Privacy and Records
Email Privacy, Retention, and Archiving for a WooCommerce Store
A practical retention plan balances customer service, operational continuity, and careful control over stored message data.
Support email can contain order numbers, delivery addresses, account details, and sometimes information a customer should not have sent by email at all. Keeping every message forever may feel safer than deleting anything, but indefinite retention also creates more data to protect and more material to search when a request or incident occurs. A thoughtful plan explains what the store keeps, why it keeps it, who can access it, and when it should be reviewed or removed.
Start by mapping the copies of a message. An email may remain in the mailbox provider, be imported into a WordPress database, appear in backups, or be exported to another system. MailBuddy runs as a WordPress WooCommerce plugin and uses your own provider's mailbox; it is not the mailbox host. Imported messages can be represented in the plugin, and an original .eml archive is available for download for messages under 8MB. These details matter when you describe storage to your team and plan backups. Do not assume that moving a conversation into a local folder removes other copies.
Define retention by purpose, not habit. Order support correspondence might need to remain available while an order issue is active and for a defined period afterward, while unsolicited inquiries or duplicate notifications may need less time. The right period depends on your business obligations, policies, and applicable law, so involve your legal or privacy adviser when the question is material. Write down the categories and the rationale in language staff can follow. A schedule that says “keep it as long as needed” without a review point is difficult to apply consistently.
Choose a reliable archive process before changing the mailbox. A local folder is a way to organize work inside the plugin; it is not automatically an independent backup or a legal records system. MailBuddy can download an original .eml file for messages under 8MB, which may help preserve message source details when needed. Establish who may download it, where it may be stored, how access is restricted, and whether the destination is included in your backup policy. Attachments can contain personal information too, so apply the same controls to the complete message as to the visible text.
Server deletion is a separate and consequential decision. MailBuddy's optional IMAP deletion is available only when the provider supports UIDPLUS, and removal happens only after the local archive step. It is not necessary to use local folders, and it should not be enabled as a substitute for a retention policy. Before considering it, test the process on suitable noncritical mail, confirm the archive is accessible, and ensure the WordPress database is backed up and recoverable. Check how your provider's other devices and retention rules behave. A successful archive in one system does not mean every backup or copy elsewhere has disappeared.
Reduce unnecessary exposure in daily work. Ask customers not to email full card numbers, passwords, or authentication codes; if they do, do not repeat that material in replies or internal notes. Limit WordPress and mailbox access to people who need it, use individual accounts, and remove access promptly when a role changes. Protect administrator accounts with strong authentication practices available in your environment. Train staff to verify the recipient before forwarding a message, especially when it contains order details or attachments.
Backups and deletion need to be considered together. A deleted record may remain in a backup until that backup expires, while restoring a backup can bring previously removed data back. Document backup frequency, access, storage location, and restoration procedures. Periodically test restoration in a controlled environment so you know whether important correspondence is recoverable without exposing production data. Avoid making promises to customers about immediate erasure until you understand the copies and obligations involved.
Finally, make the process reviewable. Assign someone to check the retention schedule and access list periodically, record when a policy changes, and give staff a simple route to ask about unusual messages or privacy requests. The separate MailBuddy Team workspace supports collaboration features such as meetings, calendar, and direct messages; it should not be confused with the WordPress plugin's support mailbox or treated as its archive. A clear map of systems and responsibilities lets the store answer customer questions more honestly and respond to operational needs without accumulating email by default.