Policy Updated: April 28th 2026
At Syncaroo, we believe privacy should be simple, transparent, and built into how systems work—not bolted on later.
This Privacy Policy explains what data we collect, how we use it, and how we protect it when you:
- Visit our website (syncaroo.com)
- Engage with us as a lead or customer
- Use our managed integration services
1. Our Core Privacy Principle
Syncaroo is designed to move data—not store it.
We act as a secure conduit between systems you own, not a database of your customer data.
- We do not persistently store personal data (PII) from integrations
- We do not sell or monetize data
- We minimize exposure by design
2. Data We Collect (Website & Marketing)
When you interact with our website, we may collect:
Contact & Lead Information
- Name
- Email address
- Company name
- Any information you submit via forms
Communications
- Messages you send us (e.g., via forms or support tools)
- Email interactions (e.g., opens, replies)
Analytics
- Basic usage data (pages visited, time on site, referring sources)
- We do not use retargeting or advertising trackers
Marketing
- If you opt in, we may send updates, insights, or product-related communications
- You can unsubscribe at any time
3. How We Share Information
Syncaroo may share, transfer, or disclose information in the following circumstances:
Service Providers and Infrastructure Partners
We may share information with trusted third-party service providers that help us operate, secure, host, monitor, and support the Services. These providers may include cloud hosting providers, logging and monitoring platforms, customer support tools, and analytics providers.
Connected Third-Party Systems
At the direction of our Customers, Syncaroo facilitates the transfer and synchronization of data between connected third-party systems and platforms selected by the Customer (such as workspace management platforms, CRMs, billing systems, analytics systems, or access control systems).
Customers control which systems are connected and what data is synchronized between them.
Authorized Users
Information may be accessible to authorized employees, contractors, or representatives of the Customer based on permissions and access controls managed by the Customer.
Legal and Compliance Obligations
We may disclose information where required to comply with applicable law, regulation, legal process, or governmental request, or where necessary to protect the rights, property, or safety of Syncaroo, our Customers, or others.
Corporate Transactions
Information may be disclosed as part of a merger, acquisition, financing, reorganization, or sale of assets involving Syncaroo, subject to appropriate confidentiality protections.
With Customer Direction or Consent
We may share information where a Customer instructs us to do so or otherwise provides consent.
Syncaroo does not sell personal information or customer data.
4. Data We Process (Integration Services)
When providing services, Syncaroo acts as a data processor on behalf of our customers.
Customers remain the owners and controllers of data processed through the Services.
Syncaroo acts as a processor or service provider with respect to customer data and processes customer data solely on behalf of and under the instructions of its Customers.
Data is processed and temporarily stored (see Limited Data Retention section below) only as necessary to facilitate synchronization, transformation, monitoring, and related platform functionality.
What This Means
- You (our customer) own and control the data
- We only process data as instructed
- We do not use this data for any other purpose
How Data Flows Through Syncaroo
- Data is temporarily processed to:
- Transform
- Normalize
- Map between systems
- During this process:
- All sensitive data is encrypted
- Our team cannot view or access PII
What We Do NOT Do
- We do not store synced personal data after transfer is complete
- We do not build user profiles
- We do not analyze end-user behavior
5. Limited Data Retention
We retain only what is necessary to operate the service:
Metadata (Non-PII)
- Sync timestamps
- System identifiers (machine-to-machine)
- Status logs (success/failure)
Logging
- Logs may contain encrypted data for debugging
- Any PII within logs is encrypted and inaccessible to humans
Caching
To improve performance, we may cache:
- Workspace availability (e.g., rooms, desks)
This cache:
- Does not include user identity or booking details
- Is used strictly to speed up synchronization
6. Security Measures
We take a defense-in-depth approach to security:
- Encryption in transit (TLS 1.2+)
- Encryption at rest
- Encryption during processing
- Strict access controls
- Separation of systems and environments
Importantly:
- Sensitive data is not readable by Syncaroo personnel
- We design systems to reduce the need for human access entirely
We are actively working toward formal security certifications (e.g., SOC 2, ISO 27001).
7. Infrastructure & Subprocessors
We operate using trusted infrastructure providers, including:
- AWS
- DigitalOcean
- SiteGround
We also use tools for:
- Monitoring and logging (e.g., Sentry)
- Customer support (e.g., GoSquared)
All infrastructure is primarily hosted in the United States.
We ensure that any subprocessors:
- Meet appropriate security standards
- Only process data as required to deliver our services
8. Your Rights (Including GDPR)
Depending on your location, you may have rights to:
- Access your data
- Correct inaccurate data
- Request deletion
- Restrict or object to processing
Important Note
For data processed via integrations:
- Syncaroo acts as a processor
- Requests should typically be directed to the data owner (our customer)
That said, we’re happy to help guide you:
📧 [email protected]
9. Data Retention
- Lead and marketing data: retained as long as necessary for business purposes or until you opt out
- Integration data: not retained after processing
- Metadata/logs: retained only as needed for system performance and reliability
10. International Data Transfers
As a U.S.-based company serving global customers:
- Data may be processed in the United States
- We apply appropriate safeguards for international transfers
- Additional Data Processing Addenda (DPAs) are available for enterprise customers
11. Children’s Privacy
Syncaroo services are not intended for individuals under 18.
We do not knowingly collect data from children.
12. Updates to This Policy
We may update this policy from time to time.
When we do:
- We’ll update the “Effective Date”
- Significant changes will be clearly communicated
13. Contact Us
If you have questions, concerns, or requests:
14. Enterprise Privacy & Data Agreements
For enterprise customers, we offer:
- Data Processing Addenda (DPAs)
- Custom security and privacy agreements
- Integration-specific data handling terms