Privacy Policy
How Syncrony Inc. collects, uses, shares, and protects personal information through its website, its client portal, and its services.
Syncrony Inc. ("Syncrony", "we", "us") is a software development company incorporated in the province of Nova Scotia, Canada. We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and we handle personal information in line with its ten fair-information principles regardless of where you are located.
This policy applies to:
- syncrony.ca, our public website;
- the Syncrony client portal at portal.syncrony.ca and its related services (the "Portal"); and
- the personal information we handle while delivering services to our clients.
If you use the Portal on behalf of a client company, that company controls its own business data. This policy describes what Syncrony does with the personal information in our care.
1. What We Collect
We collect only what we need to run the business and deliver the services.
When you contact us through the website
- Name, company, email address, and phone number (if provided).
- What you are looking for, your business type, how you heard about us, and anything you write in the message field.
- A bot-protection token generated by the form's challenge (see section 6). We do not receive your answer to the challenge, only a pass or fail token.
When you have a Portal account
- Name, email address, and the client workspace(s) you belong to.
- Login and session records: hashed password, session tokens, the time of each login, and the IP address and browser type of the device used.
- Everything you and your colleagues put in the Portal: tickets, messages, comments, attachments, scope approvals, and meeting bookings.
- Billing profile details for your company: billing contact name, billing address, and tax identifiers where applicable.
- The record of which version of our Engagement Terms you accepted, and when.
When you pay us
- Payment is processed by Stripe. We receive a Stripe customer reference, the payment status, the last four digits of a card, and the card brand. We never see or store full card numbers.
When you book a meeting with us
- The time slot, your name and email address, and the video-meeting link. Meetings are scheduled through Google Calendar and held on Google Meet.
When you email us
- Your email address, the content of the message, and any attachments. Replies sent to a ticket notification address are added to that ticket in the Portal.
Automatically, when you use the website or Portal
- Standard server logs: IP address, browser type, pages requested, and timestamps, retained briefly by our hosting provider for security and troubleshooting.
We do not buy personal information from data brokers, and we do not collect information from children. Our services are for businesses and their staff.
2. How We Use It
| Purpose | Information used |
|---|---|
| Respond to your enquiry | Contact-form details, email content |
| Set up and secure your Portal account | Name, email, password hash, session and login records |
| Deliver the services you have engaged us for | Everything in tickets, messages, attachments, and bookings |
| Record and bill time, and issue invoices | Ticket and time records, billing profile, Stripe references |
| Prove which terms you accepted | Acceptance record |
| Send transactional notifications | Email address (ticket updates, invoices, password resets, booking confirmations) |
| Keep the website and Portal safe | Server logs, bot-protection tokens, session records |
| Meet legal and tax obligations | Billing and invoice records |
We do not sell personal information. We do not use it for advertising, and we do not send marketing email unless you have asked to receive it. Every non-transactional email we send includes an unsubscribe link.
3. Consent
We rely on your consent, which you give by providing information to us through the website, by accepting an invitation to the Portal, or by engaging our services. Where a use is necessary to perform the agreement between Syncrony and your company, or is required by law, we may rely on that instead.
You can withdraw consent at any time by contacting us (section 10), subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide some services to you or your company.
4. Who We Share It With
We share personal information only with service providers that help us run the business, and only what they need. Each provider is bound by contractual terms that restrict its use of the information to the service it provides to us.
| Provider | What they do for us | Where data is processed |
|---|---|---|
| Cloudflare | Hosts the website and Portal, stores attachments, delivers email, filters bots | United States and its global network |
| Neon | Hosts the Portal database | United States |
| Tape | Our internal system of record for clients, tickets, time, and billing | European Union and United States |
| Stripe | Processes payments | United States |
| Calendar scheduling and Meet video meetings | United States | |
| GitHub | Stores source code, which may occasionally contain configuration referencing client systems | United States |
| Anthropic | AI models and developer tooling (Claude, Claude Code) used during development and in AI features we build; client data may be processed when a task requires it | United States |
We may also disclose personal information when required by law, court order, or a lawful request from a public authority, or to protect the rights, property, or safety of Syncrony, our clients, or others. Where the law allows, we will tell you before we do.
If Syncrony is ever sold or merged, personal information may be transferred to the successor, who will be bound by this policy until it is changed in accordance with section 11.
5. Where Your Information Is Stored
Syncrony is based in Canada. Our service providers store and process information mainly in the United States, and in some cases in the European Union. When personal information leaves Canada it is subject to the laws of the country where it is held, and may be accessible to that country's authorities. We choose providers with strong security practices and contractual commitments, but we cannot guarantee that foreign law will treat your information the same way Canadian law does.
6. Cookies and Similar Technologies
Website (syncrony.ca). The website sets no cookies of its own and uses no analytics or advertising trackers. The contact form uses a bot-protection challenge from a third party, which may set a cookie on its own domain to distinguish people from automated traffic. If we add analytics in future, we will update this section first.
Portal (portal.syncrony.ca). The Portal uses strictly necessary cookies to keep you signed in. They are HttpOnly, sent only over HTTPS, and are not readable by scripts. They contain session identifiers, not personal information, and expire when the session does. Your theme preference (light or dark) is stored in your browser's local storage and never leaves your device. No third-party analytics or advertising cookies are used in the Portal.
7. How Long We Keep It
- Contact-form enquiries: up to two years after our last contact with you, then deleted, unless you become a client.
- Portal accounts and content: for the life of your company's engagement with Syncrony, and for seven years afterward for the records we are required to keep for tax and accounting purposes (invoices, time records, acceptance records). Tickets, messages, and attachments are deleted or anonymized on request after an engagement ends, subject to those retention obligations.
- Session and login records: ninety days.
- Server logs: retained by our hosting provider for a short rolling window, typically less than thirty days.
- Backups: encrypted backups of the Portal database may retain deleted information for up to thirty days after deletion.
8. How We Protect It
We use industry-standard safeguards appropriate to the sensitivity of the information: encryption in transit (TLS) for every connection and at rest for databases, storage, and backups; hashed passwords; HttpOnly, secure session cookies; role-based access so people see only their own company's data; and access to production systems limited to Syncrony personnel who need it. Subcontractors who touch client systems are bound by confidentiality obligations.
No system is perfectly secure. If we discover a breach that creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as PIPEDA requires.
9. Your Rights
You may ask us to:
- See the personal information we hold about you and how we have used it;
- Correct information that is inaccurate or incomplete;
- Delete information we no longer need, subject to the retention obligations in section 7;
- Withdraw consent to a particular use, as described in section 3; and
- Stop marketing email at any time, using the unsubscribe link or by contacting us.
We will respond within thirty days. We may need to verify your identity first, and in limited cases the law allows or requires us to refuse part of a request, in which case we will tell you why.
If you are in the European Economic Area or the United Kingdom, you also have the rights to data portability, to object to processing, and to lodge a complaint with your local supervisory authority. If you are in California or another U.S. state with a privacy statute, the rights above cover what those statutes provide for business contact information.
10. How to Reach Us
Questions, requests, and complaints about privacy go to:
Syncrony Inc., Attention: Privacy Email: [email protected] Phone: (866) 777-1326
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca or 1-800-282-1376.
11. Changes to This Policy
We may update this policy from time to time. The current version is always at syncrony.ca/privacy and in the Portal. When we make material changes we will notify Portal users by email and by notice in the Portal at least fourteen days before they take effect, and we may ask you to acknowledge the updated policy in the Portal. The "last updated" date at the top of this page tells you when it last changed.
Syncrony Inc. · Bridgetown, Nova Scotia, Canada · [email protected]