SyncStation processes the information needed to operate your account and execute the sync rules you configure. HubSpot property values are normally handled only transiently while a sync runs, although limited values can appear in diagnostic or error logs as described below.
We do not sell Customer Data, use Customer Data for advertising, or use Customer Data to train machine learning models. Website analytics and advertising technologies are separate from Customer Data and are governed by your privacy choices and applicable law.
Who we are
SyncStation is a product of Cybersolve (Pty) Ltd, registration number 2020/274090/07, a company registered in South Africa ("Cybersolve", "SyncStation", "we", "us"). Our registered address is 36 Glenluce Drive, Douglasdale, 2191, South Africa.
For personal data that we collect for our own business purposes, such as account, website, support and service-administration data, Cybersolve is the controller under the EU and UK GDPR and the responsible party under South Africa's POPIA.
Our privacy contact is Cherine Grove at privacy@syncstation.app. This policy describes our privacy practices globally. Where an applicable law gives you additional rights or imposes additional requirements on us, we will apply those rights and requirements to the extent that law applies. Nothing in this policy limits a right that cannot lawfully be limited.
Scope and our privacy roles
This policy covers the syncstation.app website, the SyncStation portal, the SyncStation application listed on the HubSpot Marketplace, customer support, account communications and our handling of information connected with subscriptions and purchases.
When a Customer uses SyncStation to process personal data held in its HubSpot portal, the Customer determines why that data exists and which Sync Rules apply. For that Customer Data, the Customer is the controller or responsible party and SyncStation acts as its processor or operator. The Data Processing Agreement in Schedule 1 of our Terms and Conditions governs that processing.
This policy does not replace HubSpot's privacy terms or the privacy notices of other third-party services. When you connect HubSpot, HubSpot remains the CRM platform selected by your organisation and its own terms continue to apply to the data held there.
How we process Customer Data
To execute a Sync Rule, SyncStation reads the mapped property value from the Customer's HubSpot portal, holds it in memory for the duration of the operation and writes it to the target HubSpot object. SyncStation is not the system of record for those values and does not ordinarily create a persistent copy of them.
Limited diagnostic retention. Operational and diagnostic logs can contain property values and may be retained for up to 90 days. HubSpot error responses can also quote a rejected value; where that happens, the value can appear in the error message stored in the portal's sync error log.
AI diagnostics. Sync error messages can be sent to Anthropic's API to generate support or diagnostic responses. If HubSpot has included a rejected field value in an error message, that value can therefore be included in the prompt sent to Anthropic.
No secondary use. We do not sell or licence Customer Data, use it for advertising, or use it to train machine learning models. Customer Data is processed only to provide, secure, troubleshoot and support the Service in accordance with the Customer's instructions and our Terms.
SyncStation does not inspect CRM content in order to classify its sensitivity. Customers are responsible for ensuring that the data and properties they choose to sync may lawfully be processed using the Service, including where a property contains sensitive or specially protected information.
Personal data we process
Why we process personal data
Your HubSpot connection
When you install SyncStation, HubSpot asks you to approve the scopes required by the Service. We use HubSpot's APIs to read and update the objects and properties needed by the Sync Rules you configure, including standard and custom objects.
OAuth credentials are used only to make authorised API calls. You can revoke the connection at any time from HubSpot's connected-app settings or through available SyncStation account controls. Revoking the connection stops further syncing.
Your organisation remains responsible for the HubSpot portal and the reasons for which the CRM data in it is collected and used. SyncStation does not acquire ownership of Customer Data.
Service providers and other third parties
We use a limited number of providers to operate SyncStation. Their role depends on the service they provide. Providers that process Customer Data on our behalf are governed by the Data Processing Agreement in our Terms.
Payments. Paddle acts as our merchant of record. A buyer completes the transaction with Paddle, which independently collects and processes payment, billing, tax and fraud-prevention information under Paddle's own terms and privacy notice. SyncStation receives the subscription and transaction information needed to provision and administer the Service, but not the buyer's full card details.
Engineering tools. Our GitHub repository is private and is used for source control and deployment integration. Production Customer Data is not intentionally stored in source control and GitHub is not treated as a Customer Data sub-processor on that basis.
We will update this policy or a linked sub-processor list if we add a provider that processes Customer Data. The advance-notice and objection process for new sub-processors is described in our Data Processing Agreement.
International transfers
Cybersolve operates from South Africa. Our application and database are hosted on Railway infrastructure; HubSpot processes data in the United States and the European Union; and Anthropic, Resend and Paddle are established in the United States or process data there. As a result, personal data can be processed outside the country in which you or a Customer's data subjects are located, and the destination for each provider is identified in section 7.
Where applicable law requires a transfer safeguard, we use an appropriate lawful mechanism. Depending on the transfer, this may include an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, a recognised data-privacy framework, contractual protections under POPIA section 72, or another mechanism recognised by applicable law.
How long we keep data
Data may remain for a limited period in backups, security logs or systems that cannot reasonably be selectively purged. Such data remains protected, is not used for unrelated purposes and is deleted or overwritten through the applicable retention cycle. Third-party providers can also retain information for periods required by their own legal obligations or service terms.
Security
SyncStation is hosted on Railway using managed application and PostgreSQL infrastructure. We use transport encryption, restricted production access, role-appropriate access controls and other technical and organisational measures appropriate to the nature of the Service.
Passwords are stored as salted one-way hashes rather than readable passwords. Authentication relies on secure session/token mechanisms, and HubSpot OAuth credentials are protected and used only for authorised API operations. Our source repository is private and production Customer Data is not intentionally committed to source control.
No online service can guarantee absolute security. We maintain processes to identify, assess and respond to incidents. Where a personal-data breach occurs, we notify affected Customers, individuals and regulatory authorities where and within the timeframes required by applicable law and our contractual obligations.
Your privacy rights
Your rights depend on where you are located, the law that applies and whether SyncStation is acting as controller/responsible party or as processor/operator. Subject to those conditions, rights can include access, correction, deletion, restriction, portability, objection, withdrawal of consent and the right to complain to a regulator.
If we refuse a request. We will tell you why. You may ask us to reconsider by replying to the same address with the word "appeal"; a different person from the one who took the original decision will review it and respond in writing within thirty days. That is in addition to your right to complain to a regulator, which you may exercise at any time. Exercising any right will never lead us to degrade the Service, change your price or treat you differently. You may also appoint an authorised agent to act for you; we will ask them for written authority and may still verify your own identity.
To exercise a right or make a privacy complaint, write to privacy@syncstation.app. We may need to verify your identity and will respond within the period required by applicable law — one month where the EU or UK GDPR applies, forty-five days (extendable once by a further forty-five) under most US state laws, and fifteen days to confirm processing under Brazil's LGPD. If a request concerns Customer Data in a Customer's HubSpot portal, the Customer is ordinarily the controller/responsible party and should be contacted first; we will assist the Customer as required by our DPA.
You can unsubscribe from marketing emails at any time using the unsubscribe mechanism provided or by contacting us. You can also change website analytics and advertising choices using the cookie/privacy controls available on the site.
Cookies, analytics and advertising
The portal uses strictly necessary cookies or similar technologies for authentication, session management and security. These technologies are required for the portal to function.
The public website uses Google Tag Manager and Google Analytics, and can use the Meta Pixel, LinkedIn Insight Tag, G2 tracking and Reddit advertising technology for analytics, campaign attribution, conversion measurement, audience building and advertising. Depending on the provider and your choices, these technologies can receive device and browser information, IP-derived information, page URLs, referral information, cookie or advertising identifiers and interaction or conversion events.
We use website privacy controls to apply your choices and the requirements that apply in your region. You can review or change those choices through the cookie/privacy controls available on the site. Where consent is required, optional technologies are used only in accordance with that consent.
Where a US state privacy law gives you the right to opt out of the sale or sharing of personal information, or of targeted advertising, you may exercise that right through the cookie and privacy controls on the site or by writing to privacy@syncstation.app.
US privacy terminology. We do not sell Customer Data or account data for money. However, disclosing website identifiers or activity to advertising partners can be treated as a "sale", "sharing" or "targeted advertising" under some US state privacy laws even where no money changes hands. Where such a law applies, you may use our privacy controls to exercise the applicable opt-out right.
AI and automated processing
Claude, provided through Anthropic's API, powers the customer-facing support chatbot and an internal admin diagnostics chatbot. We send only the information needed for the relevant support or diagnostic request, but messages and error context may contain personal data as described in sections 3 and 4.
We use Anthropic's commercial API service under a written agreement, and neither SyncStation nor Anthropic uses this content to train machine learning models. Anthropic retains API inputs and outputs only for the limited period set out in its then-current commercial terms, after which they are deleted, subject to the exceptions those terms describe. Because that period is set by Anthropic rather than by us, we do not restate it here; we hold a copy of the applicable terms and will provide the current position on request.
SyncStation does not use automated processing to make decisions about individuals that produce legal or similarly significant effects. Automated monitoring may detect sync failures, trigger retries or assist with technical diagnostics, but it does not make employment, credit, eligibility or similar decisions about individuals.
Children
SyncStation is a business service and is not directed to children. We do not knowingly invite children to create SyncStation accounts. If you believe a child has provided personal data to us directly, contact privacy@syncstation.app so that we can investigate and take appropriate action.
Changes to this policy
We update this policy when our processing, providers or legal obligations materially change. The version number and date at the top of the page identify the current version. Where a change materially affects how we handle personal data, we will provide notice through an appropriate channel, such as email, the portal or the website, before the change takes effect where required.
Contact us
privacy@syncstation.app
Douglasdale, 2191
South Africa