Legal
Privacy Notice
How Northstar Prosperity Group LLC handles personal data in SyncedTAI. This document is a draft prepared by the service operator for review and has not been reviewed or approved by legal counsel.
Northstar Prosperity Group LLC · Last updated 16 September 2026
1. Who we are
Northstar Prosperity Group LLC operates SyncedTAI and is the data controller for the personal data described in this notice — we decide what is collected and why.
Where you use SyncedTAI to send your own customers' or systems' data through the service, you are the controller of that data and we act as your processor, handling it only to provide the service to you.
2. What we collect and why
- Account data — email address and sign-in credentials, held to create and secure your account. Legal basis: performance of our contract with you.
- Workspace configuration — workspace and connection names, destination addresses, field mappings, and notification preferences, held to provide the service. Legal basis: contract.
- Endpoint credentials — secrets you supply for your destination systems, encrypted at rest with AES-256-GCM in a store that only our server can decrypt. The browser only ever sees a masked hint. Legal basis: contract.
- Event and delivery data — the payloads you send us, their converted form, delivery attempts, status codes and error messages, held so the service can deliver, retry, replay and show history. This may contain personal data that you choose to send. Legal basis: contract.
- Operational and security data — IP addresses, request rate counters, timestamps and audit records of actions taken in a workspace, held to prevent abuse and to give you an accurate activity trail. Legal basis: our legitimate interest in keeping the service secure and accountable.
- Support messages — the subject, description and safe diagnostic summary you choose to send from the Support screen. Diagnostics contain counts and connection names only; never event contents, ingest keys, passwords, or payment details. Legal basis: contract and legitimate interest in supporting you.
We do not see or store payment card numbers, CVVs, or bank credentials. Payment data is collected and held by Paddle, our Merchant of Record.
3. Who we share it with
- Infrastructure and database providers that host the application and store its data.
- Our email provider, used to send failure, recovery and account notifications to the address you configure.
- Paddle, our Merchant of Record, for the sale of subscriptions, subscription management, payments, tax compliance and invoicing.
- Professional advisers such as legal and accounting support, where necessary.
- Authorities, where we are legally required to disclose information.
The destinations you configure receive the data you instruct us to deliver to them. You choose those destinations, and their own handling of that data is outside our control.
We do not sell personal data, and we do not use your event contents to train models.
4. International transfers
Our infrastructure providers may process data outside your country, including outside the UK and EEA. Where that happens, transfers are made under appropriate safeguards such as standard contractual clauses or an adequacy decision.
5. How long we keep it
- Account and workspace configuration: for as long as your account exists.
- Event, delivery and audit records: retained while your workspace exists so you can inspect, retry and replay them.
- Support requests and billing event history: retained while your account exists, and afterwards where needed for legal, tax or accounting obligations.
- After account closure: data is deleted or anonymised once it is no longer needed for the purposes above, or for any retained legal obligation.
Cancelling a subscription does not delete your data — connections are paused and history is preserved.
6. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, have it erased, restrict or object to its processing, receive it in a portable form, and withdraw consent where processing relies on consent. You also have the right to complain to your data protection supervisory authority. Where the UK GDPR or EU GDPR applies, we will respond within one month.
To exercise any of these rights, contact us through the Support screen in SyncedTAI.
7. Security
We apply appropriate technical and organisational measures, including encryption of endpoint credentials at rest, database-level isolation between workspaces, signed and replay-protected webhook ingestion, rate limiting, one-time display of ingest key secrets, and an append-only audit trail. No system is perfectly secure, but we work to keep these controls effective and to fix weaknesses promptly.
8. Cookies and similar technologies
SyncedTAI uses only essential storage: a session token that keeps you signed in and preferences needed for the interface to work. We do not use advertising or cross-site tracking cookies. Clearing your browser storage signs you out.
9. Changes to this notice
We will update this notice as the service changes, and the date at the top shows when it was last revised.
10. Contact
Use the Support screen inside SyncedTAI to reach us about privacy. For payment-related data held by our Merchant of Record, contact Paddle at paddle.net. Our Terms of Service explain the wider agreement between us.