1. What This Policy Covers
This Policy explains, in plain language, how long Candyll keeps each kind of record and exactly what happens when you delete your account. It is the detailed companion to Sections 14 and 15 of the Privacy Policy.
"Candyll", "we", and "us" mean Boryne Labs Ltd. (operating as 'Candyll'), operator of the candyll.com website and the Candyll mobile app (together, the "Platform"). Capitalized terms not defined here (such as "Deal", "Group Deal", "Pledge", "Final Confirmation", "Deal Pass", and "Redemption") have the meanings given in the Terms of Service.
Candyll never processes customer payments and holds no customer funds. You pay the Merchant directly, normally in person at the store; the Merchant is the seller and merchant of record. Because of this, Candyll keeps no customer card data, payment tokens, charges, refunds, or settlement records — the records described below are your Pledge, Deal Pass, and Redemption activity, not payment records.
This Policy is one of the Policies incorporated into the Terms of Service. On the subject of retention and account deletion, this Policy prevails over the Terms of Service; the Terms of Service govern everything else. Nothing in this Policy limits any right you have under applicable law that cannot be waived; if anything here conflicts with such a right, the right prevails.
2. Our Retention Principles
- We keep personal information only as long as it is needed — for the purpose it was collected for, for a legal obligation, or to establish or defend legal claims.
- When a record is no longer needed, we delete it or de-identify it. De-identified information can no longer reasonably be linked to you.
- Some records must outlive your account. Canadian tax, accounting, and consumer-protection laws require businesses to keep certain records — for example, Candyll's own fee, invoice, and tax records (these relate to any fees Candyll charges Merchants, not to any customer payment, which Candyll never processes). For that business-tax class we apply a single, conservative period of approximately 7 years from the end of the year the record relates to, and we use the same figure everywhere we state it (Section 3, Section 8, and Section 14 of the Privacy Policy). We keep those records for their required period even after you delete your account, but we segregate them and restrict access to them (Section 5).
- Information used to make a decision about you (for example, an account-suspension or reliability-limit decision) is kept for at least one year after the decision, so that you can ask to see it.
- The periods below are operating defaults, not promises to destroy evidence: a legal hold (Section 4) can extend them.
3. Retention Schedule by Record Class
| Record class | Examples | How long we keep it | Why |
|---|---|---|---|
| Account and profile information | Email address, display name, profile image, language and notification preferences | Life of your account; deleted or de-identified within 30 days after account deletion | Operating your account |
| Consent and acceptance records | Which terms and policy versions you accepted and when; marketing opt-ins and opt-outs | While your account is active, plus 3 years after deletion or withdrawal | Proving and honouring your choices |
| Pledge, Deal Pass, and Redemption records | Your Pledges and Final Confirmations, Deal Passes issued and their status (including Deal Passes issued through a waitlist claim), records of Deal Pass uses, Redemption/visit records, cart contents | Kept while your account is active, then deleted or de-identified within 30 days after account deletion — except where a record is needed for an open dispute or an active fraud/abuse investigation (Section 4) | Operating Deals, verifying Redemption, and preventing abuse |
| Booking-contract snapshots (Slot Bookings) | The fixed copy of the terms you agreed to when you booked an appointment: the Merchant, service, date and time, location, Group Price, party size, the cancellation, late-arrival and no-show rules shown to you, and the document versions then in force. A snapshot contains no name, email address, or phone number — the customer is recorded as an account reference only | Written once, when you book, and never edited, corrected, or overwritten — an unalterable record is the point of it. Retained with the Pledge / Deal Pass class above, and de-identified on the same 30-day schedule after account deletion (de-identifying your account removes the link between you and the snapshot), except where an open dispute or investigation requires it (Section 4) | Proving exactly what was agreed at the moment of booking, and resolving disputes about it |
| Sensitive service details | Booking information relating to a service in a sensitive category (for example beauty or fitness/wellness) | Candyll collects almost none by design: there is no free-text notes field in the booking flow, and Candyll collects no medical, diagnostic, treatment, or sexual-health information. Where a sensitive-category booking record exists it is limited to the booking facts, is shown to the Merchant under the pseudonymous reference only (Privacy Policy, Section 6), and is deleted or de-identified with the Pledge / Deal Pass class within 30 days after account deletion | Data minimization and stricter handling for sensitive services |
| Deal Pass usage-flow records | QR scan events (recorded only where scan logging is enabled: time, store location, limited device signals), short-lived usage-preparation session records, and verification-attempt records (for example, the outcome of a staff-PIN check — never the PIN itself; staff PINs are held only as hashes) | Usage-preparation sessions expire within minutes; the operational scan and verification-attempt logs are kept for 30–90 days, longer only if needed for an active investigation (Section 4) | Operating in-store Redemption, security, and abuse prevention |
| Usage-dispute and reversal records | Reports about a recorded Deal Pass use (from you or from a Merchant), Candyll's review, and any reversal/correction and replacement record | Until resolved, then at least 2 years (same class as disputes below) — a reversal/correction entry is an auditable record and is retained with the dispute it corrects | Correcting the record, resolving and defending claims |
| Candyll's own fee, invoice, and business-tax records | Fees Candyll charges a Merchant, related invoices, and Candyll's own tax records for those fees (these concern Candyll's business, not any customer payment — Candyll processes none) | Approximately 7 years from the end of the year they relate to — the single figure we use for this class throughout our documents (Section 2, principle 3; Section 8; Privacy Policy, Section 14) — these survive account deletion | Canadian tax and accounting record-keeping requirements for Candyll's own business |
| Disputes and enforcement records | Complaints, enforcement appeals, and related correspondence about Platform access or conduct | Until resolved, then at least 2 years (the general period for legal claims); longer where the record is also a tax record | Resolving and defending claims |
| Reviews and ratings | Star ratings, written review text, tags, photos | Your written text and photos are deleted or de-identified within the same 30-day window. When your review or account is deleted, your star rating is removed from live aggregate figures where feasible; de-identified statistics already produced may persist | Keeping merchant rating averages honest without keeping your identity |
| Merchant licence and verification records | For categories that require licence verification (for example Travel Agency): the licence type and number, issuing authority, the legal name of the licence holder, expiry date, verification status, verification date, the reviewer, the comparison against the Merchant's legal name, and any suspension, rejection, or expiry step taken afterwards | Kept while the Merchant lists in that category, then at least 2 years after the verification ends (expiry, suspension, rejection, or account closure) — the same period as enforcement records; longer where a regulator, a claim period, or a legal hold (Section 4) requires | Showing that a regulated Deal was verified before it could be published, and defending verification and enforcement decisions |
| Support communications | Messages to our support, privacy, and security addresses | 2 years after the matter is closed | Service quality and dispute history |
| Privacy-request records | Your access, correction, deletion, consent-withdrawal, complaint, and security-incident requests: the request reference, request type, received date, verification status, who it was assigned to, status history, the 30-day response deadline, our recorded response, and the completion date (Privacy Policy, Section 18) | 2 years after the request is completed or refused (the same class as support communications); longer where an open complaint, a regulator file, or a legal hold (Section 4) requires | Proving that we received, tracked, and answered your request within the legal deadline |
| Security and server logs | IP addresses, request metadata, crash logs | Typically 30–90 days, longer only if needed for an active investigation | Security, fraud prevention, reliability |
| Privacy-incident records | Our record of each privacy incident and breach of security safeguards — what happened, when it was detected and contained, which systems and categories of information were involved, the risk assessment, whether anyone was notified and why or why not, the root cause, and the corrective actions (Privacy Policy, Section 20) | At least 24 months from the incident, or longer where the law or a legal hold (Section 4) requires. We keep a record of every breach of our security safeguards, including incidents that fall below any reporting threshold, and we keep only the affected-person detail the record needs | Legal record-keeping for breach response, and proving how each incident was assessed and handled |
| Copyright and content-complaint records | A copyright or content complaint we receive: the claimant's name and contact details, the work claimed, the content complained about, whether the notice was complete, whether it contained a prohibited demand, whether and when it was forwarded to the uploader, any restriction or removal step, the uploader's response, our decision and reasons, and the records that identify the relevant uploader (Review & User Content Policy, Section 10A) | Kept while the complaint is open, then six months from the day we received the notice, extending to one year where we receive notice that proceedings have been commenced and the statutory condition applies. Where the classification question described in Section 10A of that Policy is unresolved, we apply the same conservative period as an operational practice. Access is restricted, the records are used only for handling that complaint, and they are destroyed when the period ends unless a legal hold (Section 4) applies | Handling copyright complaints, forwarding notices, preserving evidence, and meeting the conditional statutory preservation requirement |
| Push tokens | The token that lets us deliver notifications to your device | Until you disable notifications, sign out, uninstall the app, or delete your account | Delivering notifications you enabled |
| Location data | Device location used for nearby Deals and distances | Not retained as a history — see the Location Services Notice | Location is used transiently, not stored |
| De-identified and aggregated data | Statistics that cannot reasonably identify anyone | May be kept indefinitely | Service analytics and reporting |
4. Legal Holds and Exceptions
We may keep a record beyond its scheduled period where the law requires it or where it is reasonably needed for an active matter — for example, an unresolved dispute, an investigation of fraud or abuse, a legal claim, or a demand from a court or authority with jurisdiction. When the matter ends, the normal schedule resumes.
5. What Happens When You Delete Your Account
Deleting your account triggers the following pipeline:
- Deactivation — immediate. You can no longer sign in, your profile stops being visible on the Platform, push notifications stop, and all marketing stops immediately (see the Marketing Communications Policy).
- Live activity is closed out — in the same step. Every Pledge or booking of yours that is still live is cancelled and your place is released (so the Deal's capacity and any waitlist are corrected straight away), and every Deal Pass you hold that has not been redeemed is voided. Nothing is charged or refunded, because Candyll never took a payment.
- A deletion request is filed for you — immediately. Your deletion is recorded as a privacy request of the "account deletion" type, with its own reference, received date, and 30-day response deadline, and is tracked like any other privacy request (Privacy Policy, Section 18). You do not have to file it yourself.
- De-identification — within 30 days. Your identifying personal information (such as your email address, display name, phone number, profile image, and notification token) is deleted or de-identified, and the written text and photos of your reviews are removed — your star ratings remain in the Merchant's aggregate figures with nothing left that identifies you.
- Segregation of legally retained records. Records we must keep by law — primarily Candyll's own fee, invoice, and tax records, and records tied to an open dispute — are kept for their required period from Section 3 in a restricted state: access is limited, and they are used only for the purpose that requires keeping them (for example, a tax audit or a legal claim). When their period ends, they are destroyed on schedule.
Deletion is permanent. It cannot be reversed and your account, order history view, favourites, and saved settings cannot be restored. If you return to Candyll later, you start with a new account.
Open matters come first. If you have an unresolved dispute or an open fraud/abuse investigation when you ask to delete your account, we may need to resolve it before or alongside the pipeline above. There is no payment to settle on deletion, because Candyll never charges you.
6. What Deletion Does Not Do
To be transparent about the limits:
- it does not erase the legally retained records described in Sections 3 and 5 before their required period ends;
- it does not recall de-identified statistics already produced — your star rating is removed from live aggregate figures where feasible, and nothing retained identifies you;
- it does not recall messages already delivered to you, or any receipt the Merchant issued you for an in-store purchase;
- it does not erase a Merchant's own business records of transactions it already fulfilled — Merchants are independent businesses responsible for their own records, and what they ever received about you is limited to the short list in the Privacy Policy (Section 6 of that document).
7. How to Delete Your Account
You can delete your account:
- in the app or on the website — through your account settings; or
- by request — writing to the Privacy Officer at privacy@candyll.com, or submitting an account-deletion request from the privacy section of your account on the Candyll website. We may need to verify your identity first; this protects you.
Either route is recorded as a privacy request with a reference and a 30-day response deadline, and you can quote that reference to us at any time (Privacy Policy, Section 18).
8. Merchants and Merchant Staff
Merchant accounts follow the same principles. Most Merchant data is business information rather than personal information, but personal information of Merchant owners and staff receives the same protections as Customer data. Candyll's own fee, invoice, and tax records relating to a Merchant (for example, any fees Candyll charges the Merchant) are kept for the business-tax class of approximately 7 years from the end of the year they relate to — the same figure stated in Section 2 (principle 3), Section 3, and Section 14 of the Privacy Policy. Candyll does not hold the Merchant's customer-sales proceeds and keeps no settlement or payout records, because customers pay the Merchant directly at the store; the Merchant keeps its own sales, tax, and receipt records as an independent business. Wind-down of a Merchant account, including in-flight Deals, is governed by the Merchant Terms.
9. Where Retained Records Are Stored
Retained records are stored with the service providers listed in the Privacy Policy, some of which are located outside Canada. The cross-border storage disclosure in the Privacy Policy (Section 9 of that document) applies equally to retained and segregated records.
10. Changes to This Policy
We may update this Policy as the law, our technology, or our practices change. We will post the updated version with a new version number and effective date, and for material changes we will give reasonable advance notice by email or in-app message. Each version applies from its stated effective date.
11. Contact
Privacy Officer Boryne Labs Ltd. (operating as 'Candyll') Mailing address: 604-7769 Park Crescent, Burnaby, BC V3N 0J7, Canada privacy@candyll.com
If you are not satisfied with our response, the complaint routes in the Privacy Policy (Section 21 of that document — the BC and federal privacy regulators) are available for retention and deletion concerns too.