Privacy Policy

Last updated: July 6, 2026

Overview

Synton AI, Inc. ("Synton", "we", "us") provides an AI commerce operating system: the dashboard at app.synton.ai, apps and plugins for Shopify, WooCommerce, and Magento, hosted storefronts, mobile and desktop apps, and the marketing site at synton.ai. This policy explains what personal data we handle, why, and what rights you have.

Synton acts in two distinct roles:

  • As a controller for data about merchants and their team members (your account, billing, product usage) and about visitors to synton.ai.
  • As a processor for personal data about merchants' own customers and end users ("End Customer Data") — shoppers on a merchant's store, subscribers to a merchant's emails, participants in a merchant's meetings. We process this data on the merchant's instructions under our Data Processing Agreement.

If you are a shopper or customer of a store powered by Synton, the merchant who runs that store is the controller of your data. Please direct privacy requests to that merchant; we assist merchants in fulfilling them.

Data We Collect

Merchant account data (we are the controller)

  • Name, email address, company details, and login credentials of you and team members you invite
  • Billing information and transaction history (payment card details are handled by Stripe or Shopify, not stored by us)
  • Support conversations, feedback, and communications with us
  • Product usage data: features used, credit consumption, agent runs, and audit logs of actions taken in your account
  • Technical data: IP address, browser and device information, error logs

Store data (processed to run your account)

When you connect a store, we access data through your platform's API to provide the Service: products, orders, customers, inventory, discounts, content, and analytics. This includes End Customer Data (for example customer names, emails, and order history), which we process as your processor.

AI interaction data

  • Chat conversations, commands, and files you submit to the AI assistant
  • Agent configurations, autonomy settings, approvals, and action outcomes
  • AI memory you choose to save for personalization

Behavioral analytics (merchant-enabled, processor role)

If you enable behavioral analytics on your store, we collect visitor interaction events, session recordings, and heatmap data on your behalf. Recordings mask payment fields by default. You are responsible for disclosing this collection to your visitors in your own privacy notice and, where required, obtaining consent (for example under the ePrivacy rules).

Meetings and voice (merchant-enabled, processor role)

If you use video meetings, call recording, transcription, or AI interviews, we process audio, video, and transcripts on your behalf. Meetings and transcription run on our own self-hosted infrastructure in the EU. You are responsible for participant notice and consent.

Advertising and connected accounts

If you connect ad accounts (Meta, Google, TikTok), marketplaces (Amazon), or tools (Slack, Notion, Google Workspace, Plaid), we access the data those integrations provide — campaign structures and performance, channel messages routed to Synton, synced documents — to deliver the features you use them with.

Prospecting data (merchant-enabled)

If you use our customer-acquisition tools, we obtain business contact data (names, roles, business emails) from third-party data providers and verify deliverability. You are the controller for outreach you run with this data; we maintain suppression lists and honor opt-outs platform-wide.

How We Use Data

  • Provide, operate, and secure the Service, including running AI agents you configure
  • Process billing, meter credit usage, and prevent fraud and abuse
  • Provide support and send service communications
  • Improve the Service, including computing aggregated, de-identified patterns and benchmarks across the platform — these never expose your confidential data or your customers’ personal data to other merchants
  • Comply with legal obligations and enforce our terms

AI model training: we do not use your data to train our own or third-party foundation models, and our AI providers are contractually restricted from training on data we send them.

We do not sell personal data and we do not share it for cross-context behavioral advertising.

Who We Share Data With

We share data only with service providers (sub-processors) that help us run the platform, with services you choose to connect, and where required by law. The current list of sub-processors, their purposes, and locations is maintained at synton.ai/subprocessors. Categories include:

  • Infrastructure: hosting (primary infrastructure in the EU), CDN and edge security, object storage, email delivery
  • AI providers: large language, vision, image, and speech models used to power features — sent only the context needed for the request, with no-training commitments
  • Payments: Stripe and the Shopify Billing API
  • Connected services you enable: when you connect Shopify, WooCommerce, Magento, ad platforms, Amazon, Slack, Notion, Google, or Plaid, data flows to and from them at your direction under their own terms
  • Legal: when required by law, court order, or to protect rights, safety, or the integrity of the platform

International Transfers

Our primary application infrastructure and databases are hosted in the European Union (Germany). Some sub-processors (for example AI providers and payment processors) process data in the United States or elsewhere. Where personal data subject to GDPR/UK GDPR is transferred internationally, we rely on the EU Standard Contractual Clauses, the UK Addendum, and equivalent safeguards, as detailed in our DPA.

Security

  • Encryption: TLS 1.2+ in transit; sensitive data (tokens, stored credentials) encrypted at rest
  • Authentication: OAuth 2.0 for platform connections — we never see your platform passwords; signed, single-use magic links; role-based access control for teams
  • Integrity: webhooks verified with cryptographic signatures; administrative and agent actions recorded with explicit anchor status; only verified anchors are described as tamper-evident
  • Isolation: merchant-supplied code and automations run in permission-capped sandboxes; hosted storefronts are served from isolated runtimes
  • Operations: least-privilege access for staff, security reviews, and continuous monitoring

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you without undue delay, consistent with applicable law and the DPA.

Data Retention

Data typeRetention
Account and authentication dataLife of the account; deleted on account deletion
Store and End Customer DataWhile your store is connected; deletion begins on uninstall/disconnect (shop data erased within 48 hours, residual analytics within 30 days)
AI chat conversations90 days by default (configurable)
AI memoryPer your settings
Session recordings and heatmapsPer your configured retention window
Meeting recordings and transcriptsUntil you delete them or your account closes
Audit logs of account and agent actionsLife of the account (integrity records)
Billing records7 years (legal requirement)
BackupsRolling windows; deleted data ages out of backups automatically

Platform Compliance (Shopify and Others)

We honor each platform's mandatory privacy webhooks and data requirements. For Shopify:

  • customers/data_request: we compile the customer's data for you to fulfill the request
  • customers/redact: we delete the customer's data within 30 days
  • shop/redact: we erase shop data within 48 hours of receiving the webhook after uninstall

Your Rights

Depending on your location (including under GDPR, UK GDPR, and CCPA/CPRA), you may have the right to access, correct, delete, export, restrict, or object to the processing of your personal data, to withdraw consent, and to not be discriminated against for exercising these rights. To exercise them, email privacy@synton.ai. We respond within 30 days (45 for CCPA, extendable as permitted). You may also lodge a complaint with your local supervisory authority.

End customers: if your data was processed because you interacted with a merchant's store, contact that merchant; we will assist them in fulfilling your request.

Lawful bases (GDPR)

  • Contract: operating your account and the features you use
  • Legitimate interests: securing the platform, preventing abuse, improving the Service
  • Consent: marketing communications and optional features that request it
  • Legal obligation: tax, accounting, and compliance records

Cookies

Our use of cookies and similar technologies — on synton.ai, in the dashboard, and via merchant-enabled analytics on hosted storefronts — is described in our Cookie Policy. We do not use third-party advertising cookies.

Children

The Service is a business tool and not directed at children. We do not knowingly collect personal data from children under 16. If you believe we have, contact privacy@synton.ai and we will delete it.

Changes to This Policy

We may update this policy periodically. For material changes we will post notice in the product and update the date above; where required, we will notify you by email or seek renewed consent. The current version always lives at synton.ai/privacy.

Contact

Privacy requests and DPO: privacy@synton.ai

Legal: legal@synton.ai

General support: contact@synton.ai

Synton AI, Inc., a Delaware corporation. Merchants requiring a signed Data Processing Agreement can use our standard DPA or contact legal@synton.ai.