Trust Center/Security policy
Data Deletion and Retention Policy
How long application, bank, broker, and lead data is kept, and how deletion requests are handled.
- Effective
- August 27, 2026
- Operator
- JRJ Group Holdings LLC D/B/A UNIFY
- Application
- GroFi · 40 Wall Street, 21FL, New York, NY 10005
1. Purpose
This policy states how long JRJ Group Holdings LLC D/B/A UNIFY keeps GroFi personal and business data, and how deletion requests are handled.
2. Default periods
- Merchant applications, bank statements, Plaid-derived underwriting data, and funded files. Life of the relationship, then seven (7) years after the later of close, payoff, or last servicing activity, unless a longer legal hold applies.
- Declined or withdrawn applications. Three (3) years after the decision, then deletion or de-identification, unless needed for anti-fraud or a legal hold.
- Contact-form leads. Two (2) years, or sooner if the person asks to be deleted and no application is attached.
- Broker accounts and onboarding documents. Life of the partner relationship, then three (3) years.
- Job applications. One (1) year after a decision, unless a longer period is required by employment law.
- Security and access logs. At least one (1) year.
3. Deletion requests
Send requests to privacy@grofi.com or use the contact form. We will verify the requester, then delete or de-identify personal information we are not required to keep. We will say if a funded file, tax record, dispute, or lawful preservation notice blocks full deletion.
Disconnecting Plaid: we stop new refreshes for that Item and apply the same retention rules to data already received.
4. Backups
Deleted production records may remain in encrypted backups until those backups rotate on the provider’s schedule. Backup restoration is limited to disaster recovery.
5. Disposal
When a retention period ends, records are deleted from the application database and private storage, or reduced so they can no longer identify a person. Encrypted fields are not retained in plaintext extracts.