Legal

Privacy Policy

Last updated: 15 September 2026

SYNTRA LLC ("SYNTRA", "we", "us", or "our") operates the website at www.syntraco.tech and the SYNTRA client portal. This Privacy Policy explains how we collect, use, and protect your personal information when you use our services.

1. Information we collect

1.1 Information you provide directly

  • Name and email address when you create an account or submit the free audit form
  • Business name, industry, and company size when you complete onboarding
  • Phone number when you choose to pay via M-Pesa
  • Billing information processed securely by our payment providers (see Section 3)
  • Messages and enquiries you send to hello@syntraco.tech or support@syntraco.tech

1.2 Information collected automatically

  • IP address and approximate geolocation
  • Browser type, operating system, and device type
  • Pages visited, time on site, and referring URL
  • Portal usage: features accessed, automations run, API calls made

2. How we use your information

  • Provide, operate, and improve the SYNTRA platform and services
  • Process payments and send receipts and invoices
  • Send transactional emails (account confirmation, password reset, billing notifications)
  • Respond to support requests and enquiries
  • Analyse aggregate usage patterns to improve the product
  • Comply with legal obligations

We do not sell your personal data to third parties. We do not use your data for advertising networks or data brokers.

3. Third-party services

We use the following third-party processors to deliver our services. Each has its own privacy policy.

ServicePurposeData shared
SupabaseDatabase & authenticationEmail, hashed password, business profile
StripeCard payment processingCard details (never stored by us), email, billing address
IntaSendM-Pesa payment processingPhone number, name, payment amount
CloudflareHosting, CDN, DDoS protectionIP address (anonymised logs)

4. Data storage and security

Your data is stored on Supabase infrastructure hosted in the EU (Frankfurt). We use row-level security (RLS) policies so that each organisation can only access its own data. All data in transit is encrypted with TLS 1.2+. We follow OWASP security best practices and conduct regular dependency audits.

5. Data retention

  • Active account data: retained for the duration of your subscription
  • Billing records: retained for 7 years as required by Kenyan tax law
  • Audit logs: retained for 90 days
  • Deleted accounts: all personal data removed within 30 days of deletion request

6. Your rights

Under the Kenya Data Protection Act (2019) and applicable privacy regulations, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Request deletion of your data ("right to erasure")
  • Object to or restrict certain processing activities
  • Export your data in a machine-readable format (data portability)

To exercise any of these rights, email hello@syntraco.tech. We will respond within 30 days.

7. Cookies

We use only session cookies required for authentication and a Supabase auth cookie to keep you logged in. We do not use advertising cookies or third-party trackers. You can disable cookies in your browser, but doing so will prevent you from staying logged in to the client portal.

8. Children's privacy

Our services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal data from children under 18.

9. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify you by email.

10. Contact

For privacy-related questions or requests, contact us at:

SYNTRA LLC
Nairobi, Kenya
hello@syntraco.tech