Privacy Policy
Last updated: July 2026
1. Introduction
SyncBridge is a product of Techmarcos. This policy explains how we collect, use, store, and protect information when you use our platform and our HubSpot integration.
2. Information We Collect
- Account info: name, email, and organisation name retrieved from the HubSpot Owners API on marketplace install.
- Platform credentials: OAuth tokens and API keys — encrypted AES-256 at rest, never logged or exposed via API.
- Synced business data: contacts, companies, deals, jobs, and invoices — processed in transit, with sync logs stored for troubleshooting.
- Usage data: sync run history, error logs, and audit trail.
3. How We Use Your Information
We use your information to authenticate your identity, connect to platforms, execute sync jobs, provide monitoring, send notifications, and maintain audit logs. We do not use your data for advertising or sell it to third parties.
4. Data Storage and Security
- AES-256 encryption at rest for all credentials.
- HTTPS/TLS for all external API communication.
- MySQL 8.0 with application-layer access control.
- Role-based access control with three tiers: editor, org admin, and super admin.
- Rate limiting and security headers (Helmet, CSP, HSTS).
5. HubSpot Integration — Scopes Accessed
crm.objects.contacts.read/write— sync contactscrm.objects.companies.read/write— sync companiescrm.objects.deals.read/write— sync dealscrm.schemas.custom.read/write— custom object discoverysettings.users.read— portal owner identification at installoauth— token management
6. Data Sharing
We do not sell or share your data. Data is shared only with the connected platforms you explicitly authorise, when required by law, or with infrastructure providers under confidentiality agreements.
7. Data Retention
- Account data is retained while your account is active.
- Sync logs are retained for 90 days.
- OAuth tokens are deleted on disconnect or uninstall.
- Audit logs are retained for 12 months.
8. Uninstall
When you uninstall SyncBridge from HubSpot, your OAuth tokens are immediately revoked and deleted, and all sync jobs are paused. Account data and anonymised logs are retained until you request deletion at privacy@techmarcos.com.
9. Your Rights
You have the right to access, correct, delete, export, or object to the processing of your personal data. To exercise any of these rights, contact privacy@techmarcos.com.
10. Cookies
We use localStorage to store JWT tokens for session management only. We do not use tracking, analytics, or advertising cookies.
11. Contact
For privacy enquiries: privacy@techmarcos.com or visit syncbridge.techmarcos.com/support.