Data Retention and Deletion
Last updated: 7 February 2026
This policy explains what data COSHHmate (coshhmate.co.uk) stores, how long we keep it, and how you can request deletion. COSHHmate is operated by Crocker Digital Ltd (Company No. 17008789).
What data we store
When you use COSHHmate, we store:
- Account information: Your name, email address, and password (hashed)
- Organisation information: Your organisation name and settings
- Substances: Chemical substance records you create
- Assessments: COSHH assessment records, including hazards, risks, and control measures
- Review schedules: Dates and reminders for assessment reviews
- Email addresses: Used for authentication and transactional emails
- Billing information: Managed by Stripe; we store your subscription status and plan details but not your full card number
Retention while your account is active
We retain all of the above data for as long as your account is active. We do not automatically delete data from active accounts.
What happens when you delete your account
When you request account deletion:
- Immediate: Your account is deactivated and you can no longer log in
- 30-day retention period: We retain your data for 30 days after the deletion request. This allows you to contact us and recover your account if the deletion was accidental
- Permanent deletion: After 30 days, all your data is permanently deleted from our active systems
How to request deletion
You can delete your account in two ways:
- In-app: Use the account deletion feature in your account settings
- Email: Send a deletion request to hello@coshhmate.co.uk from the email address associated with your account
We will confirm your deletion request by email.
Export your data first
Before deleting your account, we recommend exporting your data. COSHHmate provides an in-app JSON export feature that lets you download your substances, assessments, and other records. Once your data is permanently deleted, we cannot recover it.
Backups
Supabase maintains automated database backups as part of its infrastructure. These backups are retained according to Supabase's own retention policy and are used solely for disaster recovery. Backup data is subject to the same security protections as live data and is permanently purged in accordance with Supabase's backup lifecycle.
Stripe billing data
Billing and payment records held by Stripe are subject to Stripe's own data retention policies. We can request deletion of your Stripe customer record on your behalf. Note that Stripe may retain certain records as required by financial regulations.
Contact
If you have questions about data retention or want to request deletion, contact us at hello@coshhmate.co.uk.
Questions? Email hello@coshhmate.co.uk