Legal

Privacy Policy

Effective date: August 13, 2026

This Privacy Policy explains how information is handled when you use Syncly for Gohighlevel (the "Service"). It applies to data processed through plugin features, support workflows, and integration endpoints provided by the Service.

1. Data Controller and Scope

For data processed inside your WordPress installation, you are generally the controller and we are a software provider. For data you submit directly to us (for example support requests or commercial inquiries), we may act as a controller for that information.

2. Categories of Data Processed

Depending on the features you enable, the Service may process:

  • Identity and profile data: names, emails, user IDs, account attributes, role metadata, and mapped custom fields.
  • CRM synchronization data: tags, contact properties, pipeline-related fields, and selected custom object values.
  • Integration metadata: OAuth tokens, refresh tokens, location identifiers, mapping configuration, webhook payload context, and sync status markers.
  • Operational telemetry and logs: timestamps, event type, endpoint response codes, queue/sync diagnostics, and error traces.
  • Security and abuse prevention data: IP addresses, user agent, nonce/check outcomes, and rate-limit counters where applicable.
  • Support communications: messages, attachments, and technical details voluntarily provided in support requests.

3. Sources of Data

Data may come from your WordPress site, your administrators and users, connected services (including GoHighLevel), webhook/API events, and form submissions routed by plugin features.

4. Purposes of Processing

Data is processed to:

  • Authenticate and maintain secure integrations (including OAuth flows).
  • Perform requested synchronization and automation actions.
  • Operate account, checkout, and page features provided by the Service.
  • Monitor reliability, investigate incidents, and prevent abuse.
  • Provide support, maintenance, and product improvements.
  • Comply with legal and contractual obligations.

5. OAuth, Tokens, and API Credentials

Where OAuth and token-based features are enabled, credential material is used solely to authorize permitted API operations. You are responsible for controlling admin access, rotating credentials when needed, and revoking integrations you no longer trust.

6. Cookies, Sessions, and Similar Technologies

Your WordPress site and integrated platforms may use cookies or session identifiers for login state, request integrity, preferences, analytics, and fraud protection. Cookie handling may also be affected by your theme, hosting stack, and additional plugins.

7. Legal Bases for Processing

Where required by law, processing is based on one or more of: contract performance, legitimate interests (security/operations/support), consent, and legal obligations.

8. Sharing and Disclosure

We do not sell personal information collected through the Service. Data may be disclosed to service providers and integration partners strictly as needed to deliver functionality (for example API providers, hosting providers, payment processors, and customer support tooling), or where required by law.

9. International Data Transfers

Data may be processed in jurisdictions different from your own, including locations where infrastructure providers or integration vendors operate. You are responsible for assessing cross-border transfer requirements applicable to your organization.

10. Retention

Retention depends on configuration, plan, and legal requirements. In general, data is retained only as long as needed for service delivery, troubleshooting, compliance, dispute handling, and security purposes. You may also delete certain data directly from your WordPress installation.

11. Security Measures

We apply reasonable technical and organizational safeguards. No method of transmission or storage is perfectly secure. You should enforce strong administrator controls, least-privilege access, transport security, backups, and routine patching across your environment.

12. Your Rights and Choices

Subject to local law, you may have rights to access, rectify, delete, restrict, object, and request portability of personal information. You may also disable integrations, revoke tokens, or remove plugin data from your site. Requests can be submitted through our contact channel.

13. Children's Data

The Service is not directed to children and is intended for business/organizational site operations. If you believe personal data from a child was processed improperly, contact us for review.

14. Third-Party Links and Services

Pages or templates may link to third-party services. Their privacy practices are governed by their own policies, not this one.

15. Policy Changes

We may update this Privacy Policy from time to time. Material updates will be reflected by posting a revised version with an updated effective date.

16. Contact

For privacy questions or rights requests, please use the contact page.

Legal Notice: This policy is for transparency and operational clarity and is not legal advice. You should consult qualified counsel for privacy obligations that apply to your specific jurisdiction, customer base, and business model.