Privacy and retention
Holding somebody’s details for no reason is the thing data protection law is actually about, and “we never got round to deleting it” is not a reason. Three jobs, in one place: Privacy and retention in the account menu.
How long you keep a dormant customer
Section titled “How long you keep a dormant customer”Counted from their last order, or from the day you added them if they never ordered. Seven years is the longest anyone may keep them, and it is where Bottle starts.
Why seven and not forever, and why seven rather than six: HMRC asks you to keep six years of records, and the seventh is the year that puts a dormant customer clear of that obligation. At seven years with no order there is nothing left that anybody is required to keep, so the customer goes entirely, orders and all.
Shorten the rule and that changes. An order less than six years old is still a record you must keep, so it stays, along with a customer row blanked of everything personal for it to hang on. Their phone number, email, notes and addresses go. Invoices from the last six years keep the name and address they were issued to, because a VAT invoice has to show who it was for.
Shorten it whenever you like. You will be emailed before anything goes, thirty days ahead by default, and the page lists exactly which accounts are due and when. Nothing disappears unannounced.
You can turn the sweep off entirely. Then nothing is erased unless you do it yourself, and the responsibility for how long you are holding people is yours.
Legal hold
Section titled “Legal hold”A dispute, an insurance claim, an HMRC enquiry. While one is live, deleting the file is the wrong answer, and the law allows for keeping it.
Open the customer, Account and data, Legal hold, Put on hold. Nothing erases them after that, not the nightly sweep and not the button next to it, until somebody takes the hold off. They still appear on the due list, marked, so they are not quietly forgotten.
When somebody asks what you hold
Section titled “When somebody asks what you hold”Download everything held, on the customer’s own page. One file: the customer, their addresses, the rates you agreed with them, and every order with its lines. That is what a subject access request is entitled to, and assembling it out of four screens by hand is how businesses answer these twice.
When somebody asks to be forgotten
Section titled “When somebody asks to be forgotten”Erase their details, on the same panel. The right to be forgotten is not absolute: you can keep what the law requires you to keep, and what you need to make or defend a legal claim. So what happens depends on what that is.
If they have no orders or invoices inside the last six years, the lot goes: the customer, their addresses, their agreed rates, and any orders and invoices older than that.
If they do, those orders stay with what they cost, and each invoice from those six years keeps the name and address it was issued to. HMRC requires copies of VAT invoices for six years, and a VAT invoice has to show who it was issued to; it is also what ties the money to a person if it ever comes to court. The customer row survives blanked so the orders have something to resolve to. Their phone number, email, notes and addresses go, and a one-off delivery loses the name and address it was carrying. Anything older than six years goes.
It cannot be undone. Take the export first if there is any chance they will ask for it.
Proving you did it
Section titled “Proving you did it”Every erasure is recorded: when, why, which record, whether it went entirely or was blanked, how many addresses were cleared, how many orders were left standing and how many were deleted. No names, because keeping what you erased would rather defeat it. That list is on the same page, and it is what you show somebody asking what you did about a request in March.
What Bottle’s own staff can do
Section titled “What Bottle’s own staff can do”Bottle’s staff can suspend an account or a business for abuse or non-payment, and can raise a business’s allowances. They cannot see inside your account without your say-so, and everything they do is recorded against their name.
Support access
Section titled “Support access”Bottle’s staff cannot see inside your account. What they can see is what Bottle holds about your business: your plan, your trial and your allowances.
If you want help from the inside, Business settings then Support access lets you allow it for a day or a week, at one of two levels: Look only, where a member of staff opens the account as one of your people and can change nothing, or Look and change. Bottle staff can also ask: the request arrives under the bell and by email, with the reason, and you approve or decline it there. Either way the access ends on its own, and every request they make while inside is written down with their name.
Bottle’s staff can only open your account with a grant from you, and every access is recorded, with the name of the person and what they did.
There is one exception, and it is worth knowing about rather than finding out. A senior member of Bottle’s staff can open a business without a grant, and must give a written reason to do it. It is there for the day a business is locked out of its own account, or invoices are going wrong and nobody is answering the phone. The reason and the name go into our own record, where they are reviewed, and everything done inside is written down the same way any other support access is.
Your own account
Section titled “Your own account”The same two rights, owed to you by us. Login and security, then Your data: download everything Bottle holds about you, or close your account.
Closing asks for your password again first, so a browser somebody left open cannot close an account. It then takes your password, second factor, sessions and connected apps. What you did inside a business stays as that business’s record, pointing at a closed account, so an invitation you sent still says somebody sent it. If you are the last owner of a business you are asked to hand it over first: orphaning a company is not an erasure, it is a support call.
Through the API
Section titled “Through the API”privacy:read reads the rules, what is due and what has been erased.
privacy:write changes the rules and erases somebody, and no API key or
connected app may ever hold it: erasure cannot be undone, and a retention rule
left wrong empties the book overnight. Exporting one customer needs only
customers:read, since it adds no access, only convenience.