based on legitimate interests
- Right to Data Portability - Request transfer of data to another organization
To exercise any of these rights, contact us at: makosagroups@gmail.com
8. Data Security During Retention
Throughout the retention period, data is protected by:
- Encryption - Data is encrypted at rest and in transit
- Access Controls - Role-based access controls limit who can access retained data
- Monitoring - Systems are monitored for unauthorized access
- Regular Security Assessments - We conduct regular security reviews and vulnerability assessments
- Data Minimization - We only retain data that is necessary
- Staff Training - Employees are trained on data protection and security practices
9. Data Retention Review
We regularly review our data retention practices to ensure they remain appropriate and effective.
9.1 Review Frequency
- Annual Review - Comprehensive review of retention periods and practices
- Quarterly Review - Review of data deletion logs and compliance
- Ad-hoc Review - When new laws or regulations are introduced
9.2 Review Criteria
During reviews, we consider:
- Changes in legal and regulatory requirements
- Changes in our business practices
- New technology or processing methods
- User feedback and complaints
- Security incidents or breaches
- Changes in industry standards
10. Special Circumstances
In some circumstances, we may need to retain data beyond standard retention periods:
10.1 Legal Proceedings
- Data may be retained longer when relevant to ongoing or anticipated legal proceedings
- Data subject to a legal hold or preservation order will be retained as required
10.2 Investigations
- Data may be retained during investigations of fraud, abuse, or misconduct
- Data may be retained when requested by law enforcement
10.3 Security Incidents
- Data related to security incidents may be retained for investigation and prevention
10.4 Technical Limitations
- Some data may persist in backups for a limited period after deletion from active systems
- We make reasonable efforts to remove data from backups, but some residual data may remain
11. Compliance and Enforcement
We are committed to complying with this policy and applicable data protection laws.
11.1 Monitoring
- Data retention practices are regularly monitored
- Automated systems track retention periods
- Manual reviews are conducted for non-automated data
11.2 Reporting
- Data retention compliance reports are prepared for management
- Non-compliance is escalated and addressed promptly
11.3 Training
- Staff receive training on data retention requirements
- Training is updated when policies change
Failure to comply with this policy may result in disciplinary action, up to and including termination of employment for staff and termination of contracts for vendors.
12. Data Breach Procedures
In the event of a data breach involving retained data, we have procedures in place:
- Immediate Response - Suspend affected systems and investigate the breach
- Assessment - Determine the scope and impact of the breach
- Notification - Notify affected users and relevant authorities as required by law
- Remediation - Take corrective actions to prevent recurrence
- Documentation - Document the breach and response for future reference
13. Policy Updates
This Data Retention Policy may be updated periodically to reflect changes in our practices, technology, or legal requirements.
Changes will be communicated through:
- Email notifications to registered users
- In-app notifications
- Website announcements
Continued use of Pickseat after policy updates constitutes acceptance of the revised Data Retention Policy.
14. Contact Information
For questions about this Data Retention Policy, please contact us:
Pickseat Data Protection Team
Company: Pickseat Transport Services
Email: makosagroups@gmail.com
Address: Spintex Road, Accra-Ghana