Privacy Policy
This policy explains what personal data Alync collects, why, and the rights you have over it — whether you are a customer with an account or a person whose public post was surfaced by our platform.
1. Who we are
Mirza Abdullah Baig, an individual based in Pakistantrading as “Alync” (“we”, “us”), operates https://alync.co and the Alync application at app.alync.co — a lead-generation platform that finds public buying signals across Reddit, X, Instagram, and Google Business Profiles for business customers. Alync is a trading name, not a registered company; Mirza Abdullah Baig is the data controller for the purposes of this policy. For data-protection questions, contact hello@alync.co.
2. Data we collect about customers
- Account data — email address, name, and workspace membership, collected when you sign up or accept an invite.
- Billing data — handled by our merchant of record, Paddle. We never see or store full card numbers; we store your plan, subscription status, and invoice history.
- Campaign data — what you tell us you sell, the sourcing strategies generated from it, and the leads and signals produced for your workspace.
- Usage and security data — API request logs, IP addresses, user-agent strings, session records, and an audit trail of sensitive actions (key creation, member changes, billing changes). We use these to run, secure, and bill the service.
3. Prospect data (people who don’t use Alync)
Alync’s core function is finding publicly available posts, profiles, and business listings that express commercial intent — for example a public Reddit post asking for a service recommendation, or a public business listing on Google Maps. For these people we may process: public usernames and display names, the public post content and its URL, public bios and follower counts, and — after enrichment — publicly listed business contact details (website, business email addresses, business phone numbers, social profiles).
We process this data as a service provider to our customers, who use it for business-to-business outreach. Our legal basis under the GDPR and similar laws is legitimate interest (Art. 6(1)(f)): the data is already public, is limited to what expresses commercial context, and is used for B2B contact. We do not collect private messages, non-public profiles, or special-category data, and our scoring explicitly rejects content that lacks business context.
If you are not an Alync customer and want your data removed: email hello@alync.co with the profile or post URL. We will delete the associated records from our systems within 30 days and add the identifier to a suppression list so it is not re-collected. You may also object to processing or request a copy of what we hold — same address.
4. How we use data
- Providing the service: sourcing, scoring, enriching, and delivering leads to your workspace.
- Operating AI features: campaign text is sent to large-language-model providers (via OpenRouter) to generate strategies and score signals. It is not used to train their models under our agreements.
- Billing and account management via Paddle.
- Security: fraud and abuse detection, rate limiting, audit logging.
- Transactional email (invites, alerts you subscribed to) via Resend. We do not send marketing email without consent.
5. What we never do
- We do not sell personal data.
- We do not run third-party advertising or tracking cookies on the app.
- We do not collect data from behind logins, paywalls, or private communities.
6. Sharing and subprocessors
We share data only with the infrastructure providers needed to run Alync — database and authentication, payments, scraping infrastructure, model providers, search APIs, email delivery, and hosting. The current list, with locations and purposes, is on our subprocessors page. Each is bound by a data-processing agreement. We may also disclose data when legally required.
7. International transfers
Our providers operate in the United States and the European Union. Where data of EU/UK residents is transferred outside those regions, we rely on our providers’ Standard Contractual Clauses or equivalent safeguards.
8. Retention
- Account and campaign data: for the life of your workspace, then deleted within 30 days of account deletion.
- Prospect data: retained while the sourcing customer’s workspace is active; deleted with the workspace or on a verified erasure request.
- Invoices and audit logs: retained after account deletion where tax and legal obligations require it.
- Security logs: up to 12 months.
9. Security
Data is encrypted in transit (TLS) and at rest. Stored provider credentials and webhook secrets are encrypted with AES-256-GCM; API keys are stored only as salted hashes. Access is role-based per workspace, sensitive actions are audit-logged, and tenant data is isolated by row-level security in addition to application checks. No system is perfectly secure; report vulnerabilities to hello@alync.co.
10. Your rights
Depending on where you live (GDPR, UK GDPR, CCPA, and similar), you may have the right to access, correct, export, delete, or restrict the processing of your personal data, and to object to processing based on legitimate interest. Customers can export all workspace data (Settings → Export, or GET /v1/org/export) and delete their account entirely from the app. Everyone else can exercise these rights by emailing hello@alync.co. We respond within 30 days. You also have the right to complain to your local supervisory authority.
11. Cookies
The marketing site sets no advertising cookies. The application uses strictly necessary cookies and local storage for authentication and session state only.
12. Children
Alync is a business tool and not directed at anyone under 18. We do not knowingly process children’s data.
13. Changes
We will post any material change here and update the date above; significant changes affecting customers are also announced by email. Continued use after a change means acceptance.
Last updated July 10, 2026 · Alync (alync.co)