Legal

Privacy Policy

Last updated: 3 August 2026

1. Who We Are

SyncBeacon (“we”, “us”, “our”) is a server-side conversion tracking platform operated from the European Union. We act as a Data Processor on behalf of our customers (merchants), who remain the Data Controller of their end-user storefront data.

For questions about this policy, contact us at hello@syncbeacon.cloud.

2. What Data We Collect

2.1 Merchant Account Data

When you register, we collect:

  • Email address (used for authentication and billing notifications)
  • Company name (optional)
  • Hashed password (we never store plain-text passwords)
  • Selected subscription plan

2.2 Storefront Event Data (Processed on Behalf of Merchants)

When your browser tracker or server-side webhook fires, SyncBeacon ingests:

  • Event type (Purchase, AddToCart, InitiateCheckout, PageView, etc.)
  • Order value, currency, and product identifiers (SKU)
  • Pseudonymous click identifiers (gclid, wbraid, gbraid, fbclid, ttclid, etc.)
  • SHA-256 hashed email and phone number - never plain-text PII
  • Consent signals from the end-user’s cookie banner (marketing consent source & status)

We do not use device fingerprinting or intentionally collect end-user names and postal addresses for tracking. Network metadata (such as IP address) may be processed transiently for secure request handling, anti-abuse, and delivery diagnostics.

2.3 Product Catalogue Data (Processed on Behalf of Merchants)

When you connect a storefront and enable product sync or ad-pause features, SyncBeacon may process:

  • Product name, SKU, and inventory level
  • Ad pause/resume state and configured ad entity IDs
  • Operational logs of ad-platform pause/resume API responses (success, failure, or skip status - not used for end-user profiling)

This data is used to run out-of-stock ad pause, surface product status in your dashboard, and diagnose integration issues. It does not include shopper names, emails, or postal addresses.

2.4 Payment Data

Payments are processed by Mollie B.V. (PCI DSS Level 1 certified). We never receive or store credit card numbers, IBAN details, or other payment instrument data. We only store your Mollie customer ID and subscription status.

2.5 Registration Funnel Analytics

While you use the SyncBeacon registration pages, we collect limited first-party analytics so we can see where sign-up is abandoned and improve the flow. This may include:

  • A random session identifier stored in localStorage (strictly necessary for this purpose)
  • Registration step progress (e.g. account details, privacy consent, email verification, billing)
  • Email address only after you provide a valid address and continue past the account step, or after verification / account creation
  • Approximate country (ISO country code from CDN headers or IP geolocation - no city, no raw IP stored), browser timezone, locale, referrer, and device/user-agent class
  • A one-way hash of your IP address (we do not store raw IPs for this purpose)

This data is used only for signup analytics and operational support. It is not used for marketing emails or advertising without a separate legal basis (consent). Funnel analytics rows are automatically deleted after 90 days.

2.6 Marketing Website Pageviews

On the public marketing website (syncbeacon.cloud), only after you accept analytics cookies, we may use a first-party pageview beacon so we can measure visits including in-app (SPA) navigations that do not create a full page load. With the same consent, blog pages may use a similar first-party engagement beacon (view / scroll depth). These beacons store only:

  • A random session identifier in localStorage (not shared with third parties)
  • The page path or blog slug visited (e.g. /pricing)
  • A timestamp

If you choose Reject, we do not write these session ids and do not send these client events. We do not store IP addresses or personal contact details with these events. Rows are deleted after 90 days. Separately, aggregated visit metrics may still be derived from server access logs (without storing individual IPs in our analytics database); that processing does not require the analytics cookie choice.

3. How We Use Your Data

  • To provide the SyncBeacon service - forwarding conversion events to your configured ad platforms
  • To display analytics dashboards within your SyncBeacon account
  • To manage your subscription, billing, and support requests
  • To send transactional emails (account verification, password reset, billing receipts)
  • To detect and prevent fraud or abuse of the platform
  • To monitor conversion event processing and forwarding (delivery status, errors, retries, and queue health) so we can keep the relay reliable, support you, and improve platform performance
  • To monitor synced product catalogue and ad-pause activity (inventory levels, pause/resume outcomes, and ad-platform API responses) to operate features such as out-of-stock ad pause, show status in your account, and diagnose integration problems
  • To analyse registration funnel drop-off (first-party signup analytics) and improve the onboarding experience
  • With your consent, to measure marketing-site pageviews and blog engagement via first-party analytics tags

Operational monitoring uses pseudonymous and business-operational data only. We do not use conversion or product monitoring to build advertising profiles of your customers, and we do not sell this telemetry to third parties.

We do not sell, rent, or share your data with third parties for their marketing purposes.

4. Legal Basis for Processing (GDPR Art. 6)

PurposeLegal Basis
Service deliveryContract performance (Art. 6(1)(b))
Billing & invoicingContract performance (Art. 6(1)(b))
Security & fraud preventionLegitimate interest (Art. 6(1)(f))
EU tax complianceLegal obligation (Art. 6(1)(c))
Conversion & product monitoring (reliability, troubleshooting, service improvement)Contract performance (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f))
Registration funnel analytics (signup drop-off)Legitimate interest (Art. 6(1)(f))
Marketing website pageview & blog engagement analytics (first-party client beacons)Consent (Art. 6(1)(a)); storage on your device also requires consent under TTDSG / ePrivacy
Marketing emails (future)Consent (Art. 6(1)(a))

5. Data Retention

Storefront event data is retained according to your subscription plan:

PlanRetention Period
Essentials7 days
Growth90 days
Enterprise1 year (365 days)

After the retention period, event data is automatically purged by a nightly background job.

Account data (email, company name, subscription records) is retained for the duration of your account and for up to 7 years thereafter for tax and legal compliance.

Registration funnel analytics (including optional email and technical metadata described in section 2.5) and consented marketing website pageview / blog engagement events (section 2.6) are retained for up to 90 days and then automatically purged.

6. Data Sharing & Sub-Processors

We share data only with the following categories of recipients, all bound by data processing agreements:

Sub-ProcessorPurposeLocation
Hetzner Online GmbHInfrastructure hostingGermany (EU)
Mollie B.V.Payment processingNetherlands (EU)
Ad platforms (Meta, Google, etc.)Conversion event forwarding (on merchant’s instruction)Global

7. International Transfers

Our servers are located in Germany (EU). Storefront event data may be transferred to ad platform servers outside the EEA when you configure an ad platform. These transfers are covered by the ad platforms’ own transfer mechanisms, including Standard Contractual Clauses (SCCs), where applicable.

8. Your Rights (GDPR Art. 15–22)

As a merchant account holder, you have the right to:

  • Access - request a copy of all data we hold about you
  • Rectification - correct inaccurate account information
  • Erasure - request deletion of your account and all associated data
  • Portability - receive your event data in a machine-readable format (JSON)
  • Restriction - request that we limit processing of your data
  • Objection - object to processing based on legitimate interest

You can exercise the first four rights from the GDPR Controls page in your dashboard, or email hello@syncbeacon.cloud.

9. Security Measures

  • All data in transit is encrypted via TLS
  • Passwords are stored using industry-standard hashing
  • Customer PII is SHA-256 hashed before storage where applicable
  • API access uses authenticated sessions with rotation controls
  • Webhook requests are verified and protected against replay abuse
  • Database backups are encrypted at rest

10. Cookies

The SyncBeacon dashboard ( app.syncbeacon.cloud) uses only strictly necessary cookies and localStorage items for authentication, UI preferences (theme), and a random registration-funnel session id on signup pages (first-party analytics described in section 2.5).

On the public marketing website (syncbeacon.cloud), only after you accept analytics, we may store a first-party pageview or blog session id in localStorage (section 2.6) and load Apollo (visitor identification for B2B sales analytics). If you choose Reject, those first-party analytics tags are not run and Apollo is not loaded. You can change this choice at any time via "Cookie preferences" in the site footer. Apollo is operated by Apollo.io; see their privacy documentation for how identified company/contact data is processed.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be notified by email at least 14 days before taking effect.

12. Contact & Supervisory Authority

Data Protection Contact: hello@syncbeacon.cloud

If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local supervisory authority (e.g., the BfDI in Germany).