Privacy Policy

Last updated: August 4, 2026

The short version

We store domains, never your customers’ email addresses. When we sync from Stripe, each customer email is parsed in-request to extract the company domain (e.g. jane@acme.com acme.com) and then discarded. The email address itself never touches our database, logs, or backups.

What we store

  • About you (the account holder): your email address, plan, and API key hashes. Your Stripe credential is stored only as AES-256-GCM ciphertext.
  • About your customers: company domains, subscription status, and logo assets. Nothing else.

What we never store

  • Your customers’ email addresses (parsed in-request, discarded).
  • Your customers’ names — the Stripe Customer.name field is never read at all. Display names come from Logo.dev brand data or are derived from the domain.
  • Card numbers or payment details of any kind.

Deletion

  • Erasure is immediate in production. Disconnecting Stripe or deleting your account hard-deletes the data right away.
  • Encrypted backups roll off within 30 days.
  • Restores re-apply deletions: if we ever restore from a backup, recorded erasures are replayed as a mandatory final step — a restore never resurrects deleted data.

Takedown for non-users

If your company’s logo appears on a wall we serve, you can have your domain removed without being a LogoSyncer user: /takedown. Requests are honored within 24 hours.

Subprocessors

  • VercelHosting and compute
  • NeonPostgres database
  • StripeOur own billing, and the read-only connection you authorize
  • Logo.devLogo resolution and CDN delivery
  • ResendTransactional email
  • SentryError monitoring (scrubbed of secrets and PII)
  • PostHogProduct analytics

Analytics

We use PostHog to understand how the product is used (signup funnel, API usage patterns). We don’t run third-party advertising trackers, and the embed script on your site phones home only to our own origin.

Contact

Privacy questions, data requests, anything else: abuse@logosyncer.com.