Data Retention and Deletion Requests Guide

Overview

Data retention describes how long an organization keeps personal data and the conditions under which it is stored, archived, or removed. In payments and financial services, retention is commonly driven by operational needs (such as dispute handling and fraud prevention) and legal obligations (such as accounting and anti-money laundering recordkeeping). Oobit users may also have data associated with wallet-native payment activity, including identifiers needed to process card transactions and wallet-to-bank settlements.

Common Data Categories and Retention Drivers

Retention practices often vary by data type. Account and identity verification data (for example, KYC records) is typically retained to meet regulatory recordkeeping requirements and to support audits. Transaction and ledger records may be stored to reconcile card payments, monitor chargebacks, and produce financial statements; these records may include timestamps, amounts, currency conversions, and counterparties as represented in internal systems. Security and risk data—such as device information, access logs, and fraud signals—may be kept to detect abuse patterns and to investigate incidents.

How Deletion Requests Typically Work in Payments Systems

Deletion requests generally begin with user identity verification to prevent unauthorized removal. Once verified, the request is evaluated against applicable laws and contractual duties that may require continued retention of certain records (for example, regulatory compliance, tax, or dispute resolution). In a crypto payments context, a distinction often exists between data held by the service provider and data that is inherently persistent on public blockchains: on-chain transaction data cannot be erased by a single entity, while off-chain records (support tickets, marketing preferences, or profile fields) may be eligible for deletion or anonymization.

Practical Outcomes, Exceptions, and User Controls

A completed deletion request may result in removal of optional profile data, de-linking of contact information, deletion of non-essential analytics identifiers, and closure of the account; some systems apply irreversible anonymization rather than literal deletion to preserve required financial ledgers without retaining direct identifiers. Exceptions commonly include records needed to comply with financial regulations, maintain security logs for defined periods, and resolve open disputes or chargebacks. Users can reduce future data collection by limiting optional permissions, avoiding unnecessary profile fields, and keeping wallet connections scoped to the minimum required for settlement flows.