Document Retention & Destruction Policy

Plain-language summary: We keep the records that let anyone check our work. We delete the personal information people trust us with as soon as we no longer need it. This page says which is which, and how long each is held. If an investigation starts, deleting stops immediately.


Table of Contents


Purpose

This policy sets out how Stimpunks Foundation reviews, retains, and destroys the records we create and receive. It covers every record regardless of form — paper, file, database row, email, spreadsheet, scan.

It exists for two reasons. The first is legal: under 18 U.S.C. §1519, added by the Sarbanes-Oxley Act, it is a federal crime to alter, conceal, falsify, or destroy a record with intent to obstruct an investigation or official proceeding. That statute applies to nonprofits. Having a written schedule is what makes ordinary, scheduled deletion clearly ordinary — and makes any departure from it visible.

The second reason is that we hold information about people in genuinely precarious situations, and holding it longer than we need to is a risk we impose on them rather than on ourselves.


Two Duties, Not One

Most retention policies describe a single obligation: keep things. Ours describes two, and they pull in opposite directions.

Accountability requires records. Anyone should be able to check how we govern ourselves and where the money went. That is only possible if the minutes, the ledgers, the filings, and the decisions still exist. Deleting those is not privacy — it is evasion.

Privacy requires deletion. We already say that we treat personal information as a toxic asset and do not want to keep more of it than we have to. Data we hold is data that can be breached, subpoenaed, or misused. Keeping it “just in case” moves that risk onto the person who trusted us with it.

Both are real, and neither overrides the other. The work of this policy is saying which duty applies to which record, so that nobody has to decide in the moment.


What We Delete Quickly, and Why

People applying for mutual aid tell us things they should not have to tell anyone: what their diagnosis is, what their housing situation is, why they cannot work this month, what happened to them. They tell us because the alternative is going without help.

We delete that material as soon as the decision it supported is made and recorded. Specifically, and promptly:

  • Narrative descriptions of need, hardship, diagnosis, or circumstance
  • Documents people upload to support an application — medical letters, bills, eviction notices, benefit determinations
  • Form submissions once they have been acted on
  • IP addresses and similar technical traces we have no reason to hold

What survives is the transaction, not the story. We keep who received a grant, how much, when, and under which program — because that is what makes our spending checkable, and because our filings require it. We do not keep the account of why they needed it.

This is a disability justice position as much as a compliance one. Our communities are asked to prove their need over and over, to strangers, in writing. The least we can do is not keep the file.

Anyone may also ask us to delete their information, and we will — except where the transaction record above must be retained. See our Privacy Policy and Donor Privacy Policy.


Retention Schedule

Records not listed here but substantially similar to something listed are held for the comparable period. Anything not covered either way is held for three years and then destroyed — the default our 2022 policy set, kept deliberately so that nothing falls through a gap in the schedule.

Governance — permanent

  • Certificate of Incorporation and amendments
  • Bylaws and amendments
  • Board and committee minutes, and written consents
  • Board policies and resolutions
  • IRS Form 1023 application and determination letter
  • Form 8940 filings and any advance ruling determination
  • State exemption and registration documents
  • Annual reports filed with any state

Financial — permanent

  • Forms 990, 990-PF, and 990-EZ as filed, with schedules
  • Annual financial statements and any audit
  • General ledgers

Financial — seven years

  • Bank statements, reconciliations, and deposit records
  • Invoices, receipts, and expense records
  • Journal entries and supporting schedules
  • Forms 1099 and W-2, and payroll tax returns
  • Donation records and acknowledgement letters
  • Contracts, for seven years after they end
  • Signed annual Conflict of Interest statements

Grants — five years after completion

  • Recipient name and contact details, amount, date, and program
  • Grant agreements and award correspondence

The supporting personal narrative is not retained for this period — see What We Delete Quickly.

Employment

  • Employment and termination agreements — permanent
  • Earnings and payroll records — permanent
  • Records relating to promotion, demotion, or discharge — seven years after the person leaves
  • Form I-9 — three years after hire or one year after the person leaves, whichever is later
  • Applications from people we did not hire — three years

Insurance and legal — permanent

  • Insurance policies
  • Trademark and copyright registrations
  • Records of any claim, investigation, or legal proceeding

One period is currently longer than it looks. While our conversion to public charity status is underway, records supporting the years in the transition period must be kept until the extended assessment window closes — which runs past the ordinary seven years. Nothing supporting those years is destroyed on schedule without checking with our accountant first.


Electronic Records

We are a distributed organization with no office and no filing cabinet. Nearly every record we hold is a file, a message, or a database row, and the schedule above applies to all of it exactly as written. A record does not escape this policy by being in someone’s inbox.

Deletion means deletion. Where a system keeps its own copies — trash folders, version history, backups — we clear those too, or we say plainly how long they persist. A file we believe is deleted but that survives in a backup is still a file we hold.


When Destruction Stops

This is the most important section on the page.

All scheduled destruction stops immediately the moment any of us has reason to believe that an investigation, audit, examination, claim, or legal proceeding has begun or is likely. That includes an IRS examination, a state attorney general inquiry, a Concern raised under our Whistleblower Policy, or a demand letter.

  • The hold applies to everything that could be relevant, not only the records specifically requested.
  • It applies to automatic deletion too. Any scheduled or automated purge that would touch relevant records is switched off.
  • Anyone who becomes aware of a potential proceeding tells the President and the Executive Director immediately. Nobody needs authorization to raise it, and nobody is second-guessed for raising it and being wrong.
  • The hold is lifted only when the matter concludes, and lifting it is a decision recorded in the minutes.

Destroying a record to keep it out of an investigation is a federal crime under 18 U.S.C. §1519, and the penalty falls on the individual who does it. If you are ever unsure whether to delete something, do not delete it. Nothing in this policy has ever been urgent enough to justify guessing.


Who Is Responsible

We have no chief financial officer and no finance committee, so this policy does not pretend otherwise.

  • The Executive Director runs the schedule day to day — deciding what has aged out and seeing that it is deleted.
  • The President is accountable to the Board for the policy being followed, and holds the decision to place or lift a litigation hold.
  • The Board reviews compliance annually, alongside the annual conflict of interest disclosures.
  • Our accountant is consulted before anything financial is destroyed on schedule.

This is a change from our 2022 policy, and the Board has to confirm it. That policy made the Secretary responsible for the schedule, and required each department to submit an annual list of what had been stored or destroyed. We had no departments then and we have none now, so the second half never happened. Moving the day-to-day work to the Executive Director describes what we actually do — but it is the Board’s call, not ours, and until they make it the 2022 assignment stands.

Failing to follow this policy can expose both the Foundation and the individual to civil and criminal liability, and is grounds for corrective action.


Backups and Emergencies

Records we would need to keep operating — our governing documents, our filings, our books, our grant records — are backed up somewhere separate from where they normally live, and restoring from that backup is tested rather than assumed.

Accounts holding these records are secured with unique credentials in a password manager, as described in our Privacy Policy.


Review of This Policy

The Board reviews this policy at least annually, with our accountant or counsel, and updates it when the law or our own practice changes. It will be reviewed again when our public charity reclassification takes effect.

Keeping the right records is accountability. Deleting the rest is care.


Document ID: SF-GOV-DR-1.0
Status: Draft — pending adoption by the Board of Directors
Supersedes: Document Retention Policy, Stimpunks Foundation, adopted September 2022 — which remains in force until the Board adopts this one
Adapted from: the 2022 policy above, and the Document Retention and Destruction Policy sample, Nonprofit Insurance Alliance Group, rev. 10.0128

Related: Privacy Policy · Donor Privacy Policy · Whistleblower & Concern Reporting Policy · Conflict of Interest Policy · Accountability & Transparency