Synclify
PlatformCapabilitiesTeamsPricingDocs
Sign inGet started
PlatformCapabilitiesTeamsPricingDocsSign inGet started
Legal

Privacy Policy

This policy explains what Synclify collects when you visit this site or use the service, why we collect it, who we share it with, and what you can ask us to do with it.

Effective 29 July 2026 · Last updated 29 July 2026

1. Who this policy covers

Synclify is operated by [Legal entity name] ([Registered business address]). This policy applies to the synclify.cloud website, the Synclify application, and any support or sales correspondence with us. It does not apply to Airtable, Webflow, Google, Notion, or any other service you connect — those are governed by their own policies, and connecting them does not put us in control of how they handle your data.

2. Two different roles

The distinction below determines which rights apply to which data, so it is worth stating plainly.

  • For your account, we are the controller. Your name, email address, billing details, and how you use the product are data we decide the purposes for, and this policy governs them.
  • For the records you sync, we are a processor. The content in your Airtable bases and Webflow Collections is yours. We move it between the systems you connect, on your instructions, and for no other purpose. If that content contains personal information about other people, you are the controller of it and we act on your behalf.

3. What we collect

Account information

Your name, email address, password hash (we never store the password itself), organization name, and the roles of anyone you invite. This is collected when you register and when you manage your team.

Credentials for connected services

When you connect Airtable, Webflow, Google Sheets, or Notion, we receive an OAuth access token and, where the provider issues one, a refresh token. We store these encrypted and use them only to read and write the resources you have selected. We ask for the narrowest scope each provider offers for the work you have configured. You can revoke a token at any time from your Synclify account or from the provider directly.

Customer content

The records, fields, and assets that pass through a sync. We read this content at sync time and write it to the destination you configured. We do not build a warehouse of your source data, and we do not use it to train models or to develop features unrelated to delivering your sync.

Sync metadata

To make runs auditable and debuggable, we retain metadata about each run: timestamps, which connection ran, counts of created, updated, skipped, and failed rows, record identifiers, field names, conflict state, and any error returned by a provider. Error detail can include fragments of a record value where that value is what caused the failure — a malformed date or an over-length field, for example.

Billing information

Plan, billing period, invoices, and the country you are billed in. Card details are entered directly with our payment processor and never reach our servers; we receive only the last four digits, the card brand, and the result of the charge.

Website and product analytics

We use a self-hosted, cookie-free analytics service to count page views and referrers in aggregate. It does not set advertising identifiers, does not follow you across other sites, and does not build a profile of you. Inside the application we record which features are used, so we can tell which parts of the product are worth investing in.

Support correspondence

Emails and messages you send us, and any screenshots, logs, or configuration you choose to attach to them.

4. Why we use it

  • To run the service — authenticate you, execute syncs, and show you their results.
  • To meter your plan against the number of records you keep under sync.
  • To bill you, and to send invoices and receipts.
  • To notify you about things that affect your data: failed runs, expiring credentials, approaching plan limits, and security or availability incidents.
  • To answer support requests and investigate faults you report.
  • To detect, prevent, and investigate abuse, fraud, and security incidents.
  • To improve the product, using aggregate usage patterns rather than your content.
  • To meet our legal, tax, and accounting obligations.

We send product and marketing email only where you have opted in or where the law otherwise permits it, and every such message carries an unsubscribe link. Operational notices about your own account are not marketing and cannot be unsubscribed from while the account is open.

5. Legal bases

Where the UK GDPR or EU GDPR applies, we rely on the following bases: performance of a contract, for everything needed to deliver the service you signed up for; legitimate interests, for security, abuse prevention, and product improvement, balanced against your rights; consent, for optional marketing email, withdrawable at any time; and legal obligation, for tax, accounting, and lawful requests.

6. Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose it only to the following categories of recipient:

  • Infrastructure providers that host the application, the database, and backups.
  • A payment processor that handles cards, subscriptions, and invoices.
  • An email provider that delivers transactional and support mail.
  • Error and performance monitoring that records diagnostics when something breaks.
  • The services you connect — content moves to whichever destination you configured, which is the entire point of the product.
  • Professional advisers and authorities where we are legally required to disclose, or need to establish or defend legal claims.
  • An acquirer, if the business is sold or merged. We will tell you before your data becomes subject to a different policy.

Every provider we use is bound by a contract that limits them to processing on our instructions. The current list of subprocessors, with names and locations, is available on request from support@synclify.cloud.

7. International transfers

Our providers may process data outside your country, including outside the UK and the EEA. Where that happens we rely on an adequacy decision, or on Standard Contractual Clauses together with the technical measures described in section 9. You can request details of the mechanism used for a specific transfer.

8. How long we keep it

  • Account records — for as long as your account is open, then deleted or anonymized within 90 days of closure, except where tax and accounting law requires us to keep invoices longer.
  • OAuth tokens — until you disconnect the source or close the account, whichever is first. Deletion is immediate on disconnection.
  • Customer content — held only for the duration of a run. We do not keep a standing copy of your source data.
  • Sync metadata and logs — retained on a rolling window so you can audit recent runs, then purged.
  • Backups — encrypted, rotated, and overwritten on a fixed cycle; deleted data disappears from backups as that cycle completes.

9. How we protect it

Credentials and tokens are encrypted at rest with AES-256-GCM, and all traffic to and from the service uses TLS 1.3. Access to production systems is limited to the people who need it to operate the service, is authenticated individually, and is logged. Content is read at sync time and written straight to the destination rather than warehoused. No system is perfectly secure, and we do not claim otherwise — if a breach affects your personal information we will notify you and any relevant regulator within the deadlines the law sets.

10. Your rights

Depending on where you live, you may have the right to:

  • ask what personal information we hold about you, and get a copy;
  • have inaccurate information corrected;
  • have information deleted;
  • object to or restrict processing based on legitimate interests;
  • receive your data in a portable, machine-readable format;
  • withdraw consent you previously gave;
  • be free from discrimination for exercising any of these rights — we will not degrade the service or change your price because you did.

Write to support@synclify.cloudand we will respond within one month, or tell you why we need longer. We may ask you to verify your identity first. If you are unhappy with the outcome you can complain to your local data protection authority; in the UK that is the Information Commissioner's Office.

If your request concerns records that reached us through a customer's sync rather than your own account, we will refer you to that customer, who is the controller of it.

11. Cookies and local storage

The marketing site sets no advertising or tracking cookies, which is why you are not asked to dismiss a consent banner. Your light or dark theme preference is kept in your browser's local storage and never leaves your device. The application sets a single essential cookie to keep you signed in; without it, authentication cannot work.

12. Children

Synclify is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.

13. Changes to this policy

We update this policy as the product and the law change. The date at the top always reflects the current version. If a change materially affects your rights we will email account owners before it takes effect.

14. Contact us

Questions, requests, and complaints: support@synclify.cloud, or write to [Legal entity name], [Registered business address].

Synclify

Two-way CMS synchronization for teams that run Webflow as production infrastructure.

Product
PlatformCapabilitiesGetting startedPricing
Integrations
Google SheetsAirtableNotionWebflow CMS
Resources
DocumentationSecurityQuickstartFAQ
Company
ContactSign inPrivacyTerms
© 2026 Synclify. All rights reserved.Not affiliated with Webflow, Inc.