Privacy

Personal Data Protection Policy

How personal data processed on behalf of a connected merchant is limited, isolated, accessed and deleted.

Synthesis Intelligence, Inc. · Last updated August 24, 2026

01Scope and role

This policy governs personal data that Synthesis processes on behalf of a connected merchant. In that processing the merchant is the controller and Synthesis is the processor: we act on the merchant's instructions and for the purpose of producing analysis for that merchant.

Personal data relating to our own users, such as the account you sign in with, is covered by our Privacy Policy.

02What personal data we process

The categories we hold are defined in the Data Classification Policy. In summary, personal data is limited to customer and buyer email addresses, shipping city and postal code, and raw order payloads as returned by the connected platform.

We do not collect payment card numbers, bank details, government identifiers or end-consumer passwords.

03Purpose limitation

04Data minimisation

We request the narrowest scope a connected platform offers that still answers the merchant's questions, and we prefer aggregate and derived tables over raw personal data wherever the analysis allows it. Where a platform returns a field we do not need, it is not carried into the derived tables that the product reads.

05Access

Access is role-based and enforced server-side on every request. Personnel access to production data is limited to named accounts, granted on the principle of least privilege, and removed when no longer required. Details are published in our Security overview.

06Sub-processors

We use a small number of sub-processors, including cloud infrastructure, error monitoring, and third-party model providers used to generate analysis. Model providers operate under confidentiality obligations and do not train on merchant data. The current list is maintained in our Privacy Policy.

Data is stored and processed in the United States.

07Individual rights requests

Where an individual exercises a right against a merchant, and the merchant asks us to act, we will assist with access, correction and deletion. We operate endpoints for this purpose and already service the equivalent requirements of the platforms we connect to.

Requests are actioned within 30 days unless the applicable law requires sooner.

08Retention and deletion

Merchant data is retained while the account is active and for as long as needed to provide the service. On termination, or on request, data is deleted within 30 days, except where retention is required by law.

Disconnecting a data source stops further collection. Data already collected is retained until deletion is requested or the account is terminated.

09Breach notification

Suspected or confirmed breaches are handled under the Security Incident Response Policy. Affected merchants are notified within 72 hours of confirmation, and platform partners within the window their agreement requires. We will assist a merchant in notifying their own customers where that is required of them.

10Review

This policy is reviewed at least annually, and whenever a new data source, sub-processor or model provider is introduced.