Our Privacy Commitment to Bookkeepers & Businesses
At Sync2Zero (sync2zero.com), we recognize the sensitive nature of financial invoices, supplier bills, and accounting ledgers. We do not sell your personal data or uploaded documents, and we never use your financial documents to train public artificial intelligence models.
1. Information We Collect
We collect information in the following ways when you interact with Sync2Zero:
Account Information: When you register an account, we collect your name, email address, hashed passwords, and authentication provider identifiers (such as Google OAuth profile IDs).
Uploaded Invoice & Bill Files: When you upload PDF, PNG, JPG, or WEBP invoice files for conversion, our systems temporarily process the document content (supplier names, line items, amounts, tax codes) to generate the structured extraction.
Usage & Transaction Logs: We track monthly conversion credit consumption, timestamped extraction logs, document filenames, and total invoice sums to populate your cloud dashboard history.
Technical & Analytics Data: IP addresses, browser types, session cookies, and anonymized telemetry to safeguard against abuse, enforce rate limits, and optimize web performance.
2. AI Processing & Subprocessors
Sync2Zero utilizes secure enterprise AI vision APIs (such as Google Gemini API) to perform optical character recognition (OCR) and tabular data structuring.
🔒 AI Confidentiality Guarantee:
Under our enterprise API configuration, customer-submitted documents and extracted line items are processed via encrypted endpoints and are NOT stored or used by AI providers to train, fine-tune, or improve public AI foundation models.
3. Data Security & Encryption
We implement industry-standard administrative, physical, and technical safeguards to protect your data:
Encryption in Transit: All web traffic and API communications are encrypted via TLS 1.3 (HTTPS) with strong cipher suites.
Encryption at Rest: Database records, user credentials, and session tokens are encrypted at rest using industry-standard AES-256 protocols.
Credential Security: Passwords are cryptographically salted and hashed using bcrypt (12 rounds) and are never stored in plaintext.
4. Cookies and Session Storage
We utilize essential first-party cookies to manage user authentication (NextAuth session tokens), remember theme preferences, and track guest usage rate limits. We do not use third-party cross-site advertising cookies.
5. Your Rights (GDPR & CCPA Compliance)
Depending on your location (including the European Economic Area, United Kingdom, California, and other jurisdictions), you possess certain rights regarding your personal data:
Right to Access: Request a copy of the personal information we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete profile records.
Right to Erasure ("Right to be Forgotten"): Request deletion of your account and conversion history directly from your dashboard or via email.
Right to Data Portability: Export your extraction history and line items in CSV or Excel formats at any time.
6. Privacy Inquiries & Data Requests
To exercise any of your data rights or if you have privacy-related questions, please contact our Data Protection team at:
Email: business@sync2zero.com Subject: Privacy / Data Request