Data Retention
This page documents how long Muscle LAB keeps different types of personal data and why. We keep data for the minimum period necessary - no longer.
Retention Schedule
| Data type | Retention period | Reason |
|---|---|---|
| Order records (name, email, address, items, payment reference) | 10 years | Portuguese fiscal law (Código do IVA / CIRS) requires commercial records to be kept for 10 years. |
| Contact form messages | 12 months | Retained in case of follow-up; deleted when no longer relevant. |
| Newsletter subscriptions (email) | Until you unsubscribe | Kept with your consent. Unsubscribe at any time via link in email or by contacting us. |
| Customer / Ambassador login session | Limited cookie lifetime or until logout | Authentication cookies may remain active for a limited period or until logout. No advertising cookies or third-party marketing pixels are used. |
| Ambassador account data (email, code, commission records) | Duration of ambassador relationship + 12 months | Retained for payment reconciliation and legal compliance. |
| Cart contents | Until cleared by browser or checkout preparation is completed | May be stored locally in your browser and may also be processed server-side for cart recovery or checkout preparation. |
| Language preference local only | Until cleared by browser | Stored locally to remember your selected language. No server involvement. |
| Quiz result / identity archetype | Until cleared by browser and subject to limited server-side retention | Quiz results and related events may be stored locally and may also be stored on our servers to help provide the quiz experience, prevent abuse, and improve the service. No third-party marketing tracking is used. |
How We Delete Data
Data stored in our database (Supabase) is deleted or anonymised at the end of its retention period. Browser-local data such as language preference remains on your device until you clear your browser data. Some cart and quiz data may also be processed or retained server-side for service operation, abuse prevention, cart recovery, or checkout preparation.
Your Right to Erasure
You can request deletion of your data at any time by contacting us at hi@wearmusclelab.com. We will process your request within 30 days. Note that data subject to a legal retention obligation (e.g. order records required by fiscal law) cannot be erased until the mandatory period has passed.
Questions
For any questions about how we handle your data, read our full Privacy Policy or contact us directly.
