Privacy Policy
Last updated: August 4, 2026
The short version
We store domains, never your customers’ email addresses. When we sync from Stripe, each customer email is parsed in-request to extract the company domain (e.g. jane@acme.com → acme.com) and then discarded. The email address itself never touches our database, logs, or backups.
What we store
- About you (the account holder): your email address, plan, and API key hashes. Your Stripe credential is stored only as AES-256-GCM ciphertext.
- About your customers: company domains, subscription status, and logo assets. Nothing else.
What we never store
- Your customers’ email addresses (parsed in-request, discarded).
- Your customers’ names — the Stripe
Customer.namefield is never read at all. Display names come from Logo.dev brand data or are derived from the domain. - Card numbers or payment details of any kind.
Deletion
- Erasure is immediate in production. Disconnecting Stripe or deleting your account hard-deletes the data right away.
- Encrypted backups roll off within 30 days.
- Restores re-apply deletions: if we ever restore from a backup, recorded erasures are replayed as a mandatory final step — a restore never resurrects deleted data.
Takedown for non-users
If your company’s logo appears on a wall we serve, you can have your domain removed without being a LogoSyncer user: /takedown. Requests are honored within 24 hours.
Subprocessors
- Vercel — Hosting and compute
- Neon — Postgres database
- Stripe — Our own billing, and the read-only connection you authorize
- Logo.dev — Logo resolution and CDN delivery
- Resend — Transactional email
- Sentry — Error monitoring (scrubbed of secrets and PII)
- PostHog — Product analytics
Analytics
We use PostHog to understand how the product is used (signup funnel, API usage patterns). We don’t run third-party advertising trackers, and the embed script on your site phones home only to our own origin.
Contact
Privacy questions, data requests, anything else: abuse@logosyncer.com.