Data Retention Policy

Transparency in how we store, manage, and protect your information. We only keep your data as long as necessary.

  • Secure Storage
  • Deletion On Request
  • Clear Timelines

Last updated

1. Purpose and Scope

This website is pre-launch.The personal data this site collects today comes from the waitlist form: your first and last name, email address, a self-reported debt range you choose from a list, how you heard about Ovr, a referrer, and an optional free-text answer about what you are excited about. The debt range is financial information you volunteer about yourself — it is a broad bracket, not bank-account or credit-report data, and this site never connects to your accounts. We also collect basic website analytics. Retention schedules below that cover transactions and linked accounts describe the Ovr mobile app, and will be reflected here based on the production application's implemented services before public launch.

1.1 Purpose

Ovr Finance™ (operated by JRM Creative Ventures LLC) retains personal data only for as long as necessary to:

  • Fulfill the purposes for which it was collected
  • Meet legal, contractual, and regulatory obligations
  • Support legitimate business requirements (security, fraud prevention, dispute resolution)
  • Provide Services you've requested

1.2 Principles

We adhere to data minimization and storage limitation principles:

Collect only what's necessary
Keep only as long as needed
Delete when no longer required
Secure during entire lifecycle

1.3 Scope

This Data Retention Policy applies to:

  • All personal data collected through Ovr Finance™ Services
  • Data processed on behalf of users
  • Data stored by the third-party processors listed in Section 7
  • Data in production systems, backups, and archives

3. Types of Data We Collect and Retain

3.1 Account Information

  • Full name
  • Email address
  • Password (encrypted hash)
  • Phone number (if provided)
  • Profile photo (if uploaded)
  • Account creation date and status

Purpose: Provide access to Services, communicate with you, verify identity, fraud prevention

3.2 Financial Data

  • Linked bank account identifiers (tokenized via Plaid)
  • Credit card account identifiers (last 4 digits)
  • Account balances and credit limits
  • Transaction history and payment records
  • Debt payoff goals and projections
  • Payment authorizations and consent records

Purpose: Calculate debt payoff strategies and show you what to pay and when. Ovr does not process payments.

Important: We do NOT store: Full credit card numbers, CVV codes, bank login credentials, or Social Security Numbers

3.3 Technical Data

  • Device type, model, and operating system
  • IP address and general location
  • Browser type and version
  • App version and installation date
  • Unique device identifiers

Purpose: Provide and optimize Services, detect fraud, debug technical issues, security monitoring

3.4 Usage Data

  • Pages/screens viewed and features used
  • Time spent in app and frequency
  • Interaction patterns
  • Error logs and crash reports
  • Performance metrics

Purpose: Improve user experience, develop features, identify bugs, optimize performance

3.5 Support Communications

  • Support tickets and messages
  • Screenshots or attachments
  • Feedback and survey responses
  • Resolution notes and timestamps

Purpose: Provide customer support, track issue resolution, improve Services, legal defense

3.6 Subscription Records

  • Subscription start/end dates
  • Subscription tier and status
  • App Store/Play Store transaction IDs
  • User consent records

Purpose: Tax reporting (IRS 7-year), dispute resolution, subscription management

4. Retention Periods by Data Type

Data TypeRetention PeriodLegal/Business Reason
Account & Profile DataActive + 30 daysAccount continuity, support
Financial Transaction Records7 yearsIRS requirements (26 U.S.C. §6001)
Add-On Purchase Records7 yearsIRS requirements (26 U.S.C. §6001)
AI Recalibration Usage Logs3 yearsFeature improvement, abuse detection
Subscription/Billing Data7 yearsTax and accounting compliance
Support Communications3 yearsLegal defense, quality improvement
Usage & Analytics Data18 monthsProduct optimization
Technical/Device Data12 monthsSecurity monitoring
System Backups (Encrypted)90 daysDisaster recovery
Audit Logs2 yearsSecurity compliance
Marketing Consent Records3 yearsCAN-SPAM recordkeeping
Anonymized DataIndefiniteNon-identifiable

5. Data Deletion Process

5.1 How to Request Deletion

⚠Cancel your subscription separately

Deleting your data does not cancel a paid subscription. Ovr plans are billed by Apple or Google, so you must cancel through your App Store or Google Play subscription settings. See Delete My Account for the full process.

In-App

  1. 1. Navigate to Settings → Account → Privacy & Security
  2. 2. Select "Delete My Account"
  3. 3. Confirm deletion and verify identity
  4. 4. Receive confirmation email

By Email

  1. 1. Send email to: support@ovrfinance.io
  2. 2. Subject: "Account Deletion Request"
  3. 3. Include: Full name, email, account details
  4. 4. Deletion processed within 30 days

5.2 Deletion Timeline

Day 0-1

Request received and verified

Identity verification completed, deletion queued, confirmation email sent

Day 1-7

Account deactivation

Account status changed to 'pending deletion', login access disabled, 30-day grace period begins

Day 8-30

Grace period

Data flagged for deletion but still recoverable, user can reactivate by contacting support

Day 31-60

Permanent deletion

Personal data erased from production databases, account cannot be recovered

Day 61-90

Backup purging

Data removed from encrypted backups, system logs scrubbed of personal identifiers

After Day 90

Complete erasure

All traces of personal data removed, only anonymized analytics remain

7. Third-Party Storage and Processing

Ovr Finance™ relies on third-party processors, and each one keeps data on its own schedule under its own terms — not ours. We can tell you what we send them and delete what is under our control, but we cannot shorten their retention windows for you.

Service ProviderWhat it receivesApplies to
VercelHosts this site; sees request logs and IP addressesThis website
ContentsquarePage analytics, only after you accept cookiesThis website
ResendSends the waitlist welcome email (first name, email address)This website
SheetMonkeyStores waitlist records: name, email, self-reported debt range, how you heard about Ovr, referrer, free-text answerThis website
Plaid Inc.Bank account linking; receives your credentials, we never doMobile app
Apple / GoogleApp distribution and subscription billingMobile app

Third-Party Deletion Requests

When you ask us to delete your data, we delete what we hold and ask our processors to do the same. We cannot guarantee their timing, so you may also go to them directly:

  • • Plaid (mobile app): my.plaid.com
  • • Apple: privacy.apple.com
  • • Google: support.google.com/accounts/answer/3024190

8. Data Security During Retention

Encryption

  • HTTPS/TLS for all data in transit
  • Encryption at rest provided by our hosting and email vendors
  • Access to stored data limited to those who need it

Access Controls

  • Principle of least privilege
  • Multi-factor authentication required
  • Role-based access controls
  • Quarterly access reviews

Security Monitoring

  • Intrusion detection systems
  • Anomaly detection for unusual access
  • All data access logged
  • 2-year audit trail retention

Secure Deletion

  • Cryptographic erasure (keys destroyed)
  • DoD 5220.22-M overwriting standard
  • Physical destruction of drives
  • Backup deletion on schedule

9. Your Rights

Right to Information

Know what data we retain, how long, why, and when it will be deleted

privacy@ovrfinance.io

Right to Deletion

Request deletion of your personal data (subject to legal exceptions)

support@ovrfinance.io

Right to Restrict Processing

Request that we stop processing your data while retaining it

privacy@ovrfinance.io

Right to Data Portability

Request a copy of your data in a portable format (CSV, JSON)

privacy@ovrfinance.io

Right to Object

Object to retention for certain purposes (marketing, legitimate interests)

privacy@ovrfinance.io

Right to Lodge Complaint

File complaint with supervisory authority (ICO, California AG, state AG)

10. Where We Operate

Ovr will launch in the United States only. We are not established in the EU, UK, or Canada, do not market there, and therefore do not claim GDPR, UK GDPR, or PIPEDA status. Below is what actually governs us — and the principles we borrow anyway.

CCPA/CPRA (California)

  • Right to Delete (§1798.105)
  • 45-day response time, extendable once with notice
  • We keep records of deletion requests

Other US state privacy laws

  • Virginia, Colorado, Connecticut, and Utah equivalents
  • 45-day response target applied to everyone, not just residents
  • Appeal path available if we decline a request

Principles we follow voluntarily

  • Storage limitation: keep data only as long as it serves a stated purpose
  • Periodic review of whether a retention period is still justified
  • Automated deletion where we can build it

11. Automated Deletion (Planned)

Once the app is live, we intend to run automated jobs on the schedules below so that deletion happens on time rather than on request. These processes are planned to take effect when the OVR app launches and begins processing applicable user data.

Daily
  • Delete accounts past 30-day grace period
  • Remove expired session tokens
  • Purge old error logs
Weekly
  • Delete old usage analytics (18+ months)
  • Remove expired support tickets (3+ years)
  • Scrub personal identifiers from anonymized data
Monthly
  • Delete old system logs (12+ months)
  • Purge encrypted backups (90+ days)
  • Archive financial records to long-term storage
Quarterly
  • Comprehensive retention audit
  • Deletion of inactive accounts (2+ years)
  • Encryption key rotation

12. Data Retention Audits

Planned quarterly audits (every 90 days)

This is the review cycle we intend to run once the app holds live data. It has not started yet, so no audit has been carried out to date.

  1. 1Data inventory: Catalog all data in production and backups
  2. 2Age analysis: Identify data exceeding retention periods
  3. 3Legal review: Confirm no legal holds prevent deletion
  4. 4Deletion execution: Purge data eligible for deletion
  5. 5Documentation: Record audit findings and actions taken
  6. 6Reporting: Report to management and compliance team

Independent Audits

We have not yet had an independent audit. Ovr is pre-launch, and we would rather tell you that than imply a review that has not happened.

Before the app handles live financial data, we intend to commission a third-party security assessment and publish the date it was completed here.

13. Policy Updates

We may update this Data Retention Policy to reflect changes in legal requirements, new features, or improvements to retention practices.

Material Changes

  • • Email notification to all active users
  • • In-app notification upon next login
  • • Prominent notice on website
  • • At least 30 days' advance notice

Minor Changes

  • • Updated "Last Updated" date
  • • Notice on website
  • • No individual notification required

14. Contact Us

Data Retention Questions

Email: privacy@ovrfinance.io

Subject: "Data Retention Inquiry"

Response: 5 business days

Deletion Requests

Email: support@ovrfinance.io

Subject: "Account Deletion Request"

Response: 30 days maximum

Data Retention Reports

Email: privacy@ovrfinance.io

Subject: "Data Retention Report Request"

Response: 30 days

Legal and Compliance

Email: legal@ovrfinance.io

Subject: "Legal/Compliance Inquiry"

Mailing Address

JRM Creative Ventures LLC
Attn: Privacy
111 Town Square Pl Ste 1238 PMB 877216
Jersey City, NJ 07310-1810
United States

Quick Reference Summary

Data TypeHow LongWhy
Active account dataWhile activeProvide Services
After deletion30 daysAllow reactivation
Financial transactions7 yearsTax law (IRS)
Support tickets3 yearsQuality & legal
Usage analytics18 monthsProduct improvement
Backups (encrypted)90 daysDisaster recovery
Anonymized dataIndefiniteNon-identifiable

How to Delete Your Data

  1. 1. In-app: Settings → Account → Delete Account
  2. 2. Email: support@ovrfinance.io
  3. 3. Wait: 30-day grace period (can reactivate)
  4. 4. Confirmed: Permanent deletion after 30 days

Last Updated: August 2026 | Effective Date: August 2026

© 2026 JRM Creative Ventures LLC. All rights reserved.

Ovr Finance™ is a trademark of JRM Creative Ventures LLC.