A facility team may hold a vendor contract, nightly attendance exports, inspection photos, incident reports, invoices, and access-control records in separate systems. Keeping everything forever seems safe until a former employee’s image is shared too broadly, a customer requests deletion, or an investigation requires a dependable original record. Deleting everything quickly is not safer either: the organization may lose evidence needed to verify a bill, respond to an injury, or explain a site decision.
The practical answer is a retention schedule organized by purpose, record owner, sensitivity, and applicable rule. There is no single universal retention period for every record created by an outsourced cleaning service. The facility’s obligations may differ from the cleaning employer’s payroll, personnel, and safety obligations. Decide what the client needs, what the contractor must keep, and what the client should not collect in the first place.
Inventory records before choosing a period
Begin with a record map that names each information type, where it is stored, who created it, who owns the business process, and what decision it supports. Useful categories include the signed contract and amendments, approved work schedules, building access events, checkpoint records, inspection results, service photos, invoices, complaint correspondence, safety reports, and any personal or medical information. The map should include paper files, email, mobile devices, vendor portals, backups, and exported spreadsheets.
For each category, write a purpose in plain language: establish the agreed scope, verify a billed visit, document an inspection, coordinate emergency response, or meet a specific recordkeeping requirement. If nobody can explain the purpose, the file may be unnecessary or duplicative. The Federal Trade Commission’s business guidance on protecting personal information recommends taking stock, keeping only what a business needs, restricting access, and securely disposing of information when it is no longer needed.
Do not assume that a copy in the client’s system creates a new legal duty or satisfies the vendor’s recordkeeping obligations. The contract should identify which party creates and retains which record and how each party can request a copy. If a record is subject to a legal hold, investigation, or preservation request, suspend routine deletion for the relevant records and document the hold owner and release decision.
Separate contract, service, and financial files
Keep the contract and approved changes in a controlled repository with version history, effective dates, signatories, and renewal or termination actions. Preserve the scope, site list, fee schedule, service levels, and authorized change approvals together. A current proposal alone is not proof that its terms became part of the contract. Make it straightforward for accounts payable and facility operations to locate the operative version without granting broad access to every employee record.
Invoices and payment records should tie to the contract period, invoice number, approval, disputed line, credit, and payment event. Retain the source invoice and every correction or credit memo rather than overwriting the original. A later reviewer needs to see what the supplier asked to be paid, what the buyer approved, what was adjusted, and why. Different organizations may face different tax, accounting, public-record, or contract requirements, so establish financial retention with the responsible records officer.
Service schedules, inspection reports, and change requests need enough context to reconstruct what was expected and what the facility observed. Use stable building and visit identifiers rather than relying only on a worker’s name. If a client asks for additional work, record who approved the request, when it changed the scope, and whether a separate fee or visit was authorized.
Treat attendance and payroll records as different records
A client may need to know whether contracted service occurred at a building, but usually does not need the vendor’s complete payroll register, tax forms, bank details, or employee home addresses. A vendor’s attendance or checkpoint record can support service verification without exposing wage deductions or unrelated shifts. The employer remains responsible for its own time and payroll records under the laws that apply to it; a client copy should not be described as the employer’s official wage record unless that is actually true.
The facility can retain the minimum operational fields it needs, such as worker or vendor identifier, building, service event, timestamp, checkpoint status, and exception note. Define who may see an individual’s identity and who should see only aggregate coverage. If the contract requires proof of work, specify the evidence format, access role, export option, and retention period in advance rather than asking for a full workforce database after a dispute arises.
StockPoint’s per-building punch record combines a photo and PIN with GPS presented alongside an honest accuracy indication. That can help a service provider and client review a documented visit, but it is not the same thing as a complete payroll record or proof of every task. Client access should be designed around the service-verification purpose and limited to the buildings and records the client is authorized to see.
Control photographs and location information
A service photo can contain more than the cleaned surface: employee faces, tenant names, screens, badges, license plates, customer paperwork, or security details. Decide what the camera should capture, where images may be taken, whether individuals should be excluded from the frame, and how to handle a request for removal. A facility photo policy should distinguish evidence of a completed service from general workplace surveillance; see this related guide to a cleaning vendor photo policy.
Location data should also be limited to the operational question. If the contract needs building-level arrival and checkpoint evidence, do not collect continuous location history without a defined reason and appropriate review. Explain what is collected, who can view it, how long it remains available, and how a worker or client can challenge a wrong location event. GPS precision varies with device and environment; report the signal’s accuracy rather than presenting every coordinate as exact.
When a photo or location record supports an incident, billing dispute, or legal hold, preserve the relevant original and note the reason for retaining it beyond the normal schedule. Avoid creating an unstructured “just in case” archive. The FTC’s security guidance also emphasizes limiting access to personal information according to job need; a portal should not make every site image visible to every customer contact by default.
Use OSHA rules only for the records they actually cover
OSHA retention rules apply to specified employer records, not every document a facility client happens to receive. Under 29 CFR 1904.33, covered employers must retain OSHA injury and illness logs and incident report forms for five years following the end of the calendar year those records cover, with required updates to the log during that period. The cleaning contractor generally maintains the records for its own employees; a facility’s separate incident report may have a different purpose and schedule.
A different rule, 29 CFR 1910.1020, covers access to employee exposure and medical records and establishes long retention periods for records within its scope, including employee medical records and exposure records, subject to defined exceptions. Those are not ordinary cleaning inspection photos. A client should not take possession of a vendor employee’s medical file just to document that an incident was reported. Request a privacy-protective incident summary and let the employer maintain records it is required to preserve.
The rule applicable to a record depends on the record’s content, who maintains it, and the employer and workplace involved. A vendor’s report of an injury, a client’s security incident entry, an OSHA log, and a clinician’s medical record are not interchangeable. If the record includes exposure or medical information, involve the employer’s safety and privacy professionals before copying, sharing, or applying a routine deletion rule.
Set access roles and vendor handoff rules
Use role-based access for service records. A site manager may need to see visit completion and open corrective actions, while payroll staff need wage records, and safety staff may need a restricted incident file. Do not store sensitive medical attachments in the same broadly accessible folder as a routine inspection. Review access when a contract contact changes and disable accounts when a user no longer has a business reason to view the records.
The contract should say what happens to records at renewal or termination: which files the client may export, how the vendor will return or delete client information, how long operational evidence stays accessible, and what preservation exceptions apply. Identify subcontractors and hosting providers that process information where relevant. A transfer should preserve metadata and identifiers needed to interpret records rather than delivering a folder of detached images with no dates or building context.
A portal can improve both access and control if it supports scoped permissions, audit history, and retrieval of original records. StockPoint’s client portal provides proof-of-work photos and checkpoint status; access should still follow the customer’s contract and data-minimization rules. A convenient download button does not decide whether a recipient is authorized to receive an employee-specific image or location record.
Build a defensible retention schedule
For each record category, write the trigger that begins the retention period, the minimum period required by a verified law or contract, the business period needed after that, and the secure disposal method. Identify the authoritative source and the person who approved the rule. Label a period as a company standard when it is not a legal minimum. Where federal, state, local, insurance, and customer rules differ, use a schedule reviewed by records and legal professionals rather than guessing that the longest period always controls.
Train employees not to keep permanent side copies in personal email, desktop folders, or messaging apps. The schedule needs to cover exports and backup environments as well as the vendor portal. A legal hold or active claim can suspend ordinary disposal, so staff should know how to route a preservation notice and how the hold is released. Periodic audits can confirm that the policy works in the systems people actually use.
For example, an inspection image kept for a 90-day service review might be retained longer if it becomes evidence in a documented claim, while routine images with no ongoing purpose can expire under the approved schedule. The exact period depends on contract and law; do not treat this illustration as a universal term. Record the hold reason, file owner, review date, and who authorized eventual deletion.
Apply the policy to a real building workflow
Suppose a facility team stores monthly invoices, nightly checkpoint events, restroom inspection photographs, and one worker injury report. The contract repository retains the signed agreement and fee schedules under the company’s contract schedule. Accounts payable retains invoices and approvals under its financial schedule. Service photos are accessible only to the vendor and relevant building contacts for the defined review period, while the contractor preserves its own required employee safety and payroll records.
If the injury report becomes a claim, the client preserves its own incident record and related communications under a legal hold, but does not copy a medical diagnosis into the service portal. The contractor determines and maintains its OSHA records for its employees as applicable. The client gives the insurer or counsel the relevant materials through an approved channel, records the disclosure, and limits access after the review ends.
This separation makes retention more defensible because each record has an owner, a purpose, a rule, and an access boundary. It also makes a request easier to answer: the facility can find the agreement, event, invoice, or incident file without exporting every worker record from the vendor’s system.
Keep the record useful and proportionate
A strong retention program begins by collecting less, then preserves the records needed for service management, safety response, payment, and compliance. Review both the contract and actual system settings at least when scope, law, vendor, or platform changes. If the organization cannot retrieve a record with its context or cannot explain who has access, the schedule is not yet operational.
StockPoint’s audit-logged service records can help teams keep a traceable history of building punches, photo proof, checkpoint status, and permitted client access without turning the client portal into a payroll repository. To give facility teams and field vendors a shared operational record with bilingual workforce surfaces, per-building verification, and client-facing proof of work, visit getstockpoint.com and sign up for StockPoint.