Privacy Policy
Effective date: 24 April 2026 · Last updated: 11 August 2026 (§4: corrected an inaccurate blanket statement that we do not use automated decision-making — see below)
CC+Synergy Pte. Ltd. ("SynergyWeb", "we", "our", "us") operates the platform at synergyweb.app. This Privacy Policy explains how we collect, use, share, and protect personal data in connection with our services, and your rights under applicable law — including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA / CPRA), and Singapore's Personal Data Protection Act (PDPA).
1. Who We Are
Data Controller: CC+Synergy Pte. Ltd., incorporated in Singapore.
Contact: privacy@synergyweb.app
For EU/EEA data-subject requests, please use the same address with the subject line "GDPR Request". For California residents, use subject line "CCPA Request".
2. Data We Collect
2.1 Account & Profile Data
When you register or update your profile: email address, display name, username, profile photo, cover image, bio, skills, location, social media links, and onboarding preferences.
2.2 Content You Create
Portfolio items (images, descriptions, external URLs), services and pricing, shop products, booking details, collab space posts, messages and chat history, reviews and ratings, AI sketch interpretations you submit, and text prompts you enter for AI image generation.
2.3 Transaction Data
Booking records, service agreements, payment status. We do not store raw card numbers; payment processing is handled by third-party processors who are PCI-DSS compliant.
2.4 Usage & Analytics Data
Pages visited, features used, clicks, session duration, and referral source — collected via PostHog analytics. This data is pseudonymised where possible.
2.5 Technical Data
IP address, browser type and version, device type, operating system, error logs and crash reports collected via Sentry for debugging and security monitoring.
2.6 Cookies & Local Storage
We use cookies and browser local storage for:
- Session management — strictly necessary; always active
- Theme preference — strictly necessary; always active
- Analytics (PostHog) — only set if you accept the cookie consent banner
On your first visit, a cookie consent banner is shown. Before you respond to it, we collect anonymous, cookieless usage data (e.g. page views) under legitimate interest — no persistent identifier is set, and this uses the same privacy-preserving, server-side attribution method described under Decline below. Once you respond, your choices:
- Accept — PostHog analytics cookies are set, enabling consistent session attribution across visits.
- Decline — No analytics cookies are set. PostHog switches to cookieless mode. To attribute your session without a cookie, we generate a daily-rotating server-side fingerprint: a SHA-256 hash of your IP address, browser user-agent, and hostname, salted with a secret key that changes each day. This hash resets every 24 hours and cannot be used to identify you across days or link your session to any account.
Your consent choice is stored in browser local storage. You can change it at any time by clearing your browser's local storage for this site.
3. Legal Basis for Processing (GDPR)
We rely on the following lawful bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)): Account creation, service delivery, bookings, payments, and messaging.
- Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, platform analytics, abuse detection, and the development and improvement of machine-learning and AI technologies using de-identified User Content (see Section 4). We conduct balancing tests to ensure these interests do not override your rights.
- Legal obligation (Art. 6(1)(c)): Financial record retention, responding to lawful government requests.
- Consent (Art. 6(1)(a)): Marketing communications and analytics cookies. You may withdraw consent at any time by clearing your browser's local storage for this site. If you decline, we fall back to cookieless analytics (see section 2.6).
4. How We Use Your Data
- Provide, personalise, and improve the SynergyWeb platform
- Authenticate your identity and protect your account
- Process bookings, agreements, and transactions
- Send transactional emails (booking confirmations, password resets)
- Detect and prevent fraud, abuse, and security incidents
- Analyse platform usage to improve features and fix bugs
- Develop and improve machine-learning and artificial intelligence (AI) technologies, including training AI models on de-identified User Content. We may also create aggregated, anonymised, or de-identified data from User Content for any lawful purpose; such data does not identify you (see Terms of Use, Section 4)
- Comply with legal obligations
We do not sell your personal data to third parties.
We use automated systems as part of managing platform risk — for example, to apply temporary payout holds or reserves, transaction limits, or account reviews, based on factors such as account history, transaction and dispute patterns, and verification status. These automated decisions can affect a seller's access to funds or platform features. A human reviews escalated cases, and if an automated decision affects you, you may request human review by contacting privacy@synergyweb.app. We are preparing a more detailed disclosure of these systems.
5. Data Sharing & Processors
We share data only with the following categories of recipients, all bound by data processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Convex Inc. | Database hosting & backend infrastructure | USA |
| Stripe, Inc. | Payment processing, escrow, connected account payouts | USA |
| Resend | Transactional email delivery | USA |
| Anthropic PBC | AI-powered features: sketch interpretation (opt-in), support assistant, transaction assistant, feedback triage, dispute triage (summarisation & recommendation only — outcomes are human-reviewed), image/listing analysis, board content tools, portfolio description drafting, and image-generation prompt refinement (opt-in) | USA |
| Hugging Face Inc. | AI image generation from text prompts (opt-in) — renders the image after Anthropic optionally refines the prompt text | USA |
| PostHog Inc. | Product analytics | USA / EU |
| Sentry (Functional Software) | Error monitoring & crash reporting | USA |
International transfers to the USA are covered by Standard Contractual Clauses (SCCs) or equivalent adequacy mechanisms where required by GDPR.
6. Data Retention
- Account data: Retained while your account is active, plus 30 days after deletion (backup purge cycle). You may request immediate deletion.
- Financial/transaction records: 7 years from the date of transaction (regulatory requirement).
- Error logs: 90 days rolling window.
- Analytics data: 24 months, then aggregated and anonymised.
- AI processing data: Content sent to Anthropic for AI features — sketch interpretation, the support and transaction assistants, dispute triage, image/listing analysis, board content tools, portfolio description drafting, and image-generation prompt refinement — is not stored by SynergyWeb after the response is returned; subject to Anthropic's retention policy. Dispute triage produces summaries and recommendations only; any resulting action (e.g. a refund or payout) is taken by a human reviewer. Exception — feedback triage: your feedback message and any AI-generated reply are retained as part of your feedback record (so our team can follow up), separately from Anthropic's own retention of the content it processed.
- AI image generation prompts: Text prompts are sent to Hugging Face at the moment of generation and not stored by SynergyWeb; generated images are stored in your account until you remove them. Subject to Hugging Face's retention policy.
Financial and transaction records — including milestone agreements and consent records — are retained for a minimum of 7 years regardless of account deletion status, as required by applicable law. This obligation takes precedence over the standard 30-day post-deletion purge for general account data.
7. Platform Messaging, Collab Board & Video Meetings
Messaging (Chat)
Messages sent through SynergyWeb are stored in our database in readable form. Access is restricted to the participants of each conversation; however, messages are not end-to-end encrypted. As the platform operator, CC+Synergy Pte. Ltd. and its infrastructure provider (Convex) have technical access to stored message content for purposes of security monitoring, moderation, and legal compliance. Do not send sensitive credentials, financial information, or legally privileged content through the platform's messaging feature.
Collab Board
Collab Board content (sticky notes, text, sketches, uploaded images) is stored in our database in readable form and is accessible to all members of the collab group. Access is restricted to verified collab members; non-members cannot view board content. As with messaging, board data is not end-to-end encrypted and remains accessible to platform administrators for operational and legal purposes. Do not post confidential trade secrets or sensitive personal information on a Collab Board.
Video Meetings
Video meetings on SynergyWeb are conducted through Jitsi Meet, a third-party open-source service operated independently of CC+Synergy Pte. Ltd. When you join a meeting:
- Your video, audio, and in-meeting chat may be processed on Jitsi Meet's servers, which are outside SynergyWeb's control
- Meeting rooms are accessible to anyone who possesses the meeting link — SynergyWeb distributes links only to the confirmed booking participants, but we cannot prevent link forwarding
- Jitsi Meet may collect usage data in accordance with its own privacy and security policy
- Meeting links do not expire automatically; if you believe a link has been compromised, contact us at contact@synergyweb.app to cancel and reissue it
- SynergyWeb does not record, store, or have access to the audio or video content of your meetings
By using the video meeting feature you acknowledge and accept these third-party service conditions.
8. Your Rights
8.1 Rights Under GDPR (EU / EEA Residents)
- Access (Art. 15): Obtain a copy of your personal data.
- Rectification (Art. 16): Correct inaccurate data.
- Erasure (Art. 17): Request deletion of your data ("right to be forgotten").
- Restriction (Art. 18): Limit how we process your data.
- Portability (Art. 20): Receive your data in a machine-readable format.
- Object (Art. 21): Object to processing based on legitimate interests.
- Supervisory authority: Lodge a complaint with your local data protection authority.
8.2 Rights Under CCPA / CPRA (California Residents)
- Right to Know: What personal information we collect, use, and share.
- Right to Delete: Request deletion of your personal information.
- Right to Correct: Correct inaccurate personal information.
- Right to Opt-Out of Sale: We do not sell personal information.
- Right to Limit Use of Sensitive PI: We do not use sensitive personal information for secondary purposes.
- Non-Discrimination: We will not discriminate against you for exercising your rights.
8.3 Rights Under Singapore PDPA
- Access and correction of personal data held by us.
- Withdrawal of consent (where consent is the basis), subject to legal limitations.
- Data portability (effective 1 February 2022 amendments).
To exercise any right, email privacy@synergyweb.app with your request. We will respond within 30 days (GDPR / PDPA) or 45 days (CCPA).
9. Security
We implement appropriate technical and organisational measures to protect your data, including:
- TLS encryption in transit for all data
- Encrypted database storage via Convex
- Authentication via industry-standard session management (Better Auth)
- Server-side input validation and content moderation
- Regular security reviews and dependency updates
- Restricted access controls with least-privilege principles
- Optional TOTP-based two-factor authentication (2FA) available to all users
In the event of a data breach that is likely to result in high risk to your rights, we will notify affected users within 72 hours of becoming aware, and notify relevant supervisory authorities as required by law.
8.1 Your Responsibility for Account Security
While we take significant steps to secure our platform, account security is a shared responsibility. You are solely responsible for:
- Keeping your password confidential and not reusing it across services
- Choosing whether to enable two-factor authentication (2FA), which is strongly recommended
- Maintaining secure custody of any authenticator device or backup codes
- Notifying us promptly at security@synergyweb.app if you suspect your account has been compromised
CC+Synergy Pte. Ltd. is not responsible for unauthorised access to your account resulting from compromised credentials, phishing, credential reuse, or failure to enable available security features such as 2FA. Enabling 2FA is optional and at your sole discretion; however, choosing not to enable it increases the risk of unauthorised access for which you accept full responsibility.
10. Children's Privacy
SynergyWeb is not directed at anyone under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided personal data without parental consent, contact us at privacy@synergyweb.app and we will delete it promptly.
11. Business Transfers
If CC+Synergy Pte. Ltd. is involved in a merger, acquisition, asset sale, corporate restructuring, or similar transaction, your personal data may be transferred to the successor or acquiring entity as part of that transaction. We will notify you via email or a prominent notice on the platform before your personal data becomes subject to a materially different privacy policy. If you do not consent to the transfer, you may close your account before the transfer takes effect.
In connection with any such transaction, we may also share your personal data with prospective purchasers or their advisers on a confidential basis and solely for the purpose of evaluating the transaction. Any such disclosure is subject to appropriate confidentiality obligations.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the platform at least 14 days before taking effect. Continued use of SynergyWeb after the effective date constitutes acceptance of the revised policy.
13. Contact Us
For privacy queries, requests, or concerns: privacy@synergyweb.app
CC+Synergy Pte. Ltd. · Singapore
