This policy explains what personal data Syntaximos collects, why, and what you can do about it. It is written to describe what our software actually does rather than to cover every possibility, so where it says we do not collect something, we do not collect it.
Syntaximos is operated by Syntaximos LLC, 30 North Gould Street, Sheridan, WY 82801, United States ("we", "us"). You can reach us at support@syntaximos.com or through syntaximos.com/contact.
What this policy covers
This policy covers the Syntaximos website at syntaximos.com and your Syntaximos account.
Our browser extensions are separate software that runs inside your browser, and each one has its own privacy policy describing what it does on your machine. Those policies are linked from each extension's page and from its Chrome Web Store listing. The Shotdex extension's policy is at syntaximos.com/extension/shotdex/privacy. Nothing in this policy describes what an extension does, and nothing in an extension's policy describes what this website does.
The short version
- We collect an email address, a username, a first and last name, and a country when you register. That is the whole of it.
- We do not use analytics. There is no Google Analytics, no Google Tag Manager, no Facebook pixel, no Hotjar, no session recording, and no third-party analytics of any kind on this site.
- We do not track you across the web, and we do not run advertising cookies.
- We never see your card details. Payments go directly to Stripe.
- We never sell your personal data and never share it for anyone else's advertising.
- Deleting your account is immediate and permanent, and you can do it yourself.
1. What we collect
1.1 Your account
When you register we store:
| Field | Why |
|---|---|
| Email address | Identifies your account; used for sign-in, password resets, licence and receipt messages, and support replies |
| Username | Shown to you in the dashboard |
| First name, and last name if you give one | Used to address you in the dashboard and in email |
| Country | Used for tax and for showing relevant pricing |
| Password | Stored only as a bcrypt hash. We cannot read it or recover it |
| Sign-in method | Whether you registered with an email address or with Google |
| Account timestamps | When you registered and when your account was last changed |
| Whether your email is verified | Tells us whether you still need to confirm your address |
| Your Stripe customer reference, and which plans you hold | See section 1.3 |
If you sign in with Google, we receive your email address, name and profile picture from Google. We do not receive your Google password, and we ask for nothing beyond basic profile information.
1.2 What we do not collect
We want to be specific, because generic privacy policies tend to claim more than the software does. Syntaximos does not collect:
- Your phone number.
- Your street address, city, state or postal code.
- Your date of birth, gender, or any demographic profile.
- Any special category data — health, biometrics, political or religious views, or anything similar.
- Your browsing history, or any record of the sites you visit.
There are no fields for these anywhere in our system.
1.3 Payments
Payments are processed by Stripe. Your card number never reaches our servers and is never stored by us — it goes directly from your browser to Stripe.
What we keep is a Stripe customer reference against your account, the plan you bought, and its status. Stripe sends us a record of each payment event, which we store so we can answer questions about your subscription and reconcile our records. That record contains the billing details Stripe collected from you at checkout, which may include your name, email address and billing address. Stripe is an independent controller of the data you give it; its privacy policy is at stripe.com/privacy.
1.4 Server logs
Our servers keep a technical log of each request, containing the request's URL and method, the response status and timing, a request identifier, your IP address, and your user ID if you were signed in. This is what lets us investigate a fault you report and detect abuse.
Session cookies, authorization headers, passwords, tokens and secrets are automatically stripped from these logs before they are written. We do not log request bodies.
1.5 Advertising attribution
When you arrive from one of our ads, we count the visit against that ad campaign. What we store is a counter per campaign — the campaign and ad name and identifier, the source, and a number of visits. No user ID, no IP address and nothing else personal is stored with it, and it cannot be traced back to a person. It tells us that an ad produced fifty visits, not who those fifty people were.
2. Cookies
We use cookies only to make signing in work. There are no advertising cookies and no analytics cookies on this site.
| Cookie | Purpose | Lifetime |
|---|---|---|
SYNUID | Your user ID | Session |
SYNA | Signs you in | 15 minutes, renewed automatically |
SYNR | Lets your session renew without re-typing your password | 7 days |
SYNEMAILVERIFY | Carries you through email verification | Short-lived |
SYNREDIRECT | Remembers where to send you back to after signing in | 30 minutes |
SYNFM, SYNSD | Tells the Fiverr Mate and Shotdex extensions that you are signed in | 7 days |
All of these are first-party, strictly functional, and set by us. Clearing them signs you out and does nothing else.
Google reCAPTCHA (section 3) sets its own cookie when it loads.
3. Third parties
We use as few as possible. This is the complete list.
| Service | What it does | What it receives |
|---|---|---|
| Stripe | Takes payments and manages subscriptions | Your card details, name, email and billing address, given directly to Stripe at checkout |
| Google reCAPTCHA v3 | Stops automated abuse of our forms. It loads on every page of this site | Your IP address, and browser and interaction signals that Google uses to score whether you are human |
| Google Sign-In | Optional way to register and sign in | Only used if you choose it |
| Our email provider | Delivers account and product email | Your email address and the message |
| Our hosting provider | Runs our servers | Everything above, as the infrastructure it is stored on |
Every one of these processes data on our instructions, except Stripe and Google, which are also independent controllers of what they collect. Their policies: stripe.com/privacy and policies.google.com/privacy.
We do not use any analytics, advertising, attribution, error-reporting, chat, heatmap, or session-recording service.
4. How we use it
- To create and run your account, and to sign you in.
- To give you the extensions and features you are entitled to.
- To take payment and to send you receipts and licence information.
- To answer you when you contact support.
- To keep the service secure and working, and to investigate faults and abuse.
- To send you product news, only if you asked for it — see section 5.
We do not make any decision about you by automated means that has a legal or similarly significant effect.
5. Email
Account email is not optional. Password resets, email verification, receipts and licence changes are part of running your account, and we will send them.
Product news is optional. You choose at signup whether you want it, every such email carries a one-click unsubscribe link, and unsubscribing takes effect straight away. Unsubscribing from product news does not stop account email.
We never give your email address to anyone else for their own marketing.
6. How long we keep things
| Data | Retained |
|---|---|
| Your account | Until you delete it. |
| Password-reset sessions | 1 hour, then deleted automatically. |
| Payment and subscription records | 1 year. Stripe keeps its own record independently, under its policy. |
| Server logs | 90 days, then deleted. |
| Advertising counters | Indefinitely — they contain no personal data. |
7. Deleting your account
You can delete your account yourself, from Dashboard → Settings → Close account, or by emailing support@syntaximos.com.
Deletion is immediate and permanent. When you confirm it we erase your user record — your email address, name, username, country and password hash — along with your authentication tokens and your subscription records, and we delete your customer record at Stripe. None of it is recoverable, and there is no grace period, so please be certain before you confirm.
Two things survive, and you should know about both:
- Payment event records, for the period in section 6, because we have to be able to account for money we have been paid. These come from Stripe and may contain the name, email address and billing address you gave at checkout.
- Server logs, for up to 90 days, after which they are deleted on their normal cycle.
Deleting your account does not touch anything stored on your own computer by our extensions. That data is yours and never reached us; remove it by clearing the extension's library or uninstalling it.
8. Sharing and disclosure
We do not sell your personal data, and we do not share it for anyone else's advertising or marketing. We disclose it only:
- To the providers in section 3, to the extent each needs it to do its job.
- Where the law requires it, such as a valid legal request.
- To a successor entity in a merger or acquisition, in which case this policy continues to apply to the data transferred.
9. Your rights
You may ask us to give you a copy of your data, correct it, export it, delete it, restrict or object to how we use it, and withdraw consent to product email at any time. Email support@syntaximos.com and we will respond within 30 days. Exercising any of these costs nothing and we will not treat you differently for it.
Most of it you can also just do yourself: your details are in Dashboard → Settings, unsubscribe links are in every product email, and account deletion is in section 7.
If you are in the European Economic Area or the United Kingdom, our legal bases are performance of a contract (running your account and your licences), legitimate interests (keeping the service secure and working, and counting ad campaign visits, which involves no personal data), legal obligation (keeping payment records), and consent (product email, withdrawable at any time). You may also complain to your local data protection authority.
If you are a California resident, you have the rights described in the CCPA/CPRA, including the right to know, delete and correct. We do not sell or share personal information as that law defines those terms.
Where your data is processed
Syntaximos LLC is established in the United States and your data is stored and processed there. If you use Syntaximos from the European Economic Area, the United Kingdom or elsewhere, the data you give us is sent to and held in the United States, which may protect personal data differently from your own country.
10. Children
Syntaximos is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email support@syntaximos.com and we will delete it.
11. Security
Traffic to our site and API is encrypted with HTTPS. Passwords are stored only as bcrypt hashes and cannot be read by us or recovered. Sessions are held in cookies that expire, with a short-lived access token renewed from a separate refresh token, so a stolen token has a limited life. Credentials are stripped from our logs automatically rather than by hand.
No system is perfectly secure, but we do not hold card numbers and we do not hold your browsing history, which limits what a breach of our systems could expose.
12. Links to other sites
Our site links to sites we do not control, including the Chrome Web Store and our payment processor. This policy does not apply to them, and we are not responsible for their content or their handling of your data.
13. Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects how we handle your personal data, we will tell you by email or on the site before it takes effect.
14. Contact
Questions about this policy, or about your data: