Data Retention
Purpose
This policy explains how the public FTN Platform website currently retains information.
It applies only to ftnplatform.org and not to separate FTN applications or enterprise systems.
Current Website Data
The current platform separates these data classes:
- Supabase Auth account and session records;
- protected FTN contact/creator transaction records;
- browser-local preferences, drafts, saved sources and project recipes;
- Community Connect records in its separate protected application boundary;
- hosting, security and Cloudflare delivery/analytics records controlled through infrastructure configuration.
FTN does not collect a data class merely for future use. A form must state whether it is browser-local or submitted, why contact data is needed and whether a successful server transaction was created.
Local Device Preferences
Interface preferences stored through local storage remain on the visitor’s device until:
- the visitor clears them;
- the browser removes them;
- the website changes or retires the relevant storage key.
Browser-local data is not a cloud backup and remains until the visitor clears it, the browser removes it or the relevant FTN feature removes/exports it. Authenticated products may separately sync an explicitly chosen record under Row Level Security.
Hosting and Infrastructure Records
The website’s hosting, domain, security or delivery providers may retain ordinary technical records such as:
- IP addresses;
- request timestamps;
- browser or device information;
- security events;
- error logs;
- network request details.
Those records are controlled through the relevant infrastructure accounts and provider arrangements rather than the website’s client-side application code.
Where FTN can configure retention, it should retain such records only for legitimate security, operational, legal or diagnostic purposes.
Third-Party Resources
Third-party providers such as font or hosting providers may retain request information according to their own policies.
FTN does not control every aspect of third-party retention.
For FTN ibis Pro, FTN retains order references, payment-status identifiers, event hashes and entitlement dates for service delivery, dispute handling, accounting and legal obligations. FTN does not retain card numbers, CVV values or WAM wallet credentials. WAM controls retention of payment information processed on its hosted checkout.
Retention Principles
When FTN begins centrally retaining information, it will apply the following principles:
- collect only what is reasonably necessary;
- define the reason for retention;
- restrict access;
- protect information appropriately;
- retain information only for legitimate operational, historical, contractual or legal purposes;
- review retention periods;
- securely delete or anonymise information when continued retention is no longer justified;
- preserve information where required by valid legal process.
Separate FTN Products
Community Connect and other operational FTN products will require separate retention schedules before processing public submissions.
Those schedules must address, where applicable:
- reports;
- photographs;
- GPS information;
- contact details;
- moderation records;
- audit trails;
- backups;
- account information;
- government or enterprise records;
- legal preservation requirements.
This website policy must not be interpreted as the retention policy for those separate products.
Legal Preservation
FTN may preserve relevant information where reasonably necessary to:
- comply with a lawful obligation;
- respond to litigation or anticipated litigation;
- investigate security incidents;
- enforce contractual or legal rights;
- protect users, the public or the platform.
Review
This Data Retention Policy must be reviewed whenever the website begins collecting or centrally storing new categories of information.
Contact
Questions about this Data Retention Policy may be submitted through the General Enquiries pathway on the FTN Contact page.