Privacy Policy
Last updated: March 22, 2026
Effective date: March 22, 2026
Contents
1. Who We Are
Synquic is a technology company that builds the Slide platform an enterprise omnichannel automation tool. Synquic operates as the data controller for the personal data processed through Slide.
For any privacy-related enquiries, you can reach us at: privacy@synquic.com
2. Information We Collect
We collect the following categories of information:
When you sign in via Google or Microsoft OAuth (powered by Firebase Authentication), we receive and store:
- Full name (first and last name)
- Email address
- Profile photo URL (if provided by your identity provider)
- Unique identifier from your identity provider (UID)
- Sign-in method (Google or Microsoft)
We do not receive or store your Google/Microsoft passwords. Authentication is handled entirely by Firebase Authentication (Google LLC).
- Organization name and settings
- Your role and permissions within the organization
- Invitation records (email addresses of people you invite)
- Organization-level configuration and disabled modules
When you build and run automation flows, we may process:
- Flow configurations and trigger conditions
- Message templates and chatbot scripts
- Contact lists and audience segments you upload
- Execution logs and error reports
- Instagram and WhatsApp message content (where required for flow processing)
Message content from Instagram and WhatsApp is processed transiently to execute automation flows. We do not read, sell, or use this content for advertising purposes.
- Browser type, device type, and operating system
- IP address and approximate location
- Pages visited, features used, and time spent
- API request logs and error records
- Session tokens and authentication state
3. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the platform: To authenticate you, maintain your session, display your organization's data, and operate automation flows.
- Processing automations: To execute Instagram and WhatsApp flows, trigger pipeline stage transitions, and send templated messages on your behalf.
- Account management: To process invitations, manage roles and permissions, and enforce organization-level settings.
- Security and fraud prevention: To detect unauthorized access, enforce rate limits, and protect the integrity of the platform.
- Platform improvement: To analyse usage patterns (in aggregate, non-personally-identifiable form) to improve features and performance.
- Communications: To send transactional emails (e.g., invitation emails, system alerts). We do not send unsolicited marketing emails.
- Legal compliance: To comply with applicable laws, respond to lawful requests, and enforce our Terms of Service.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
4. Third-Party Services and APIs
Slide integrates with the following third-party services. Each service has its own privacy policy that governs their data practices:
Firebase Authentication (Google LLC)
Google Privacy Policy ↗Purpose: User authentication via Google and Microsoft OAuth.
Firebase receives your sign-in credentials and issues authentication tokens. We do not receive or store passwords.
Meta Platforms Instagram Business API
Meta Privacy Policy ↗Purpose: Automating Instagram DMs, comments, and story interactions.
We access your Instagram Business Account via Meta's official API under your authorization. Message content is processed only to execute your configured automations. We comply with the Instagram Platform Policy and Meta Platform Terms.
Meta Platforms WhatsApp Business API
WhatsApp Privacy Policy ↗Purpose: Sending and receiving WhatsApp messages through automation flows.
We use the official WhatsApp Business API. All message templates must be approved by Meta. End-user data (phone numbers, conversation content) is processed solely for delivering your automations. We do not access this data for any other purpose.
Infrastructure Providers
Purpose: Hosting, database, and compute services.
Your data is stored on secure, enterprise-grade cloud infrastructure. Providers operate under strict data processing agreements (DPAs) with Synquic.
5. Data Storage and Security
All data is stored on cloud infrastructure with industry-standard security practices:
- Encryption in transit: All communication between your browser and our servers uses TLS 1.2+.
- Encryption at rest: Database records and file storage are encrypted at rest.
- Access control: Access to production data is restricted to authorized Synquic personnel only, with audit logging.
- Authentication tokens: We use short-lived JWT tokens with rotation. Refresh tokens are stored securely.
- No plaintext credentials: We never store passwords. Authentication is delegated to Firebase/Google.
While we implement robust security measures, no system is 100% immune to breaches. In the event of a data breach affecting your personal data, we will notify affected users in accordance with applicable law (typically within 72 hours for GDPR-regulated incidents).
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the service:
- Account data: Retained as long as your account exists. Deleted within 30 days of account deletion request.
- Automation flow data: Retained for the duration of your subscription plus 90 days for recovery purposes.
- Message processing logs: Retained for up to 12 months for debugging and compliance purposes.
- Billing records: Retained for 7 years as required by financial regulations.
- System logs: Retained for 90 days, then automatically purged.
You may request deletion of your personal data at any time by emailing privacy@synquic.com. We will process deletion requests within 30 days, subject to legal retention requirements.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Right to access
Request a copy of your personal data we hold.
Right to rectification
Request correction of inaccurate or incomplete data.
Right to erasure
Request deletion of your personal data ("right to be forgotten").
Right to portability
Receive your data in a structured, machine-readable format.
Right to restrict processing
Request we limit how we use your data in certain circumstances.
Right to object
Object to processing based on legitimate interests or for direct marketing.
Right to withdraw consent
Withdraw consent at any time where processing is consent-based.
Right to complain
Lodge a complaint with your local data protection authority (e.g., ICO in the UK, CNIL in France).
To exercise any of these rights, email privacy@synquic.com. We will respond within 30 days. We may ask you to verify your identity before processing requests.
8. Cookies and Tracking
Slide uses the following types of cookies and local storage:
- Authentication cookies: Strictly necessary. Used to maintain your signed-in session via Firebase. Cannot be disabled while using the platform.
- Preference storage: Stores your UI preferences (e.g., selected organization) in browser local storage. No personal data leaves your browser.
- Analytics (if enabled): We may use privacy-preserving analytics to understand platform usage. No personally identifiable information is used for analytics.
We do not use third-party advertising cookies or sell cookie data to data brokers.
9. Children's Privacy
Slide is an enterprise platform intended for business use by adults aged 18 and over. We do not knowingly collect personal data from children under the age of 13 (or the applicable minimum age in your jurisdiction). If you believe a child has provided personal data to us, please contact us immediately at privacy@synquic.com and we will delete such data promptly.
10. International Transfers
Your data may be stored and processed in countries outside your country of residence, including countries where data protection laws may differ from those in your jurisdiction.
Where we transfer personal data from the European Economic Area (EEA), UK, or Switzerland to third countries, we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Data Processing Agreements with all sub-processors
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify signed-in users via the platform or email for significant changes
We encourage you to review this Privacy Policy periodically. Continued use of Slide after changes are posted constitutes your acceptance of the revised policy.
12. Contact Us
For privacy-related questions, data subject requests, or concerns, please contact:
Synquic Data Privacy
Email: privacy@synquic.com
Website: synquic.com