Legal · Effective 17 August 2026
Data Retention Policy
Default production retention periods for Trakio measurement and attribution data.
Default periods
| Data | Default | Reason |
|---|---|---|
| Raw click IP address | 90 days | Fraud investigation and security |
| Click and conversion records | 760 days | Attribution, reporting, disputes, and trend comparison |
| Audit records | 730 days | Security and accountability |
| Raw postback response headers | 30 days | Delivery troubleshooting |
| Conversion identity claims | 30-day active comparison window by default | Duplicate-event review using scoped, one-way hashes; expired claims no longer influence new decisions |
| App Set ID and consented Advertising ID | Stored only as workspace-and-application-scoped hashes | Repeat-device fraud evidence; raw identifiers are never retained by Trakio |
| Account and device attribution bindings | Active while required for the customer's configured attribution, fraud-review, and dispute windows | Immutable acquisition and device-migration evidence; direct identifiers are scoped hashes and are pseudonymized after a verified deletion request |
| Play Integrity evidence | Aligned with the associated measurement record | Signed-token verification and replay review; raw tokens and nonces are not retained |
| Postback attempts | 395 days | Operational and partner delivery evidence |
| Encrypted logical backups | 14 days | Operational recovery |
| Encrypted physical base backups | 8 days | Point-in-time disaster recovery |
| Account data | Agreement term plus required legal period | Service delivery, security, and legal obligations |
Deletion and exceptions
Automated jobs enforce configured operational periods. Data may be retained longer where required by law, a preservation request, fraud investigation, dispute, or security incident, and is then restricted to that purpose. Tenant-configured periods may differ where the agreement and applicable law permit. Deletion from rotating encrypted backups occurs when those backups expire.
A verified account-deletion workflow removes active external identity from installations, events, and conversions and replaces the account binding with a random pseudonymous tombstone. This prevents the old identifier from being reconstructed while allowing restricted, non-identifying evidence to preserve financial, security, dispute, or legal audit integrity where required.
Requests
Customers can request export or deletion through their account contact. Individuals should normally contact the advertiser that collected their data; contact@trakiommp.com can help route a verified request.
