Last updated: March 12, 2024
This Privacy Policy describes how OnSync, Inc. (a Wyoming corporation located at 30 N Gould St, STE R, Sheridan, WY 82801, USA) collects, uses, discloses, and protects information when providing our messaging automation platform and related services (“Services”). OnSync acts as a data controller for information we collect about you directly (for example, when you visit our website, create an account, or receive marketing communications) and as a data processor for the workspace data and WhatsApp content you upload to the Services on behalf of your organization. We process data worldwide but store and safeguard it in the United States using industry-standard security and cross-border transfer mechanisms.
Please review this notice carefully. If you do not agree with the practices described below, do not use the Services. Capitalized terms not defined here have the meaning supplied in our Terms of Service.
Name, business profile, role, email addresses, phone numbers, authentication credentials, support requests, survey responses, and preferences collected when you register, log in, or interact with us.
Customer contact lists, WhatsApp Business conversations, message templates, attachments, automation rules, and other information you and your teammates choose to import to the Services. Your organization controls this data and instructs our processing through the platform settings and agreements.
Device identifiers, browser type, IP address, log files, performance diagnostics, cookies, SDK data, and analytics about how you navigate the Services or marketing properties. See our Cookie Notice for additional details.
Subscription tier, order history, invoices, tax identifiers, and limited payment instrument data processed on our behalf by Stripe and other PCI-compliant providers.
We process data only when we have a lawful basis under applicable data-protection laws:
We do not sell personal information. We share it only with:
We apply administrative, technical, and physical safeguards designed to keep data secure, including least-privilege access controls, encryption in transit and at rest, vulnerability management, employee background checks and training, third-party monitoring, and redundant hosting environments within audited data centers. We regularly review our controls and will notify you of any breach as required by law and our agreements.
We retain personal information for as long as it is needed to deliver the Services, comply with legal obligations, resolve disputes, and enforce agreements. Typical retention periods include:
When you request deletion we remove or anonymize data from active systems and cycle encrypted backups within approximately 35 days. Submit a request through our Data Deletion Request page or email privacy@onsync.com. We may retain limited information when necessary for legal compliance, billing, or to honor opt-out preferences.
We primarily store data in the United States. When transferring personal information from the European Economic Area (EEA), United Kingdom, Switzerland, or other regions with data-transfer restrictions, we rely on Standard Contractual Clauses (and the UK Addendum where applicable), transfer impact assessments, and supplementary safeguards such as encryption and access controls. We maintain a list of subprocessors and provide a Data Processing Addendum (DPA) upon request by contacting privacy@onsync.com.
Depending on your location, you may have the right to access, correct, update, export, restrict, object to, or delete your personal information, and to withdraw consent or opt out of marketing. To exercise any right, submit a request via privacy@onsync.com. We verify identity before responding and will complete requests within the timelines set by law.
If you receive marketing emails, use the “unsubscribe” link or adjust preferences in your workspace profile. For cookies or tracking technologies, manage choices in your browser or through the banners and controls described in our cookie notice.
You may contact our Data Protection Officer at privacy@onsync.com and have the right to lodge a complaint with your local supervisory authority. When we act as a processor, please direct requests to your organization so we can support them under our DPA.
We honor applicable rights under the CCPA/CPRA, CPA, CTDPA, VCDPA, and similar statutes, including the right to know, correct, delete, and opt out of “selling” or “sharing” personal information and targeted advertising.
The Services are designed for business users and are not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child provided information to us, contact us so we can remove it.
We may update this Privacy Policy to reflect operational, legal, or regulatory changes. We will post the revised notice with an updated “last updated” date and notify you through email or in-product alerts when material changes occur.
Reach out with any privacy questions, complaints, or DPA requests: