ImportDocket

Data handling

Privacy, retention and deletion

This page describes the current private-testing product behavior. Hosting, backup and processor retention settings still need operator verification before ImportDocket accepts customer documents.

Shipment files

When a shipment is created, its owner chooses a 30, 90 or 365 day retention period; 90 days is the default. Source files and shipment records are scheduled for removal when that period expires. An owner can also delete a shipment earlier. File removal runs in the background and retries if private object storage is unavailable.

Deleting a workspace

An owner can request deletion from account settings. ImportDocket first checks its billing ledger and the bound Stripe test account. Deletion is blocked while a paid period, subscription, open billing change or unsettled invoice remains. ImportDocket does not cancel subscriptions or delete Stripe records from this flow.

Once accepted, workspace access closes immediately. Queued work is stopped; in-flight work must reach a safe terminal state. The cleanup worker then removes source files and workspace records in bounded batches. The workspace stays in a deleting state while this runs.

Deleting an account

An account can be deleted after its owned workspace has finished cleanup. Its login sessions, password and linked sign-in records are removed. Access to other teams’ workspaces is revoked, and the account’s review and processing attribution is anonymised; those teams’ shipment records remain with their workspace owners.

Copies held by other services

Deleting an ImportDocket workspace does not erase invoices or other records held by Stripe. Application logs and error-tracking systems do not receive raw document contents by design, but their retention windows are controlled by separate operators and have not been verified for this testing build.

Application deletion does not immediately rewrite historical database backups. The required isolated restore and deletion-suppression check is still outstanding, so this page does not claim that backups or all processor copies are erased on request.