FinStitch← Back to home

Data Retention Policy

Last updated 20 July 2026

This policy explains how long FinStitch keeps different categories of data, when data is deleted or anonymised, and the limited circumstances in which we are required to retain information for longer. It supports our Privacy Policy and applies alongside our GDPR, AML and Customer Verification policies.

1. Purpose

FinStitch Limited (“FinStitch”, “we”, “our” or “us”) keeps personal data only for as long as necessary for the purposes for which it was collected, or as required by law. This Data Retention Policy sets out our retention principles and the periods that apply to the main categories of data we hold.

2. Retention Principles

  • We collect only the data we need to provide our Services.
  • We keep data only for as long as there is a valid purpose or legal requirement.
  • When data is no longer needed, we delete it or irreversibly anonymise it.
  • Retention periods are reviewed periodically and when our Services or obligations change.

3. Retention Periods

The following periods apply to the principal categories of data we process:

  • Account & profile data — kept while your account is active, and deleted or anonymised within 30 days of account closure or a verified erasure request.
  • Financial data (holdings, balances, transactions you record or import) — kept while your account is active and deleted within the same 30 days of closure or erasure.
  • Connected-account access tokens and API keys — revoked and deleted immediately when you disconnect an account or close your account.
  • Billing and payment records — retained for 6 years where required under UK tax and accounting law, then securely deleted.
  • Verification and financial-crime records (identity, sanctions or fraud checks, where performed) — retained for the period required by applicable AML and record-keeping obligations, then securely deleted.
  • Support and complaints correspondence — retained for as long as needed to handle the matter and for a reasonable period afterwards for quality assurance and legal-defence purposes.
  • Security and audit logs — retained for a limited period sufficient to investigate and respond to security incidents, then rotated out.
  • Backups — deleted data ages out of our encrypted backups within the backup cycle, a rolling window of up to 35 days.

4. Legal & Regulatory Retention

In some cases we must keep certain information for longer than the periods above to comply with legal, regulatory, tax, accounting, fraud-prevention or dispute-resolution obligations. Where this applies, we retain only the specific information required, for only as long as required, and then securely delete it.

5. Account Closure & Erasure

You can request deletion of your FinStitch account at any time. When your account is closed, we take reasonable steps to delete or anonymise your personal information within 30 days, unless we are required to retain certain information for the reasons set out in Section 4. Some backup copies may remain for a limited period before being securely removed as part of our normal backup cycle. See our GDPR & Your Rights page for how to exercise your right to erasure.

6. Anonymisation

Where we no longer need to identify you but retain value in aggregate or statistical data, we may irreversibly anonymise your information so it can no longer be linked to you. Anonymised data is not personal data and may be retained without the time limits in this policy.

7. Third-Party Providers

Some data is processed by trusted third-party providers — for example payment processing, identity verification, Open Banking connectivity and infrastructure. These providers operate under their own retention obligations and our contractual data-protection requirements. See our Subprocessors page for who we work with.

8. Policy Review

This policy is reviewed at least annually and whenever there are significant changes to applicable legislation, regulatory guidance, our Services or our data-processing operations.

9. Related Policies

  • Privacy Policy
  • GDPR & Your Rights
  • Anti-Money Laundering Policy
  • Customer Verification & Onboarding (KYC/KYB)

10. Contact

FinStitch Limited, registered in England & Wales (company number 17242791). For questions about data retention or to exercise your rights, email privacy@finstitch.com; for general help, use the Support page in the FinStitch app or email support@finstitch.com.

© 2026 FinStitch
Trust CenterSecurityPrivacyTermsHome