This Privacy Policy explains how NearSync handles personal data when you visit our website, evaluate the product, or use the NearSync platform. NearSync is a multi-tenant business operations platform covering sales, communications, finance, people, and operations, with a built-in AI assistant.
The service is offered by Near Sync FZ LLC (Ras Al Khaimah, United Arab Emirates), trading as NearSync Technologies, with engineering and processing support from NearSync Technologies Private Limited (Srinagar, India). Together these entities are referred to as “NearSync”, “we”, or “us”. Full company details are on the Imprint.
Two deployment models
How we handle data depends on how you run NearSync:
- Managed. Your workspace runs on NearSync’s shared infrastructure (a managed PostgreSQL database on Supabase), where tenants are isolated by an organisation identifier and Row-Level Security. For personal data your team puts into the platform, you are the data controller and NearSync is your processor. See the Data Processing Agreement.
- Self-hosted (BYOK). The platform runs against your own Supabase project and infrastructure. You control and host the data; NearSync provides the software and support. In this model NearSync does not operate your production database.
This Privacy Policy describes NearSync’s own processing - the website, your account, billing, and the Managed infrastructure we run. For customer content inside your workspace, the DPA governs.
What we collect
- Account and identity data: name, work email, organisation, role, and authentication details.
- Billing data: plan, billing contact, and payment status. Card details are handled by Stripe and are not stored by NearSync.
- Usage and device data: log data, IP address, browser and device type, pages viewed, and feature interactions, used to run and secure the service.
- Support and sales data: messages you send us, demo requests, and onboarding notes.
- Customer content (Managed): the records your team creates in the platform (contacts, deals, invoices, messages, documents, and similar). We process this on your instructions as your processor.
How we use personal data
We use personal data to provide and secure the platform, authenticate access, process payments, respond to support and sales enquiries, send service and (where permitted) product messages, and meet legal obligations. We do not sell personal data.
Legal bases
Where the GDPR or similar laws apply, we rely on: performance of a contract (providing the service and billing), legitimate interests (securing, improving, and supporting the service), consent (non-essential cookies and marketing email, which you can withdraw), and legal obligation (tax and compliance records).
Connected email and calendar accounts
Users can connect their own Google or Microsoft work account to NearSync. When you connect an account, we request the narrowest permissions the features need:
- Sending email (Google
gmail.send, MicrosoftMail.Send): emails you compose in NearSync are sent through your own connected account so they come from your real work address. We do not read, modify, or delete anything in your mailbox, and we do not request read access to it. - Calendar events (Google
calendar.events, MicrosoftCalendars.ReadWrite): we sync events between your connected calendar and your NearSync calendar, push events you create or change in NearSync back to your provider, send your RSVP responses, and create booking events when someone books a meeting through your booking page. We do not create or delete calendars themselves. - Files you pick (Google
drive.file): when you attach a file to an email, you choose it in the provider’s own file picker. We can only access the specific files you select, never the rest of your drive.
Access tokens for connected accounts are stored encrypted and used only to provide these features to you. Data obtained through these permissions is not sold, is not shared with third parties except as needed to deliver the feature you invoked, is not used for advertising, and is never used to train AI models. Disconnecting the account in NearSync deletes the stored tokens, and you can also revoke NearSync’s access at any time from your Google or Microsoft account security settings.
Your connected account is for individual business correspondence only: emails you personally compose and send to people you have a business relationship with. It is never used for bulk, automated, or scheduled sending. Email campaigns and sales cadences run on NearSync’s own sending infrastructure with your separately verified sending domain - never through your connected Google or Microsoft account - and every such email carries a working unsubscribe link and one-click unsubscribe headers. Recipients who opt out are excluded from all future campaign and cadence sends. You must not use NearSync, including your connected account, to send unsolicited mail or to contact recipients who have not consented or have opted out; doing so violates our Acceptable Use Policy and can lead to suspension. NearSync does not supply a database of leads or contact details: contact records exist because you or your team added them, imported them, or connected a third-party data provider under your own agreement with that provider.
NearSync’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI processing
The platform uses third-party AI models to power features such as search, drafting, and analysis. We do not use your customer content to train public or foundation AI models. On Managed, prompts and the necessary context are sent to our AI providers solely to return a result to you. Self-hosted customers may configure their own AI providers and keys. See sub-processors below.
Sharing and sub-processors
We share personal data only with service providers that help us run NearSync, under contract and limited to what each needs. Current sub-processors include:
| Sub-processor | Purpose |
|---|---|
| Supabase | Managed database, auth, and storage |
| Vercel | Website and application hosting, CDN |
| Stripe | Subscription billing and payments |
| Google Cloud (Vertex AI / Gemini) | AI features and embeddings |
| OpenAI, Anthropic | AI model providers |
| Resend | Transactional and notification email |
| Twilio | Voice and SMS, where enabled |
| Sentry | Error monitoring |
We may also disclose data where required by law, or in connection with a merger or acquisition, subject to appropriate safeguards.
International transfers
NearSync operates between the UAE and India, and our sub-processors may process data in other regions. Where personal data is transferred across borders, we rely on appropriate safeguards such as Standard Contractual Clauses and equivalent mechanisms, together with technical protections described below.
Retention
We keep account and billing records for as long as your account is active and as required for tax and legal purposes afterwards. Customer content on Managed is retained per your workspace settings and the DPA, and is deleted or returned on termination as described there.
Security
We protect data with encryption in transit (TLS 1.3) and at rest (AES-256), tenant isolation through Row-Level Security, least-privilege access controls, and audit logging. No system is perfectly secure, but we work to protect personal data proportionate to its sensitivity.
Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or restrict certain processing. For customer content held in a workspace, please contact the workspace owner (the controller); we will assist them as processor. To exercise rights over data NearSync controls, email privacy@nearsync.ai.
Children
NearSync is a business tool and is not directed to children under 16. We do not knowingly collect their personal data.
Changes
We may update this Policy as the product and our practices evolve. Material changes will be posted here with a new effective date, and where appropriate we will notify account owners.
Contact
Privacy questions: privacy@nearsync.ai. General contact and registered addresses are on the Imprint.
Questions about this document? Write to legal@nearsync.ai. Company details are on the Imprint.