SYNC-Gift is committed to handling your data responsibly and in compliance with applicable privacy regulations, including Canada's PIPEDA, the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA/CPRA).
We process your personal data under the following legal bases:
If you are located in the EEA or UK, you have the following rights under GDPR:
To exercise these rights, contact our Data Protection Officer at dpo@sync-gift.com.
California residents have the right to:
Submit CCPA requests to privacy@sync-gift.com.
We collect, use, and disclose personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). You may withdraw consent at any time, subject to legal or contractual restrictions. Contact our Privacy Officer at privacy@sync-gift.com.
We retain personal data for as long as your account is active or as necessary to fulfil the purposes described in our Privacy Policy, comply with legal obligations, resolve disputes, and enforce agreements. Financial transaction records are retained for a minimum of 7 years as required by Canadian and US financial regulations.
Your data may be processed in Canada, the United States, or other jurisdictions where our service providers operate. We ensure appropriate safeguards are in place for any cross-border transfers, including Standard Contractual Clauses where applicable under GDPR.
We implement industry-standard security measures including AES-256 encryption at rest, TLS 1.3 in transit, bcrypt password hashing, role-based access controls, and regular security audits. KYC documents are stored in encrypted cloud storage with restricted access.
As a financial services platform, SYNC-Gift complies with applicable AML regulations. We may perform identity verification, monitor transactions for suspicious activity, and report to relevant authorities as required by law. We reserve the right to freeze accounts or transactions pending AML review.
For data-related enquiries contact dpo@sync-gift.com. If you believe we have not handled your data appropriately, you have the right to lodge a complaint with your local data protection authority (e.g., the Office of the Privacy Commissioner of Canada, or your EU supervisory authority).