HomeGift policy
HomeGift Data Retention and Deletion Policy
This policy defines how HomeGift retains, deletes, anonymises and reviews personal data.
- Effective date
- 18 July 2026
- Version
- 2026-07-18.v1
- Owner
- SENDHOME.ONLINE LTD
- Contact
- support@sendhome.online
Purpose And Scope
HomeGift follows data-minimisation principles and retains data only where needed for product operation, payment tracking, church administration, security, legal compliance, audit, support, provider investigation, reconciliation or dispute handling.
This policy applies to donor payment sessions, provider payment sessions, manual transfer records, payment initiation and status records, disclosure acknowledgements, anonymous session identifiers, audit and security logs, admin user records, church configuration records, provider metadata, support requests, database backups and logs.
Retention Schedule
| Data category | Example data | Default retention |
|---|---|---|
| Disclosure acknowledgement | Church slug, anonymous session ID, disclosure type, version and timestamps | 30 days for donor flow continuity; event record retained up to 13 months |
| Anonymous donor session | Session ID, selected church, selected amount, flow timestamps | 13 months |
| Payment initiation or provider record | Reference, provider session ID, payment status, amount, church | 6 years where needed for accounting, audit, dispute or reconciliation |
| Manual transfer record | Reference, amount, selected church, self-reported transfer status | 6 years where needed for accounting, audit, dispute or reconciliation |
| Provider diagnostic metadata | Redacted payload field list, response status, correlation headers | 18 months |
| Security logs | IP address, request metadata, failed admin attempts, rate-limit events | 12 months |
| Admin audit logs | Admin actions, church setting changes, provider configuration changes | 6 years |
| Church configuration | Parish name, payment settings, provider recipient IDs, approved bank-transfer details | For the duration of the church relationship plus 6 years |
| Support correspondence | Emails, support notes, issue history | 3 years after closure unless needed longer |
| Backups | Database and system backups | 30-90 days where technically feasible |
| Non-essential analytics | Analytics identifiers or usage metrics | Do not collect unless separately approved and consented where required |
Deletion And Anonymisation
Retention is currently policy-based and operationally reviewed. When a record reaches the end of its retention period, HomeGift will delete or anonymise it unless continued retention is required for legal compliance, accounting or audit, dispute handling, fraud prevention, security investigation, provider investigation, regulatory enquiry or backup integrity.
Where full deletion would break accounting, audit or security integrity, HomeGift may anonymise direct identifiers and retain non-identifying operational records.
User Deletion Requests And Backups
If a donor, administrator or church contact requests deletion, HomeGift will assess the request under applicable data-protection law. HomeGift may refuse or limit deletion where records must be retained for legal, security, audit, dispute, fraud-prevention, provider-investigation or accounting reasons.
Deleted records may remain in encrypted backups until the backup expires or is overwritten. HomeGift will not restore deleted personal data into live systems unless required for disaster recovery, security investigation or legal obligation.
Review
This policy must be reviewed at least annually and whenever HomeGift adds a new payment provider, payment method, Gift Aid processing, donor accounts, analytics, marketing, new categories of personal data or new jurisdictions.