1. Introduction
SyncBooks ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cloud-based accounting, payroll, and AI-powered financial management platform. This policy complies with the Ghana Data Protection Act, 2012 (Act 843), the Ghana Revenue Authority Act (Act 896), and international data protection standards.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number, company name, business registration details
- Financial Data: Bank account details, transaction records, invoices, expenses, payroll information, tax records
- Payment Information: Credit card details, billing address (processed securely through third-party payment processors)
- Employee Data: Names, contact details, salary information, tax identification numbers, employment records
- AI Interaction Data: Questions, prompts, and conversations with our AI assistant
2.2 Automatically Collected Information
- Usage Data: Pages visited, features used, time spent, click patterns
- Device Information: IP address, browser type, operating system, device identifiers
- Cookies and Tracking: Session cookies, preference cookies, analytics cookies
- Log Data: Access times, error logs, system activity
3. How We Use Your Information
- Service Delivery: Provide accounting, payroll, invoicing, expense tracking, and reporting features
- AI Features: Process your queries through OpenAI's API to provide financial insights and automation
- Account Management: Create and manage your account, authenticate users, process payments
- Communication: Send transactional emails, service updates, security alerts
- Improvement: Analyze usage patterns to enhance features and optimize performance
- Security: Detect fraud, prevent unauthorized access, ensure data integrity
- Compliance: Meet legal obligations, tax reporting requirements, and regulatory standards
4. AI Data Processing
Our AI features are powered by OpenAI's GPT models. When you use AI features:
- Your prompts and financial data summaries are sent to OpenAI's API for processing
- OpenAI does not use your data to train their models (as per their enterprise agreement)
- AI conversations are stored in our secure database for your reference
- You can delete AI conversations at any time from your dashboard
5. Data Sharing and Disclosure
5.1 Third-Party Service Providers
- OpenAI: AI processing and natural language understanding
- Payment Processors: Paystack for payment processing
- Cloud Hosting: AWS, Vercel for infrastructure and hosting
- Email Services: For transactional and notification emails
5.2 Legal Requirements
We may disclose information to comply with legal obligations, court orders, or government requests.
6. Data Security
- Encryption: AES-256-CBC encryption for sensitive data, HTTPS/TLS for data in transit
- Access Controls: Role-based access, multi-factor authentication, session management
- Authentication: Secure JWT-based authentication with refresh tokens
- Monitoring: Activity logging and audit trails
7. Data Retention
- Active accounts: Data retained while your account is active
- After cancellation: Non-financial data deleted within 60 days; financial records retained for 7 years per Ghana Revenue Authority Act (Act 896)
- AI conversations: Until you delete them, or 60 days after account closure
- Audit logs: 2 years for active accounts
8. Your Rights (Ghana Data Protection Act)
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data (subject to 7-year statutory retention for financial records)
- Portability: Export your data in CSV, JSON, Excel, or PDF format
- Restriction: Limit how we process your data
- Objection: Object to processing for marketing purposes
- Withdraw Consent: Revoke consent for optional data processing
To exercise these rights, contact us at privacy@syncbooksapp.com
9. Google User Data
SyncBooks uses Google OAuth for authentication and may access Google services with your explicit consent. Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
9.1 What Google Data We Access
- Google Account Profile: Name, email address, and profile picture — used for authentication and account creation
- Google Drive (if connected): Write access to upload backup files to your Google Drive — used only for automated data backups you initiate
- Google Sheets (if connected): Read/write access to spreadsheets — used to push/pull financial data for reporting and bulk import
- Google Calendar (if connected): Create and manage events — used to sync tax filing deadlines, invoice due dates, bill payment dates, payroll dates, and project milestones to a dedicated "SyncBooks" calendar
- Gmail (if connected): Send-only access — used to send invoices, receipts, and documents from your own email address. We cannot read your inbox.
- Google Contacts (if connected): Read/write access — used to import contacts as customers or vendors, and to export new customers you create back to Google Contacts
- Google Forms (if connected): Create forms and read responses — used to create expense submission forms for your employees and import their responses as expense records
9.2 How We Use Google Data
- Authenticate your identity and create/manage your SyncBooks account
- Upload backup files to your Google Drive (only when you explicitly enable this feature)
- Sync financial data to/from Google Sheets for reporting
- Create calendar events for tax deadlines and payment due dates (only when you connect Google Calendar)
- Send invoices and business documents from your Gmail (only when you connect Gmail)
- Import/export contacts between SyncBooks and Google Contacts (only when you connect Google Contacts)
- Create expense submission forms and read responses (only when you connect Google Forms)
- We do NOT use Google data for advertising, marketing, or any purpose unrelated to providing our service
- We do NOT read your Gmail inbox, calendar events created by others, or contacts you haven't explicitly imported
9.3 Storage and Sharing
- Google OAuth tokens are encrypted (AES-256-CBC) and stored securely in our database
- We do NOT share Google user data with any third parties
- We do NOT sell Google user data
- Access tokens are refreshed automatically and old tokens are overwritten
- Each Google service requires separate authorization — connecting one does not grant access to others
9.4 Revoking Access
You can revoke SyncBooks' access to any Google service at any time:
- From within SyncBooks: Settings → Integrations → Disconnect
- From Google: Visit your Google Account Permissions page
- Revoking access immediately stops all data sync for that service
- Data already imported into SyncBooks (e.g., contacts, expenses) remains in your account unless you delete it
10. International Data Transfers
Your data may be transferred to and processed in countries outside Ghana, including the United States (OpenAI servers, Vercel, AWS). We ensure adequate safeguards through standard contractual clauses and data processing agreements.
11. Cookies and Tracking
- Essential Cookies: Authentication, security, session management (cannot be disabled)
- Functional Cookies: Remember preferences, language settings
- Analytics Cookies: Understand usage patterns (can be disabled)
12. Children's Privacy
SyncBooks is not intended for individuals under 18 years of age. We do not knowingly collect data from children.
13. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified via email and in-app notification 30 days before taking effect.
14. Contact Us
For privacy-related questions, requests, or complaints:
Data Protection Commission (Ghana): If you're not satisfied with our response, you can lodge a complaint at www.dataprotection.org.gh
© 2025 SyncBooks Ltd. All rights reserved. | syncbooksapp.com