Data Retention and Protection Policy

How long we keep data and how we protect it. Last updated: July 2026

← Back to ProfileTo

This policy explains how Innocode Ventures (operating as ProfileTo) retains and protects personal data processed through ProfileTo. It supplements our Privacy Policy and Security Policy.

1. Protection measures

  • HTTPS/TLS for production traffic
  • Encrypted storage of OAuth access and refresh tokens (Google Calendar / Zoom)
  • Authentication required for dashboard and connection management
  • Environment-based storage of application secrets
  • Regional databases for application data
  • Contracts / provider controls with infrastructure vendors that process data on our behalf

2. Retention overview

We retain personal data only as long as needed to provide ProfileTo, meet legal or accounting obligations, resolve disputes, or enforce agreements. Exact periods can vary by data type and legal requirements.

Data typeTypical retention
Account profile and login dataWhile the account remains active; deleted or de-identified after account deletion, subject to legal retention needs
Public profile contentWhile published by the profile owner; removed when unpublished or account deleted
Booking / appointment recordsWhile needed to operate scheduling history and support; removed or reduced when bookings/accounts are deleted under product and legal rules
Google Calendar OAuth tokensWhile Calendar / Google Meet remains connected; deleted on disconnect or account deletion
Zoom OAuth tokensWhile Zoom remains connected; deleted on Disconnect Zoom or account deletion
Zoom meeting ID / join URL on a bookingWith the booking record for as long as that booking is retained; cleared when the meeting is cancelled while connected, or removed with booking/account deletion
Referral cookie (`ptvia`)Up to 30 days (see Cookie Policy)
Billing / security / support logsAs needed for operations, fraud prevention, and legal/accounting requirements

3. Zoom data handling (summary)

  • Purpose: create, update, and delete Zoom meetings for ProfileTo bookings; confirm the connected Zoom user
  • Tokens: encrypted at rest
  • Meeting ID and join URL: stored on the booking so we can display the link and manage the meeting
  • Disconnect: Dashboard → Appointments → Connections → Disconnect Zoom
  • Details: Privacy Policy (Zoom user data) and Zoom Integration Guide

4. Deletion and user rights

Users may request access, correction, or deletion where applicable law provides those rights (including GDPR, CCPA/CPRA, and India DPDP, as described in the Privacy Policy). Contact [email protected]. We respond within legal timeframes.

Disconnecting an integration deletes stored OAuth tokens for that integration. It does not always delete historical booking records or meetings already created in the third-party service, except where ProfileTo is still connected and performs cancellation cleanup as described in product behavior and the Privacy Policy.

5. Contact

Privacy and retention questions: [email protected]. Operating company: Innocode Ventures (operating as ProfileTo).