01Scope and role
This policy governs personal data that Synthesis processes on behalf of a connected merchant. In that processing the merchant is the controller and Synthesis is the processor: we act on the merchant's instructions and for the purpose of producing analysis for that merchant.
Personal data relating to our own users, such as the account you sign in with, is covered by our Privacy Policy.
02What personal data we process
The categories we hold are defined in the Data Classification Policy. In summary, personal data is limited to customer and buyer email addresses, shipping city and postal code, and raw order payloads as returned by the connected platform.
We do not collect payment card numbers, bank details, government identifiers or end-consumer passwords.
03Purpose limitation
- Personal data is used only to produce analysis for the merchant it came from.
- It is never sold, rented, or used for advertising or targeting.
- It is never used to train a machine-learning model, by us or by any provider we use.
- It is never combined across merchants. Each merchant's data is isolated and access is checked per request.
04Data minimisation
We request the narrowest scope a connected platform offers that still answers the merchant's questions, and we prefer aggregate and derived tables over raw personal data wherever the analysis allows it. Where a platform returns a field we do not need, it is not carried into the derived tables that the product reads.
05Access
Access is role-based and enforced server-side on every request. Personnel access to production data is limited to named accounts, granted on the principle of least privilege, and removed when no longer required. Details are published in our Security overview.
06Sub-processors
We use a small number of sub-processors, including cloud infrastructure, error monitoring, and third-party model providers used to generate analysis. Model providers operate under confidentiality obligations and do not train on merchant data. The current list is maintained in our Privacy Policy.
Data is stored and processed in the United States.
07Individual rights requests
Where an individual exercises a right against a merchant, and the merchant asks us to act, we will assist with access, correction and deletion. We operate endpoints for this purpose and already service the equivalent requirements of the platforms we connect to.
Requests are actioned within 30 days unless the applicable law requires sooner.
08Retention and deletion
Merchant data is retained while the account is active and for as long as needed to provide the service. On termination, or on request, data is deleted within 30 days, except where retention is required by law.
Disconnecting a data source stops further collection. Data already collected is retained until deletion is requested or the account is terminated.
09Breach notification
Suspected or confirmed breaches are handled under the Security Incident Response Policy. Affected merchants are notified within 72 hours of confirmation, and platform partners within the window their agreement requires. We will assist a merchant in notifying their own customers where that is required of them.
10Review
This policy is reviewed at least annually, and whenever a new data source, sub-processor or model provider is introduced.