Privacy Policy
Effective Date: October 12, 2025
Last Updated: September 6, 2026
1. Introduction
Synoro (“we,” “our,” or “us”) values your privacy. This Privacy Policy explains how we collect, use, store, and protect information when you use our platform and related services.
2. Information We Collect
We may collect the following types of data:
- Personal Information: Name, email address, phone number, and company details.
- Financial Data: Accounting records, bank information, and transaction details you connect to our platform.
- Usage Data: Log files, browser type, IP address, and device identifiers.
- Cookies & Analytics: To improve functionality and measure performance.
- Assistant connection records: When you authorize a third-party AI assistant (for example through MCP), we store the grant, chosen scopes, company restrictions, client identifier, and tool-invocation audit metadata. We do not persist live access tokens as reusable secrets.
3. How We Use Your Information
We use your data to:
- Provide and maintain our services.
- Improve AI-powered accuracy and automation.
- Communicate with you about your account or updates.
- Generate reports and insights requested by you.
- Fulfill tool requests from AI assistants you authorize, and keep an audit trail of those calls.
- Comply with legal and regulatory requirements.
4. Data Sharing
We do not sell or rent your personal information. We may share data only with:
- Service providers assisting in operations (e.g., hosting, analytics, or customer support).
- Compliance partners when legally required or when you authorize integrations (e.g., QuickBooks, Stripe, or banks).
- Third-party AI assistants and MCP clients you explicitly authorize (for example ChatGPT or Claude). Those providers receive the tool results your grant allows—company roster, accounting snapshots, workflow and document text you can already access, and similar operational data. Their use of that data is governed by their own privacy policies. You can revoke a grant in Synoro; revocation stops further access and does not by itself erase data the assistant already received or Synoro audit rows.
We do not give assistants a shared firm token or workspace-wide API key. Access is limited to the signed-in user, their membership, company visibility, and the scopes they granted. All partners we contract with are bound by confidentiality and data-protection agreements. Authorized assistants you choose are not Synoro subcontractors; you are authorizing a third-party connection.
5. Data Security
We use 256-bit encryption and role-based access controls to protect your data from unauthorized access, disclosure, or misuse.
6. Data Retention
We retain your data only as long as necessary to provide services or meet legal obligations. You can request deletion of your data anytime by contacting support@synoro.com.
7. Your Rights
Depending on your location, you may have the right to:
- Access, correct, or delete your data.
- Withdraw consent for data processing.
- Request a copy of your stored information.
8. Cookies
We use cookies to enable site functionality and analytics. You can manage or disable cookies in your browser settings.
9. Children's Privacy
Our Services are intended for business users aged 18 and older. We do not knowingly collect data from minors.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last Updated” date reflects the latest version. Continued use of our Services indicates acceptance of any updates.
11. Contact
If you have questions about this policy or your data rights, please contact us at: privacy@synoro.com