End baskets nobody will finish, and delete orders past their retention
Adds order_retention and nothing that reads it, so the sweep can be reviewed on its own merits.
A state-keyed mapping on yoyaku.settings and yoyaku.tenant.*, resolving tenant then site. Deliberately not on the booking channel: how long a booker's session lasts is a front's own business, but how long data is kept is the realm's, and an order must not be kept for longer or shorter because of the door the booker came through.
A state naming no period is never deleted, the reading a policy's enabled already carries. Two ship with a default: empty at P7D, an emptied order being definitionally contentless, and cancelled at P30D, a cancelled order being the record of a booking that did not happen.
Not to be merged before the sweep that reads it. The sweep needs a seam core does not have: two of its three guards (a running Orchestra instance, a payment row) live in submodules core cannot depend on. That design is the substance of this issue and is why the configuration was taken back out of [#3615440] rather than shipped inert.