Legal

Privacy Policy

Last updated: March 22, 2026

Effective date: March 22, 2026

This Privacy Policy explains how Synquic ("Synquic", "we", "us", or "our") collects, uses, stores, and shares information when you use Slide, our omnichannel automation platform. By accessing or using Slide, you agree to this Privacy Policy.

1. Who We Are

Synquic is a technology company that builds the Slide platform an enterprise omnichannel automation tool. Synquic operates as the data controller for the personal data processed through Slide.

For any privacy-related enquiries, you can reach us at: privacy@synquic.com

2. Information We Collect

We collect the following categories of information:

2.1 Account & Identity Data

When you sign in via Google or Microsoft OAuth (powered by Firebase Authentication), we receive and store:

  • Full name (first and last name)
  • Email address
  • Profile photo URL (if provided by your identity provider)
  • Unique identifier from your identity provider (UID)
  • Sign-in method (Google or Microsoft)

We do not receive or store your Google/Microsoft passwords. Authentication is handled entirely by Firebase Authentication (Google LLC).

2.2 Organization & Role Data
  • Organization name and settings
  • Your role and permissions within the organization
  • Invitation records (email addresses of people you invite)
  • Organization-level configuration and disabled modules
2.3 Automation & Workflow Data

When you build and run automation flows, we may process:

  • Flow configurations and trigger conditions
  • Message templates and chatbot scripts
  • Contact lists and audience segments you upload
  • Execution logs and error reports
  • Instagram and WhatsApp message content (where required for flow processing)

Message content from Instagram and WhatsApp is processed transiently to execute automation flows. We do not read, sell, or use this content for advertising purposes.

2.4 Usage & Technical Data
  • Browser type, device type, and operating system
  • IP address and approximate location
  • Pages visited, features used, and time spent
  • API request logs and error records
  • Session tokens and authentication state

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing the platform: To authenticate you, maintain your session, display your organization's data, and operate automation flows.
  • Processing automations: To execute Instagram and WhatsApp flows, trigger pipeline stage transitions, and send templated messages on your behalf.
  • Account management: To process invitations, manage roles and permissions, and enforce organization-level settings.
  • Security and fraud prevention: To detect unauthorized access, enforce rate limits, and protect the integrity of the platform.
  • Platform improvement: To analyse usage patterns (in aggregate, non-personally-identifiable form) to improve features and performance.
  • Communications: To send transactional emails (e.g., invitation emails, system alerts). We do not send unsolicited marketing emails.
  • Legal compliance: To comply with applicable laws, respond to lawful requests, and enforce our Terms of Service.

We do not sell, rent, or trade your personal data to third parties for marketing purposes.

4. Third-Party Services and APIs

Slide integrates with the following third-party services. Each service has its own privacy policy that governs their data practices:

Firebase Authentication (Google LLC)

Google Privacy Policy

Purpose: User authentication via Google and Microsoft OAuth.

Firebase receives your sign-in credentials and issues authentication tokens. We do not receive or store passwords.

Meta Platforms Instagram Business API

Meta Privacy Policy

Purpose: Automating Instagram DMs, comments, and story interactions.

We access your Instagram Business Account via Meta's official API under your authorization. Message content is processed only to execute your configured automations. We comply with the Instagram Platform Policy and Meta Platform Terms.

Meta Platforms WhatsApp Business API

WhatsApp Privacy Policy

Purpose: Sending and receiving WhatsApp messages through automation flows.

We use the official WhatsApp Business API. All message templates must be approved by Meta. End-user data (phone numbers, conversation content) is processed solely for delivering your automations. We do not access this data for any other purpose.

Infrastructure Providers

Purpose: Hosting, database, and compute services.

Your data is stored on secure, enterprise-grade cloud infrastructure. Providers operate under strict data processing agreements (DPAs) with Synquic.

5. Data Storage and Security

All data is stored on cloud infrastructure with industry-standard security practices:

  • Encryption in transit: All communication between your browser and our servers uses TLS 1.2+.
  • Encryption at rest: Database records and file storage are encrypted at rest.
  • Access control: Access to production data is restricted to authorized Synquic personnel only, with audit logging.
  • Authentication tokens: We use short-lived JWT tokens with rotation. Refresh tokens are stored securely.
  • No plaintext credentials: We never store passwords. Authentication is delegated to Firebase/Google.

While we implement robust security measures, no system is 100% immune to breaches. In the event of a data breach affecting your personal data, we will notify affected users in accordance with applicable law (typically within 72 hours for GDPR-regulated incidents).

6. Data Retention

We retain your data for as long as your account is active or as needed to provide the service:

  • Account data: Retained as long as your account exists. Deleted within 30 days of account deletion request.
  • Automation flow data: Retained for the duration of your subscription plus 90 days for recovery purposes.
  • Message processing logs: Retained for up to 12 months for debugging and compliance purposes.
  • Billing records: Retained for 7 years as required by financial regulations.
  • System logs: Retained for 90 days, then automatically purged.

You may request deletion of your personal data at any time by emailing privacy@synquic.com. We will process deletion requests within 30 days, subject to legal retention requirements.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

Right to access

Request a copy of your personal data we hold.

Right to rectification

Request correction of inaccurate or incomplete data.

Right to erasure

Request deletion of your personal data ("right to be forgotten").

Right to portability

Receive your data in a structured, machine-readable format.

Right to restrict processing

Request we limit how we use your data in certain circumstances.

Right to object

Object to processing based on legitimate interests or for direct marketing.

Right to withdraw consent

Withdraw consent at any time where processing is consent-based.

Right to complain

Lodge a complaint with your local data protection authority (e.g., ICO in the UK, CNIL in France).

To exercise any of these rights, email privacy@synquic.com. We will respond within 30 days. We may ask you to verify your identity before processing requests.

8. Cookies and Tracking

Slide uses the following types of cookies and local storage:

  • Authentication cookies: Strictly necessary. Used to maintain your signed-in session via Firebase. Cannot be disabled while using the platform.
  • Preference storage: Stores your UI preferences (e.g., selected organization) in browser local storage. No personal data leaves your browser.
  • Analytics (if enabled): We may use privacy-preserving analytics to understand platform usage. No personally identifiable information is used for analytics.

We do not use third-party advertising cookies or sell cookie data to data brokers.

9. Children's Privacy

Slide is an enterprise platform intended for business use by adults aged 18 and over. We do not knowingly collect personal data from children under the age of 13 (or the applicable minimum age in your jurisdiction). If you believe a child has provided personal data to us, please contact us immediately at privacy@synquic.com and we will delete such data promptly.

10. International Transfers

Your data may be stored and processed in countries outside your country of residence, including countries where data protection laws may differ from those in your jurisdiction.

Where we transfer personal data from the European Economic Area (EEA), UK, or Switzerland to third countries, we rely on appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Data Processing Agreements with all sub-processors

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify signed-in users via the platform or email for significant changes

We encourage you to review this Privacy Policy periodically. Continued use of Slide after changes are posted constitutes your acceptance of the revised policy.

12. Contact Us

For privacy-related questions, data subject requests, or concerns, please contact:

Synquic Data Privacy