Moneytronix International Capital Partners, LLC · Last updated July 19, 2026
Click Download PDF to generate a ready-to-upload PDF copy of this policy for submission to Plaid.
This Data Retention and Disposal Policy ("Policy") establishes the requirements and timeframes for the retention, storage, and secure disposal of data collected, processed, and stored by Moneytronix International Capital Partners, LLC ("Moneytronix," "we," "us," or "our") in connection with the operation of its membership-based real-estate and mortgage-note investment platform (the "Application"). This Policy applies to all personal, financial, and operational data handled by Moneytronix, including data retrieved through the Plaid API, and to all personnel, contractors, and third-party processors acting on our behalf. This Policy is a companion document to the Moneytronix Information Security Policy and Privacy Policy.
Data is classified into the following categories for retention purposes: (a) Consumer Financial Data — data retrieved via Plaid (account metadata, balances, transaction history) and Plaid access tokens; (b) Identity Data — KYC/AML verification data, government-issued ID details, national/taxpayer IDs, date of birth; (c) Membership & Investment Data — membership contributions, funding-source configuration, tokenized membership unit records, distributions, and wallet addresses; (d) Account & Authentication Data — email, password hashes, session logs, role assignments; (e) Operational & Security Logs — audit trails, incident records, bug-intelligence data; (f) Contract & Legal Records — signed agreements, disclosures, escrow/title documentation.
The following retention timeframes apply from the date of data creation or last activity, whichever is later: Consumer Financial Data (Plaid-derived, including transaction history): retained only as long as necessary to provide the service for which it was collected; access is revoked and the data is deleted or anonymized upon member account closure or verified deletion request, subject to legal recordkeeping requirements. Plaid access tokens: revoked via Plaid processor-token revocation immediately upon account closure or consent withdrawal. Identity / KYC-AML Data: retained for 5 years after the end of the membership relationship to satisfy U.S. anti-money-laundering and beneficial-ownership recordkeeping obligations. Membership & Investment Records: retained for 7 years after the related membership interest is redeemed, sold, or the series closes, to satisfy tax and securities recordkeeping obligations. Account & Authentication Data: retained for the life of the account plus 90 days, then deleted. Operational & Security Logs: retained for 12 months, then deleted or anonymized. Contract & Legal Records: retained for 7 years after expiration or termination of the related contract or offering. Where two requirements conflict, the longer retention period applies.
Retention timeframes are established to comply with applicable U.S. federal and state obligations, including Bank Secrecy Act / AML recordkeeping rules (generally 5 years), IRS tax-record requirements (generally 7 years), SEC Regulation D and related securities-offering recordkeeping obligations, and applicable state contract-limitation periods. Moneytronix does not retain personal data longer than necessary to fulfill the purposes for which it was collected or to meet legal obligations.
All retained data is encrypted in transit (TLS 1.2+) and encrypted at rest at the volume/storage level by the managed cloud platform that hosts Moneytronix. Plaid access tokens are persisted server-side only, are never returned to any client, and are retrievable only through role-restricted, MFA-gated administrative paths. Raw banking credentials are never stored. Access to retained data is governed by role-based access control (RBAC) and record-level security, and is reviewed quarterly. Production secrets and signing keys are stored in a managed secret store separate from the application database.
Upon expiration of the applicable retention period, or upon a verified member deletion request, data is disposed of as follows: Application-database records are permanently deleted via irreversible deletion operations. Plaid access tokens are revoked through Plaid processor-token revocation so linked financial data can no longer be retrieved. Backups and snapshots containing the data are overwritten on the next scheduled rotation cycle of the managed platform (platform-managed backup lifecycle). Paper records, if any, are cross-cut shredded. Digital files stored outside the application database are securely overwritten. Deletion is verified by the Managing Member (Class A) or a designated administrator. Where anonymization is used in lieu of deletion, the data is rendered such that it can no longer be associated with an identifiable individual.
Members may request access to, correction of, or deletion of their personal data at any time by contacting craig@moneytronix-realestate.com. Upon a verified deletion request, Moneytronix will remove the member's data from the application database and revoke any associated Plaid processor token within 30 days, subject to legal recordkeeping requirements that may necessitate retaining certain records (e.g., KYC/AML and tax records) for the periods stated in Section 3; in such cases the retained data is minimized to what is legally required and is otherwise disposed of at the end of that period.
Where data is processed by third parties on Moneytronix's behalf (e.g., Plaid, KYC/AML providers, payment processors, note servicers, title/escrow agents, cloud infrastructure providers), retention and disposal by those processors are governed by the applicable processor agreement and the processor's own policies. Moneytronix requires processors to retain data only as necessary and to dispose of it securely when no longer required, consistent with this Policy.
The Managing Member (Class A) is accountable for this Policy and for ensuring compliance. The Managing Member or a designated administrator is responsible for executing deletions, verifying disposal, maintaining the retention schedule, and conducting periodic reviews. All personnel and contractors are responsible for adhering to this Policy and for reporting suspected retention or disposal violations.
This Policy is reviewed at least annually and upon any material change to applicable law or to Moneytronix's data processing activities. Material changes will be documented and the "Last updated" date revised accordingly.
Questions regarding this Policy may be directed to Moneytronix International Capital Partners, LLC, Attn: Privacy / Managing Member, at craig@moneytronix-realestate.com.