Legal & Compliance

Privacy Policy

Last Updated: July 8, 2026

At SYNTR, we are committed to protecting your privacy. This Privacy Policy describes how SYNTR ("we", "us", or "our") collects, uses, processes, and protects your personal and business data when you access or use our AI-powered operating system, including email automation, WhatsApp CRM, smart tracking tools, commerce integrations, analytics, and associated services (collectively, the "Services" or "Platform").

This policy applies to information collected through our website (syntr.co), our platform, and any integrations you connect through the Services. It does not apply to information collected offline or through third-party websites or services that may link to or from our platform.

By accessing or using the Platform, you consent to the data collection and practices described in this Privacy Policy. If you do not agree with any terms of this policy, please do not use our services.

1. Definitions

  • "Controller" — The entity that determines the purposes and means of processing Personal Data.
  • "Processor" — The entity that processes Personal Data on behalf of the Controller.
  • "Subscriber" or "Merchant" — A business or individual who creates a SYNTR account and uses our Services.
  • "End-User" or "Customer" — A customer, lead, subscriber, or contact of the Merchant whose data is processed through the Services.
  • "Personal Data" — Any information relating to an identified or identifiable individual.
  • "Platform" or "Services" — The SYNTR platform, website, APIs, integrations, and all associated tools and features.

2. Information We Collect

To provide our multi-channel automation and intelligence services, we collect data under the following categories:

  • Account Information: Name, business email address, phone number, organization name, billing address, and account credentials.
  • Integration Data: API tokens, authentication credentials, and system IDs for connected mailboxes (SMTP/IMAP credentials, Google OAuth tokens, Outlook tokens), WhatsApp Business API configurations, and connected commerce platforms (such as Shopify).
  • Commerce & Store Data: When you connect an e-commerce store, we access — with your authorization and only through the platform's official APIs — customer information (name, email address, phone number), store activity and history (checkout details for cart recovery, order history, and product catalog items), and store identity data.
  • Campaign & Outreach Content: Content of automated emails, follow-up sequences, templates, and WhatsApp messages compiled and dispatched through our platform.
  • Recipient and Lead Data: Information uploaded or synced by you concerning your leads, subscribers, or clients, including email addresses, phone numbers, interaction history, and custom metadata.
  • Usage & Device Analytics: IP addresses, browser configurations, operating systems, clickstream records, referral sources, and platform interaction histories.

3. How We Use Your Information

We process your data to deliver the core functional benefits of SYNTR. We collect and use only the data necessary to provide the features you enable. Specific uses include:

  • Provision of Services: Creating and managing accounts, delivering email sequences, dispatching automated WhatsApp follow-ups, managing deal pipelines, sending automated checkout recovery templates, and triggering promotional messages.
  • Commerce Automation: Syncing store data to construct CRM contact profiles and timelines, power automated checkout recovery workflows (such as abandoned-cart reminders), and enable order-triggered campaign workflows.
  • AI Engine Refinements: Operating our built-in AI agents that draft follow-ups, enrich lead profiles, and optimize send timings. (Note: We do not use your proprietary business leads or sensitive text content to train public foundation models.)
  • System Performance & Tracking: Monitoring system uptime, analytical conversions, and providing metrics on tracking performance.
  • Billing & Account Management: Verifying credentials, managing monthly/annual subscriptions, processing invoices, and responding to support requests.
  • Security: Detecting, preventing, and addressing fraud, abuse, and security incidents.
  • Legal Compliance: Complying with applicable laws, regulations, and legal processes.

Where required by applicable law (such as the GDPR for users in the EEA or UK), our legal bases for processing include: performance of a contract with you, our legitimate business interests (such as improving our Services and preventing fraud), your consent where applicable, and compliance with legal obligations.

4. Data Sharing and Third Parties

We do not sell, rent, or trade your Personal Data or your End-Users' Personal Data to any third party for marketing or commercial purposes.

We share data only with the following categories of service providers to execute outreach and operations:

  • Infrastructure & Hosting Providers: Data is securely hosted on premium cloud providers (such as Amazon Web Services and Google Cloud Platform).
  • Communications Gateways: SMTP servers, Twilio (for WhatsApp), and official Meta WhatsApp Business API channels to deliver your communications.
  • Commerce Platforms: Connected platforms such as Shopify, via their official APIs, to access and sync store data necessary to deliver our services.
  • Payment Processors: Credit card processing is handled securely via Stripe, and no raw billing credentials are saved on SYNTR servers.
  • Legal Compliance: We may disclose information if required by applicable local regulations, court subpoenas, or if we deem disclosure necessary to protect against fraud or security vulnerabilities.

All third-party service providers we work with are bound by confidentiality obligations and data processing agreements.

5. Role as Data Processor

When processing End-User data on behalf of a Subscriber (for example, customer records synced from a connected store, uploaded contact lists, or message recipients), SYNTR acts as a Data Processor. The Subscriber is the Data Controller for such data.

As a Data Processor, we:

  • Process End-User data only as directed by the Subscriber.
  • Do not use End-User data for our own independent purposes.
  • Assist Subscribers in fulfilling data subject requests where applicable.
  • Honor data subject requests received through connected platforms — for example, we respond to Shopify's mandatory privacy webhooks (customer data requests, customer data erasure, and shop data erasure) and delete or export the relevant data accordingly.

We collect information under the direction of our Subscribers and have no direct relationship with the End-Users whose personal information we process. If you are an End-User and wish to exercise your data rights, please contact the Subscriber (the business whose services you use) directly.

6. Data Security

We maintain industry-standard physical, administrative, and technological guardrails to prevent unauthorized access, alteration, or destruction of your data. These measures include:

  • Encryption of data in transit using TLS/SSL protocols.
  • Secure connection to external mail servers via SSH/SSL protocol.
  • Encryption of credentials and tokens at rest using AES-256 standards.
  • Access controls and authentication for platform and infrastructure access.
  • Regular security reviews and monitoring.

While we strive to protect your information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.

7. Data Retention and Deletion

We store account information and client database details as long as your SYNTR subscription remains active. Specifically:

  • Account Data: Retained while your subscription is active. Upon account termination, data is retained for up to 30 days to allow for reactivation, after which it is permanently deleted upon request.
  • Integration Data: When you disconnect a third-party integration (for example, uninstalling our app from an e-commerce platform such as Shopify), we revoke and delete the associated access tokens immediately. Synced data from that integration is retained for up to 30 days to allow for re-connection, after which it is permanently deleted.
  • Communication Logs: Campaign, email, and message logs are retained in accordance with your subscription plan and are deleted upon account termination and verified deletion request.

Upon account termination, you may request deletion of all connection tokens, email logs, and customer databases. Data will be permanently purged within 30 days of a verified deletion request. You may request export or deletion of your data at any time by contacting us at privacy@syntr.co.

8. Your Data Rights

Depending on your location and applicable laws (including the GDPR and CCPA), you may have the following rights regarding your Personal Data:

  • Access — Request a copy of the Personal Data we hold about you.
  • Correction — Request that we correct inaccurate or incomplete data.
  • Deletion — Request that we delete your Personal Data.
  • Portability — Request your data in a structured, commonly used format.
  • Objection — Object to certain types of data processing.
  • Restriction — Request that we restrict how we process your data.

To exercise any of these rights, please contact us at privacy@syntr.co. We will respond to your request within a reasonable timeframe in accordance with applicable law.

If you are an End-User of one of our Subscribers, please direct your data rights requests to the Subscriber, as they are the Data Controller for your information.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We take appropriate steps to ensure that international transfers of Personal Data are conducted with adequate safeguards in compliance with applicable data protection laws, including the use of Standard Contractual Clauses where required.

10. Children's Privacy

Our Services are intended for business use and are not directed at individuals under the age of 18. We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently collected information from a child under 18, we will take reasonable steps to delete such data promptly.

11. Cookies and Tracking Technologies

We use cookies and similar technologies on our website to enhance user experience and collect usage analytics. For more information about the cookies we use and your choices regarding them, please refer to our Cookie Policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we do, we will revise the Last Updated date at the top of this page. We encourage you to review this policy periodically.

13. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about our data practices, please contact our privacy compliance officer at:

Email: privacy@syntr.co