Field Wizard — Data Retention and Deletion
Last reviewed: 2026-08-09 Next review: 2026-11-09 (quarterly) Questions: privacy@gofieldwizard.com
Plain answer up front: your business data is yours, it stays for as long as your account is open, you can download all of it at any time, and you can have it deleted.
1. What we store, and where
| Data | Contains | Where it lives |
|---|---|---|
| User accounts | Name, email, bcrypt password hash, role, company, preferences, verification state | MongoDB Atlas |
| Company records | Company name, industry, logo, settings, enabled modules | MongoDB Atlas |
| Customers / accounts | Your customers' company names, contacts, emails, phones, addresses | MongoDB Atlas |
| Jobs and scheduling | Job details, status, assignments, scheduled dates, crews, regions | MongoDB Atlas |
| Form templates | The forms you build, their fields, PDF layouts, automations | MongoDB Atlas |
| Form submissions | Every answer your crews submit in the field — the operational record | MongoDB Atlas |
| Financial records | Invoices, estimates, line items, totals, payment status | MongoDB Atlas |
| Employee records | Names, emails, phones, roles, skills, hourly rates, timesheets, time-off requests | MongoDB Atlas |
| Inventory | Items, SKUs, quantities | MongoDB Atlas |
| Safety records | Inspections, incidents, observations, toolbox talks, training, permits | MongoDB Atlas |
| Data tables | Custom tables and their records | MongoDB Atlas |
| Uploaded files | Job photos, captured signatures, attached PDFs and documents — plus GPS coordinates when a photo was captured with location on | Cloudflare R2 object storage (live since 2026-08-13) for everything uploaded from that date; files uploaded earlier remain on the persistent volume at the hosting provider (Railway) until a one-time migration runs, and the application serves each file from wherever it actually lives. Objects are written private with server-side encryption. Metadata in MongoDB Atlas. |
| Audit log | Who did what: user, tenant, action, resource, client IP, UTC timestamp | MongoDB Atlas |
| Email delivery log | Recipient, subject, delivery result | MongoDB Atlas |
| Subscription records | Plan, status, Stripe identifiers. No card numbers — those live at Stripe only. | MongoDB Atlas |
| API keys and webhooks | SHA-256 key hashes, display prefixes, endpoint URLs, signing secrets | MongoDB Atlas |
| Short-lived tokens | Password reset, email verification, portal magic links, API rate-limit counters | MongoDB Atlas, auto-expiring |
Everything above is tenant-scoped: it carries your company id and every query filters on it.
2. Retention periods
Automatic, enforced by the database
These are not policy statements someone has to remember. They are TTL indexes: the database deletes the documents itself.
| Data | Retention | Mechanism |
|---|---|---|
| Audit log entries | 400 days | TTL index on the timestamp, plus a daily sweeper as a backstop. One year plus about five weeks of margin — sized for a SOC 2 Type II observation window, where the auditor looks back a full 12 months and fieldwork happens some weeks after the window closes. |
| Password reset tokens | 1 hour | Single-use, plus TTL index on expiry. Using one invalidates all others for that user. |
| Email verification tokens | 24 hours | Single-use, plus TTL index on expiry. |
| Portal magic links | Short-lived | Single-use, plus TTL index on expiry. |
| API rate-limit counters | 2 minutes | TTL index. |
Note on the audit log: the in-app lookback window matches the retention window, so what you can query and what we keep are the same thing. Audit detail is redacted of credentials before it is ever written. If your industry requires audit records for longer than 400 days, export them before they age out, or contact us.
Retained while your account is active
| Data | Retention |
|---|---|
| All business records — customers, jobs, forms, submissions, invoices, estimates, employees, inventory, safety, tables | For the life of the account. We do not silently age out your operational history. Field records get subpoenaed and warranty-claimed years later; deleting them on a schedule you did not choose would be a defect, not a feature. |
| Uploaded files (photos, signatures, documents) | For the life of the account, or until you delete them |
| User accounts | For the life of the account |
| Email delivery logs | 24 months |
| Subscription and billing records | 7 years after the last transaction, for tax and accounting purposes. Stripe retains its own records under its own policy. |
You can delete individual records at any time from within the product. Deletes are tenant-scoped and immediate — the record is removed from the database, and deleting an upload removes the file from disk as well as the metadata row.
3. Getting your data out (export)
Any account holder can download the entire dataset at any time. No support ticket, no waiting period, no fee.
It produces a ZIP containing, for each collection, both a CSV (opens in Excel) and a JSON file (preserves nested structure such as form pages, fields, and submission answers), plus a manifest.json recording the export time and the row count per collection.
Covered: accounts, jobs, form templates, form submissions, invoices, estimates, employees, inventory, approvals, service agreements, timesheets, notifications, data tables, and table records.
Deliberate choices:
- Plain ZIP of CSV and JSON, not a proprietary archive. It opens anywhere
and needs nothing from us to be useful.
- Credentials are stripped. Password hashes, tokens, API key hashes, portal
access code hashes, and payment session identifiers never appear in an export.
- Export is account-holder-only (
data.exportcapability). A manager can run
your business but cannot bulk-export it.
Uploaded binary files are not inside the ZIP today; the export includes their metadata and identifiers. If you need the raw files in bulk, email privacy@gofieldwizard.com and we will provide them. Including files directly in the export archive is planned alongside the object-storage migration.
4. Deleting your data
In-product
- Individual records — delete anything from its own screen. Immediate.
- Bulk data deletion — an account holder can clear the company's operational
data (customers, jobs, forms, submissions, invoices, estimates, employees, inventory, safety records, timesheets, crews, regions and related collections) in one action. Admin-only, tenant-scoped, immediate, and irreversible. There is no undo and no recovery from our side — export first.
Full account closure and deletion
Email privacy@gofieldwizard.com from the account holder's registered address, or use the account closure flow when it ships.
What happens:
| Step | Timing |
|---|---|
| We confirm the request with the account holder | Within 2 business days |
| Subscription cancelled, no further billing | Immediately on confirmation |
| A final export is offered before anything is deleted | Before deletion |
| Grace period — account disabled but recoverable, in case the request was a mistake or made by the wrong person | 30 days (you can waive it and ask for immediate deletion) |
| Production data deleted: all business records, user accounts, and uploaded files | Within 30 days of confirmation |
| Data ages out of any backups still holding it | Within a further 30 days |
| Confirmation of deletion sent to you | On completion |
Honest caveat about backups. Once continuous backups are in place, deleted data may persist in encrypted backup snapshots until those snapshots rotate out. It is not accessible through the application and it is not used for anything. It expires on the backup schedule. See §6.
What survives deletion, and why:
- Financial and tax records — invoices we issued to you, payment records —
for 7 years. Required by law; we cannot delete these on request.
- Audit log entries relating to the deletion itself, so we can prove what
was deleted and when. These age out on the normal 400-day schedule.
- Stripe's records — retained under Stripe's policy, not ours.
- Aggregate, fully anonymised counts that cannot be traced back to you or
your customers.
5. What happens when you cancel or stop paying
| Event | What happens to your data |
|---|---|
| You cancel your subscription | Access continues to the end of the paid period. Data is retained. |
| Paid period ends | Account moves to read-only. You can still log in and export everything. We do not hold data hostage behind a payment. |
| 90 days read-only with no reactivation | We email a warning to the account holder's address at 60 and 80 days. |
| After 90 days plus the warnings | We may delete the account and its data. Nothing is deleted without at least two prior emails and a clear deadline. |
| You ask for deletion | The process in §4 runs, whatever the billing state. |
| Payment fails | Retries and email notice first. A failed card does not delete anything. |
A cancelled customer who returns six months later and finds their data gone — without ever having been told it would be — is a betrayal, not a policy. Hence the warnings and the read-only export window.
6. Backup retention
Current state, stated honestly: database backup coverage depends on the hosting tier, and the current production tier's coverage is limited. Upgrading the cluster tier specifically to get continuous backups with point-in-time restore is an active item (our security overview §12, #3). We are not claiming a tested backup retention schedule we do not yet operate.
Target once the upgrade lands:
| Backup type | Retention |
|---|---|
| Continuous point-in-time restore | 7 days |
| Daily snapshots | 30 days |
| Deleted data lifetime in backups | ≤ 30 days after deletion from production |
Backups are encrypted at rest, held by MongoDB Atlas, and restorable only by the account holder using provider MFA.
Uploaded files are on a single persistent volume today, with no versioning and no independent backup copy. That is a real gap (our security overview §12, #4) and it is the reason the object-storage migration is in progress.
Source code is retained indefinitely in git history. It contains no customer data and no secrets.
7. Your rights
If GDPR or CCPA/CPRA applies to you, see our Privacy Policy for the full statement. In short:
- Access and portability — built into the product; one action, full export,
open formats.
- Correction — edit anything in the app.
- Deletion — §4 above.
- Where your customers' data is concerned, you are the controller and Field
Wizard is the processor. If one of your customers asks you to delete their record, you can do it yourself in the app; you do not need us.
Response time for a written request: 30 days, and usually much faster.
Related: our security overview · our subprocessor list · our Privacy Policy
Questions about this document
Email Support@gofieldwizard.com and a person will answer. Our security controls and subprocessor list are published at the Trust Center.