Security

Data retentionA lifecycle, not one timer

What Wox keeps to run your workspace, how access is limited, what you can request, and why deletion timing can differ by data type and obligation.

Data lifecycle

From active use to verified removal

01 — 04

01

Created and used

Account, restaurant, purchasing, inventory, and uploaded data support the workflows your team chooses to run.

02

Scoped and protected

Access follows authenticated organization, location, and role context; protected files remain private.

03

Exported or corrected

Authorized users can use product exports, while personal-data requests can cover access, correction, or portability.

04

Deleted or expired

Account and organization deletion workflows remove active access; remaining copies age out according to the applicable lifecycle.

What the policy covers

Different data serves different purposes.

Retention decisions are tied to the kind of record and why it exists—not applied as one blanket duration to the entire workspace.

01

Account and access data

Identity, membership, roles, authentication settings, and recovery information used to secure access.

02

Operational records

Orders, inventory, purchasing, vendors, locations, and reporting history used to run and explain the business.

03

Uploaded and generated files

Invoices, documents, images, and exports stored privately and delivered through authorized access paths.

04

Service and security data

Technical records needed to operate, troubleshoot, protect, and improve the service.

Your controls

Access, export, correct, or delete

Use the dedicated request route when the in-product workflow does not cover what you need. Include the account email and organization context so the request can be verified and scoped correctly.

  • 01Request access to personal data associated with your account.
  • 02Ask for inaccurate personal information to be corrected.
  • 03Request a portable copy or deletion where applicable.
  • 04Use authenticated account or organization controls for workspace closure.
Submit a data request

Important context

Deletion is not identical for every record.

Legal, accounting, fraud-prevention, dispute, and security obligations can require some records to be kept longer than active workspace data. Deletion can also take time to propagate through protected recovery copies, which are isolated from normal product access and expire through their own lifecycle.

Need a current schedule for a specific data class?

Ask about retention