Purpose
This policy supports the Privacy Policy by describing how Availight expects to retain, minimize, delete, export, and audit personal information across Availight Cloud, the customer portal, support workflows, connected-service features, and related public website tools.
The goal is to keep enough data to operate Autopilot, support device ownership, troubleshoot reliability, and protect the service without keeping sensitive data longer than necessary.
Data Categories
- Account profile: email, account ID, and profile timestamps kept while the account is active.
- Claimed devices: Controller install ID, product type, room name, firmware/protocol versions, and claim timestamps kept while the device is claimed.
- Delivery tokens: hashed Controller delivery token and active/revoked state kept while needed for device delivery and security.
- Pending deliveries: normalized event delivery or clear-source commands kept until acknowledged, expired, failed, or device unclaimed.
- Provider connections: provider source, encrypted token reference, selected calendars, and connector settings kept while connected.
- Provider event cache: redacted event window, source, status, title if needed, and transition timing kept only as needed for sync and upcoming context.
- Cloud audit events and diagnostics: privacy-safe claim, unclaim, token rotation, provider connect/disconnect, delivery, sync, and health information kept for support and security review.
- Support and privacy requests: ticket messages, user-submitted attachments, privacy-request status, approval evidence, and customer-authored support content kept only as needed to resolve, audit, or legally preserve the request.
- Order requests and accepted orders: contact details, preferred contact method, requested quantity, shipping ZIP code, customer notes, request status, consent timestamp, and fulfillment records kept only as needed for sales follow-up, fulfillment, support, warranty, tax, fraud-prevention, dispute, and legal obligations.
- Website and portal analytics: cookie notice acknowledgement, page and portal-screen visits, downloads, feature interactions, form and support workflow outcomes without submitted contents, performance measurements, technical failures, request status and timing, and aggregate site behavior after the visitor accepts analytics cookies.
Deletion Triggers
Disconnecting a provider should delete or invalidate its encrypted token reference, clear source-specific active events, stop provider polling or webhook/watch channels where supported, and queue a clear delivery to the Controller.
Unclaiming a Controller should revoke active Controller delivery tokens, fail or clear pending deliveries, disable cloud polling from the mobile app when local access is available, and remove the device from the account's active registry.
Confirmed in-app account deletion removes Availight Cloud access and eligible data immediately, including device claims, delivery credentials, connected-service authorization, owned support files, and profile data. Limited support or security evidence may remain only in detached or anonymized form where legally or operationally required.
Data Minimization Rules
- Do not store Wi-Fi passwords or setup codes in Availight Cloud.
- Do not return OAuth tokens, delivery tokens, token hashes, or feed URLs through diagnostics.
- Do not intentionally send names, email addresses, support ticket messages, OAuth tokens, feed URLs, or device delivery tokens to Google Analytics.
- Avoid storing provider raw payloads after normalization.
- Avoid storing attendees, descriptions, locations, and conference links unless a future feature explicitly requires user consent.
- Prefer current state plus short operational history over indefinite logs.
Operational Retention Targets
- Pending deliveries should expire at or before their event transition or queue expiry.
- Provider event cache should keep only current and near-future windows needed for Autopilot, generally within the next 18 hours unless sync requires a provider token cursor.
- Audit events should be kept 90 days during beta unless investigating abuse or support issues.
- Connector diagnostics should keep latest state and last sync/error timestamps.
- Approved data exports should be stored outside the public website, expire, and be downloadable once by the verified account owner.
- Support and privacy case content should be retained only as long as needed to resolve the case, maintain required evidence, handle warranty or legal obligations, or prevent abuse.
- Uncompleted order requests should be deleted or anonymized within 12 months unless the customer asks for continued follow-up or the record is needed for security, dispute, or legal reasons. Accepted-order records may follow longer tax, warranty, and transaction-retention requirements.
- Support-managed deletion requests may use a 30-day recovery and compliance hold before cleanup, except where a legal preservation requirement applies. Confirmed in-app self-service deletion does not use that hold.
User Request Process
Signed-in mobile users can delete their Availight Cloud account from the Account screen. Users can also submit a managed deletion request from the customer portal's Account Settings Danger Zone or contact Availight Support for account, device, access, export, correction, deletion, appeal, or partial-removal requests.
Availight verifies account ownership and request authority before approving an action. Some records may remain in limited form when security, fraud prevention, warranty, tax, legal, backup, or audit obligations require retention.
- Email: support@availight.com
- Phone: 832-449-6080
- Website: https://www.availight.com
Legal And Operational Exceptions
Deletion, correction, export, and partial-removal requests may be limited when Availight must preserve records for security investigations, fraud prevention, warranty support, legal compliance, tax records, dispute handling, backup recovery, or required audit evidence.
When a full deletion is not legally or technically practical, Availight should minimize, detach, aggregate, or anonymize retained records where practical.
