Privacy Policy
Last updated: February 3, 2026
At Syncra, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and service, including all related applications, software, tools, and services that link to this Privacy Policy (collectively, the "Service").
Contents
1. Information We Collect
Account Information
When you create a Syncra account, we collect information necessary to establish and manage your account, including:
- •Full name and email address
- •Profile information (profile picture, bio, company)
Authentication Information
We use Auth0 as our authentication provider. When you authenticate through Auth0, we receive and store your verified identity information. Auth0 may collect additional information according to their privacy policy, and we recommend reviewing it at https://auth0.com/privacy.
Authentication is handled exclusively by Auth0. We do not store passwords in our database.
Social Media Account Connections
To provide the core functionality of Syncra, we collect information related to your social media accounts:
- •OAuth tokens and credentials for connected platforms (Twitter, LinkedIn, Facebook, Instagram, etc.)
- •Account identifiers from each social platform
- •Public profile information from connected accounts
- •Audience insights and metrics from your social media accounts (follower counts, engagement data)
Important: OAuth tokens are encrypted and stored securely. They are used only to perform the actions you authorize through Syncra (posting, scheduling, retrieving analytics). We never use these tokens for any other purpose.
Workspace and Team Data
If you create or join a workspace, we collect:
- •Workspace name and description
- •Team member information and roles
- •Workspace settings and preferences
- •Billing and subscription information
- •Payment method details (processed through secure payment providers)
Post and Content Data
Syncra stores content you create, including:
- •Draft posts and scheduled content
- •Published posts and content metadata
- •Images, videos, and media attachments
- •Post scheduling and publishing history
- •Comments, approvals, and collaboration data
Analytics and Usage Data
We automatically collect information about your interactions with Syncra:
- •Pages visited, features used, and actions taken
- •Login times, session duration, and access patterns
- •Device information (browser type, operating system, device type)
- •Engagement metrics and feature adoption data
Communication Data
When you contact us or communicate through the Service:
- •Support tickets and customer service communications
- •Feedback, feature requests, and bug reports
- •Email correspondence and chat messages
2. How We Use Your Information
We use the information we collect to:
- •Provide and operate the Service – Creating and maintaining your account, processing posts, managing scheduling, and delivering the core features you use.
- •Enable social media publishing – Connecting to your social media accounts, scheduling posts, retrieving analytics, and publishing content.
- •Manage team collaboration – Processing approvals, assignments, comments, and workspace permissions.
- •Process payments – Billing, invoicing, and managing your subscription.
- •Improve the Service – Analyzing usage patterns, identifying features that need improvement, fixing bugs, and developing new features.
- •Provide customer support – Responding to inquiries, troubleshooting issues, and providing technical assistance.
- •Send communications – Account updates, security alerts, service changes, product updates (with your consent for marketing).
- •Ensure security – Detecting and preventing fraud, abuse, and unauthorized access.
- •Comply with legal obligations – Meeting regulatory requirements and responding to lawful requests.
- •Conduct research and analytics – Understanding user behavior, testing features, and creating aggregated, anonymized insights.
Legal Basis: We process your information based on: (a) your consent, (b) contract performance (providing the Service), (c) compliance with legal obligations, and (d) our legitimate business interests in improving the Service and ensuring security.
3. Disclosure of Your Information
We may disclose information in the following circumstances:
Service Providers
We share information with third-party vendors who perform services on our behalf under strict data processing agreements, including:
- •Cloud infrastructure providers (hosting, databases, backups)
- •Payment processors (for billing and transactions)
- •Analytics providers (anonymized usage data)
- •Customer support platforms
- •Email service providers
Legal Requirements
We may disclose information when required by law, including in response to subpoenas, court orders, or other legal processes. We will provide notice of such requests unless legally prohibited.
Business Transfers
If Syncra is involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and provide you with choices regarding your information.
Consent
We may disclose information when you provide explicit consent or request disclosure.
Aggregated Data
We may publicly share aggregated, anonymized information that cannot reasonably be used to identify you (e.g., "our users published 1M posts this month").
4. Data Security & Storage
Security Measures
We implement comprehensive security measures to protect your information from unauthorized access, alteration, disclosure, or destruction:
- •Encryption in transit – All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security) protocol.
- •Encryption at rest – Sensitive data including passwords, OAuth tokens, and payment information is encrypted when stored in our databases.
- •Access controls – Role-based access control ensures only authorized employees can access your data, and only for legitimate business purposes.
- •Firewalls and intrusion detection – Network-level security prevents unauthorized access attempts.
- •Regular security audits – We perform regular penetration testing and security assessments.
- •Employee training – Our team undergoes regular security and privacy training.
- •Incident response plan – We have documented procedures to respond to and report security incidents.
Note: While we implement industry-standard security measures, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your password. If you believe your account has been compromised, please contact us immediately.
Data Storage Location
Your data is stored on secure cloud infrastructure in Europe. We maintain redundant backups in geographically diverse locations for disaster recovery purposes. For users in the EU, we ensure data is stored within the EU to comply with GDPR requirements, or with appropriate safeguards if data processing occurs outside the EU.
5. Your Privacy Rights
GDPR Rights (EU Users)
If you are located in the European Union, you have the following rights under the General Data Protection Regulation (GDPR):
- •Right to access: You have the right to request a copy of your personal data in a structured, commonly used, and machine-readable format.
- •Right to rectification: You can request correction of inaccurate or incomplete personal data.
- •Right to erasure: You can request deletion of your personal data (subject to legal retention obligations).
- •Right to restrict processing: You can request that we limit how we use your data.
- •Right to data portability: You can request a copy of your data to transfer to another service.
- •Right to object: You can object to certain types of processing, including marketing communications.
- •Right to lodge a complaint: You have the right to file a complaint with your local data protection authority.
CCPA Rights (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- •Right to know: You can request what personal information we collect and how it is used.
- •Right to delete: You can request deletion of personal information collected from you (subject to exceptions).
- •Right to opt-out: You can opt out of the sale or sharing of your personal information.
- •Right to correct: You can request correction of inaccurate personal information.
- •Right to limit use: You can limit our use of sensitive personal information.
How to Exercise Your Rights
To exercise any of these rights, please contact us at - with:
- •A clear description of your request
- •Sufficient information to identify your account
- •Proof of identity (for security purposes)
We will respond to requests within 30 days (or as required by applicable law). You can also manage some preferences directly in your account settings.
Do Not Track
Some browsers include a Do Not Track (DNT) feature. We do not currently respond to DNT signals, but we provide other privacy choices as described in this policy.
6. Third-Party Services
Syncra integrates with third-party services. We are not responsible for their privacy practices. We recommend reviewing their privacy policies:
Auth0
Authentication service that securely handles your login credentials.
Privacy Policy: https://auth0.com/privacy
Social Media Platform APIs
We connect to Twitter, LinkedIn, Facebook, Instagram, and other platforms via their official APIs to enable publishing, scheduling, and analytics features.
Important: Your social media account data is governed by each platform's privacy policy. OAuth tokens we receive are used solely to perform actions you authorize.
- Twitter: https://twitter.com/privacy
- LinkedIn: https://www.linkedin.com/legal/privacy-policy
- Facebook: https://www.facebook.com/privacy/explanation
- Instagram: https://help.instagram.com/519522125107165
Analytics Services
We use Google Analytics (planned for future implementation) to understand how users interact with Syncra and improve the product.
Email Services
Google Cloud is used for email delivery to send transactional emails and notifications.
Privacy Policy: https://cloud.google.com/privacy
Payment Processing
Billing is handled by Polar (polar.sh). Payment information is not stored on our servers. All transactions are encrypted and PCI-DSS compliant.
Privacy Policy: https://polar.sh/legal/privacy
7. Cookies & Tracking Technologies
What Are Cookies?
We use an encrypted session cookie for authentication. This cookie enables you to stay logged into your account.
Managing Cookies
Our encrypted session cookie is essential for authentication. You can clear cookies in your browser settings, but this will log you out of your account.
8. Children's Privacy
Syncra is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without parental consent, we will promptly delete it.
For users between 13 and 18 (minors), we provide additional protections consistent with applicable laws regarding online privacy for minors.
If you believe we have collected information from a child under 13, please contact us immediately.
9. Data Retention
We retain information for as long as necessary to provide the Service and comply with legal obligations. Specific retention periods include:
Account Information
Retained while your account is active after account deletion for legal and business purposes.
Post and Content Data
Retained as long as needed for backup, recovery, and legal compliance. Deleted posts may remain in backups before permanent deletion.
Usage and Analytics Data
Aggregated analytics are retained indefinitely. Individual usage logs are retained then anonymized or deleted.
Communication Records
Retained for customer service and dispute resolution purposes.
Legal and Compliance Records
Retained as required by law, typically two years from the date of collection.
Account Deletion: You can delete your account in your account settings. We will delete your personal data, but some information may be retained in anonymized or aggregated form, or as required by law.
10. International Data Transfers
Syncra operates globally. Your information may be transferred to, stored in, and processed in countries other than your country of residence, which may have different data protection laws.
EU Users and Standard Contractual Clauses
If you are located in the EU, when we transfer data outside the EU, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection. These contractual mechanisms ensure your data receives equivalent protection regardless of where it is processed.
GDPR Data Processing Agreement
For business customers subject to GDPR, we offer a Data Processing Agreement (DPA) that specifies how data is processed, including your rights and our obligations.
By using Syncra, you consent to the transfer of your information to countries outside your country of residence.
11. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by updating the "Last Updated" date at the top of this policy and, for significant changes, by sending you an email notice or displaying a prominent notice within Syncra.
Your continued use of Syncra after any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this policy regularly to stay informed about how we protect your information.
If you do not agree with the updated policy, you may delete your account and cease using Syncra.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Privacy Contact
Syncra
-
-
Spain
Response Times
We aim to respond to all inquiries within 10 business days. Privacy requests (such as data access or deletion) will be handled in accordance with applicable law (typically 30 days for GDPR requests).
Supervisory Authority
EU users have the right to lodge a complaint with your local data protection authority:
EU Data Protection Authorities: https://edpb.ec.europa.eu/about-edpb/board/members_en
Thank you for trusting Syncra with your data. We are committed to protecting your privacy while providing you with powerful tools for social publishing.