CareSwaps
Home How It Works Pricing FAQ For Facilities Subscribe

Data Retention Schedule

Effective March 24, 2026 · HIPAA, IRS, AKS, and Colorado Retention Rules

1. Overview

This Data Retention Schedule describes how long CareSwaps, LLC retains each category of data and how we dispose of it when the retention period ends. Retention periods reflect the longest applicable legal obligation, including HIPAA (45 CFR § 164.530(j), six years minimum), IRS recordkeeping (seven years for tax records), the federal Anti-Kickback Statute (documentation retained indefinitely to support a defense), and Colorado consumer-protection recordkeeping.

Legend: PHI Protected Health Information · PII Personal Identifying Information · OPS Operational data (de-identified) · FIN Financial/billing · LEGAL Legal and compliance.

2. Protected Health Information (PHI)

Data CategorySystemRetentionDisposal
PHI Resident identifiers, DOB, POA status, care needsGoogle Sheets (Master PHI DB)6 years after subscription end (HIPAA minimum)Secure Deletion w/Audit Log
PHI Jotform intake submissionsJotform HIPAA Gold6 years after submissionSecure Deletion w/Audit Log
PHI Outbound email with PHIPaubox (encrypted) · Gmail (under Workspace BAA)6 yearsSecure Deletion w/Audit Log
PHI PHI access / audit logsGoogle Apps Script + Workspace audit6 years minimumSecure Deletion w/Audit Log
HIPAA Minimum: 45 CFR § 164.530(j) requires covered entities and business associates to retain HIPAA-related documentation for six years from the date of its creation or the date when it last was in effect, whichever is later. CareSwaps applies this minimum to all PHI records and all PHI-related audit logs.

3. Personal Identifying Information (PII — Non-PHI)

Data CategorySystemRetentionDisposal
PII Subscriber account (name, email, state)Google Workspace / AirtableLife of subscription + 3 yearsSecure Deletion
PII Support tickets and communicationsGoogle Workspace (Gmail)3 years after resolutionSecure Deletion
PII Marketing / waitlist signups (pre-subscription)Airtable · Make.com2 years from signup or opt-outSecure Deletion

4. Operational Data (De-identified — No PHI)

Data CategorySystemRetentionDisposal
OPS Swap IDs, match status, timestampsAirtable6 years (consistent with HIPAA audit trail)Secure Deletion
OPS Facility roster (business info, not PHI)AirtableLife of contract + 6 yearsSecure Deletion
OPS Automation execution logs (Make.com)Make.com90 days (rolling)Automated Purge
OPS Website analytics (GA4, aggregated, IP-anonymized)Google Analytics14 monthsAutomated Purge

5. Financial and Billing Data

Data CategorySystemRetentionDisposal
FIN Invoices, receipts, subscription historyStripe · Accounting7 years (IRS)Secure Deletion
FIN Refund records, chargebacks, disputesStripe7 yearsSecure Deletion
FIN Tax returns and supporting documentsAccounting7 yearsSecure Deletion

6. Legal, Regulatory, and Compliance Records

Data CategorySystemRetentionDisposal
LEGAL Executed BAAs with facilitiesGoogle Drive (secured)Term + 6 yearsSecure Deletion
LEGAL Executed Client Subscription AgreementsGoogle DriveTerm + 6 yearsSecure Deletion
LEGAL Executed Technology Services AgreementsGoogle DriveTerm + 6 yearsSecure Deletion
LEGAL Anti-Kickback Statute compliance documentationGoogle DriveIndefinite (to support defense)No automatic disposal
LEGAL Breach investigation recordsGoogle Drive6 years after incident close (HIPAA minimum)Secure Deletion w/Audit Log
LEGAL Complaint records (customer, OCR, AG)Google Drive6 yearsSecure Deletion
LEGAL Policies, procedures, audit reportsGoogle Drive6 years after each version retiredSecure Deletion

7. Disposal Methods

MethodDescriptionApplies To
Secure Deletion w/Audit LogRecord is cryptographically erased or fully deleted from primary and backup systems; disposal action is recorded with actor, timestamp, and record ID.PHI and PHI-adjacent records
Secure DeletionRecord is deleted from primary and backup systems. Disposal recorded at the aggregate level.PII, FIN, LEGAL (non-PHI)
Automated PurgeSystem-level purge governed by the service provider's retention controls (e.g., Make.com 90-day log retention, GA4 14-month data retention).Operational logs, analytics
Standard DeletionStandard user-initiated deletion where formal audit logging is not required.Marketing / top-of-funnel records
No Automatic DisposalRecords retained indefinitely to support regulatory defense. Reviewed annually.AKS documentation

8. Legal Holds

When CareSwaps receives notice of litigation, a governmental investigation, a subpoena, or a regulatory audit, the records implicated are placed under a legal hold. Retention and disposal schedules are suspended for those records until the hold is released in writing by the Privacy Officer or outside counsel.

9. Contact

Questions about retention or disposal: privacy@careswaps.com · (970) 306-7131 · CareSwaps, LLC, 2519 S. Shields St., Suite 1K PMB 1159, Fort Collins, CO 80526.

CareSwaps

Healthcare technology platform enabling families to find senior care facility transfer opportunities — across skilled nursing, assisted living, memory care, and more — through algorithmic matching and swap chain technology.

hello@careswaps.com

Fort Collins, Colorado

Platform

How It Works Pricing FAQ Subscribe — $299/mo

Legal

Terms of Service Privacy Policy HIPAA Notice Data Retention Cancel Subscription For Facilities →

© 2026 CareSwaps, LLC. Healthcare technology platform. All rights reserved. CareSwaps does not provide medical care, clinical recommendations, or transportation services.

Accessibility: CareSwaps is committed to ensuring digital accessibility for people with disabilities. If you experience difficulty accessing any content on this site, please contact us at hello@careswaps.com or (970) 306-7131.

This site uses analytics cookies (Google Analytics) to understand how visitors use our platform. No health information is collected through cookies. See our Privacy Policy for details.