1. Purpose and Scope
This Data Deletion Procedures document ("Procedures") is published by Allospend Technologies LLC ("Allospend," "we," "us," "our"), the operator of the Allospend consumer brand and the Allospend iOS mobile application. It describes the technical and organizational steps Allospend takes to delete personal information when a triggering event occurs, in compliance with:
- California Consumer Privacy Act / California Privacy Rights Act — Cal. Civ. Code §§1798.105, 1798.130, and 11 CCR §7060 et seq.;
- EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") — Articles 5(1)(e), 17, and 19;
- UK Data Protection Act 2018 and UK GDPR;
- Gramm-Leach-Bliley Act ("GLBA"), 15 U.S.C. §6801 et seq. — financial-institution record-keeping obligations;
- Bank Secrecy Act ("BSA") / Anti-Money-Laundering laws — 31 U.S.C. §5311 et seq., 31 CFR §1010.430, and 12 CFR §21.11 (bank-record retention);
- Internal Revenue Code §6501 (statute of limitations on assessment) and IRS Publication 552 (record-keeping guidance).
Capitalized terms not defined here have the meaning given in the Privacy Policy.
2. Triggers for Deletion
Allospend initiates the deletion procedures upon any of the following triggers:
- Account-closure request. A request to close the Allospend account, submitted from the account settings in the iOS app or by emailing
privacy@allospend.app. - Data-subject request. A verifiable consumer request to delete personal information under CCPA §1798.105 or GDPR Art. 17, including the right-to-be-forgotten claims.
- Automatic inactivity purge. No login, transaction, or active support interaction for 24 consecutive months, after which we send two warnings (at 18 months and 23 months) and then initiate closure. This is consistent with the storage-limitation principle in GDPR Art. 5(1)(e).
- Sanctions match. A positive match against the OFAC Specially Designated Nationals ("SDN") List, the U.S. Department of Commerce Denied Persons List, the UN Security Council Consolidated List, or any equivalent national or supranational sanctions list, in which case the account is suspended and data is retained and disclosed only as required by the Office of Foreign Assets Control ("OFAC") regulations at 31 CFR Part 501.
- Regulatory order. A binding order, subpoena, or warrant from a U.S. federal or state court, regulator, or law-enforcement body requiring deletion or restriction of personal information.
3. Data Inventory to Delete
The deletion procedures cover every category of personal information collected and processed through the Allospend service. The inventory below mirrors the categories described in our Privacy Policy.
3.1 Account and Identity Data
- Account email address, password (rendered unrecoverable — we hold only the salted-and-hashed verifier), display name, profile photo, phone number, date of birth, residential address (if collected for tax or KYC purposes).
- KYC verification artifacts provided to Stripe Identity or Plaid (see Section 4) — government ID images, selfie, document metadata, address proof. KYC artifacts are deleted by the KYC vendor under their own retention policy; we delete only the reference IDs and verification status fields stored in our database.
3.2 Biometric Data
- Biometric templates generated by Apple Face ID, Touch ID, and Passkeys. These are stored only locally on the device Secure Enclave and are never transmitted to our servers. When the account is deleted, we instruct the iOS app to clear the local biometric opt-in flag; the device-side templates themselves are owned and controlled by Apple and are destroyed automatically when the user disables the biometric or uninstalls the app (see our Biometric Information Notice for the full treatment).
3.3 Financial Data
- Wallet balances, transaction history (NFC payments, Cash App, Venmo, PayPal, Apple Pay routing metadata, withdrawals), recurring-expense configurations, group expense records, and aggregate financial analytics.
- We retain no more than 5 years of transaction history in compliance with the BSA / AML record-keeping rule (31 CFR §1010.430) and GLBA safeguarding requirements, even after account closure; the 7-year IRS retention overrides for any transaction that affects a tax-reportable event under IRC §6501.
3.4 Group and Social Data
- Memberships in NFC payment groups, expense splits, owed balances, settlement status, and direct messages sent inside group threads. Group members are notified via in-app message and email that a participant has left (subject to the notice opt-out on the requester's behalf).
3.5 NFC Sticker Records
- Sticker identifiers purchased, paired, and assigned to groups or vehicles. Deletion of an account triggers remote deactivation of any NFC sticker identifiers registered to that account (Section 7).
3.6 Communications
- Support emails and chat transcripts sent to
support@allospend.appand forms handled by our transactional email provider or our in-app Help Center are deleted when the underlying support ticket is closed and any post-closure retention window has expired. - Marketing emails sent through our newsletter provider are deleted from mailing lists within 24 hours of an unsubscribe request or account closure.
3.7 Smart Notes AI Data
- Prompts and outputs generated by the Smart Notes feature, which is processed through OpenAI, Anthropic, or Google Cloud AI under zero-retention / "data not used to train public models" terms. On account closure we issue a deletion request to the relevant AI provider under their account-data deletion API and delete the prompts, outputs, and intermediate embeddings we store.
3.8 Device Tokens
- Push tokens registered with OneSignal for the iOS app.
- Sign-in credentials from Apple "Sign in with Apple" and Google "Sign in with Google."
3.9 Marketing and Analytics
- Pseudonymized analytics events tied to the user's identifier. The identifier is deleted; aggregated, non-identifying analytics may be retained in aggregate form indefinitely.
4. Cascading Deletion Across Sub-Processors
We instruct each sub-processor to delete or return the relevant personal data in accordance with our Data Processing Addendum and the underlying vendor terms. The deletion cascade executes as follows:
| Sub-processor | What we instruct |
|---|---|
| Stripe / Stripe Identity | Initiate deletion of any stored identity-verification records and metadata. |
| Plaid | Disconnect the linked bank accounts and delete the access token. |
| MongoDB Atlas | Remove the user's account record, wallet, transactions, and group memberships. Tax / AML-retained records are preserved under the retention exceptions in Section 6. Group ownership is transferred or marked for handoff as described in Section 7. |
| AWS S3 | Purge receipt-scanned images, profile photos, and AI-prompt logs from user-scoped prefixes in our production storage. |
| Vercel | Edge cache is purged; user-specific authentication cookies expire automatically. |
| OneSignal | Remove every registered device token. |
| SendGrid | Remove the contact from our marketing lists; suppression-list entries are retained only to honor opt-out obligations. |
| Twilio | Mark Verify service entries for deletion and instruct Twilio to delete phone-number OTPs and verification attempts after their default retention period. |
| Apple | Disconnect Sign-in-with-Apple credential, revoke push tokens. |
| Disconnect Google Sign-in credential. | |
| OpenAI / Anthropic / Google Cloud AI | Submit a deletion request through the provider's data-deletion API for any stored prompts, completions, and embeddings. |
The cascade runs as a coordinated deletion job with explicit completion checkpoints and retry-with-backoff.
5. Verification of Deletion
After the deletion cascade completes, Allospend performs a verification pass:
- Database re-scan. A nightly compliance job re-runs the MongoDB deletion filter against the closed user set; any residual document is reviewed by the Privacy Officer and either deleted or moved into the documented retention-exception bucket.
- Search-engine deindexing. Public-profile pages that no longer exist return HTTP 410 (Gone).
- Receipt delivery. The Privacy Officer emails a "Deletion Complete" receipt to the registered email within 14 days of the cascade finishing. The receipt identifies the categories deleted and the categories retained under the retention exceptions (Section 6), with a clear legal citation for each exception.
6. Retention Exceptions
Allospend does not delete, and instead retains under controlled-access retention buckets, the following categories of personal information after account closure or a delete request, where retention is required or permitted by law:
6.1 Bank Secrecy Act / AML Records — 5 Years (31 CFR §1010.430(d))
We retain any record of funds transmittals, currency-transaction reports, suspicious-activity reports, and the underlying account information sufficient to reconstruct the transaction, for five years from the date of the transaction or the date the report was filed, whichever is later. After the 5-year period, the records are deleted.
6.2 Tax Records — 7 Years (IRC §6501; IRS Pub. 552)
We retain tax-reportable transactions (1099-K-eligible gross payments and similar records) and the related party information for seven years from the date of the transaction. After the seven-year period, the records are deleted.
6.3 Fraud Investigations — 3 Years After Closure
If the account has been flagged for suspected fraud, sanctions exposure, or anti-money-laundering review, we retain internal investigation notes, chargeback records, and dispute logs for three years after the account is closed, in accordance with the consumer-fraud statute-of-limitations in most U.S. states and the SAFE Act record-keeping obligations. Records are accessible only to the Compliance Officer and the legal team.
6.4 Pending Litigation Hold
If the user is involved in active litigation (or is reasonably anticipated to be) at the time of a delete request, Allospend issues a litigation hold that suspends deletion of the relevant records until the hold is released by counsel.
6.5 Required by Other Law
Where a federal, state, or foreign law requires retention, we retain for the period required and then delete.
7. Group Impact and Outstanding Payments
Closing an account that has open group obligations triggers a structured handoff:
- Outstanding balances. If the user owes money on any expense split at the time of deletion, the request to close the account is paused and the user is prompted to settle before closure. We do not delete financial records that would extinguish a group member's claim against another user.
- Owner-of-group transfer. If the user is the sole owner of an NFC payment group or expense group, ownership is automatically transferred to the longest-tenured active member; if no such member exists, the group is marked for handoff, no new spending is permitted, and the group's pool balance is refunded to the source payment instrument within 14 days.
- Anonymization in remaining groups. Where the user was a member (not owner) of groups still active after closure, the user is anonymized to other members (
Former Memberplaceholder, profile picture removed, display name replaced with the initialsF.M.); the user's individual transactions remain visible only to the group owner for accounting purposes. - Notification to other members. Other group members are notified by in-app message that a member's account has been closed and that any unpaid balances owed by or to that member are now subject to the outlined retention rules.
8. NFC Sticker Deactivation
When an account is closed:
- We call our sticker-authority service to deactivate every NFC sticker identifier registered to the user.
- The deactivation is logged to an immutable audit table; even if the user later re-opens an account, NFC stickers deactivated under a prior closure are not automatically re-paired — the user must purchase or re-register stickers.
- Apple Wallet passes issued for the deactivated stickers are revoked by the device side on the next NFC interaction (the Apple Wallet framework marks the pass as no longer active and refuses to transmit the underlying token).
- Where the sticker is associated with a vehicle or a business asset, the deactivation does not affect the physical sticker — the user is instructed to physically destroy the sticker; in the meantime, the sticker cannot authenticate to the Allospend network.
9. Backups and Disaster-Recovery Copies
Personal data is backed up to encrypted, append-only cold storage on a 30-day rotation. Backups are not modified by the live deletion cascade. Within 90 days of account closure, the affected backup snapshots are rotated out and securely overwritten using NIST SP 800-88 Rev. 1 (Clear or Purge, depending on the storage class). Verification: we run a "post-rotation audit" that confirms the user is not present in any remaining backup chain.
10. Confirmation Email and Acknowledgement
Within 14 days of cascade completion, we send a deletion confirmation email to the registered address. The email:
- restates the categories deleted;
- restates the categories retained under the documented exceptions, with the legal citation for each;
- provides a link to appeal or to request a final export;
- references these Procedures.
If a back-up rotation is still in progress at the 14-day point, the confirmation email notes the rotation timeline; a final "back-up rotation complete" notice is sent within 90 days of cascade completion.
11. Appeal
If you believe your deletion request was not properly fulfilled, you may appeal as set out in the Data Subject Request & Consumer Rights Procedures (Section 8) by emailing compliance@allospend.app within 30 days of the deletion receipt.
12. Contact Information
- Deletion requests:
privacy@allospend.app - In-app: Settings → Privacy → Privacy Data → Close Account
- Appeals:
compliance@allospend.app - General support:
support@allospend.app
Allospend Technologies LLC 725 Kingsland Avenue, Suite 100 St. Louis, MO 63130 USA
© 2026 Allospend Technologies LLC. All rights reserved. Allospend and Dummii are trademarks of Allospend Technologies LLC.