This Privacy Policy explains how Prydly LLC, doing business as SyncTIDY ("SyncTIDY," "we," "us," or "our"), collects, uses, discloses, stores, and protects personal information in connection with the SyncTIDY service, including its industry-specific products, websites, and subdomains (collectively, the "Service"). It also explains the choices and rights available to individuals whose personal information we process.
The Service is operated by Prydly LLC, a Washington limited liability company, doing business as SyncTIDY.
SyncTIDY acts as a controller when it determines why and how personal information is processed for account administration, service security, support, legal compliance, and its own business operations. When a business customer uses the Service to process email content and other personal information on the customer's instructions, the customer generally acts as controller and SyncTIDY acts as its processor or service provider. In that setting, the customer's privacy notice and any applicable data-processing agreement also govern the processing.
Our service providers, including the providers identified in Section 6, process personal information for us under their applicable contractual terms. Google remains responsible for its own processing in providing Gmail and Google account services to its users.
The personal information we collect depends on how the Service is configured and used. It may include:
gmail.readonly restricted scope. This scope permits the Service to read Gmail resources and metadata, including message content, headers, sender and recipient information, timestamps, labels, and attachments. The Service cannot use that scope to send, modify, label, or delete email.Email and attachments may contain sensitive personal information, such as the contents of communications, account credentials, financial information, health information, government identifiers, or information revealing protected characteristics. SyncTIDY does not require those categories for every use and processes them only as needed to provide the user-directed Service, protect the Service, or comply with law.
For individuals in the EEA or UK, our legal bases depend on the context. We process account and service information as necessary to perform a contract or take steps requested before entering one; to comply with legal obligations; and for legitimate interests in operating, securing, supporting, and improving the Service, where those interests are not overridden by individual rights. Where SyncTIDY acts as a processor, the customer is responsible for identifying the lawful basis and providing required notices. We rely on consent only where applicable law requires it, and consent may be withdrawn without affecting earlier lawful processing.
The Service uses automated tools to classify content and extract fields into records. It does not, as currently described, make decisions that produce legal or similarly significant effects about individuals. Users remain responsible for reviewing extracted records before relying on them.
SyncTIDY's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Those commitments apply to raw Google user data and to data aggregated, anonymized, or derived from it.
Before you connect Gmail, we display an in-product disclosure identifying the data requested, the purposes of access, and the service-provider processing described in Section 6, and you must take an affirmative action to authorize that access.
We disclose personal information only as described below and only to the extent reasonably necessary for the stated purpose.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising and do not disclose it to third parties for their independent marketing purposes.
SyncTIDY uses administrative, technical, and organizational safeguards designed to protect personal information against accidental or unlawful loss, alteration, access, use, or disclosure. These safeguards include: encryption of data in transit over public networks (TLS); encryption at rest for all database tables and database logs; an application-to-database connection over a local socket with no network exposure, with insecure transport refused by the database server; least-privilege database access controls, with application access restricted to narrowly scoped accounts; secrets maintained outside the code repository in access-restricted storage, enforced by automated pre-commit secret scanning; encryption-key backup held off-server; key-based, password-disabled administrative access to the hosting environment, with automated intrusion mitigation and system access logging; and routine, integrity-checked backups. No security measure is absolute, and we cannot guarantee that information will never be accessed, used, or disclosed without authorization.
If a personal-data breach occurs, we will provide notices to affected individuals, customers, regulators, or other parties when and as required by applicable law and our contractual obligations.
SyncTIDY is based in the United States, and the Service is hosted in Oregon. Personal information from the EEA, UK, Switzerland, and other jurisdictions may therefore be processed in the United States and in other countries where our service providers operate.
Where a restricted transfer requires a transfer mechanism, we use the applicable European Commission Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Addendum or International Data Transfer Agreement, unless an adequacy decision or another lawful mechanism applies. We may rely on the EU-U.S. Data Privacy Framework, its UK Extension, or the Swiss-U.S. Data Privacy Framework only for a recipient that is actively certified for the relevant framework and data. Prydly LLC does not claim certification under any Data Privacy Framework in this Policy. A copy of applicable transfer safeguards may be requested at support@synctidy.com, subject to appropriate redactions.
You may disconnect Gmail at any time through your Google Account permissions. Disconnecting stops future Gmail access by SyncTIDY. You may also ask us to access, correct, export, or delete personal information associated with your SyncTIDY account by contacting support@synctidy.com.
Subject to applicable law and exceptions, individuals in the EEA and UK may request access to, correction or deletion of, or restriction of processing of their personal information; object to processing based on legitimate interests; receive portable data; withdraw consent where processing relies on consent; and complain to the supervisory authority in the country where they live or work or where an alleged violation occurred. Where SyncTIDY processes personal information only on a customer's instructions, we may refer the request to that customer and assist it as required by contract and law.
Providing account and connected-email data is not generally required by statute, but it is necessary to provide the requested Service. Without it, the relevant features cannot operate.
This subsection applies if the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA"), applies to Prydly LLC and the relevant processing.
During the preceding 12 months, SyncTIDY may have collected the following CCPA categories: identifiers; customer-record information; commercial information; internet or other electronic-network activity; professional or employment-related information; inferences generated from connected content; and sensitive personal information, including account credentials and the contents of email and attachments. The exact categories depend on the account content selected by the user.
We collect those categories from users, connected Google accounts, individuals who communicate with connected accounts, service providers, and information generated through use of the Service. We use them for the purposes in Section 4. We may disclose those categories for business purposes to the service providers described in Section 6, with the category disclosed depending on the service performed.
Submit a California request to support@synctidy.com. We will verify the request using information reasonably necessary to match it to an account or record. An authorized agent must provide proof of authority, and we may verify the request directly with the consumer. We will respond within the time and in the manner required by applicable law.
Residents of certain U.S. states may have rights to access, correct, delete, or obtain a copy of personal information, or to opt out of sale, targeted advertising, or certain profiling. SyncTIDY does not sell personal information, use it for targeted advertising, or use it to make decisions producing legal or similarly significant effects. Where applicable law provides an appeal right, a denied request may be appealed by replying to our decision or emailing support@synctidy.com with the subject line "Privacy Appeal."
As of the effective date, the public SyncTIDY website pages do not set cookies. Before the Service enables session, authentication, analytics, advertising, or other browser-storage technologies, SyncTIDY will update this Policy or publish a separate cookie notice describing them and will obtain consent where required before enabling any non-essential technologies.
Because SyncTIDY does not sell personal information or use cross-site data for targeted advertising, it does not currently respond differently to browser "Do Not Track" signals. If practices change in a way that requires recognition of an opt-out preference signal, including Global Privacy Control, SyncTIDY will implement the required response before that change takes effect.
The Service is a business tool intended for adults and is not directed to children under 18. We do not knowingly collect personal information directly from a child through a child account. If you believe a child has provided personal information to us, contact support@synctidy.com.
We may update this Policy to reflect changes in the Service, our practices, or applicable requirements. We will post the updated Policy with a revised effective date. If a change materially affects how we use Google user data or other personal information, we will provide additional notice or obtain consent when required before the change applies.
Prydly LLC, d/b/a SyncTIDY
522 W Riverside Ave Ste N
Spokane, WA 99201
support@synctidy.com