FranchiseHQ / Trust
Data retention
FranchiseHQ favors recoverability and competitive audit integrity. Records are not silently treated as disposable merely because a newer import or message exists.
Retention principles
- Keep one explicit active snapshot while retaining prior, failed, malformed, and private candidates for diagnosis and recovery.
- Keep source captures, validation evidence, audit history, trade reviews, transaction history, and recovery records linked to their tenant.
- Do not interpret blocked or missing Free Agent data as zero.
- Do not reset, delete, rotate an export URL, archive a season, transition a game year, or restore a database as an automatic cleanup action.
- Use a reviewed, tenant-scoped operation when deletion is genuinely required.
Current record groups
| Record | Current treatment |
|---|---|
| Sessions | Normal browser sessions use an idle and absolute expiry and may be revoked earlier after logout, membership change, or a security event. Session tokens are stored as hashes. |
| League membership & ownership | Current authority can be removed, while the global identity and reviewed ownership/audit history remain available for integrity. |
| Madden exports & snapshots | Active, previous, failed, malformed, and candidate evidence is retained unless a separately authorized lifecycle or deletion process applies. |
| Trades, reviews & transactions | Workflow revisions, votes, reasons, messages, canonical transaction history, and reconciliation evidence are retained for league review. |
| Discord delivery | Delivery intents, attempts, sanitized destination failures, and resolution links are retained. A safe retry creates a new intent and does not delete the original failure. |
| Security, audit & recovery | Privacy-minimized security events, tenant audits, database bookmarks, and reconciliation evidence are retained for incident response and accountability. |
Correction and deletion requests
Ask your league commissioner to correct current league membership, team assignment, or published league information. Requests to delete platform or historical records require an exact-scope review because removal can affect fraud prevention, competitive history, foreign-key integrity, recovery, and other members' records.
A request does not authorize a broad reset or season transition. FranchiseHQ may retain records required for security, legal obligations, dispute resolution, backup integrity, or the rights of other league members.
Backups and recovery
Cloudflare D1 Time Travel bookmarks and retained archives are used for controlled recovery. A bookmark is not a second active league. An actual restore can overwrite the selected database and therefore requires a separately authorized incident procedure with exact-target verification and post-restore reconciliation.
When a retained item is resolved, FranchiseHQ records the resolution rather than erasing the evidence. This is why resolved Discord failures and superseded snapshots may remain visible to authorized operators.