Retention, export and deletion
What can be removed today, where additional copies may remain and what committees should agree before use.
Version 1.1 · Updated 7 September 2026. Published by Glu IO Pty. Ltd., the owner and operator accountable for Helper Shifts. Committee-specific agreements take effect when signed.
Current retention schedule
| Record | Current behaviour | Limitations |
|---|---|---|
| Volunteer registrations and events | No automatic age-based expiry. Event deletion cascades to registrations; eligible helper cancellation deletes the selected registration. | Does not erase emails, exports, account records or provider backups. |
| Organiser accounts and memberships | Retained for account access; owners can manage team membership. | Removing membership is not whole-account erasure. Full closure needs an administrative process. |
| Access and reset tokens | Purpose-specific validity periods; helper links expire after 24 hours and are single-use. | Expiry prevents use; it is not proof that the database row or backups were deleted. |
| Session cookies | Organisers: eight hours. Helpers: 30 days. Relevant cookie cleared on sign-out. | Local storage and downloaded files remain separately. |
| Remembered details and editor drafts | Browser local storage; no automatic expiry. Clear through the UI or browser site-data settings. | Local to that browser/site. Other devices must be cleared separately. |
| Application logs | Terraform default: 14 days in CloudWatch. | Live setting, log contents and other infrastructure logs need confirmation. |
| Abuse-control records | Keyed identifiers and timestamps support rolling request limits. | Window expiry is not a verified maximum physical retention period. |
| Backups, email and support records | Provider and operator settings determine retention. | Service backups are stored in Australia. Maximum retention periods, erasure procedures and external mailbox locations require an agreed schedule. |
Requesting an export or deletion
Organisers can export an event’s volunteer list as CSV from the event dashboard. This is an event-level export, not a complete account portability package. Ask the organiser for access to your records; for full group closure, account records or a broader export, contact the service operator through the contact page.
Specify the group, record types and desired outcome. Verify identity and authority before acting. The organising entity should determine which records it must retain under applicable law or its own recordkeeping obligations. A deletion request may need to be limited or deferred where law requires retention; the reason and period should be explained.
Clearing browser details, signing out, cancelling one shift and closing an account are different actions. No single existing action certifies erasure from all systems.
Retention terms to agree with committees
Agree an event-review interval, maximum live retention, records-transfer responsibility, account-closure procedure, export formats and assistance, log/token retention, backup expiry, legal holds and deletion confirmation. Align the schedule with the committee’s records obligations rather than choosing an arbitrary universal period.
The DPA sets 30-day live deletion and 90-day backup expiry periods unless the signed committee schedule specifies otherwise. These periods apply under the executed agreement. Before signing, test all affected systems, record exceptions and establish how deletion instructions are reapplied after a restore.
Document history: version 1.1 — clarified independent committee use and contact responsibilities, 7 September 2026; version 1.0 — published documents, Australian data storage and Glu IO Pty. Ltd. operator identity, 7 September 2026; version 0.2 — clarified administrator contact-use restrictions, 7 September 2026; version 0.1 — initial publication, 6 September 2026. Print or save this page as PDF to retain this version. Committee agreements and applicable law take priority over general guidance.