Privacy Policy
Last updated 27 June 2026
This Privacy Policy explains how Synca Ltd(“Synca”, “we”, “us”) collects, uses, and protects your personal data when you use our website, apps, and booking services (the “Service”).
This is a starting template and not legal advice — please have it reviewed by a qualified solicitor and complete the bracketed details before relying on it.
1. Who we are
Synca Ltd is the data controller for personal data processed through the Service. You can contact us at privacy@synca.org.uk or by post at [registered address].
2. The data we collect
- Account data — name, email, password, and profile details.
- Booking data — the businesses, services, staff, dates, and notes for your appointments.
- Payment data — handled by our payment processor (Stripe). Synca never stores your full card details.
- Usage data — device, browser, IP address, and how you interact with the Service.
- Communications — messages, reviews, and support requests you send us.
3. How and why we use your data
We process your data on the following lawful bases:
- Contract — to create your account, take and manage bookings, and process payments.
- Legitimate interests — to operate, secure, and improve the Service and prevent fraud.
- Consent — for optional marketing, which you can withdraw at any time.
- Legal obligation — to meet tax, accounting, and other legal requirements.
4. Sharing your data
We share data only as needed to run the Service, including with:
- The businesses you book with, so they can provide your appointment.
- Stripe for payment processing, and Resend for transactional email.
- Hosting and infrastructure providers that run our platform.
- Authorities or advisers where required by law.
We never sell your personal data.
5. Cookies
We use cookies and similar technologies to keep you signed in and to understand usage. See our Cookie Policy for details.
6. Data retention
We keep personal data only as long as necessary for the purposes above, or as required by law (for example, financial records). When no longer needed, data is securely deleted or anonymised.
7. Your rights
Under UK GDPR you have the right to:
- Access, correct, or delete your personal data.
- Restrict or object to certain processing.
- Request portability of data you provided.
- Withdraw consent at any time.
To exercise these rights, email privacy@synca.org.uk. You may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
8. International transfers
Where data is processed outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or adequacy decisions.
9. Security
We use technical and organisational measures — including encryption in transit and access controls — to protect your data. No system is completely secure, so we cannot guarantee absolute security.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect their data without appropriate consent.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the “Last updated” date above.
12. Contact us
Questions about this policy? Email privacy@synca.org.uk.