OWFI Legal
Data Retention and Deletion Policy
Effective date: June 15, 2026
This policy describes OWFI's intended retention and deletion practices for account, deal, document, payment workflow, and provider verification data.
Retention Principles
OWFI retains data only for as long as reasonably needed to operate the platform, support active or historical transactions, maintain security and audit records, comply with legal obligations, and resolve disputes.
Where data is no longer needed, OWFI will delete, de-identify, or archive it according to operational, legal, and security requirements.
Account and Profile Data
Account and profile data is retained while an account is active. After account closure or verified deletion request, OWFI will delete or de-identify account data unless retention is required for transaction records, legal obligations, security, or dispute resolution.
Buyer Applications and Provider Data
Buyer application records are retained while the related transaction is active and for a reasonable period afterward for audit, transaction history, and dispute support.
Plaid access tokens and similar provider credentials should be deleted when they are no longer needed, when the user disconnects the provider, or when a verified deletion request is approved. Provider tokens are intended to be encrypted at rest.
Documents and Messages
Uploaded documents, title-company messages, inbound email content, and related metadata are retained while needed for transaction workflow and audit history.
Some deal records and document metadata may be retained even after a deletion request when needed for legal, accounting, audit, fraud prevention, or transaction integrity purposes.
Logs and Audit Records
Security, audit, webhook, payment, and operational logs may be retained to investigate incidents, enforce access controls, troubleshoot errors, and maintain platform integrity.
Logs may contain limited personal data and are access-restricted.
Deletion Requests
Users may request access, correction, deletion, or provider disconnection by contacting info@owfi.io. OWFI will verify the requester before acting on sensitive data requests.
OWFI will respond to deletion requests in accordance with applicable law and will explain when data cannot be deleted because of legal, audit, transaction, or security requirements.
Review
This policy should be reviewed at least annually and whenever OWFI materially changes its data providers, transaction workflow, or legal obligations.