Legal
Data Retention Schedule
Default ShipMsg retention periods and the exceptions that control deletion timing.
Effective September 3, 2026
Default schedule
| Data category | Default retention |
|---|---|
| Message content and media | 30 days by default; customer configurable from 1 to 365 days, or longer by enterprise agreement |
| Message metadata and delivery state | 13 months by default; up to 7 years by contract |
| Contact identifiers | For the contact lifetime, then 30 days after deletion |
| Raw provider ingress | 7 days; unknown-asset quarantine 72 hours |
| Customer webhook attempts and event bodies | 30 days |
| Events API records | 30 days |
| Idempotency records | 24 hours by default |
| Encrypted broker content topics | No more than 7 days |
| Application logs and traces | 30 days and 14 days respectively in production |
| Content-free analytics facts | 13 months by default; up to 3 years by contract |
| Billing, invoices and pricing snapshots | 10 years |
| Audit records | 7 years |
| Consent evidence | Consent lifetime plus 3 years after withdrawal |
| Backups | 35-day recovery window; monthly snapshots retained 13 months |
How retention is applied
Customer-configurable settings apply prospectively within supported limits. Financial, consent, security and audit evidence may outlive message content because law, dispute handling, abuse prevention and accountability require different periods. Retained records are minimized or pseudonymized when full identifying content is no longer needed.
Deletion and backups
Deletion removes or makes customer content unreadable across active databases, object storage, caches and indexes. Short-lived encrypted broker copies expire within seven days. Protected backups age out through their lifecycle; the 35-day recovery window is the outer operational bound for ordinary backup expiry. Disaster-recovery restoration does not revive a completed deletion: the deletion ledger is reapplied before restored data is returned to service.
Legal holds and required records
A valid legal hold, fraud or security investigation, tax or accounting obligation, payment dispute, or binding legal demand may suspend deletion for the minimum necessary scope and time. Access remains restricted, the reason is recorded, and deferred deletion resumes when the hold ends.
Contact
ShipMsg legal questions: legal@shipmsg.com. Privacy questions and rights requests: privacy@shipmsg.com. ShipMsg support questions: support@shipmsg.com. Do not email passwords, payment-card data, message content, or identity documents; ShipMsg will provide a secure verification channel when needed.