Privacy Policy
Last updated: February 9, 2026
SyncIn (“we”, “us”, or “our”) operates the website syncin.pro and provides a service that synchronises WhatsApp and LinkedIn messages to your CRM (the “Service”). This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our Service.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data We Collect
Account Data
- Email address (used for authentication and communication)
- Password (hashed — we never store plaintext passwords)
Connection Data
- Unipile account identifiers for your connected WhatsApp and/or LinkedIn accounts
- CRM access token (encrypted at rest, used to sync data to your CRM)
Message Data
- Message content, sender/recipient identifiers, and timestamps received via webhooks
- Contact names and identifiers used to match messages to CRM contacts
Message data is processed in transit and logged for sync tracking. We do not use message content for any purpose other than delivering it to your CRM.
2. How We Use Your Data
We process your personal data to:
- Authenticate you and manage your account
- Connect your messaging platforms to your CRM via Unipile
- Receive, process, and forward messages to your CRM
- Display sync status and history in your dashboard
- Send transactional emails related to your account (e.g. password resets)
We do not use your data for advertising, profiling, or any purpose unrelated to providing the Service.
3. Legal Basis for Processing
Under the GDPR, we process your data on the following legal bases:
- Contract performance — Processing is necessary to provide the Service you signed up for (Article 6(1)(b) GDPR).
- Consent — You explicitly consent to our terms and this policy when creating an account (Article 6(1)(a) GDPR).
- Legitimate interest — For security measures, fraud prevention, and service improvement (Article 6(1)(f) GDPR).
4. Third-Party Services
We use the following third-party services to operate SyncIn:
- Supabase — Authentication, database hosting, and serverless functions (EU region). Supabase acts as a data processor on our behalf.
- Unipile — Messaging platform integration. Unipile delivers webhook events for WhatsApp and LinkedIn messages to our servers.
- CRM Providers (e.g. HubSpot, Salesforce, Zoho, Pipedrive, Attio) — Your CRM. Messages are forwarded to your own CRM account using credentials you provide. SyncIn does not have independent access to your CRM data.
- Vercel — Website hosting and edge delivery.
We do not sell, rent, or share your personal data with any third party for their own marketing purposes.
5. Cookies
SyncIn uses only essential cookies required for authentication and session management. These cookies are set by Supabase Auth and are strictly necessary for the Service to function.
We do not use any tracking cookies, analytics cookies, advertising cookies, or third-party cookies. No cookie consent banner is required under the ePrivacy Directive because our cookies are exempt as strictly necessary.
6. Data Retention
We retain your data only for as long as necessary to provide the Service:
- Account data is retained until you delete your account.
- Message logs are retained for sync tracking and troubleshooting. They are deleted when you delete your account.
- Sync history is retained for your dashboard and deleted with your account.
When you delete your account, all associated data is permanently removed from our systems.
7. Your Rights Under GDPR
If you are in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of access — Request a copy of the personal data we hold about you.
- Right to rectification — Request correction of inaccurate data.
- Right to erasure — Request deletion of your data. You can delete your account at any time from your Settings page.
- Right to data portability — Request your data in a structured, machine-readable format.
- Right to restrict processing — Request that we limit how we use your data.
- Right to object — Object to processing based on legitimate interests.
- Right to withdraw consent — Withdraw consent at any time by deleting your account or contacting us.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Data Security
We implement appropriate technical and organisational measures to protect your data, including:
- Encryption in transit (TLS/HTTPS) and at rest
- Row Level Security (RLS) on all database tables
- Hashed passwords (never stored in plaintext)
- Access tokens encrypted at rest
- Webhook signature validation
- Security headers (X-Frame-Options, CSP, etc.)
9. International Data Transfers
Our primary infrastructure is hosted in the EU (Supabase EU-West region). Where data is processed outside the EEA by our sub-processors, appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
10. Children's Privacy
SyncIn is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, contact us at:
You also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.