Records Retention Policy

VouchSite LLC · Effective date: September 5, 2026

1. Why this policy runs the other way

Most retention policies exist to justify deleting things. This one exists to justify keeping them.

VouchSite's purpose is to let a general contractor prove, years after a project ends, what insurance was on file for a subcontractor on a particular date. A record that has been tidied away is a record that cannot be produced when it is finally needed — and it is needed precisely when someone is being sued.

So the governing principle here is simple: compliance evidence is retained by default and deleted only for a reason. Nothing is purged on a housekeeping schedule.

This policy explains what we keep, for how long, what happens when someone asks us to delete something, and where the limits are.

2. What this policy covers

Every record created or received in operating the VouchSite service, wherever it is held — the application database, document storage, the certificate intake mailbox, messaging records, billing records, and backups.

It sits alongside section 10 of our Terms of Service and section 7 of our Privacy Policy. Where those documents state a period, this one states the same period in more detail. If they ever appear to conflict, the Terms of Service governs.

3. Why the periods are what they are

Construction claims are governed by statutes of repose — absolute outer deadlines that cut off a claim regardless of when the problem was discovered. They are the reason a general contractor needs compliance evidence long after a job closes.

They vary widely by state. The two nearest our own operations:

  • Washington — a claim must accrue within six years after the later of substantial completion of construction or termination of services. Claims that have not accrued in that window are barred. (RCW 4.16.310)
  • Oregonten years after substantial completion or abandonment for residential and small commercial structures, and for claims brought by a public body. Six years for large commercial structures. (ORS 12.135)

Elsewhere the range is much wider, and in two states there is no outer deadline at all. Periods run from roughly three years to twenty depending on the state, the structure, and who is being sued. New York and Vermont have no construction statute of repose, which means a contractor there can be answerable indefinitely. Maryland reaches twenty years for certain defendants, Pennsylvania twelve with a possible extension, Iowa fifteen in cases of fraudulent concealment, and Indiana twelve for design defects.

So we do not set a single global expiry. Our rules are:

  • A six-year floor. No compliance record is disposed of sooner, anywhere.
  • A ten-year default, measured from the later of the policy expiration date shown on the certificate or the completion of the project the certificate was submitted for. The clock does not start at the date we received the document, because a certificate submitted at bid time for a multi-year project would otherwise age out while the project is still exposed.
  • Longer where the project's state requires it. Where the state in which the project is located provides a period beyond ten years, or provides none at all, records for that project are retained for that longer period or indefinitely, as the case may be.
  • Longer again under a legal hold. See section 8.

In practice this means we keep compliance records at least ten years and often longer, and we do not treat a fixed date as permission to destroy evidence a customer may still need.

4. Retention schedule

Record Retained for Clock starts
Certificates of insurance as submitted Six-year floor, ten-year default, longer where the project's state requires it or where a legal hold applies — see section 3 Later of policy expiration or project completion
Extracted values and verification method Same as the certificate they came from
Activity log — requests, submissions, status changes, decisions Same as the certificate the entry relates to
Exception and waiver records — reason, approver, expiry Same as the certificate
Subcontractor and broker records As long as any compliance record linked to them is retained
Project records and configured minimums Same as the certificates submitted against them
Consent attestations — attesting user, timestamp, source address With the subcontractor record, and never less than four years after the last message sent Last message sent to that number
Messaging records — message as sent, provider message identifier, delivery status Four years Date sent
Opt-out records Indefinitely. Never deleted.
Account, organization, and user records Seven years after the account closes Account closure
Billing and payment records Seven years Transaction date
Support correspondence Three years Last message in the thread
Certificate intake mailbox messages Deleted once the document is written to storage and the write is confirmed; seven days at the outside Write confirmation
Access and security records we keep — sign-ins, failed link validations, lockouts, administrative actions Twelve months Date of the event
Hosting platform diagnostic logs — workflow execution traces kept by our application platform Approximately two weeks, set by that platform and not adjustable by us Date of the event
Backups Thirty-five days, rolling Date the backup was taken

Four of these deserve a word of explanation.

Compliance records have no single expiry date. Section 3 explains why. The short version is that the correct period depends on where the project is, and in two states there is no outer deadline at all.

Messaging records are kept four years because that is the federal limitations period for claims about automated messaging under 28 U.S.C. § 1658, and the clock runs from the date each message was sent. Keeping the message, the delivery status, and the consent that authorized it for that long is what allows either us or a customer to answer a complaint with evidence rather than recollection.

Opt-out records are never deleted. This is the one place where deleting a record would cause harm rather than prevent it — remove the record that someone opted out, and that person can be contacted again. If you have asked us to stop messaging you, we keep the fact that you asked, permanently, and nothing else about you is needed to honor it.

The last two log rows are different in kind. The activity log near the top of this table is the compliance record — it is our data, held in our database, and it is what appears in an audit packet. The diagnostic logs kept by our hosting platform are that platform's own operational telemetry, retained on its schedule rather than ours, and they are not the source of any compliance record. Where we need a durable security record, we write it into our own database rather than relying on platform logs.

5. What deletion means here

We do not perform hard deletes in the application. A record removed by a user is marked deleted, hidden from the interface, and retained in the database with a log entry recording who removed it and when.

There are two reasons. The first is evidentiary: a compliance record that can be destroyed by a single click is not evidence, and an audit trail that can be broken by deleting the thing it points at is not an audit trail. The second is practical: people delete the wrong row.

Records marked deleted are still subject to the periods in section 4, and are purged only when those periods expire.

6. Storage tiering is not deletion

Older documents are moved to lower-cost storage tiers as they age. This changes what we pay to keep a document, not whether we keep it. A certificate in a lower tier is retrieved the same way, may take slightly longer to retrieve, and is complete and unaltered.

We mention it because "archived" in some products means "gone." Here it does not.

7. Deletion requests

Anyone may ask us to delete information about them by emailing support@vouchsite.com. Our Privacy Policy explains how we verify identity and how quickly we respond.

We will honor a deletion request except where retaining the record is required by law, is reasonably necessary to establish or defend a legal claim, is subject to a legal hold under section 8, or is an opt-out record.

If the requester is a subcontractor or a broker, the compliance records concerning them belong to the general contractor who entered them, and that general contractor decides whether they are deleted. We will identify the customer and forward the request. We honor a request to stop messaging immediately and directly, without involving anyone else and without verification.

We will always say plainly which parts of a request we cannot honor and why.

8. Legal hold

When we know, or reasonably should know, that records are relevant to actual or reasonably anticipated litigation, a regulatory inquiry, a subpoena, or an insurance claim, those records are placed on legal hold.

Records on legal hold are exempt from every period in section 4 and from deletion requests under section 7, and are retained until the matter concludes and the hold is lifted. A hold takes precedence over everything else in this policy.

A customer may ask us to place a hold on their own records. We will do so.

9. Cancellation

Cancelling an account does not delete anything.

For ninety days after cancellation, a former customer may generate and download a complete audit packet — certificates, extracted values, verification methods, the full activity log, and exception records. After that window, access to the application ends, but the records themselves continue to be retained under section 4, because the obligations that made them worth keeping do not end when a subscription does.

A former customer who needs a copy after the export window has closed may contact us.

10. Backups

Backups are taken nightly and kept on a thirty-five-day rolling basis. They exist to restore the service after a failure and are not used to answer information requests.

One honest limitation. When a record is deleted, it may persist in backups until those backups age out — up to thirty-five days. We do not selectively edit backups, because a backup that has been altered is not a reliable backup. Deleted records are not restored to the live system if a restore is performed.

11. Responsibility and review

The owner of VouchSite LLC is responsible for this policy and for the retention controls that implement it.

This policy is reviewed at least annually, and additionally whenever we add a service provider that stores customer information, change where documents are stored, or begin operating in a state whose statute of repose exceeds the outer bound in section 3.

12. Changes

We may update this policy. When we do, we will change the effective date above and post the updated version here. We will not shorten a retention period for records already collected in a way that would destroy evidence a customer is relying on.

13. Contact

VouchSite LLC 522 W Riverside Ave STE N Spokane, WA 99201 support@vouchsite.com