Legal
Privacy Policy
In short: we collect what we need to run your account and the products you use, keep your data only as long as your plan says, never sell it or use it for advertising, and set a single sign-in cookie.
1. Who we are and our role
SyncYak runs SyncYak. This policy explains what personal data we handle, why, and the choices you have.
- Account data (who you are, your team, billing, how you use the dashboard): we decide how it is used, so we are its controller.
- Customer Data (the leads, emails, CRM records, logs and tunnel traffic you send through SyncYak): you decide what it is and why it is processed. You are the controller and we are your processor; we handle it only on your instructions, as set out in the Terms of Service.
2. What we collect
- Account details: your name, email address, company, role and industry if you give them, and a hash of your password (never the password itself). The same for team members you invite.
- Billing: Stripe collects and stores your card details; we keep your Stripe customer reference, plan, invoices and usage counts. We never see your full card number.
- Technical data: IP address, browser and device type, the time of requests, and an audit trail of account actions (sign-ins, key changes, plan changes), used for security and support.
- Connections: the API keys, OAuth tokens and passwords you give us to reach CRMs, mailboxes, Google Sheets and databases. They are encrypted at rest and used only for the connection you set up.
- Customer Data passing through the products: emails sent to Parse inboxes and what is parsed from them, mailbox messages synced or sent through Mail (including open and click events when you turn tracking on), records synced by CRM, error events and logs sent to Cloud Logging, and request details shown in the Tunnel inspector.
- Messages to us: what you write to contact@syncyak.com.
3. How we use it
- to run the Services you signed up for and do what you configure (contract);
- to bill you, and to keep the records tax law requires (contract, legal obligation);
- to secure accounts, prevent abuse and fix problems (legitimate interest);
- to send service emails: email confirmation, password resets, invoices, usage and security alerts, and notice of changes to these policies (contract, legitimate interest);
- to answer you when you write to us (legitimate interest).
We do not sell personal data, do not show advertising, do not use Customer Data to train machine-learning models, and do not send marketing email without your consent.
6. How long we keep it
Each product keeps Customer Data for the retention period of your plan, then deletes it automatically:
| Product and data | Free | Hobby | Pro | Business |
|---|---|---|---|---|
| ParseReceived emails and parsed results | 7 days | 30 days | 90 days | 180 days |
| MailSynced and sent messages | 7 days | 30 days | 90 days | 1 year |
| CRMSync and webhook request history | 3 days | 7 days | 30 days | 30 days |
| Cloud LoggingError events and logs | 14 days | 30 days | 90 days | 180 days |
| TunnelRequests in the tunnel inspector | 24 hours | 3 days | 7 days | 30 days |
Account details are kept while the account is open. When you close your account we keep it for 30 days, so it can be restored if that was a mistake, and then delete its data. Database backups are kept for 14 days, so a deleted account disappears from them within 14 days of deletion. Invoices and the records tax law requires are kept for as long as that law says.
7. How we protect it
Traffic to SyncYak is encrypted with TLS. Passwords are hashed, and credentials for your connections are encrypted at rest. Each account’s data lives in its own store on its home server, access to the servers is restricted to the people who run them, and every sensitive action in an account is recorded in its audit log. No system is perfectly secure; if a breach affects your personal data, we tell you without undue delay.
8. Where it is processed
Our servers and our providers may be in countries other than yours, including the United States. Where the law requires it, we protect transfers with recognised safeguards, such as the European Commission’s standard contractual clauses.
9. Your rights
Depending on where you live (for example under the GDPR in the EU and UK, or the CCPA in California), you can ask to access, correct, delete or receive a copy of your personal data, and to object to or restrict how we use it. You can do most of this yourself in the dashboard: edit your profile in Settings, remove team members, and close the account. For anything else, write to contact@syncyak.com; we answer within 30 days. You may also complain to your data protection authority.
If you are someone whose details a SyncYak customer processes (for example, a lead in an agent’s CRM), please contact that customer first: they decide how your data is used. We will help them answer you.
10. Children
SyncYak is for businesses and is not meant for anyone under 18. We do not knowingly collect their data.
11. Changes to this policy
When we change this policy in a way that matters, we email account owners before the change takes effect and update the date at the top of this page.
Questions about this page: contact@syncyak.com. See also the Terms of Service, the Privacy Policy and Help.