Yolobeam

Legal

Data retention policy

This policy states how long Yolobeam LLC retains each category of data, what happens to your records when a subscription ends, how backups and legal holds affect deletion, and how to make a deletion request.

Effective
July 28, 2026
Last updated
July 28, 2026

1.Purpose and scope

This policy applies to all data Yolobeam LLC processes in operating the Yolobeam platform, marketing website, and support channels. It covers customer data, account records, billing records, logs, and backups.

It supplements the privacy policy, which explains what we collect and why, and the terms of use, which govern the subscription itself.

2.Retention principles

  1. Keep data only as long as it serves a stated purpose, or as long as the law requires.
  2. Set a defined period for every category of data, rather than retaining indefinitely by default.
  3. Prefer deletion or irreversible anonymization over indefinite archiving.
  4. Give customers control over the records they load into the platform, including the ability to export and delete them.
  5. Apply the same periods consistently across production systems, backups, and logs, allowing for the backup cycle described below.

3.Who decides retention

For customer data, the subscribing organization decides what to keep and for how long. Administrators can delete individual records, archive members, and configure retention for the record types their plan supports. We apply the periods below as defaults and as outer limits; we do not delete customer data early on our own initiative.

For account, billing, log, and support data, we decide retention, and the periods below apply.

4.Retention schedule

Periods run from the trigger stated in the last column. Where a longer period is required by law or by a legal hold, that period controls.

Data categoryRetention periodMeasured from
Member, alumni, and prospect recordsLife of the subscription, unless deleted earlier by the organizationOngoing
Events, tasks, forms, announcements, and filesLife of the subscription, unless deleted earlier by the organizationOngoing
Recruitment and prospect engagement records24 months by default, or as configured by the organizationLast engagement with the prospect
Dues, donation, and financial transaction records7 yearsEnd of the fiscal year in which the transaction occurred
Invoices, billing records, and tax documentation7 yearsDate of issue
Audit and activity logs within the platform24 monthsDate the entry was written
Application and infrastructure logs90 daysDate the entry was written
Web server and marketing site access logs30 daysDate of the request
Authentication sessions and tokens30 days, or until sign-outIssue of the session
Product analytics events12 monthsDate the event was captured
Session replay recordings1 monthDate the session was recorded
Support tickets and correspondence24 monthsClosure of the ticket
Soft-deleted records awaiting purge30 days, restorable by an administrator during that windowDate of deletion
Encrypted backups35 days rollingDate the backup was taken
Marketing and sales contact records36 months, or until an unsubscribe or deletion requestLast meaningful contact
Aggregated and de-identified statisticsRetained indefinitely; cannot be re-associated with an individual

5.What happens when a subscription ends

  1. Days 0 to 30 — export window. The account moves to read-only. Administrators can sign in and export records, files, and reports. We do not delete anything during this window.
  2. Day 30 — access ends. Sign-in is disabled and the account is scheduled for deletion.
  3. Within 90 days — deletion from production. Customer data is deleted from live systems. Records we are required to keep — chiefly financial and tax records — are retained separately for the periods in the schedule above and are not used for any other purpose.
  4. Within 125 days — deletion from backups. Deleted data ages out of the rolling backup cycle. We do not restore backups to recover data that has been deleted at a customer's request.

Export your data before day 30. After access ends we cannot reliably reconstruct a deleted account, and after the backup cycle completes the data is gone.

A customer may request accelerated deletion in writing, and we will complete deletion from production within 30 days of the request, subject to legal retention requirements and any legal hold.

6.Backups and disaster recovery

We take encrypted backups on a rolling 35-day cycle to protect against data loss and to support disaster recovery. Backups are immutable within their retention window, which means an individual record cannot be surgically removed from an existing backup.

When a record is deleted from production, it persists in backups until those backups expire. We do not use backups to restore deleted records, and access to backups is restricted to a small number of authorized personnel for recovery purposes only.

8.Deletion requests from individuals

If you are a member, prospect, alumnus, parent, or advisor whose record lives in an organization's account, contact that organization. It controls the record and can delete it directly. We do not delete customer data on an individual's request without the organization's instruction, except where applicable law requires us to act.

For records we control — such as marketing contacts and support correspondence — email support@yolobeam.com. We will verify your identity and respond within the period required by applicable law. See the privacy policy for the full list of rights available to you.

9.How we delete data

  • Records are removed from the primary database and from search indexes.
  • Uploaded files are deleted from object storage, including any generated thumbnails or derived copies.
  • Where a record must be preserved for referential integrity — for example a financial record referencing a member — identifying fields are irreversibly anonymized rather than the row being retained intact.
  • Decommissioned storage media are cryptographically erased or destroyed in accordance with our hosting providers' procedures.
  • Deletion actions on customer data are written to the audit log so that administrators can see what was removed and when.

10.Service providers

Providers that process data on our behalf are contractually required to delete or return it at the end of their engagement, and to apply retention periods no longer than those in this policy. We review these commitments when onboarding a provider and periodically thereafter.

11.Review of this policy

We review this policy at least annually, and whenever we materially change our systems or the law changes. Material changes are announced to account administrators before they take effect, and the effective date at the top of this page is revised.

12.Contact us

Questions about retention, or requests for accelerated deletion, can be sent to support@yolobeam.com.

Related documents

Questions about this document? Email support@yolobeam.com.