SheerID maintains specific protocols for the retention of data and assets. This article provides an overview of our standard policies and instructions for customizing these configurations to meet your specific organizational requirements.
More information about personal data and purge compliance is available here.
Core definitions
To manage your setting effectively, you must understand the distinction between data and assets.
- Data: This term refers to the personal information consumers provide the verification process, including their first and last name. By default, SheerID retains this data for 13 months. This policy also affects full verification reporting results.
- Assets: Assets are the official documents that users upload to verify their eligibility status, such as student class schedule or military documentation. Our standard policy is to retain these documents for seven (7) days after the review process is complete. After this period, the documents are purged from our systems automatically.
Accessing your settings
Users with the account owner permission can update these configurations directly within the MySheerID platform. Note that changes made at the account level will serve as the default for all your programs.
- Log in to your MySheerID account
- Open the user menu located in the navigation bar
-
Select the Data Retention & Privacy option
-
On this page, the user can see their current data retention limits for Personally Identifiable Information (PII) and Document Upload, as well as their opt-in status to product improvement
Account-level configurations
Users assigned the Account Owner role have the authority to modify retention policies. Please only assign the Account Owner role to a person who has the authority to make these decisions. Click the Edit button to adjust the following intervals:
- Personal data: You may choose from 30, 90, 400, or 730 days
- Asset uploads: Available options include 7, 30, 400, or 730 days
SheerID does not recommend selecting the shortest available retention policies. Reducing these windows can negatively impact our ability to provide consumer support or protect your offers from discount abuse. Any modifications you save will apply only to data collected after the change is made.
Note on default values: Customers who onboarded prior to May 1, 2024 will have a default value of 730 days. Customers who onboarded after will have a default value of 400 days.
Product improvement participation
This account-level setting authorizes SheerID to utilize your data to enhance our products and services. When you toggle this setting to the "on" position, the change takes effect immediately. If your organization decides to opt out later, you can use the toggle to turn it off again.
Program-specific overrides
Certain programs may require unique retention settings to comply with specific legal or regional requirements. You can establish independent limits for a single program without altering your entire account.
- Navigate to the specific program you wish to modify
-
Locate the Data Retention Limits section within the program Settings
-
Adjust the personal data or asset policies as needed
Settings configured at the program level take precedence over the account-level defaults. Similar to account changes, these updates only apply to future data collection.
If the program has a current setting that is not one of these values, that setting will show here. Any changes to that setting will need to either be one of the dropdown values, or be handled by submitting a ticket to SheerID Product Support.Monitoring and auditing
To help your brand track policy modifications, we provide an audit log and an automated alerting feature.
Email alerts: Click the email icon to designate recipients who should be notified whenever a policy change occurs
Change log: You can review a complete history of updates made to your data retention and product improvement settings
Data retention FAQ
What happens to my data when it reaches the retention (purge) period?
Once the configured retention period expires, all Personally Identifiable Information (PII) and any uploaded documents are permanently deleted from SheerID's systems. A (pseudonymized) hashed value of each PII field supplied for the verification is kept for system integrity and auditing. These hash values allow SheerID customers to prevent offer abuse by enforcing verification usage limits, as well as support verification search and audit use cases including the handling of Data Subject Access Requests (DSAR).
What will I see after the purge?
The verification record may still appear in MySheerID or the Report Center; however, all PII and uploaded documents associated with that verification will have been purged. This retained information contains no viewable PII or documents and cannot be used to reconstruct the original personal information. It simply allows SheerID and its customers to confirm that a verification event previously occurred without retaining the individual's underlying personal data.
Will I receive webhook notifications when data is purged, or will I see the purge data in reporting?
No. SheerID does not emit webhook events when records are purged. If a purge is initiated, you will see when it was initiated in the customer service search tool.
For records that expired based on the data retention period, you will not see a date but you will see that they have been purged.