Passenger links
A passenger token currently expires 36 hours after the scheduled landing time. Removing a booking from Operations revokes its passenger token immediately while preserving the event record.
Bookings and timestamped events
Booking records and their append-only events are retained while the company account remains active so operators can resolve coordination questions and preserve operational evidence. They are not overwritten merely because a booking is completed.
Account and authentication records
Company-account records are retained while the account is active. Supabase and Google may retain authentication and security logs according to their applicable policies and legal obligations.
Deletion requests and backups
A company can request deletion or account closure at info@paxwhere.com. Deletion may be delayed where records are needed for security, disputes or legal compliance. Residual encrypted backups and provider logs may remain for a limited period before normal rotation.