Legal / Compliance
Data Retention and Deletion Policy
Last updated: August 2, 2026 · Reviewed periodically for privacy and operational compliance
VenueCore Systems (“VenueCore,” “we,” “us,” or “our”) maintains this Data Retention and Deletion Policy to define how long we keep information, when we delete or anonymize it, and how the policy is enforced and reviewed. This policy is designed to support compliance with applicable data privacy laws and our published Privacy Policy.
1. Purpose
We retain information only as long as reasonably necessary to:
- Operate our websites and business software platforms
- Provide customer support and fulfill service requests
- Demonstrate SMS/text messaging consent and honor opt-out requests
- Meet legal, accounting, tax, security, and dispute-resolution requirements
- Protect the security and integrity of our systems
2. Scope
This policy applies to personal and business information processed by VenueCore Systems in connection with:
- venuecoresystems.com and related public pages
- SMS opt-in, consent, and messaging program records
- Customer support and sales communications
- Business software platforms we operate (including accounting, operations, and related office systems)
- Hosting, messaging, and other service providers acting on our behalf
3. Retention schedule
Unless a longer or shorter period is required by law or a written customer agreement, VenueCore applies the following retention guidelines:
| Data category | Typical retention | Deletion / disposition |
|---|---|---|
| Website contact and inquiry forms | Up to 24 months after last meaningful contact, or sooner if no longer needed | Delete or anonymize on request or when retention ends |
| SMS opt-in / consent records | For the life of the messaging relationship, plus up to 4 years after opt-out or last message (to prove consent and compliance) | Retain proof of consent/opt-out; stop active messaging immediately on STOP |
| SMS message logs / delivery metadata | Up to 24 months, unless needed longer for abuse investigation, billing disputes, or legal hold | Delete or minimize when no longer needed |
| Support emails and tickets | Up to 36 months after closure of the matter | Delete or archive/minimize according to business need |
| Customer account / platform records | For the active customer relationship, then up to 7 years for accounting, tax, audit, and legal records where applicable | Delete, export to customer, or anonymize after contract end subject to legal retention |
| Security logs and access records | Typically 12–24 months | Delete or aggregate when no longer needed for security monitoring |
| Marketing suppression / do-not-contact lists | Kept as long as needed to honor opt-out requests | Not treated as active marketing data; retained to prevent re-contact |
Where a provider (for example, Twilio or hosting) retains technical logs under its own schedule, VenueCore limits its own copies according to this policy and contractual need.
4. Deletion and disposal procedures
- Customer / individual requests: Email support@venuecoresystems.com to request access, correction, or deletion. We verify the request and respond within a reasonable time consistent with applicable law.
- SMS opt-out: Reply STOP. Active SMS sending stops promptly. Consent and opt-out proof may be retained as described above.
- Account closure: When a customer relationship ends, we disable unnecessary access and schedule deletion or anonymization of personal data that is not subject to legal or accounting retention.
- Operational deletion: Data past its retention period is deleted, anonymized, or securely disposed of from systems under VenueCore control.
- Backups: Deleted data may remain in encrypted backups for a limited backup-cycle period until those backups expire or are overwritten.
- Legal holds: If information is subject to investigation, claim, or legal process, deletion is suspended until the hold is released.
5. Enforcement
This policy is enforced through:
- Documented retention guidelines and owner/operator responsibility
- Access controls limiting who can export or delete customer data
- Process for handling deletion and privacy requests via support@venuecoresystems.com
- Vendor agreements and configurations that limit processing to service purposes
- Alignment with our Information Security Policy and Privacy Policy
6. Privacy-law alignment
VenueCore designs retention and deletion practices to support applicable privacy requirements relevant to our business, including principles of data minimization, purpose limitation, and responding to valid consumer/customer privacy requests where required. Because VenueCore primarily serves business customers, retention for accounting, tax, and contractual records may continue where legally necessary even after a deletion request for other personal data.
7. Periodic review
This Data Retention and Deletion Policy is reviewed at least annually, and sooner when:
- Applicable privacy laws or guidance change
- We add material products, vendors, or messaging channels
- A security or privacy incident identifies a retention gap
- Customer contracts or industry requirements change retention needs
The version published at venuecoresystems.com is the current public reference. The “Last updated” date is revised when the policy changes.
8. How to submit a deletion request
Email support@venuecoresystems.com with:
- Your name and business name
- The email and/or phone number involved
- What you want deleted or corrected
- Whether the request relates to SMS, website forms, support history, or a platform account
We may need to verify identity or authority before completing the request.
9. Related documents
10. Contact
VenueCore Systems
Website: https://venuecoresystems.com
Email: support@venuecoresystems.com