LEGAL
DATA RETENTION & DISPOSAL POLICY
Effective July 22, 2026
This policy describes how long Ralph Bridges, doing business as Kloud Realty ("we," "us," or "our"), retains personal and financial data collected through the dashboard application at ralphbridges.com, and how that data is disposed of once it is no longer needed. It reflects our commitment to data minimization: we do not keep data longer than is operationally or legally necessary.
1. Data We Retain
| Data category | Examples | Source |
|---|---|---|
| Plaid access credentials | Encrypted Plaid access token, item status | Plaid Link |
| Bank account data | Account name, mask, type, balances | Plaid /accounts |
| Transaction data | Amount, date, merchant, category, raw payload | Plaid /transactions |
| Investment data | Holdings, investment transactions | Plaid /investments |
| Payroll data | Gross/net pay, tax withholding, deductions | Manual entry / CSV import |
| Accounting records | Journal entries, invoices, bills, accounts | Manual entry / CSV import / Plaid |
| Authentication data | Google OAuth identity, API keys | Sign-in flow |
We do not collect or store Social Security numbers, dates of birth, or government ID numbers.
2. Retention Periods
| Data category | Retention period | Basis |
|---|---|---|
| Plaid access tokens | Deleted immediately upon Item disconnection or revocation | No legitimate use after disconnection |
| Bank account & transaction data | Retained while the linked Plaid Item is active; deleted within 30 days of disconnection, subject to the tax-record exception below | Operational necessity |
| Payroll and tax withholding records | 7 years from the applicable tax year | IRS recordkeeping guidance for employment tax records |
| Invoices, bills, journal entries | 7 years from the transaction date | General financial recordkeeping / IRS guidance |
| Investment holdings & transactions | 7 years from the transaction date | Consistent with financial recordkeeping above |
| Authentication data | Deleted upon account closure; sessions expire per session configuration | Operational necessity |
| API keys | Deleted immediately upon revocation | Security best practice |
| Database backups | Rolled off on a 30-day cycle | Disaster recovery necessity, not indefinite retention |
Data may be retained beyond these periods only where required to comply with a legal obligation, resolve a dispute, or enforce an agreement.
3. Disposal Method
- Database records are hard-deleted once the applicable retention period expires or upon a valid deletion request.
- Plaid access tokensare deleted from the database, and the corresponding Item is removed via Plaid's Item removal endpoint so Plaid also ceases to retain the access grant.
- Backups are purged automatically on a 30-day rotation; no indefinite archival copies are kept.
4. Requesting Deletion
You may request deletion of your data at any time by contacting ralph.bridges@kloudrealty.com. Upon a verified request, we remove the associated Plaid Item(s) and delete associated account, transaction, and investment data within 30 days, except records that must be retained under Section 2 (in which case we will notify you of the applicable retention basis).
5. Review
This policy is reviewed annually and whenever there is a material change to the data we collect, our technology stack, or applicable legal requirements. See our Privacy Policy for how this data is collected and used.
6. Contact
Ralph Bridges, Owner, is responsible for this policy. Questions can be directed to ralph.bridges@kloudrealty.com.