Privacy Policy
Effective Date: June 4, 2026
Version: 1.5
Synergy In Construction, LLC ("SynC™," "we," "us," or "our"), a Wyoming limited liability company located at 30 N Gould St Ste N, Sheridan, WY 82801, is committed to protecting your privacy and ensuring transparency about how we collect, use, disclose, and safeguard your personal information. This Privacy Policy describes our practices regarding the information we collect through our platform, website, and related services (collectively, the "Services").
By accessing or using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
1. Information We Collect
We collect information in several ways when you use our Services:
1.1 Information You Provide Directly
Account Registration Information:
- Full name (first and last name)
- Email address
- Password (encrypted and securely stored)
- Phone number (optional)
- Job title and role
- Company name and information
- Profile information
User Content and Project Data:
- Construction project specifications and documents
- Equipment datasheets and technical information
- Project files, drawings, and attachments
- Comments, annotations, and collaboration messages
- AI chat interactions and queries
- Custom templates and saved preferences
- SynC Standards wiki contributions
Payment Information:
- Billing name and address
- Payment method details (processed securely through third-party payment processors)
- Purchase history and subscription information
Communications:
- Email correspondence with our support team
- Feedback, surveys, and reviews
- Contact form submissions
1.2 Information Collected Automatically
When you access or use the Services, we automatically collect:
Usage Information:
- Pages viewed and features accessed
- Time spent on pages and in the application
- Click patterns and navigation paths
- Search queries and AI interaction history
- Feature utilization and engagement metrics
- Files uploaded, downloaded, and shared
Project Sharing and Distribution Analytics:
- Share link creation, acceptance, and forwarding activity
- Access records tracking which users have accepted shared project access
- Sharing chain data (how access has been forwarded through delegation)
Device and Technical Information:
- IP address and geolocation (city/region level)
- Browser type and version
- Operating system and device type
- Screen resolution and display settings
- Unique device identifiers
- Referring URLs and exit pages
Cookies and Similar Technologies:
We use cookies, web beacons, pixels, and similar tracking technologies to:
- Maintain your session and keep you logged in
- Remember your preferences and settings
- Analyze usage patterns and improve Services
- Prevent fraud and enhance security
- Deliver personalized content and recommendations
For more information, see Section 10 (Cookies and Tracking Technologies).
1.3 Information from Third Parties
Third-Party Integrations:
- Information from services you connect to SynC (with your permission)
- Data from authentication providers (e.g., Google, Microsoft)
Business Partners:
- Information from companies that collaborate with you on projects
- Referral information from partners
Public Sources:
- Publicly available business information
- Industry data and construction standards
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Service Delivery and Operations
- Provide, maintain, and improve the Services
- Create and manage your account
- Process transactions and subscriptions
- Store and organize your project data and User Content
- Enable collaboration features with team members
- Provide customer support and respond to inquiries
- Send transactional emails (account notifications, password resets, etc.)
2.2 AI and Machine Learning
Important Notice Regarding AI Training and Improvement:
We use your information to power and improve our artificial intelligence and machine learning capabilities:
AI Feature Delivery:
- Process your queries and requests through AI services
- Generate AI-assisted content and recommendations
- Analyze specifications and documents using natural language processing
- Provide predictive analytics and intelligent suggestions
AI Training and Model Improvement:
- We may use your User Content to train and improve our AI models and algorithms
- Before using User Content for training, we anonymize it by removing:
- Your name and contact information
- Company names and project names
- Location-specific identifiers
- Any other personally identifiable information
- Anonymized data may be aggregated with data from other users to:
- Improve accuracy and relevance of AI responses
- Develop new AI-powered features
- Create industry benchmarks and insights
- Enhance construction specification standards
Third-Party AI Services:
- We utilize third-party AI services and APIs (including Grok by xAI, Google Gemini, OpenAI, Anthropic, and others) to power certain features
- When you use AI features, your queries and content may be transmitted to these third-party providers
- Third-party AI providers process data according to their own privacy policies and terms
- We implement contractual protections to limit how third parties can use your data
Your Rights Regarding AI Training:
- You have the right to opt out of having your User Content used for AI training purposes
- To opt out, contact us at privacy@synergyinconstruction.com
- Note: Opting out may limit certain AI-powered features
- Your opt-out preference will be honored for future training; previously anonymized data in existing models cannot be removed
2.3 Analytics and Service Improvement
- Monitor and analyze usage patterns and trends
- Conduct research and development for new features
- Perform statistical analysis and create aggregated reports
- Measure effectiveness of features and user experience
- Identify and fix technical issues and bugs
- Optimize performance, speed, and reliability
2.4 Personalization
- Customize your experience based on preferences and usage
- Provide relevant recommendations and content
- Remember your settings and preferences
- Display personalized dashboards and workflows
2.5 Communication
- Send important service announcements and updates
- Notify you of new features and improvements
- Request feedback and conduct surveys
- Provide educational content and best practices
- Send marketing communications (with your consent, where required)
2.6 Security and Fraud Prevention
- Detect, prevent, and investigate fraud and security incidents
- Protect against unauthorized access and malicious activity
- Monitor for violations of our Terms of Service
- Ensure platform integrity and user safety
- Comply with legal obligations and enforce our policies
2.7 Legal Compliance
- Comply with applicable laws, regulations, and legal processes
- Respond to lawful requests from public authorities
- Protect our rights, privacy, safety, and property
- Resolve disputes and enforce agreements
3. Legal Basis for Processing (GDPR Compliance)
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal information based on the following legal grounds:
Contract Performance:
- Processing necessary to provide the Services you've requested
- Account creation and management
- Transaction processing
Legitimate Interests:
- Improving and optimizing our Services
- Fraud prevention and security
- Analytics and business intelligence
- Direct marketing to existing customers
- Detecting, diagnosing, and remediating errors and service-impacting incidents through our error-monitoring processor (see Section 4.1)
- Measuring product engagement, conversion funnels, and feature usage through our product-analytics processor (see Section 4.1), subject to your consent for any non-essential cookies that processor sets
Consent:
- AI training using anonymized User Content (you may withdraw consent)
- Marketing communications to prospects (you may withdraw consent)
- Non-essential cookies and tracking, including the product-analytics processor's cookies and session-replay recordings (you may manage preferences)
Legal Obligation:
- Compliance with applicable laws and regulations
- Responding to legal requests
You have the right to object to processing based on legitimate interests. See Section 8 for more information about your rights.
4. How We Share Your Information
We do not sell your personal information to third parties. We share your information only in the following limited circumstances:
4.1 Service Providers and Processors
We engage trusted third-party service providers to perform functions on our behalf, including:
Our processors change over time. The specific processors named in this Section are those we use as of the Effective Date of this Policy. We may add, replace, or discontinue processors from time to time; where we do, the categories of data, purposes, and safeguards described in this Section continue to apply to any processor performing the same function. The processors named here describe our current arrangements and are not an exhaustive or permanent list. A current list of our third-party subprocessors is available on request at privacy@synergyinconstruction.com, and we will update this Policy in accordance with Section 13 when changes are material.
Infrastructure and Hosting:
- Cloud hosting providers (e.g., Amazon Web Services, Microsoft Azure, Google Cloud Platform)
- Content delivery networks (CDNs)
- Data storage and backup services
AI and Machine Learning:
- AI service providers (including Grok by xAI, Google Gemini, OpenAI, Anthropic)
- Natural language processing platforms
- Machine learning infrastructure providers
Business Operations:
- Payment processors (e.g., Stripe, PayPal)
- Email delivery services (e.g., SendGrid, Mailgun)
- Customer support platforms (e.g., Zendesk, Intercom)
- Analytics services (see Web Analytics, Product Analytics, and Error Monitoring below for our current analytics and observability processors)
- Authentication services (e.g., Auth0, OAuth providers)
Web Analytics — our current web-analytics processor (Cloudflare Web Analytics):
- Processor: Cloudflare, Inc., based in the United States, with global processing infrastructure
- Purpose: Aggregate, privacy-respecting measurement of site traffic and performance for our public website and wiki (e.g., page views, referrers, country-level visitor distribution, page load timing)
- Categories of data received: URL of the page visited, referring URL, anonymized browser and operating system family, country (no precise geolocation), and basic connection performance metrics
- What is NOT received: Cloudflare Web Analytics is cookieless — it does not set cookies, does not assign visitor identifiers, and does not perform cross-site tracking. No persistent identifier is created in your browser by this processor.
- Where deployed: The analytics beacon is loaded only on the production hostname (
synergyinconstruction.com). It is not loaded in local development or on staging environments.
- Consent banner: Because the beacon is cookieless and does not create or read any persistent identifier on your device, it does not require consent under the ePrivacy Directive's cookie rule. No consent banner is required for this processor.
- Cloudflare privacy commitments: https://www.cloudflare.com/web-analytics-privacy/
Product Analytics — our current product-analytics processor (PostHog):
- Processor: PostHog, Inc., based in the United States. SynC uses PostHog's US-region cloud instance (
app.posthog.com), so product-analytics event data and session recordings are transferred to and processed in the United States.
- Purpose: Measure how visitors and signed-in users move through the application — page views, feature interactions, conversion funnels (e.g., from a wiki standard page to a created project), and qualitative diagnosis of drop-off via session replay
- Categories of data received:
- Event data: Event names (e.g.,
wiki.cta.shown, wiki.cta.clicked, project.created, datasheet.revision_saved), URLs of pages visited, referring URLs, browser and operating system family, screen size, country-level geolocation derived from IP address, and a per-browser distinct identifier
- Identification: Once you sign in or create an account, we associate your distinct identifier with your user ID and email address via PostHog's
identify mechanism so that pre-signup and post-signup activity can be analyzed as a single journey
- Session replay: PostHog records DOM-level interactions on the application (mouse movement, clicks, navigation, scroll, and the rendered page structure) so that we can diagnose user-experience issues and conversion drop-off
- What is NOT received / how sensitive data is protected:
- Input masking: Session replay is configured to mask user-typed text by default. Password fields are always masked. Form inputs, text areas, and other typed content are masked unless explicitly marked as safe to record. As a result, the content you type into specifications, datasheets, AI chat, or other input fields is not captured in session recordings.
- DOM redaction: Elements containing sensitive content can be excluded from recording via the
ph-no-capture CSS class. We use this mechanism to suppress capture of high-sensitivity surfaces.
- No payment data: Payment card details are entered into our payment processor's hosted fields and are not present in the DOM available to PostHog.
- Where processed: United States (PostHog US cloud at
app.posthog.com)
- Cookies set: PostHog sets first-party cookies (including
ph_<project>_posthog) on your browser to maintain the distinct identifier across sessions. These are non-essential cookies and are subject to your consent where required (see Section 10).
- Session replay opt-out / right to object: You may object to session replay or to product-analytics processing at any time by contacting privacy@synergyinconstruction.com (see Section 8).
- PostHog privacy policy: https://posthog.com/privacy
- PostHog Data Processing Addendum: https://posthog.com/dpa
Error Monitoring — our current error-monitoring processor (Sentry):
- Processor: Functional Software, Inc. d/b/a Sentry, based in the United States. SynC uses Sentry's US-region ingestion endpoint, so error data is transferred to and processed in the United States.
- Purpose: Detect, diagnose, and remediate frontend (JavaScript) and backend (server) errors and service-impacting incidents
- Categories of data received: Error message and stack trace, the URL and HTTP method of the request that triggered the error, browser and operating system information, and a breadcrumb trail of recent user actions in the application leading up to the error
- What is NOT received:
- We configure Sentry with
sendDefaultPii: false, so Sentry does not receive your IP address or your browser cookies by default
- Sensitive HTTP headers are automatically scrubbed before transmission, including
Authorization, Cookie, and Set-Cookie
- Request and response body fields with sensitive names — including
password, secret, token, api_key, access_token, and refresh_token — are automatically scrubbed before transmission
- Routine 4xx client errors (e.g., validation failures, "not found," "unauthorized") are filtered server-side before transmission and are not sent to Sentry; only 5xx server errors and uncaught exceptions are reported
- Where processed: United States (US-region ingest at
ingest.us.sentry.io)
- Sentry privacy policy: https://sentry.io/privacy/
- Sentry Data Processing Addendum: https://sentry.io/legal/dpa/
These service providers have access to personal information only to perform services on our behalf and are obligated to protect your information through contractual agreements and data processing addendums.
4.2 Collaboration and Sharing Features
When you use collaboration features, we share information with:
- Team members and colleagues you invite to projects
- Companies and organizations you collaborate with
- Users you grant access to specific documents or projects through share links
You control what information is shared through your permission settings and project configurations.
4.3 Company Profile Visibility
When your company creates a profile on the Services, the following information is visible to other authenticated users through the company search and discovery features:
- Company name
- Company type(s)
- Company description
- City, state, and country (no street address is disclosed)
- Website URL
This visibility enables essential platform functionality, including allowing users to join their company, discover collaborators, and invite companies to bid on or participate in projects. Individual user information (names, emails, phone numbers) is not exposed through company search.
4.4 SynC Standards Attribution
When you contribute to SynC Standards, your contributor attribution — which may include your display name, account identifier, and the name of your affiliated organization at the time of contribution — is displayed on adopted revisions in accordance with the CC-BY-SA 4.0 license attribution requirements. The treatment of contributor attribution is governed by our separate Contributor License Agreement ("CLA"), Section 2A.
If you delete your account, your public-facing contributor attribution is removed from the SynC Standards Wiki and from any project that has imported your contribution by reference, so that a member of the public can no longer identify you as the contributor (CLA §2A.3). Your contribution itself remains in the public repository under CC-BY-SA 4.0 (see Section 5.1). Separately, SynC retains a limited, non-public, access-restricted record linking each contribution to the contributor who made it, kept only as reasonably necessary to establish, exercise, or defend legal claims and to maintain the integrity of the attribution and licensing chain required by CC-BY-SA 4.0 (CLA §2A.4). Because that retained record makes it possible, in principle, to re-associate an otherwise public-anonymized contribution with you, the overall treatment of your contributor-attribution data is pseudonymization rather than anonymization for the purposes of data-protection law. The retained record remains personal data, and this Privacy Policy and applicable data-protection law continue to apply to it.
4.5 Aggregated and Anonymized Data
We may share aggregated, anonymized, or de-identified data that does not identify you personally with:
- Research partners and academic institutions
- Industry organizations and standards bodies
- Business partners for analytics and insights
- The public for industry reports and benchmarking
This data cannot be used to identify you and is not considered personal information.
4.6 Business Transfers
If SynC is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Services before your personal information is transferred and becomes subject to a different privacy policy.
4.7 Legal Requirements and Protection
We may disclose your information if required to do so by law or in good faith belief that such action is necessary to:
- Comply with legal obligations, court orders, or subpoenas
- Protect and defend the rights or property of SynC
- Prevent or investigate possible wrongdoing in connection with the Services
- Protect the personal safety of users or the public
- Protect against legal liability
4.8 With Your Consent
We may share your information for other purposes with your explicit consent or at your direction.
5. Data Retention
5.1 Retention Periods
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Account Information:
- Retained for the duration of your active account
- Retained for up to 90 days after account deletion for backup and recovery purposes
- Certain information may be retained longer to comply with legal obligations
User Content and Project Data:
- Retained for the duration of your active account
- Retained for up to 30 days after account deletion to allow for data export
- May be retained in backup systems for up to 90 days after deletion
SynC Standards Contributions:
- Contributions licensed under CC-BY-SA 4.0 are retained as part of the public standards repository even after account deletion, as they are licensed to the public
- Following account deletion, your public-facing contributor attribution is removed (pseudonymized as described in Section 4.4); SynC retains a limited, non-public, access-restricted record linking each contribution to you only as reasonably necessary for legal-claims and licensing-integrity purposes (CLA §2A.4)
Anonymized Data:
- Anonymized data used for AI training and analytics is retained indefinitely
- Once anonymized, this data cannot be re-associated with you
Usage and Analytics Data:
- Typically retained for 24-36 months for trend analysis
- May be retained indefinitely in aggregated, anonymized form
- Cloudflare Web Analytics data is retained by Cloudflare under their published retention policies; because no visitor identifier is created, this data cannot be re-associated with you
Product Analytics Data (PostHog):
- Event data is retained by PostHog under the retention policy applicable to our PostHog plan (typically 7 years for events, configurable down to 30 days)
- Session recordings are retained on a shorter schedule, typically 30 days under PostHog's default for our plan, after which they are deleted by PostHog
- Upon a verified deletion request (see Section 8), we will delete or anonymize identified product-analytics data associated with your user ID via PostHog's delete-person API
Error Monitoring Data:
- Error events transmitted to Sentry are retained according to Sentry's standard retention for our plan and are used solely to diagnose and remediate errors
- Scrubbed and filtered as described in Section 4.1 prior to transmission
Legal and Compliance Data:
- Retained as required by applicable law (typically 3-7 years for financial records)
- Retained as necessary to resolve disputes or enforce agreements
5.2 Deletion Requests
You may request deletion of your personal information at any time (see Section 8). Upon deletion:
- We will delete or anonymize your personal information within 30 days
- Backups may retain data for up to 90 days
- We may retain certain information as required by law or for legitimate business purposes
- Anonymized data in AI models cannot be removed
- SynC Standards contributions licensed under CC-BY-SA 4.0 remain part of the public repository; following account deletion your public-facing attribution is removed (pseudonymized) as described in Section 4.4, while a limited, non-public linking record is retained for legal-claims and licensing-integrity purposes (CLA §2A.4)
6. Data Security
6.1 Security Measures
We implement industry-standard technical and organizational measures to protect your information, including:
Technical Safeguards:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Secure authentication and password hashing (bcrypt)
- Regular security audits and penetration testing
- Intrusion detection and prevention systems
- Automated backup and disaster recovery
- Secure API authentication and rate limiting
Organizational Safeguards:
- Limited access to personal information on a need-to-know basis
- Employee training on data protection and security
- Confidentiality agreements with employees and contractors
- Vendor security assessments and data processing agreements
- Incident response and breach notification procedures
6.2 Limitations
While we take reasonable measures to protect your information, no security system is impenetrable. We cannot guarantee absolute security of data transmitted over the internet or stored on our systems. You are responsible for:
- Maintaining the confidentiality of your account credentials
- Using strong, unique passwords
- Enabling two-factor authentication (if available)
- Reporting any suspected security incidents
6.3 Security Incidents
In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law, typically within 72 hours of discovering the breach.
7. International Data Transfers
7.1 Cross-Border Transfers
SynC is based in the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate.
These countries may have data protection laws that differ from those in your country of residence.
Specifically, the third-party processors disclosed in Section 4.1 as of the Effective Date include:
- Cloudflare, Inc. (Web Analytics) — global processing infrastructure with US headquarters
- PostHog, Inc. (Product Analytics) — US-region cloud (
app.posthog.com) with US headquarters
- Functional Software, Inc. d/b/a Sentry (Error Monitoring) — US-region ingestion endpoint
As described in Section 4.1, this list reflects our current processors and is not exhaustive or permanent; a current subprocessor list is available on request.
7.2 GDPR Protections
For users in the EEA, UK, or Switzerland, we implement appropriate safeguards for international data transfers, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Additional technical and organizational measures to ensure data protection
7.3 Data Processing Addendum
Business customers may request a Data Processing Addendum (DPA) to formalize our data protection commitments. Contact privacy@synergyinconstruction.com to request a DPA.
8. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information:
8.1 Rights for All Users
Access and Portability:
- Request a copy of the personal information we hold about you
- Receive your data in a structured, machine-readable format
Correction:
- Update or correct inaccurate or incomplete personal information
- You can update most information directly in your account settings
Deletion:
- Request deletion of your personal information (subject to certain exceptions)
- Note: Anonymized data in AI models cannot be removed
- Note: SynC Standards contributions licensed under CC-BY-SA 4.0 remain in the public repository; your public-facing attribution is removed (pseudonymized) on account deletion as described in Section 4.4
Opt-Out of AI Training:
Opt-Out of Product Analytics and Session Replay:
- Request that your activity not be captured by our product-analytics processor (PostHog), including session replay
- Contact privacy@synergyinconstruction.com to opt out
- Where required by law, you may also decline non-essential cookies via the cookie controls described in Section 10
8.2 Additional Rights for EEA, UK, and Swiss Users (GDPR)
Right to Restriction:
- Request restriction of processing in certain circumstances
Right to Object:
- Object to processing based on legitimate interests
- Object to direct marketing at any time
Right to Withdraw Consent:
- Withdraw consent for processing based on consent (does not affect prior processing)
Right to Lodge a Complaint:
- File a complaint with your local data protection authority
8.3 California Residents (CCPA/CPRA Rights)
California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Right to Know:
- Request disclosure of categories and specific pieces of personal information collected
- Request disclosure of categories of sources, purposes, and third parties with whom we share information
Right to Delete:
- Request deletion of personal information (subject to exceptions)
Right to Opt-Out:
- We do not sell personal information, but you may opt out of sharing for cross-context behavioral advertising
Right to Correct:
- Request correction of inaccurate personal information
Right to Limit Use of Sensitive Personal Information:
- Request limitation of use of sensitive personal information (if applicable)
Right to Non-Discrimination:
- You will not receive discriminatory treatment for exercising your privacy rights
Authorized Agent:
- You may designate an authorized agent to make requests on your behalf
8.4 How to Exercise Your Rights
To exercise any of these rights, contact us at:
We will respond to verifiable requests within:
- 30 days for most requests
- 45 days for CCPA requests (with possible 45-day extension)
- As required by applicable law
We may need to verify your identity before processing your request.
9. Children's Privacy
The Services are not intended for children under the age of 18, and we do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly.
If you believe we have collected information from a child under 18, please contact us immediately at privacy@synergyinconstruction.com.
10. Cookies and Tracking Technologies
10.1 Types of Cookies We Use
Strictly Necessary Cookies:
- Essential for the Services to function (e.g., session management, authentication)
- Cannot be disabled without impairing functionality
Functional Cookies:
- Remember your preferences and settings
- Enhance user experience and personalization
Analytics Cookies:
- Collect information about how you use the Services
- Help us improve performance and user experience
- Our product-analytics processor (PostHog) sets first-party cookies on your browser to maintain a distinct identifier across sessions and to enable session replay. These are non-essential cookies. See Section 4.1 for the full disclosure of what PostHog receives and how sensitive content is masked.
Note on Web Analytics: Our current public-site web analytics processor (Cloudflare Web Analytics) is cookieless and does not set, read, or rely on any cookie or other persistent identifier on your device. See Section 4.1 for details. This is distinct from our product-analytics processor (PostHog), which does set cookies; the two processors serve different purposes and are deployed on different surfaces.
Marketing Cookies:
- Track your activity across websites for targeted advertising
- Only used with your consent (where required)
10.2 Cookie Management
You can control cookies through:
- Browser Settings: Most browsers allow you to refuse cookies or delete existing cookies
- Cookie Preference Center: Available in your account settings, where required by law you can decline non-essential cookies (including the product-analytics processor's cookies and session replay)
- Opt-Out Tools: Industry opt-out tools like Network Advertising Initiative or Digital Advertising Alliance
Note: Disabling certain cookies may limit functionality of the Services.
10.3 Do Not Track
Some browsers support "Do Not Track" (DNT) signals. Currently, there is no industry standard for how to respond to DNT signals. We do not currently respond to DNT signals.
11. Third-Party Links and Services
The Services may contain links to third-party websites, applications, or services that are not operated by SynC. This Privacy Policy does not apply to those third-party services.
We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you access.
Third-Party AI Services:
When you use AI features powered by third-party services, your interactions are subject to those providers' privacy policies:
12. Marketing Communications
12.1 Types of Communications
With your consent (where required), we may send you:
- Product updates and new feature announcements
- Educational content and best practices
- Industry news and insights
- Special offers and promotions
- Invitations to webinars and events
12.2 Opting Out
You may opt out of marketing communications at any time by:
Note: You cannot opt out of transactional emails (e.g., account notifications, password resets, billing statements) that are necessary for the Services.
13. Changes to This Privacy Policy
13.1 Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
13.2 Notice of Material Changes
When we make material changes, we will notify you by:
- Posting the updated Privacy Policy with a new Effective Date
- Sending email notification to your registered email address
- Displaying a prominent notice in the Services
13.3 Your Acceptance
Continued use of the Services after changes become effective constitutes your acceptance of the updated Privacy Policy. If you do not agree to the changes, you must discontinue use of the Services.
13.4 Review History
Previous versions of this Privacy Policy are available upon request by contacting privacy@synergyinconstruction.com.
13.5 Changes from Version 1.2
Version 1.3 (effective May 27, 2026) carries v1.2 forward in full and adds disclosures for one newly added third-party data processor:
- PostHog (Product Analytics + Session Replay) — a product-analytics and session-replay processor used to measure feature usage, conversion funnels, and qualitative drop-off across the application. Added to Section 4.1 with full disclosure of categories of data received (event data, identified user association after login, and session recordings), processing location (United States, PostHog US cloud at
app.posthog.com), session-replay input masking (typed text masked by default, password fields always masked, ph-no-capture DOM redaction), and the fact that PostHog sets first-party cookies on your browser.
- Section 3 (Legal Basis) was updated to add product-analytics processing under Legitimate Interests (subject to consent for non-essential cookies) and to call out the product-analytics processor's cookies and session-replay recordings under Consent.
- Section 5.1 (Data Retention) was updated to add retention notes for PostHog event data and session recordings, and to describe the deletion mechanism for identified product-analytics data.
- Section 7.1 (Cross-Border Transfers) was updated to add PostHog as an additional US-based recipient of transferred data.
- Section 8.1 (Rights for All Users) was updated to add an explicit opt-out for product analytics and session replay.
- Section 10.1 (Cookies) was updated to disclose that PostHog sets first-party cookies (in contrast to the cookieless Cloudflare Web Analytics processor), and Section 10.2 was updated to note that you can decline non-essential cookies (including PostHog) where required by law.
- Section 15.3 (CCPA categories disclosed) was updated to reflect that Internet activity is now disclosed to web-analytics, product-analytics, and error-monitoring providers.
No other substantive changes were made; all prior obligations, definitions, and user rights from v1.2 remain in effect.
13.6 Changes from Version 1.3
Version 1.4 (effective May 29, 2026) carries v1.3 forward in full and makes one clarifying change to how third-party processors are described. It does not add, remove, or change any processor, data category, processing purpose, safeguard, or user right.
- Section 4.1 (Service Providers and Processors) now states expressly that the named processors are those used as of the Effective Date, that the list is not exhaustive or permanent, that the categories of data, purposes, and safeguards described continue to apply to any processor performing the same function if a processor is later added, replaced, or discontinued, and that a current subprocessor list is available on request. The three analytics/observability processor headings (Web Analytics, Product Analytics, Error Monitoring) were reworded to identify each named vendor as our current processor for that function rather than as the sole permanent provider.
- Section 7.1 (Cross-Border Transfers) was conformed to describe the listed processors as those disclosed as of the Effective Date and to cross-reference the non-exhaustive framing in Section 4.1.
This change was made so that adding, replacing, or discontinuing a processor in the ordinary course — for the same function and within the same categories of data, purposes, and safeguards already disclosed — does not render this Policy inaccurate. A change of that kind is not, in itself, a material change; material changes (for example, a new category of data, a new processing purpose, or a new transfer destination) continue to be handled under Sections 13.1–13.3. No other substantive changes were made; all prior obligations, definitions, and user rights from v1.3 remain in effect.
13.7 Changes from Version 1.4
Version 1.5 (effective June 4, 2026) carries v1.4 forward in full and makes two corrections. It does not add, remove, or change any processor, data category, processing purpose, safeguard, or user right.
- Contributor-attribution treatment corrected and clarified as pseudonymization. Sections 4.4, 5.1, 5.2, and 8.1 were corrected to describe accurately what happens to your SynC Standards contributor attribution when you delete your account. The prior text stated that contributions remain in the public repository "with attribution." In fact, on account deletion your public-facing attribution is removed so that the public can no longer identify you (CLA §2A.3), while SynC retains a limited, non-public, access-restricted record linking each contribution to its contributor only as reasonably necessary for legal-claims and licensing-integrity purposes (CLA §2A.4). Because that retained record can in principle re-associate a contribution with you, the overall treatment of your contributor-attribution data is pseudonymization rather than anonymization for data-protection purposes. The contribution content itself continues to be retained under CC-BY-SA 4.0. This conforms the Privacy Policy to the Contributor License Agreement, Section 2A.
- Entity-name correction. The data controller is now identified consistently as "Synergy In Construction, LLC, a Wyoming limited liability company" (preamble and Section 14.1), correcting the prior description "a Wyoming corporation" to match the legal entity named in the Contributor License Agreement and the Terms of Service.
No other substantive changes were made; all prior obligations, definitions, and user rights from v1.4 remain in effect.
14. Contact Information
14.1 Data Controller
Synergy In Construction, LLC is the data controller responsible for your personal information.
Contact Details:
Synergy In Construction, LLC
30 N Gould St Ste N
Sheridan, WY 82801
United States
14.2 Privacy Inquiries
For questions, concerns, or requests regarding this Privacy Policy or our data practices, contact:
Privacy Team:
Email: privacy@synergyinconstruction.com
Subject Line: "Privacy Inquiry"
General Support:
Email: support@synergyinconstruction.com
14.3 Data Protection Officer
For GDPR-related inquiries, you may contact our Data Protection Officer:
Email: privacy@synergyinconstruction.com
Subject Line: "Attention: Data Protection Officer"
14.4 Response Time
We aim to respond to all privacy inquiries within:
- 5 business days for general inquiries
- 30 days for data subject rights requests (GDPR)
- 45 days for CCPA requests
15. Additional Disclosures
15.1 California "Shine the Light" Law
California Civil Code Section 1798.83 permits California residents to request certain information about disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
15.2 Nevada Privacy Rights
Nevada residents may opt out of the sale of certain personal information. We do not sell personal information as defined under Nevada law. If you have questions, contact privacy@synergyinconstruction.com.
15.3 Categories of Personal Information (CCPA)
In the past 12 months, we have collected and disclosed the following categories of personal information for business purposes:
Categories Collected:
- Identifiers (name, email, IP address)
- Commercial information (purchase history, subscription data)
- Internet activity (usage data, browsing history on our Services, session recordings)
- Geolocation data (city/region level)
- Professional information (job title, company)
- Inferences (preferences, characteristics)
- Sensitive personal information (account credentials)
Categories Disclosed for Business Purposes:
- Identifiers (to service providers for hosting, product analytics, support)
- Internet activity (to web-analytics, product-analytics, and error-monitoring providers)
- Commercial information (to payment processors)
Categories NOT Sold or Shared:
- We do not sell or share personal information for cross-context behavioral advertising
15.4 Data Processing Impact Assessment (DPIA)
We have conducted Data Protection Impact Assessments for high-risk processing activities, including AI training and automated decision-making. Summaries are available upon request.
Last Updated: June 4, 2026
Version: 1.5
This Privacy Policy was drafted to comply with applicable privacy laws, including GDPR, CCPA/CPRA, and other relevant regulations as of the Effective Date.
For questions or to exercise your privacy rights, please contact privacy@synergyinconstruction.com.