Privacy Policy
Last updated: August 5, 2026
The short version
We store company domains, never your customers’ email addresses. When we sync from Stripe, each customer record’s email field is parsed in-request to extract the registrable company domain (jane@acme.com → acme.com) and the address is then discarded. It never reaches our database, our logs, or our backups. We never read the customer’s name field at all, and we never see card data.
Who we are, and how to reach us
LogoSyncer is operated by Kraftscale GmbH, a limited liability company (GmbH) incorporated in Switzerland. Kraftscale GmbH is the controller of the account data described below and the processor of the subscriber-domain data we handle on your instruction.
For anything about privacy (access, deletion, questions, or a report about a logo you have seen), write to abuse@logosyncer.com. That is also our privacy contact address: it is a real inbox read by a human, and we would rather point you at one that works than publish a second one that nobody watches.
We have not appointed a data protection officer. Privacy requests go to the address above and are handled by us directly. We hold no certifications, audit reports, or attestations, and we do not claim any.
Depending on where you and your customers are, Swiss and EU data-protection rules may both be relevant to this processing: the Swiss FADP because Kraftscale GmbH is a Swiss company, and the GDPR where you or your data subjects are in the EEA. We describe our practices below in GDPR terms because they are the more detailed of the two; that is a drafting choice, not a claim about adequacy, certification, or any formal status.
Two different roles
Which rules apply depends on whose data it is, so it’s worth being precise:
- We are the controller of data about our own account holders: your email address, your plan, your billing records, your API key hashes, your audit trail. We decide why and how that is processed, and this policy is our notice to you about it.
- We are a processor of the subscriber-domain data we derive from your connected Stripe account. You instruct us to read it; you decide which companies appear and what your site says about them. You are the controller of that data, and you are responsible for what you publish on your own website. The terms of that processing are in the section below.
If you are a company whose logo appeared on someone’s website and you found us from that page: we are the processor, not the publisher. See “If your company appears on a wall”.
What we store
- Account email address: Sign-in, verification, billing and service notices. Until you delete the account.
- Plan, billing customer id, account timestamps: Running the plan you are on. Until you delete the account; billing records may be kept longer where tax or accounting law requires it.
- API keys: Authenticating your API and MCP calls. Stored as a SHA-256 hash plus an 8-character public prefix, never the secret itself. Until revoked or the account is deleted.
- Stripe connection credential: Reading your customers, subscriptions and events. AES-256-GCM ciphertext bound to your account, never plaintext. Deleted the moment you disconnect.
- Company domains (e.g. acme.com): The wall itself: which companies appear, their rank, subscription-status rollups, logo status. Until the domain stops being eligible and you delete it, or you delete the account. This is the only subscriber-derived data we keep.
- Verification codes: Proving you control the signup inbox and the connected Stripe account's inbox. Hashed, single-use, 15-minute expiry.
- Audit events: A record of security-relevant actions (connections, publishes, unpublishes, reports received). Retained while the account exists; deleted with the account.
- Rate-limit counters: Abuse prevention. A hashed key plus a counter and window. Rolls off with the window (typically minutes to an hour).
If you send us a report about a listing, we also keep the domain, the contact address you gave us, and your note, as a record that the report was received and forwarded. It is used only for that, never for marketing, and never added to any logo wall.
What we never store
- Your customers’ email addresses. Parsed in-request, discarded. Personal-inbox domains (gmail.com and friends) and disposable domains are filtered out entirely and never become a wall entry.
- Your customers’ names. The Stripe
Customer.namefield is never read. Display names come from the logo provider’s brand data or are derived from the domain itself. - Card numbers or payment details of any kind, yours or your customers’. Payments run through Stripe Checkout; we never see the card.
- Amounts, invoices, or line items from your Stripe account. We read subscription status, not what anyone paid.
A work email domain is about as little as a customer list can be reduced to and still be a customer list. That is the deliberate design: the minimization is structural, not a policy promise we could quietly drop.
Legal bases (GDPR Art. 6)
- Performance of a contract (running the service for you): your account, the sync, the wall, billing.
- Legitimate interests: keeping the service secure and abuse-free (rate limiting, audit events, error monitoring) and understanding how the product is used in aggregate (analytics). We have weighed these against your interests; the data involved is minimal and none of it is used to profile individuals.
- Legal obligation: keeping billing and tax records, and responding where the law requires it.
- For subscriber-domain data we process on your instruction, the legal basis is yours to determine as controller. See below.
Cookies and analytics
ls_session: strictly necessary. A signed, httpOnly, SameSite=Lax cookie that keeps you signed in to the dashboard for 7 days. It contains only your account id and an expiry. No consent banner is needed for it because the service cannot work without it.- PostHog: product analytics. Loaded on our own marketing site and dashboard only, with autocapture off and session recording off. It sets a pseudonymous identifier so we can see funnels (signup → verified → connected → embed live). We respect Do Not Track: if your browser sends DNT, PostHog is never initialized at all.
- Nothing on your website. The embed script sets no cookies and uses no storage. It fetches the wall JSON from our origin and sends one anonymous render beacon (the wall’s public id and the preset name, no visitor identifier). We run no advertising trackers anywhere.
Subprocessors
We use these third parties to run the service. Each receives only what it needs:
- Vercel: Hosting, CDN and serverless compute (US and EU edge). Everything the service serves or receives passes through it: wall JSON, API requests, IP addresses in request logs.
- Neon: Managed Postgres database. The stored data described above: account email, hashed API keys, encrypted Stripe credentials, company domains, audit events.
- Stripe: Our own billing, and the read-only connection you authorize. Your billing details for Pro (Stripe is the controller of its own payment data). In the other direction, Stripe is the source we read your customer records from.
- Logo.dev: Logo images and brand names. The company domain we are resolving a logo for. Because logo images are served from their image CDN, your site visitors' browsers also make a request there per logo (no cookies, no LogoSyncer identifier).
- Resend: Transactional email. The recipient email address and the message: verification codes, connection alerts, billing notices, forwarded reports.
- PostHog: Product analytics. Pageviews and product events for our own site and dashboard, with a pseudonymous identifier. Not loaded on your website, and not used for advertising.
- Sentry: Error monitoring. Stack traces and request metadata from server errors, scrubbed of secrets and key-shaped values.
We’ll update this list before adding or replacing a subprocessor, and account holders can ask to be notified of changes at abuse@logosyncer.com.
International transfers
Several of the providers above are US-based or operate globally, so data may be processed outside the EEA, the UK, and Switzerland. Where that happens we rely on the transfer mechanisms those providers offer: Standard Contractual Clauses, and their certification under the EU–US Data Privacy Framework where applicable. The data involved for your subscribers is company domains, which is about the least sensitive form this could take.
Your rights
If you are in the EEA, the UK, or Switzerland you have the rights to access, rectification, erasure, restriction, portability, and objection; similar rights exist under other laws, including California’s. We do not sell personal data and we do not share it for cross-context behavioural advertising.
- If you are an account holder: most of it is self-serve. The dashboard shows your data, lets you disconnect Stripe, and deletes your account outright. For anything else, email abuse@logosyncer.com from your account address and we’ll respond without undue delay and within one month, as the GDPR requires.
- If you are a listed company: see the next section.
- You may also complain to your supervisory authority: in Switzerland the FDPIC, in the EU your national DPA.
If your company appears on a wall
The website you saw the logo on is run by our customer, and they decide what appears on it; they hold the exclusion controls and the relationship with you. For that data we are the processor and they are the controller, so a request to be removed is theirs to act on. The fastest route is to contact them directly.
You can also tell us at /takedown or abuse@logosyncer.com. We forward reports to the account holder responsible for that wall, and we will suppress an asset across the service where we are legally required to. We do not commit to a response time and we cannot guarantee removal from someone else’s website.
Processing on your behalf
This section sets out the terms on which Kraftscale GmbH (the processor) processes subscriber-domain data on behalf of the account holder (the controller). It forms part of the terms of service and applies for as long as you have an account.
- Parties: you, the account holder, as controller; Kraftscale GmbH, Switzerland, operator of LogoSyncer, as processor.
- Subject matter: deriving company domains from your connected Stripe account, resolving a logo for each, and serving the result as a wall.
- Duration: for as long as your account exists, ending on deletion or disconnection.
- Nature and purpose: collection by API read, extraction, storage, organization (ranking, exclusion), and disclosure by publishing the wall you configure, all on your documented instruction, which is your use of the dashboard and API. We process it for no other purpose, and we do not sell it or use it to train anything.
- Categories of personal data: business domain names, plus the subscription-status rollups attached to them. No names, no email addresses, no contact details, no payment data. No special-category data under Art. 9.
- Categories of data subjects: your business customers. In most cases a company domain is not personal data at all; where a one-person business uses its own domain, it can be.
- Confidentiality: anyone with access is bound to confidentiality.
- Security: the measures summarized below and in /docs/security, appropriate to the risk of data that is business domains only.
- Subprocessors: you give general authorization for the subprocessors listed above. We’ll update this page before engaging a new one, and you may object; if you do and we can’t resolve it, you can terminate.
- Assistance: we’ll help you respond to data-subject requests (the exclusion controls do most of this on their own), and give you the information you need for a DPIA or for your own accountability records.
- Breach notification: we notify you without undue delay after becoming aware of a personal-data breach affecting your data, with what we know and what we’re doing about it.
- Deletion: on termination we delete the data as described under “Deletion and backups”. Nothing is retained beyond what law requires.
- Audit: we’ll answer reasonable written questions about this processing and make available the information needed to demonstrate compliance. We hold no third-party audit report or certification and do not claim one.
Security
Stripe credentials are AES-256-GCM ciphertext before they touch the database, with key versioning and the ciphertext bound to its owning account. Stripe access is read-only by construction: we never hold a credential that can write or move money. A wall serves publicly only after a publish gate that requires a verified signup inbox and proof of control over the connected Stripe account. API keys are stored as hashes. Full details: /docs/security.
Deletion and backups
- Erasure is immediate in production. Disconnecting Stripe or deleting your account hard-deletes the data right away.
- Encrypted backups roll off within 30 days. Backups are envelope-encrypted; Stripe credentials are already ciphertext before they reach one.
- Restores re-apply deletions. If we ever restore from a backup, recorded erasures are replayed as a mandatory final step; a restore never resurrects deleted data.
Breach notification
If a breach affects personal data we hold, we notify affected account holders without undue delay, and the relevant supervisory authority within 72 hours where the law requires it. Where we are your processor, we notify you so you can meet your own obligations as controller.
Children
LogoSyncer is a business tool and is not directed at children. We don’t knowingly collect data from anyone under 16. If you believe we have, write to abuse@logosyncer.com and we’ll delete it.
Changes to this policy
We’ll post material changes here with a new “last updated” date and email account holders before they take effect. The subprocessor list is updated in place as it changes.