Data Retention Schedule
This schedule describes MedicalRide.org's baseline retention targets for personal information collected through ride coordination, provider, payment, privacy, analytics, and security workflows.
Publisher details are available in the Legal Notice.
Last updated: 2026-08-03
MedicalRide.org is operated by Tipmunk SASU. Retention periods may be extended where needed for disputes, chargebacks, fraud prevention, safety incidents, tax/accounting obligations, legal claims, regulatory requests, or preservation holds. Vendor and backup deletion can also depend on processor tools and contractual terms.
Retention controls around the schedule
The schedule is supported by privacy request intake, legal holds, vendor evidence review, and approval steps for eligible deletion or redaction.
- Clear operator identity
MedicalRide.org is operated by Tipmunk SASU, with public controller and contact details listed in the Legal Notice and Privacy Policy.
Legal Notice - Directory platform boundary
MedicalRide presents a directory and request platform. Independent providers remain responsible for transportation services, vehicles, drivers, licensing, insurance, pricing, and ride completion.
Terms - Consent and privacy choices
Non-essential analytics and advertising tags stay off unless allowed, Global Privacy Control is honored where applicable, and key consent choices are recorded.
Privacy Choices - Rights request workflow
People can request access, correction, deletion, portability, consent withdrawal, and California privacy choices through a dedicated intake form.
Data Rights - Retention and deletion controls
MedicalRide publishes baseline retention categories and uses review, legal-hold, and approval steps before eligible deletion or redaction runs.
Retention - Vendor transparency
The vendor register lists core provider categories, data categories, transfer evidence, BAA availability, and public legal evidence links.
Subprocessors - Security and audit controls
Admin/session controls, role-based permissions, rate limits, same-origin checks, and sensitive-access audit logs support privacy operations.
Security - Organization agreement evidence
Organizations can accept directory-platform terms through an electronic agreement flow that records authority, accepted text, and request context.
Organization agreement
Retention matrix
| Data category | Default retention | Trigger | Disposal action |
|---|---|---|---|
Incomplete ride request drafts Saved form progress, quote intent, contact details, route details, mobility notes entered before final submission. Short retention reduces exposure for abandoned sensitive forms while preserving enough time for a requester to finish a booking. | 30 days after last update. | Draft has not been completed or updated. | Delete the draft record or de-identify it so it no longer identifies a requester, passenger, route, or device. |
Unbooked or cancelled ride requests Submitted requests that do not become a completed ride, no-provider cases, declined quotes, cancelled callbacks. Retention may be extended for disputes, chargebacks, complaints, fraud review, safety issues, or legal holds. | 2 years after cancellation, closure, or last material activity. | Request is closed without a completed transportation outcome. | Redact passenger/requester identifiers, direct contact details, pickup/dropoff addresses, mobility notes, and message content; retain minimal operational and legal-defense metadata. |
Completed ride requests Booked and fulfilled ride coordination records, selected provider, price, ride status, support notes. Retention may reflect French, US, payment, insurance, dispute, and legal-obligation requirements. | 6 years after ride completion or final payment activity. | Ride is completed and payment/support activity has ended. | Redact sensitive passenger details and direct contact information while retaining payment, tax, dispute, and legal-defense records as needed. |
Payment and billing records Stripe customer IDs, checkout sessions, payment intents, invoices, provider-fee records, refunds, chargebacks, membership billing events. MedicalRide should not store full card numbers; processor retention is also governed by vendor terms. | 7 years after the transaction, invoice, refund, chargeback, or tax period closes. | Payment record is final and no active dispute or legal hold exists. | Retain minimum accounting/payment metadata; delete or tokenize unnecessary personal details where supported by the payment processor. |
Consent and legal acceptance evidence Contact consent, sensitive-data consent, cookie consent, privacy choices, terms acceptance, provider terms, payment authorization language. Consent logs are intentionally persistent evidence but should not become a broader profile of the person. | Life of the related record plus 6 years, or longer when needed for legal claims. | Related request, provider account, or visitor choice record expires. | Retain minimal evidence needed to prove notice and consent; remove extra metadata that is no longer necessary. |
Privacy rights and DSAR records Access, deletion, correction, portability, objection, California opt-out, identity verification, response notes. This supports GDPR accountability and US state privacy response evidence without keeping unnecessary identity documents. | 3 years after closure. | Request is fulfilled, denied, withdrawn, or otherwise closed. | Retain minimal request evidence, outcome, dates, and lawful basis for any denial; delete extra verification material unless a legal hold applies. |
Provider accounts, directory, and membership records Provider profile, owner/user account, service areas, insurance/licensing metadata, pricing, membership, subscription, operational notes. Public business-listing data may also come from public sources, but internal account and contact records still need controlled retention. | Active account life plus 6 years after removal, termination, or final billing activity. | Provider is removed, deactivated, or no longer has an active billing/account relationship. | Remove public listing data where no longer needed; retain billing, contract, dispute, and safety records; de-identify operational notes where practical. |
Communications and support history Emails, SMS, phone logs, masked-call events, outreach logs, provider replies, customer support notes. Vendor-side retention at email, SMS, and voice vendors must be reviewed and aligned. | 2 years after the related request closes, or 6 years when tied to payment, complaint, safety, or legal-defense records. | Related request or provider relationship closes and no dispute, safety incident, or legal hold remains. | Delete message bodies and transcripts not needed for support or legal defense; keep minimal delivery/audit metadata where necessary. |
Analytics, ads, and attribution data Cookie choices, GCLID/UTM values, tag events, directory analytics, conversion markers, IP/device-derived location. Non-essential tags must remain consent-gated and must honor opt-out, GPC, and limit-sensitive-use choices. | 13 months for analytics/ads identifiers unless a shorter vendor default applies. | Visitor event or attribution record is created. | Delete or aggregate identifiers and event data; retain only non-identifying performance statistics. |
Security, admin, and operational logs Admin account logs, audit events, webhook events, fraud signals, error and security logs. Sensitive payloads should be redacted from logs before they are stored. | 12 months for routine logs; up to 6 years for incident, fraud, dispute, or legal-hold evidence. | Log event is created or incident file is closed. | Delete routine logs; retain incident evidence with access restrictions and redaction where practical. |
Vendor and processor-held data Cloud hosting, database backups, payment processor records, email/SMS/voice provider logs, AI/vendor processing traces. Vendor processing is managed through applicable contractual, transfer, sensitive-data, and retention controls. | Match MedicalRide schedule where configurable; otherwise document vendor default and deletion limits. | Vendor service processes or stores MedicalRide personal data. | Configure vendor retention/deletion where possible; document exceptions, backup windows, and support-ticket deletion limits. |
Deletion and privacy requests
People may request access, correction, deletion, restriction, objection, portability, consent withdrawal, or California privacy choices through the Data Rights Request form. MedicalRide may need to verify identity or authority before acting on a request.
Some information cannot be deleted immediately if it is needed for payment, fraud, safety, legal, accounting, regulatory, or dispute purposes. In those cases MedicalRide will aim to restrict use and retain only the minimum evidence needed for the lawful purpose.
