This Privacy Policy explains how Cloud Mizan LLC, operating as Sync, collects, uses and protects information in connection with the Sync application at rs-sync.com. It covers both the account holders who sign up for Sync and, where relevant, the people whose information a Sync customer enters into the product (for example, an employee added to the payroll module).
Account information: your name, email address and password (stored as a hash, never in plain text) when you or your organization sign up.
Business data you enter: invoices, bills, bank transactions and statements you upload, client and vendor records, contracts, and similar operational records.
HR and payroll data, where you use those modules: employee names, contact details, attendance, leave, compensation, and documents you choose to attach (for example, contracts or identity documents).
Usage and log data: basic technical information like IP address, browser type, and pages accessed, used for security and troubleshooting.
Communications: messages you send us for support, and transactional emails the Service sends on your behalf (for example, invoice or payslip notifications).
For your own account information, Sync is the data controller. For information you enter about your own employees, clients or vendors, your organization is the data controller and Sync acts as a data processor on your behalf — we process that data only to provide the Service, and only under your instructions.
We don't sell your data, and we don't share it with third parties for their own advertising purposes. We share information only with:
Every organization's data is scoped by the organization it belongs to at the database query level — not just hidden in the interface — and that scope is read from a signed authentication token rather than trusted from the request itself, so one organization can never reach another's data through normal use of the product. Passwords are hashed, login attempts are rate-limited, and we run an automated test suite that specifically tries to access data across organizations on every release.
No system is perfectly secure, and we can't guarantee absolute security, but data isolation between customers is a structural property of how Sync is built, not an afterthought.
We retain your data for as long as your account is active. If you cancel your subscription, we retain your data for a reasonable period to let you reactivate or export it, after which it is deleted from active systems. You can request earlier deletion by contacting us.
Depending on where you're located, you may have the right to access, correct, export or delete your personal information. To exercise these rights, use "Report an issue" in the app (or in your employee portal, if you're a resource) — every report reaches our team directly. For information your employer has entered about you in Sync's HR modules, please contact your employer directly, as they control that data — we'll assist them with your request.
Sync doesn't use tracking or advertising cookies. Session and login state are kept in your browser's local storage rather than cookies. See our Cookie Policy for details, including about third-party cookies Stripe may set on its own hosted payment pages.
The Service is intended for business use by adults and is not directed at children. We don't knowingly collect personal information from children.
Depending on where our hosting and service providers operate, your data may be processed in a country other than your own. Where that happens, we take reasonable steps to make sure it continues to be protected consistently with this Policy.
We may update this Privacy Policy from time to time. We'll post the updated version here with a new "last updated" date, and for material changes, make reasonable efforts to let you know.
Questions about this Policy, or a request about your data? Reach us through "Report an issue" in the app (or in your employee portal, if you're a resource) — every report reaches our team directly.