Legal

Privacy policy

Last updated: 15 August 2026

1. Who we are

The data controller for the data described in section 3.1 is SyncDec, Dehradun, Uttarakhand 248007, India. Privacy contact: info@syncdec.com, phone +91 75000 13369.

SyncDec provides Travel OS, and is developing Booking OS and a WhatsApp Business Platform integration. This policy covers our websites and those products.

2. Controller and processor roles

Our customers are travel agencies, tour operators and hotels. When a customer enters its own clients' data into its account, that customer is the controller of that data and SyncDec is a processor acting on its instructions. We process it to provide the service, and we do not use it for our own purposes.

For the account data of the customer's own staff, and for our website and billing records, SyncDec is the controller.

3. What we collect

3.1 Customer account data

  • Names, work email addresses, phone numbers, roles and permissions of agency staff who hold logins.
  • Company details of the customer: business name, address, tax registration, invoice and branding settings.
  • Authentication data, login timestamps and IP address, and activity logs of actions taken in the account.
  • Billing and subscription records.

3.2 Data the customer enters about its own clients

  • Traveller and enquiry details: name, phone number, email address, city, party size, passenger details, travel dates.
  • Operational records: enquiries, quotations, itineraries, bookings, invoices, payments, follow-up notes and activity history.
  • Supplier and staff records the customer maintains: hotels, vehicles, drivers, employees, salary and leave records.

3.3 WhatsApp data

  • When a customer connects its own WhatsApp Business number, we process message content and metadata for that number — sender and recipient phone numbers, timestamps, delivery status, attachments and template usage — together with the WhatsApp Business Account identifiers needed to operate the connection.
  • Access tokens and credentials for the connection are stored encrypted and are never displayed back in the interface.

3.4 Website data

This website serves static pages. We do not use advertising trackers or third-party analytics cookies on it. Standard server request logs may record IP address, user agent and requested URL.

4. Why we process it, and legal basis

To provide and operate the products
Performance of the contract with our customer. For a customer's client data, our instructions come from the customer.
To authenticate users, secure accounts and prevent abuse
Legitimate interests in the security and integrity of the service.
To deliver WhatsApp conversations to the connected account
Performance of the contract with our customer, who is responsible for its own lawful basis and recipient consent for the messages it sends.
To bill, keep accounts and meet tax obligations
Legal obligation and performance of the contract.
To answer enquiries sent to us
Legitimate interests, or steps taken before entering a contract.

5. Hosting and sub-processors

Data is hosted with cloud infrastructure located in India. We use a limited set of sub-processors to run the service:

  • Hosting and database: cloud infrastructure in India
  • Transactional email and notifications: email delivery provider hosted in India
  • WhatsApp message delivery: Meta Platforms, through the WhatsApp Business Platform, for customers who connect a number
  • Payments and subscription billing: Razorpay Software Private Limited, India

Sub-processors are bound by contract to process data only on our instructions and to protect it.

6. Retention

  • Account and operational data: kept while the subscription is active, then deleted within 30 days of a verified deletion request, or within 90 days of the subscription ending.
  • WhatsApp conversation content and metadata: kept for 12 months unless the customer requests earlier deletion. On disconnection, history is retained read-only for the customer for the same period.
  • Security and access logs: 12 months.
  • Invoices and accounting records: kept for the period required by law in India.

See data deletion for how to request deletion.

7. Security

  • Encryption in transit over TLS for all traffic.
  • Encryption at rest for integration credentials and access tokens.
  • Per-tenant isolation: every record is scoped to a single customer account and queries are constrained to that account.
  • Role-based access control inside each account, set by the customer.
  • Restricted staff access on a need-to-know basis, with access logged.
  • Backups of daily backups retained for 30 days.

8. How WhatsApp and Meta data is handled

  • WhatsApp message content and metadata are used only to provide the inbox and CRM features to the customer whose number is connected.
  • They are not sold, not shared with other customers, and not used for advertising or for profiling unrelated to the service.
  • They are not used to train models.
  • Meta processes messages as part of delivering the WhatsApp Business Platform. Meta's own handling of that data is governed by its terms and policies.

9. Your rights

Subject to applicable law, you may request access to your personal data, correction, deletion, restriction of processing, portability, or object to processing based on legitimate interests. You may also withdraw consent where processing relies on it.

If your data was entered into a customer's account by that customer — for example you are a traveller who enquired with an agency — please contact that agency, which is the controller. If you contact us instead, we will refer your request to them and support them in answering it.

Write to info@syncdec.com. We respond within 30 days. You may also complain to the supervisory authority in India.

10. Children

The products are sold to businesses and are not directed at children. We do not knowingly collect data from children through our website.

11. Changes

If we change this policy we update the date at the top of this page and, for material changes, notify account owners by email.