Legal Document

Data Retention Policy

Version 1.0 β€” Last updated: January 29, 2025

Back to Security

User Data

Account lifetime + 30 days after deletion

Transaction Data

7 years (legal requirement)

Session Data

24 hours after last activity

1. Purpose

This Data Retention Policy establishes guidelines for how long Magia Menu retains personal and business data, and how data is securely disposed of when no longer needed. This policy ensures compliance with:

GDPR Article 5(1)(e) - Storage limitation principle
GDPR Article 17 - Right to erasure
PCI DSS Requirement 3.1 - Data retention policies
Tax/Legal requirements for business records -
2.1 User Personal Data
Data TypeRetention PeriodDeletion Method
Active User ProfileAccount lifetime + 30 daysAnonymization
Inactive User Profile2 years after last activityAnonymization
Guest User (Anonymous)90 daysHard Delete
Email/PhoneAccount lifetime + 30 daysHard Delete
2.2 Authentication Data
Data TypeRetention PeriodDeletion Method
Access Tokens15 minutesAuto-expire
Refresh Tokens30 daysHard Delete
Session Data24 hours after last activityHard Delete
Magic Link Codes15 minutesHard Delete
2.3 Transaction Data
Data TypeRetention PeriodLegal Basis
Orders7 yearsTax Law
Payment Records7 yearsTax Law / PCI DSS
Receipts7 yearsTax Law
Refunds7 yearsTax Law
2.4 System Logs
Data TypeRetention Period
Security Audit Logs1 year
API Access Logs90 days
Application Logs30 days
Debug Logs7 days
3. Deletion Methods

Hard Delete

Complete removal from database

Soft Delete

Marked as deleted, not visible to users

Anonymization

Personal identifiers removed/replaced

Secure Delete

Cryptographic erasure for sensitive data

4. Your Rights

Right to Erasure (GDPR Article 17)

You can request deletion of your data when:

  • Data is no longer necessary for original purpose
  • You withdraw consent
  • You object to processing
  • Data was unlawfully processed

Response Time: 30 days (extendable by 60 days for complex requests)

Right to Portability (GDPR Article 20)

You can export your data in JSON or CSV format. Request via Profile settings or email.

Right to Access (GDPR Article 15)

You can request information about what data we hold and how it is processed.

5. Exceptions

Data may NOT be deleted if:

  • Required for legal compliance (tax records: 7 years)
  • Required for legal claims defense
  • Needed for public health purposes
  • Used for historical/statistical purposes (anonymized)
6. Backups
Daily Backups30 days retention
Weekly Backups12 weeks retention
Monthly Backups3 months retention
Annual Archives7 years (encrypted, restricted access)
7. Third-Party Processors
ProcessorData SharedRetention
IyzicoPayment dataPer Iyzico policy
MapboxLocation (anonymized)Per Mapbox policy

8. Contact

For data retention inquiries:

magiamenu@gmail.com