Retention periods depend on the information type, service relationship, order status, support matter, dispute handling, security audits, and legal obligations. We do not apply one fixed period to every category; instead, we retain, archive, delete, or de-identify information based on the criteria below.
Account and order records
Usually retained while the portal account and order relationship continue. After the relationship ends, necessary records may still be retained for billing reconciliation, dispute handling, security investigations, or legal obligations.
Access and security logs
Retained for the period needed for anomaly detection, incident investigation, access tracking, and system security audits. Once no longer necessary, they are deleted, aggregated, or made less identifiable.
Support communication records
Retained while an issue is being handled and, after closure, selected portions may remain available when directly relevant to recurring-issue investigation, service-quality review, or dispute handling.
Payment and billing status
Retention periods are determined by order management, transaction confirmation, refund or dispute handling, and applicable legal obligations. Complete payment credentials are not collected through support channels.
Security measures include role-based access controls, records of critical administrative actions, session and authentication safeguards, log reviews, necessary data-transmission protections, unusual-activity detection, and access revocation. Only personnel who need to perform service delivery, support, security, or compliance tasks may access relevant information according to their permissions.
You should also protect portal credentials, SSH keys, code repository access, build variables, and signing materials. Do not place passwords, private keys, original signing certificates, or payment credentials in tickets, emails, scripts, or shareable logs. Before sending diagnostic materials to support, redact them and keep the original copy locally.