Privacy Policy

This Privacy Policy explains how SyncFerry (“we,” “us”) collects, uses, and protects information in connection with the SyncFerry service (the “Service”). It complements our Terms of Service.

Scope #

This policy covers our website (and subdomains), our web application, our customer communications, and any interaction where this policy is referenced.

Information we collect #

A. Information you provide

  • Account data — name, email, organization name, and preferences.
  • Authentication data — credentials you set, or sign-in via a third-party identity provider, plus multi-factor settings.
  • Billing information — processed by our payment processor; we receive only limited details (e.g., plan, status, and the last four digits of a card).
  • Support communications — messages you send us via email, forms, or chat.

B. Connected-services data (Stripe & HubSpot) When you connect your accounts and authorize a sync, we process:

  • Stripe data — customers, subscriptions, invoices, products/prices, charges and their amounts/timestamps, and related metadata, read on your behalf.
  • HubSpot data — the companies, contacts, products, subscriptions, invoices, and line items we read and write to perform the sync, plus the mappings between them.

We process this business data on your behalf to provide the Service. We do not act as a payment processor.

C. Usage and diagnostic data — technical information such as IP address, browser/device type, pages and features used, timestamps, and performance and security logs.

D. Cookies and similar technologies — strictly necessary cookies (authentication and security) and, where applicable, analytics and preference cookies. Disabling some cookies may affect functionality.

Where applicable we rely on: performance of a contract (to deliver the Service); legitimate interests (security, fraud prevention, and improvement); consent (withdrawable, for non-essential purposes); and compliance with legal obligations.

How we use information #

To provide and maintain the Service and perform the syncs you configure; to set up mappings; to secure accounts and prevent abuse; to provide support; to comply with legal obligations; and to improve the Service. We send service-related communications, and marketing communications only with your opt-in or as permitted by law. We do not sell personal information.

Roles (controller / processor) #

For your account information we act as a controller. For the business data we sync between your Stripe and HubSpot accounts, we act as a processor on your behalf, and you are the controller. A Data Processing Addendum governs that processing (see below).

How we share information #

  • Service providers (sub-processors) — vetted vendors that help us run the Service (for example hosting/infrastructure, database hosting, and transactional email), bound by confidentiality and data-protection terms. We maintain a current sub-processor list and provide 30 days’ notice before adding or replacing one.
  • Connected platforms — data is exchanged with Stripe and HubSpot per your authorization.
  • Legal and safety — when reasonably required by law or to protect rights, property, or safety.
  • Business transfers — in connection with a merger, acquisition, reorganization, or asset sale, with notice to you.

Security #

We protect data with measures including AES-256-GCM encryption of connection credentials at rest (which are never returned by our API), TLS in transit, role-based access controls, and monitoring for unauthorized access. No security measures are perfect, but we work to protect your data.

Data retention #

We retain data while your account is active to provide the Service, including persistent sync mappings used for history and de-duplication. After your account is cancelled we delete or de-identify customer data within 30 days, and purge it from encrypted backups within 90 days, except where we must retain it to comply with legal obligations.

International data transfers #

We process information in the United States and other locations. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the Standard Contractual Clauses and the UK International Data Transfer Addendum.

Your rights and choices #

You may access, update, or correct your account information in the app or by contacting us. Depending on your location (e.g., under GDPR, CCPA/CPRA) you may have rights to access, correct, delete, port, or restrict/object to processing of your personal information. We respond to verified requests as required by law. Requests about an end customer’s data in your connected accounts are referred to you as the controller.

Children’s privacy #

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 16 and will delete it promptly if we learn we have.

Data Processing Addendum #

Business customers are covered by a separate Data Processing Addendum (available on request) that specifies the controller/processor roles, sub-processors, and security commitments for the business data we process on your behalf.

Changes to this policy #

We may update this policy and will revise the “updated” date above; we will notify you of material changes via the Service or by email.

Contact #

Questions or privacy requests? Contact SyncFerry at [email protected].