Legal

Privacy Policy

Last updated: 28 July 2026

1. Who we are

Sync is a product of Sync Suite Limited, a company incorporated in Kenya ("Sync", "we", "us"). You can reach our privacy team at privacy@sync.ke. This policy explains how we handle personal data in line with Kenya's Data Protection Act, 2019 (the "DPA") and, where it applies to you, the EU and UK General Data Protection Regulation ("GDPR").

2. Scope

This policy applies to sync.ke, the Sync web application, and any related communications from us (email, SMS, support conversations). It does not cover third-party websites you reach from Sync.

3. What we collect

  • Account data you provide at sign-up: full name, email address, phone number, company name, and a hashed password.
  • Business data you enter to run your books: customers and suppliers, invoices, payments, transactions, documents, and files you upload. We keep this only to operate the service for you.
  • Technical data: IP address, browser and device information, pages viewed, and referrer — collected through analytics only after you accept the cookie banner.
  • Payment data: handled by our payment processor. We store your subscription status and a reference to the transaction — not full card details.

4. How we use it

  • Provide, secure, and support the Sync service.
  • Authenticate you and keep each company's records isolated.
  • Deliver invoices, receipts, and other transactional messages.
  • Meet Kenyan tax and accounting obligations (for example eTIMS submission).
  • Improve the product through opt-in analytics.
  • Detect and prevent fraud, abuse, and security incidents.

5. Lawful grounds

Under section 30 of the DPA and Article 6 of the GDPR, we rely on: performance of our contract with you (to run the service you signed up for); our legitimate interests (security, service improvement, direct communication with customers); your consent (for analytics and marketing, which you can withdraw at any time); and compliance with legal obligations (tax, accounting, and lawful requests from authorities).

6. Analytics and cookies

We use PostHog for privacy-friendly product analytics. PostHog does not load until you accept the consent banner. Before you sign in you are anonymous; after sign-in your analytics events are linked to your account so we can support you. You can withdraw consent at any time by clearing site data in your browser or emailing us.

7. Subprocessors

We share data with the following processors, strictly to run the service:

  • Lovable Cloud — application hosting.
  • Supabase — database, authentication, and file storage.
  • PostHog — product analytics (only after consent).
  • Paystack — subscription payments.
  • Kenya Revenue Authority (eTIMS) — statutory invoice transmission.
  • Safaricom (M-Pesa) — payment reconciliation for Paybill and Till accounts.
  • Email delivery provider — transactional and account emails.

8. Where your data is stored

Sync is operated from Kenya. Our infrastructure and subprocessors may store or process personal data in the United States and the European Union. For users in Kenya, this constitutes a cross-border transfer under Part VI of the DPA; we rely on adequacy, appropriate safeguards, or your consent as applicable. For users in the EU/UK, we rely on Standard Contractual Clauses with our processors.

9. How long we keep it

  • Visitor analytics: retained for 48 months from the date of collection.
  • Account and business data: retained for the life of your account. If you delete your account, we delete or anonymize your personal data within 30 days — except records we are legally required to retain, such as invoices under the Tax Procedures Act (typically five years).

10. Your rights

Under the DPA and the GDPR, you have the right to access your data, correct it, have it erased, restrict or object to processing, port it to another service, and withdraw consent at any time. To exercise any of these rights, email privacy@sync.ke. You may also lodge a complaint with the Office of the Data Protection Commissioner in Kenya, or with your local supervisory authority in the EU/UK.

11. Security

We encrypt data in transit, scope database access with row-level security, enforce role-based permissions, and keep audit logs of sensitive actions. No online service can be 100% secure, but we work to protect your data and will notify affected users and the Data Commissioner of any qualifying breach as required by law.

12. Children

Sync is not directed to individuals under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

13. Changes to this policy

We will post any changes to this page and update the "Last updated" date above. For material changes we will also notify signed-in users by email or in-app.

14. Contact

Sync Suite Limited · Nairobi, Kenya · privacy@sync.ke