Privacy Policy
This policy explains how Synkro handles personal information across our website, products, and services.
Last updated September 20, 2026
Scope
This Privacy Policy describes how Synkro Labs Inc (“Synkro,” “we,” “us,” or “our”) handles personal information when you visit synkro.sh, request access, communicate with us, or use our software, APIs, command-line tools, integrations, and related products and services (collectively, the “Services”).
This policy does not apply to information that we process on behalf of a customer under a services agreement or data processing agreement (“Customer Data”). For that information, the customer determines why and how it is processed, and Synkro acts as its service provider or processor. If you use the Services through an organization, that organization’s privacy notices and agreements with Synkro govern its Customer Data. Privacy requests concerning Customer Data should be directed to that organization.
Information we collect
Information you provide
- Access and contact information. Your name, work email address, organization, role, and information you include in a request or communication.
- Account information. Authentication identifiers, profile information, organization membership, account settings, and administrative preferences.
- Commercial information. Subscription, order, billing-contact, transaction, and payment-status information. Payment card details may be collected directly by a payment processor rather than Synkro.
- Communications. Support requests, product feedback, survey responses, event registrations, and other communications you send us.
Information generated through the Services
- Product and usage data. Features used, actions taken, workspace and integration settings, timestamps, performance data, and diagnostic events.
- Agent activity and decision data. Depending on a customer’s configuration, the Services may process information about agent sessions, tool-call requests, commands, edits, installations, deployment actions, applicable rules, consent decisions, outcomes, and related technical metadata. When processed for an organization, this information is generally Customer Data governed by that organization’s agreement with Synkro.
- Security data. Authentication events, IP address, device and browser information, access logs, suspected abuse, and other information used to protect accounts and the Services.
Information collected automatically
- Device and network data. IP address, browser and device type, operating system, referring page, and similar technical information.
- Website usage data. Pages viewed, approximate visit time, referring sources, interactions, and diagnostic or security events.
- Local preferences. Interface preferences stored in your browser, such as theme or sidebar state.
Information from other sources
We may receive information from your organization, organization administrators, integrations you or your organization connect to the Services, business partners, public sources, and service providers that help us operate and secure the Services. The information received from an integration depends on the permissions and settings selected by you or your organization.
How we use information
We use personal information to:
- receive, review, and respond to access requests;
- create and administer accounts, workspaces, subscriptions, and customer relationships;
- provide the Services, including applying customer-defined rules to agent activity, recording decisions, and supporting customer-directed integrations;
- authenticate users and send service, security, support, and administrative messages;
- maintain, troubleshoot, test, analyze, and improve the Services;
- monitor performance and protect the Services, customers, and others from fraud, abuse, and security threats;
- communicate about Synkro products, events, and updates, subject to your choices;
- comply with law, respond to lawful requests, and enforce our agreements; and
- carry out another purpose disclosed when information is collected or with your consent.
Where applicable law requires a legal basis, we rely on performance of a contract, compliance with legal obligations, our legitimate interests in operating, improving, and securing the Services, and consent where requested. When we rely on legitimate interests, we consider their effect on your rights.
Customer Data
Customers control the Customer Data they submit to or make available through the Services, including the data their users, agents, repositories, development tools, and connected systems generate. We process Customer Data only to provide, secure, support, and improve the Services as permitted by the applicable customer agreement, customer instructions, and law.
Customers are responsible for providing required notices, obtaining required permissions, configuring their integrations and retention settings, and responding to requests from people whose personal information appears in Customer Data. If you believe your personal information is included in Customer Data, contact the customer that controls the relevant workspace. We will assist that customer as required by our agreement and applicable law.
How we disclose information
We may disclose personal information to:
- Service providers. Companies that provide infrastructure, hosting, security, authentication, communications, analytics, customer support, billing, and other services on our behalf. They may process information only for the services they provide to us and under appropriate contractual restrictions.
- Your organization and its administrators. If you use an organization-managed account, its administrators may access and manage your account and associated activity.
- Integrations and parties you direct. Third-party products or services that you or your organization connect to Synkro, in accordance with the permissions and instructions provided.
- Professional advisers. Lawyers, accountants, insurers, auditors, and similar advisers where reasonably necessary.
- Authorities and other parties. When we reasonably believe disclosure is required by law, necessary to protect rights or safety, or appropriate to investigate fraud, abuse, or security incidents.
- Transaction participants. Parties involved in a financing, merger, acquisition, reorganization, sale of assets, bankruptcy, or similar corporate transaction, subject to appropriate confidentiality protections.
- Affiliates. Current or future companies under common control with Synkro, consistent with this policy.
We do not sell personal information for money, and we do not share personal information for cross-context behavioral advertising. If our practices change, we will update this policy and provide any choices required by law.
Cookies and similar technologies
We may use cookies, local storage, pixels, and similar technologies that are necessary to operate and secure the Services, remember preferences, understand usage, and measure communications. We do not currently use advertising cookies. You can control cookies and local storage through your browser, but some features may not function as intended afterward.
Because there is not a consistent industry standard for “Do Not Track,” we do not currently respond to that signal. Where required, we honor legally recognized browser-based opt-out preference signals.
Data retention
We retain personal information for as long as reasonably necessary to provide the Services, maintain customer and security records, comply with legal obligations, resolve disputes, and enforce agreements. Retention depends on the nature of the information, why it was collected, customer configuration and instructions, contractual requirements, and applicable law. We may retain deidentified or aggregated information that cannot reasonably be used to identify you.
Customer Data is retained and deleted in accordance with the applicable customer agreement, workspace settings, and legal requirements. Backup copies may remain for a limited period before being overwritten through our ordinary systems.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information. No system or transmission is completely secure, and we cannot guarantee absolute security. You are responsible for protecting account credentials, configuring access appropriately, and notifying us promptly if you suspect unauthorized access.
Your choices and privacy rights
Depending on where you live, you may have the right to request access to, correction or deletion of, or a copy of personal information associated with you. You may also have rights to object to or restrict processing, withdraw consent, opt out of certain uses, or appeal a decision. These rights may be subject to exceptions. We may verify your identity and authority before acting on a request.
You may opt out of promotional email using the unsubscribe link in the message. We may still send non-promotional communications about your account, the Services, security, or this policy. Where permitted, you may use an authorized agent. We will not discriminate against you for exercising a privacy right.
To submit a request concerning information Synkro controls, email team@synkro.sh or write to the address below. To appeal a decision, reply to our response and state that you are submitting a privacy appeal. For Customer Data, contact the organization that controls the relevant Synkro workspace.
Additional US state disclosures
In the preceding 12 months, we may have collected the categories described above: identifiers and contact information; commercial information; internet, network, and electronic activity; professional or employment-related information; approximate geolocation derived from IP address; and inferences drawn from account and usage information. We collect these categories from you, your organization, connected services, your device, public sources, and service providers, and use and disclose them for the purposes described in this policy.
We do not use or disclose sensitive personal information to infer characteristics about a person. We do not knowingly sell or share the personal information of anyone under 18. We retain each category only as long as reasonably necessary under the factors described in “Data retention.”
International data transfers
Synkro is based in the United States. Your information may be processed in the United States and other countries where we or our service providers operate. Those countries may have different data-protection laws. Where required, we use contractual and other safeguards designed to support lawful transfers.
If you are in the European Economic Area, United Kingdom, or Switzerland, you may also have the right to lodge a complaint with your local data-protection authority. We encourage you to contact us first so we can try to address your concern.
Children’s privacy
The Services are intended for business users and are not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided personal information to us, please contact us so we can take appropriate action.
Third-party services
The Services may contain links to or interoperate with third-party products and services. When you direct information to a third party or leave the Services, that third party’s privacy policy governs its handling of information. We encourage you to review those policies and integration permissions before connecting a service or providing information.
Changes to this policy
We may update this policy as our Services, practices, or legal obligations change. We will post the revised policy on this page and update the date above. If a change materially affects how we use personal information, we will provide additional notice when reasonably practicable.
Contact us
Synkro Labs Inc is responsible for the personal information described in this policy when it acts as a controller. Questions and privacy requests may be emailed to team@synkro.sh or mailed to:
Synkro Labs Inc
Attn: Privacy
390 NE 191st St, STE 54917
Miami, FL 33179
United States