YNF Deals · Legal
Data Storage & Retention Policy
This policy explains where YNF Deals stores your data, how we protect it, and — most importantly — how long we keep each kind of record before it is deleted or anonymized. If you remember one thing, make it this: we keep personal data only as long as we need it for a stated purpose or as the law requires, and when you delete your account we strip your identity from everything except the order records tax law obliges us to keep.
1. Where your data lives
YNF Deals ("we", "us") stores customer data on servers located in the United States. All traffic to ynfdeals.com passes through Cloudflare, our CDN and security provider, which shields those servers with a web application firewall and DDoS protection. Backups of our systems are encrypted.
Some of your data is held by service providers acting on our behalf, in their own systems and under their own privacy policies:
- Stripe — website payments. Your payment credentials go directly to Stripe (a PCI-DSS Level 1 processor); we never store full card numbers.
- TikTok / TikTok Shop — purchases made through our live auctions ("YNF Deals" and "YNF Fragrance" shops) are processed by TikTok's own checkout, under TikTok's terms.
- Google — if you sign in with Google (OAuth).
- Resend — transactional email delivery (order confirmations, verification codes).
- USPS, UPS, and FedEx — name and delivery address, shared to deliver your order.
What each provider receives and why is described in our Privacy Policy. This document focuses on storage, protection, and retention.
2. How we protect data at rest and in transit
2.1 In transit
Every page of ynfdeals.com is served over HTTPS/TLS. There are no unencrypted pages, forms, or endpoints — data moving between your device and our servers is always encrypted.
2.2 At rest
Passwords are stored hashed, never in plain text; no one at YNF Deals can read your password. Backups are encrypted. Payment data is handled exclusively by Stripe, so full card numbers never touch our systems at all. Consent records are written to a tamper-evident, hash-chained audit log (see Section 4).
2.3 Who can see your data
Staff access is role-based: team members can only reach the data their job requires. A packing operator scanning orders does not see payment details; support staff see the records needed to resolve your ticket.
3. How long we keep your data
We keep each category of data for a defined period tied to its purpose. When the period ends, the data is deleted or anonymized in the ordinary course of operations. The schedule:
| Data category | Retention period | Why |
|---|---|---|
| Account data (profile, addresses, fragrance profile, saved items) | While your account is active, and up to 2 years after your last activity | To operate your account and customer portal at /my |
| Order & tax records | 7 years | Legal and accounting obligations, including sales tax |
| Support tickets & related messages | 3 years after the ticket is closed | Resolving disputes and tracking service quality |
| Security & login logs | 12 months | Fraud detection and security investigation |
| Consent records (terms acceptance, cookie and marketing consent) | Indefinitely | Tamper-evident legal evidence — see Section 4 |
| Packing quality-assurance videos | 90 days, unless needed for an active dispute | Quality assurance and fraud prevention for shipped orders |
Each period runs from its natural trigger: last account activity, the date of the order, ticket closure, the log event, or the day your order was packed. Where a record is needed for an active dispute, investigation, or legal claim, we hold it until the matter is resolved, then the normal schedule applies.
4. Consent records: why we keep them permanently
When you accept our Terms of Service, make cookie choices, or consent to marketing email, we record that event: what you agreed to, which version of the document it was, and when. These consent records are our legal evidence that consent was actually given — and yours that it was given on specific terms.
They are stored in a hash-chained audit log: each entry is cryptographically linked to the entry before it, so no record can be edited or deleted — by anyone, including us — without visibly breaking the chain. That tamper-evidence is the entire point. A consent log that could be quietly rewritten would prove nothing.
Because their value as evidence does not expire, consent records are retained indefinitely. They contain only what is needed to prove the consent event, and they remain in place even after account deletion, with personal identifiers minimized as described in Section 5.
5. Account deletion & anonymization
5.1 How to request deletion
Use the privacy tools in your account at /my, or email [email protected]. Deletion is one of several rights you hold — access, correction, and export are covered in our Privacy Policy, including CCPA/CPRA rights for California residents and GDPR rights for EU/UK visitors.
5.2 What happens when your account is deleted
We anonymize your personal fields: your name, email address, phone number, saved addresses, fragrance profile, and similar details are removed or replaced so the remaining records no longer identify you. Your account is closed and can no longer be signed into.
Two categories survive deletion, in reduced form:
- Order records stay for the 7-year tax and accounting period, but with personal identifiers minimized — they document that a sale occurred and what tax was owed, not who you are.
- Consent records stay in the tamper-evident log (Section 4), likewise with identifiers minimized.
Everything else follows its normal schedule from Section 3 and then disappears.
6. Backups
We take regular encrypted backups of our systems so that a hardware failure or incident cannot destroy your orders, your account, or our ability to serve you. Backups exist for disaster recovery only — we do not use them as a working copy of your data.
Backups cycle out on a schedule: older backups are replaced by newer ones, so data deleted or anonymized from our live systems ages out of the backup set as it rotates. If we ever restore from a backup, deletion and anonymization requests completed before the restore are honored in the restored data.
7. Contact
Questions about this policy, or a retention or deletion request:
YNF Deals
585 W Merrick Rd Ste 28 C
Valley Stream, NY 11580, United States
Email: [email protected]
Phone: +1 516-884-3338
This policy is governed by the laws of the State of New York, USA. It works alongside our Privacy Policy, Cookie Policy, and Terms of Service. For order issues, use the Support area at /my/support.