Omnaris retains each record class for the time needed to operate the service, keep inventory and financial truth accurate, protect the platform, meet customer instructions, resolve claims, and satisfy contractual and legal obligations—then deletes, anonymizes, aggregates, or isolates it through an approved process.
Purpose and Scope
This policy explains how Omnaris Fulfillment determines retention for website, quote, customer account, integration, support, warehouse, inventory, parcel, billing, communication, scanner, and security records. It applies across the marketing site, customer dashboard and API, Enigma, scanner service, providers, logs, and backups.
Different records require different periods. Omnaris retains information only as long as reasonably needed for an active service, customer instructions, inventory and financial accuracy, safety, security, dispute resolution, legal claims, contracts, tax, customs, accounting, carrier, insurance, or other legal obligations.
Retention Criteria
The retention decision considers:
- whether an account, quote, integration, inbound, inventory balance, fulfillment request, parcel, return, invoice, payment, dispute, claim, or support case remains active
- whether goods remain in custody, transit, quarantine, return, claim, recall, legal hold, or final disposition
- the time needed for reconciliation, fraud and security detection, backups, provider callbacks, audits, and recovery
- contractual, carrier, customs, insurance, tax, accounting, employment, safety, and legal limitation periods
- the sensitivity, volume, purpose, access need, and risk of retaining or deleting the record
- a verified customer or individual request and any exception that requires continued retention
Account, Quote, and Commercial Records
Account identity, organization membership, roles, accepted agreements, company information, quote requests, onboarding, notification preferences, and account correspondence are retained while needed to administer the relationship and afterward for contract, consent, security, dispute, and legal evidence. Closed or rejected quotes may be deleted or anonymized when no longer needed for follow-up, abuse prevention, or legal obligations.
Removing a user from an account ends future access but may not erase the user's name from a historical authorized action, agreement acceptance, financial record, warehouse event, support reply, or security audit.
Warehouse, Inventory, and Order Records
Product, inbound, receiving, damage, quarantine, putaway, balance, reservation, pick, verification, packing, proof, handoff, parcel, tracking, delivery, return, disposition, location, and exception records are retained while inventory or related work remains active and afterward as needed for reconciliation, customer history, claims, recalls, carrier evidence, contracts, safety, and law.
Immutable execution and audit events are preserved because deleting them can make physical inventory, billing, or worker accountability incorrect. Products and accounts should be archived rather than hard-deleted when referenced by retained warehouse, order, return, billing, or audit history.
Billing and Payment Records
Balances, invoices, payments, Stripe references, refunds, disputes, adjustments, taxes, notices, reconciliation incidents, and transaction audit records are retained for accounting, tax, fraud, chargeback, contract, and legal periods. Omnaris does not intentionally retain complete card numbers or card security codes entered through Stripe Checkout.
A payment-provider reference may remain after an account closes so Omnaris can prove, reconcile, refund, dispute, or audit a transaction. Customer API projections may be removed while the authoritative Enigma financial ledger remains under its required schedule.
Support and Communications
Support tickets, replies, attachments, customer notifications, quote correspondence, and delivery metadata are retained while the matter is active and afterward as needed for service history, commitments, claims, safety, abuse prevention, and legal obligations. Optional communication preferences remain while needed to honor the choice.
Customer API mail records retain safe delivery and provider status needed for retry, support, suppression, and audit. Enigma's encrypted failed-message resend snapshot is removed after provider acceptance or the third failed resend attempt; it is never used as a general message archive. Permanent-bounce and complaint suppressions remain while needed to prevent unsafe repeated sends.
Security, Sessions, and Devices
Authentication, verification, password, invitation, API-key, role, session, device, badge, IP, rate-limit, webhook, idempotency, and security-event records are retained for their active lifetime and afterward only as needed to revoke access, prevent replay, investigate incidents, support audits, or satisfy legal obligations. Secrets are rotated or revoked rather than retained merely for history.
Scanner session material is short-lived and stored separately from warehouse truth. Device-registration and revocation history may remain longer for accountability. Enigma inventory and worker events are not deleted when a scanner session expires.
Browser and Demo Storage
The first-party optional-cookie decision lasts up to 180 days and the dashboard sidebar preference up to seven days unless changed or cleared sooner. Customer dashboard session storage normally ends with the applicable browser session. See the Cookie Policy for category and scope details.
The demo dashboard intentionally keeps sample records and settings in local browser storage until the user resets the demo or clears browser data. Demo records are not production customer, warehouse, support, or billing records.
Providers and Integrations
Cloudflare, Stripe, Resend, Shopify, carriers, and other authorized providers retain information under their own services, contracts, legal duties, and configured controls. Disconnecting an integration stops future authorized synchronization but does not automatically erase records already required for completed orders, payments, webhooks, security, or audit.
Omnaris limits provider access and retention through configuration and contracts where reasonably available. A provider may keep independent legal, fraud, payment, carrier, or security records beyond Omnaris's active connection.
Backups, Logs, and Exports
Backups rotate on an operational schedule and may retain deleted data for a limited additional recovery period. Backup access is restricted, and data is not restored merely to reintroduce a record properly deleted from the active system unless required for incident recovery or law.
Application and infrastructure logs are retained only as needed for reliability, security, deployment, incident, and audit purposes. Customer data exports are generated for a verified request, transferred through an approved secure channel, and securely deleted from temporary export storage after delivery and the applicable recovery window.
Deletion, Anonymization, and Legal Holds
When information is no longer required, Omnaris deletes it, anonymizes it, aggregates it, or isolates it from ordinary use through an approved application process. Routine staff must not manually delete production database rows or tables because dependent inventory, order, billing, support, and audit records can become inconsistent.
Deletion may be delayed or denied for active services, goods in custody, unpaid amounts, security investigations, disputes, claims, recalls, contracts, tax, accounting, customs, carrier, insurance, backup cycles, or a legal hold. When a hold ends, the normal retention decision resumes.
Retention and Deletion Requests
A person or authorized customer representative may request access, correction, export, or deletion through the website contact form, dashboard Support, or support@omnarisfulfillment.com. Include enough safe context to locate the relevant account or record without sending passwords, full card data, API secrets, or unnecessary identity documents.
Omnaris may verify identity, authority, account ownership, and the customer's instructions. Shipment-recipient requests may need to be directed to the customer that originally supplied the data. Omnaris will explain when it cannot delete a record and, where practical, restrict it to the required purpose.
Retention Schedule and Changes
Omnaris maintains an internal system-level retention schedule that assigns an owner, trigger, period or decision rule, disposal method, and legal-hold behavior to each record class. A fixed public date is not promised where the applicable tax, customs, carrier, insurance, contract, claim, or legal period depends on transaction and jurisdiction.
This policy may be updated as systems, providers, obligations, or approved schedules change. A shorter schedule is not applied when it would make active inventory, billing, security, or legal records inaccurate; a longer schedule requires a documented purpose and owner.
The business owner and qualified privacy, tax, customs, insurance, employment, and legal advisers must approve the internal record-level schedule and jurisdiction-specific periods before production use.

