Legal
Data Retention and Disposal Policy
Effective September 4, 2026
Prove USA Inc keeps ProveBooks data while an account is open so the service can maintain the company's books. A verified request to close the account starts permanent deletion of everything associated with it, including copies held in backups and by service providers.
1. Purpose and governing rule
This policy governs information created, received, stored, or processed by Prove USA Inc through ProveBooks. Its rule is simple: keep data only while there is a defined service need, protect it while it exists, and permanently dispose of all of it when the customer closes the account.
Account closure means deletion, not suspension, soft deletion, deactivation, archiving, or removal only from the user interface. Deleted information is not available for restoration or later account reactivation.
2. Data covered
The deletion obligation covers all data associated with the account:
- user profiles, authentication links, company memberships, roles, invitations, preferences, and contact information;
- company profiles, source-system identifiers, accounting settings, books, journal entries, reports, reconciliations, tax mappings, questions, decisions, approvals, work product, and audit records;
- uploaded documents and other source files, object-storage copies, extracted or redacted evidence, metadata, citations, hashes, and derived facts;
- conversations, prompts, responses, automated-agent sessions, provider events, tool calls and results, jobs, wakeups, and queued work;
- connected-service authorizations, credentials, tokens, scopes, webhook registrations, cached records, and synchronization state;
- billing and support records held for ProveBooks, including the closure request and confirmation after deletion is complete;
- application, security, diagnostic, access, and operational logs that can be linked to the account or a person; and
- replicas, exports, temporary files, disaster-recovery copies, backups, and copies processed by a service provider for us.
3. While an account is open
ProveBooks retains account and customer data while the account is open when it is needed to provide the service, preserve the integrity and provenance of the company's books, secure the account, resolve a support request, or administer the customer agreement. Because books depend on their source records and revision history, we do not automatically erase an open account's older accounting records based only on age.
Temporary copies and routine operational logs are kept only for the shortest period reasonably needed for their stated purpose. Access is limited by role and system need. We review data stores and service providers at least annually and when a material system changes so unneeded copies do not become a shadow archive.
4. How to close an account
Email support@provebooks.com from the address associated with the account and say that you want to close it and delete its data. We will verify the requester's identity and, for company data, authority to close the company account. This verification protects the company from an unauthorized or accidental deletion.
Before confirming, download anything the company must keep. Customers are responsible for their own tax, employment, corporate, and other recordkeeping duties. We cannot recover a record after disposal.
5. What happens after verification
Prove USA Inc will:
- block further sign-in and stop imports, synchronizations, jobs, automated-agent work, and new collection for the account;
- revoke and delete connected-service credentials and registrations;
- permanently delete every category in Section 2 from production databases, private object storage, search or cache layers, operational systems, and internal tools;
- send deletion instructions to each service provider processing a copy for us and track the request through confirmation;
- prevent any residual backup copy from being used for ordinary operations and permanently delete it through the backup-destruction cycle; if a disaster recovery restores an older copy before that cycle finishes, reapply the deletion before returning the system to service; and
- confirm completion to the requester only after the account's data has been removed from all of those locations.
We do not keep a copy for business analytics, product improvement, security history, fraud prevention, dispute defense, tax records, or possible future reactivation. We do not turn identifiable account data into a retained “anonymous” substitute during closure.
6. Timing and status
We acknowledge a closure request within 10 business days. After verifying it, we complete the deletion without undue delay and ordinarily within 45 calendar days after receiving the request. If a backup or service-provider deletion needs more time, we tell the requester why during that first 45-day period, keep the data unavailable for every other purpose, and complete and confirm the deletion no later than 90 calendar days after receiving the request.
The request remains open until all locations and providers are accounted for. A failed object deletion, unavailable provider, or incomplete backup cycle is retried and escalated; it is not treated as successful disposal.
7. Narrow legal prohibition
If a binding law, court order, or regulator expressly makes deletion of a particular record illegal, we segregate only the exact record covered, block ordinary access and use, preserve it only for that requirement, and permanently delete it as soon as the prohibition ends. This is not a general legal, accounting, security, or litigation retention exception and does not permit us to retain the rest of the account.
8. Disposal methods
Structured records are hard-deleted from the owning data store. Object-storage items and their versions are deleted by exact object key. Credentials and encryption material are revoked or destroyed so they cannot be reused. Caches, replicas, queues, exports, and temporary files are purged. Backups expire or are cryptographically destroyed through their controlled destruction cycle. Physical media, if used, is securely erased or destroyed before reuse or disposal.
Disposal work is limited to authorized personnel and systems, logged without reproducing customer content, verified against an inventory of account data locations, and reviewed when an exception or failure occurs.
9. Responsibilities and review
Prove USA Inc owns this policy. Personnel and service providers with access to ProveBooks data must follow it, receive appropriate security and disposal instructions, and report disposal failures. We review this policy, the data inventory, access rules, backup behavior, processor contracts, and deletion tests at least annually and after a material change or security incident.
10. Related policies and contact
See the Privacy Policy for collection, use, disclosure, and rights information, and the Terms of Service for the account agreement. Questions and closure requests may be sent to Prove USA Inc at support@provebooks.com.