Synhelm
Privacy Policy
Last updated September 15, 2026.
Draft for lawyer review. Not legal advice. Do not treat this as a certification or a finished contract.
Who we are
This Privacy Policy describes how the operator of Synhelm (“we”, “us”) handles information when you use Synhelm — the website, the office app, the crew home, and related services (together, the “Service”).
This is a draft for lawyer review. It is not a certification of PIPEDA, CCPA/CPRA, GDPR, or any other regime. Do not publish it as final until counsel has signed off.
Whose information we handle
Business owners create a shop in Synhelm and invite office admins. Field crew sign in with a PIN on a shop link — they do not get a website account.
A shop may store information about its own employees, clients, jobs, and documents. That shop is the controller of its business records. We process that information to provide the Service.
Information we collect
Account: name, email, password (stored hashed by the sign-in service), and shop profile (company name, address, logo, hours, tax, terms).
Operations: clients, jobs, tasks, time punches, time-off requests, safety answers, chat messages, estimates, invoices, and related files.
Photos and files you upload, including captions and optional drawings.
Location, only when a shop turns on location stamps and the device allows it — typically a GPS point on a clock punch or a photo. We do not silently track people in the background.
Payments: if card pay is on, a processor token, last four digits, and brand. Full card numbers are not stored in the Service.
Device and diagnostics: pages visited in-app, approximate browser/device, timestamps, and error reports you send or that the app records (with secrets stripped).
We do not require children’s accounts. The Service is for businesses.
How we use information
To run the shop you signed up for: time, jobs, paper, photos, chat, and settings.
To send estimates, invoices, and transactional mail when you ask us to send them. Envelope-from is our mail service; Reply-To is your shop email.
To bill the monthly plan when you subscribe, and to let your clients pay an invoice by card when you turn that on.
To keep the Service reliable: health, error reports, and abuse prevention.
We do not sell personal information. We do not use shop data to train public AI models.
Where information lives and who sees it
Each shop’s records are isolated by shop. A customer shop cannot open another shop. Platform operators (our staff) may open a shop profile only to diagnose a problem you report.
Processors we use may include hosting/database, sign-in, email delivery, and card processing. They see only what they need to perform that job.
Crew PINs identify a person on a kiosk. Treat the crew link like a worksite tool — do not post it publicly.
Retention
We keep shop data while the account is open. Operational logs are pruned on a rolling window (currently about 14 days).
If you close a shop, we will delete or anonymize personal information within a reasonable period unless law requires a longer hold (for example, tax or dispute records).
You can export shop data from Settings while the account is open.
Your choices and rights
Shop owners can correct profile, crew, client, and job records in the app, and can export a copy.
If you are in Canada, you may have rights under PIPEDA and applicable provincial law, including access and correction. If you are in the United States, you may have rights under applicable state law (for example access, deletion, or opt-out of certain sharing). If you are in the UK or the European Union, you have rights under the GDPR, including access, correction, deletion, and objection. If you are in Australia, the Privacy Act 1988 may apply. We will not pretend those statutes do not apply — and we will not claim we are certified under them until counsel says so.
To make a privacy request, use the Contact page. We may need to verify that you are the shop owner or an authorized person.
Cookies and similar tech
We use a session cookie or equivalent so owners stay signed in. Crew PIN sessions are stored on the device. We do not run advertising pixels in the product.
Changes
We will post updates here and change the date at the top. Material changes should be announced in the product or by email to the shop owner when the Service is in production.
Contact
Use the Contact page in Synhelm until a dedicated privacy inbox is published.