A2X Data Retention Policy - A2X

This policy was last updated on August 28th 2026.

Purpose, Scope, and Users

This policy sets the required retention periods for specified categories of data stored by A2X (further: the “Company”). It also sets out the general standards applied to data while stored and retained by the Company, as well as processes applied when destroying data no longer retained.

This Policy applies to all Company officers, directors, employees, agents, affiliates, contractors, consultants, advisors, or service providers that may collect, process, or have access to data (including personal data and / or sensitive personal data). It is the responsibility of all of the above to familiarize themselves with this Policy and ensure adequate compliance with it.

This policy applies to all data collected to support processing of customer data, including from third-party sales channels through API integration of customer transaction information, and customer support records. Examples of this data include:

  • Raw transaction data files stored in Google Cloud Storage Buckets
  • Synthesized accounting data stored in A2X database(s)
  • Customer support notes, email, call recordings, and other customer artifacts

General Retention Policy

Company will define a retention schedule for all customer-related data in use within the organization and will document that in the Data Retention Schedule below.

Data retention schedule for customer data

A2X retains customer data only for as long as reasonably necessary for the purposes for which it was collected, including to provide the Service, support customers, maintain and improve the product, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud or abuse, and support security, audit, tax, accounting, and financial reporting requirements.

Retention periods vary depending on the account status, data type, business purpose, and applicable legal or compliance requirements. A2X does not retain customer application data indefinitely.

For the purposes of this policy, customer application data means data imported, generated, processed, or stored within the Service in connection with a customer’s use of A2X, including ecommerce, marketplace, accounting, reconciliation, payout, transaction, tax, fee, and related integration data.

A2X may apply the following lifecycle management periods to standard accounts:

  • Trial accounts: Where an account is created for a trial but does not convert to a paid subscription, A2X may automatically close the account and delete or de-identify associated customer application data 30 days after the account creation date.
  • Churned paid accounts: Where a paid account unsubscribes or otherwise ceases to maintain a paid subscription, A2X may automatically close the account and delete or de-identify associated customer application data 90 days after the unsubscription date.

These lifecycle management periods are intended to reduce unnecessary storage of inactive customer application data and support data minimization.

A2X may retain certain information for longer where required or permitted by law or where reasonably necessary for legitimate business purposes. This may include billing records, invoices, payment records, subscription history, support records, audit logs, security logs, system logs, records of user consents and preferences, legal records, tax and accounting records, backups, and records required to resolve disputes, enforce agreements, prevent fraud or abuse, investigate security issues, comply with legal obligations, or maintain business records.

Data retained after account closure will be limited to the minimum reasonably necessary for the applicable purpose, protected by appropriate safeguards, and accessible only to authorized personnel with a legitimate business need.

Deletion may not occur immediately in all systems. Customer data may remain for a limited period in backups, logs, archives, or other systems before being deleted or de-identified in accordance with A2X’s retention practices.

Safeguarding of Data During Retention Period

Measures will be taken to ensure that the information can be accessed only by authorized users during the retention period and will be stored according to data security best practices.

Data security controls include:

  • All data stored within the Google Cloud Platform (GCP) infrastructure is encrypted at rest
  • Strict Identity and Access Management (IAM) controls are enforced within the GCP
  • Application controls prevent unauthorized access except as approved through application privileges and credentials

Data safeguarding is the responsibility of the Company engineering team.

Destruction of Data

The Company and its employees should therefore, on a regular basis, review all data, whether held electronically on their devices or stored within third-party providers, to decide whether to destroy or delete any data once the purpose for which those documents were created is no longer relevant. Overall responsibility for the destruction of data falls to the Data Protection Officer (details are provided at the end of this Policy).

Once the decision is made to dispose of data according to the Retention Schedule, data will be deleted from all necessary systems to fulfill the retention schedule requirements. Data will be disposed of appropriately upon the nature of the document. All data managed under this policy is digital and will be disposed of accordingly.

Policy Enforcement

The Company Data Protection Office is responsible for ensuring compliance with this policy and will assist with the protection of Company systems and data. Any employee found to willfully or intentionally violate this policy may be subject to disciplinary action, up to and including termination of employment.

Data Protection Officer

Kirsten Finlayson You may contact the Data Protection Officer via email at  kirsten@a2xaccounting.com

Ready to get started?

Save time, work smarter and get reliable Amazon and Shopify financials you can trust, in a matter of minutes.