Data Retention Schedule

Version 1.1 | 05 March 2026

This Data Retention Schedule sets out how long StoreNova Ltd ("StoreNova") retains personal data relating to Customers, Vendors, Couriers and Platform operations.

Retention periods are set in accordance with:

• UK GDPR

• Data Protection Act 2018

• HMRC tax record- keeping requirements (6 years)

• Companies Act 2006

• Limitation Act 1980 (contract claims up to 6 years)

• Food safety enforcement requirements

• Operational and fraud- prevention best practice

StoreNova deletes or anonymises data at the end of each retention period unless a legal obligation requires longer retention (e.g., litigation hold).

1. ACCOUNT & IDENTITY DATA

Data CategoryDescriptionRetention PeriodLegal Basis / Reason
Customer Account DataName, email, contact details, login information, order history6 years from last activityCompanies Act 2006, HMRC retention rules, Limitation Act (contractual claims)
Vendor Account DataBusiness information, contact details, compliance records6 years from account closureHMRC records, contractual limitation period
Identity Documents (Vendor)Passport, driving licence, KYC documentation6 yearsAnti-fraud and AML verification, audit trail
Stripe Biometric DataFace-matching templates used during ID verificationNot stored by StoreNova; deleted by StripeStripe is the independent Data Controller

2. ORDER, TRANSACTION & PAYMENT DATA

Data CategoryDescriptionRetention PeriodReason
Customer Order DataOrder contents, delivery info, timestamps6 yearsHMRC and audit requirements
Vendor Transaction RecordsPayout logs, fees, commissions, earnings6 yearsFinancial compliance
Payment Metadata (Stripe)Transaction IDs, card last4, auth tokens6 yearsChargebacks, fraud prevention, accounting
Refunds & ChargebacksRefund reasoning, evidence, dispute logs6 yearsFinancial dispute obligations

3. DELIVERY & LOCATION DATA

Data CategoryDescriptionRetention PeriodReason
Courier GPS LogsRoute details, timestamps90 daysDelivery investigations
Customer GPS DataReal-time delivery tracking (permissioned)90 daysFraud prevention, operational accuracy
Proof of Delivery Photoscouriers180 daysDispute resolution
Delivery Contact DetailsPhone number shared with courier24 hours post-deliveryData minimisation

4. CUSTOMER-VENDOR DATA SHARING

Customer Name & Address (shared with Vendor): Required for order fulfilment - Vendor must delete within 24 hours of successful delivery - Strict minimisation under UK GDPR and Vendor Terms

Vendors are prohibited from retaining, storing, exporting, or re- using customer data.

5. COMMUNICATIONS & SUPPORT DATA

Data CategoryDescriptionRetention PeriodReason
Customer Support TicketsChat logs, email requests6 yearsLegal defence, audit
Vendor Support TicketsCompliance communications6 yearsRegulatory need
Dispute EvidencePhotos, screenshots, courier logsResolution + up to 24 monthsAudit and fraud prevention

6. MARKETING & CONSENT DATA

Data CategoryDescriptionRetention PeriodReason
Soft Opt-In Marketing DataPurchase + marketing flagsUntil customer unsubscribesPECR Regulation 22
Email Marketing LogsDelivery logs, unsubscribe logs24 monthsPECR compliance
Explicit Consent RecordsThird-party marketing consentUntil withdrawn + 24 monthsICO consent evidence
Suppression List Data"Do not contact" listIndefinitelyRequired to prevent marketing after opt-out

7. ANALYTICS, TECHNICAL & PLATFORM DATA

Data CategoryDescriptionRetention PeriodReason
Device DataDevice IDs, OS, model12 monthsDebugging, optimisation
Crash/Error LogsServer logs, crash dumps12 monthsEngineering and security
Session LogsLogin attempts, session tokens12 monthsFraud monitoring
Aggregated/Anonymised AnalyticsNon-personal usage statisticsIndefinitelyNot personal data

8. FRAUD, SECURITY & COMPLIANCE DATA

Data CategoryDescriptionRetention PeriodReason
Fraud FlagsSuspicious activity indicators5 yearsFraud prevention
Blocked Vendor AccountsBanned accounts, reasons6 yearsRepeat-fraud prevention
Device FingerprintingRisk-scoring data2 yearsPrevent evasion

9. INTERNAL ADMINISTRATIVE RECORDS

Data CategoryDescriptionRetention PeriodReason
KYC/AML LogsID verification metadata (non-biometric)6 yearsAML laws, financial record-keeping
Complaint LogsICO/legal/customer complaints6 yearsRegulatory expectations
Vendor Compliance NotesAccount warnings, strikes6 yearsPlatform integrity
Internal Billing & Ledger DataFinancial summaries6 yearsCompanies Act & HMRC

10. INTERNATIONAL TRANSFERS

Vendor and customer data may be accessed outside the UK. All international transfers are protected using:

• UK International Data Transfer Agreement (IDTA)

• UK Addendum to the EU Standard Contractual Clauses (SCCs)

StoreNova ensures all onward transfers provide equivalent UK GDPR protection.

11. DELETION OR ANONYMISATION PROCEDURE

At the end of the retention period:

Personal data is securely deleted, or Irreversibly anonymised so it is no longer personal data.

Data subject deletion requests are honoured unless a legal retention requirement applies (e.g., HMRC 6- year rules).

12. POLICY REVIEW

This Retention Schedule is reviewed every 12 months, or sooner if regulatory or operational changes require it.

Version Control: Version 1.1 | Date: 05 March 2026