Features Why switch How it works FAQ Sign In Try for free
Legal

Privacy Policy

Last updated: 10 September 2026

1. Who we are

Synctillate ("Synctillate", "we", "us") builds management software for DGR-sponsored private security agencies in India. Our platform has two parts: a web-based admin portal that an agency's staff use to run their business (attendance, payroll, compliance, billing, and communication with guards), and a mobile app that individual security guards use for clock-in/out, live location sharing while on duty, and receiving instructions from their employer.

This policy explains what data we collect through both parts of the platform, why we collect it, and how it's protected. If you're a guard, your employer (the security agency you work for) is the one who sets up your account in Synctillate — we act as their service provider for storing and processing this data.

2. Information we collect

From an agency admin

  • Account details — name, email address, mobile number, and organization details (agency name, address, PSARA licence number, GST number, bank account details used for invoicing clients).
  • Business records — client/deployment locations, invoices, wage registers, and statutory documents the platform generates on the agency's behalf.

From a security guard

  • Identity and employment details — name, father's name, date of birth, address, mobile number, designation, and photo.
  • Government ID and financial details — Aadhaar number, PAN, bank account number, and IFSC code, collected because DGR and statutory payroll compliance (EPF, ESI, GST) legally require an agency to hold and report this information for its deployed guards. These fields are encrypted before they're stored.
  • Attendance and location — see the dedicated section below.
  • Uploaded documents — scans/photos of ID and bank proof a guard submits for verification.

3. Location data

The guard app collects GPS location only while a guard is clocked on duty. This is used to:

  • Verify a guard is within their assigned deployment site's geofence, for automated attendance marking.
  • Show an agency's own dispatch/monitoring staff where their guards currently are, for safety and operational coordination.

Location is not collected while a guard is off duty, and is not shared with anyone outside the guard's own employer. A guard can see, from their own app, whenever live location sharing is active for their account.

4. Google Account / Gmail integration

An agency admin can optionally connect their own Gmail account to send invoices and other documents to their clients directly from their own email address, instead of downloading a PDF and attaching it manually elsewhere.

What we request: two scopes only — gmail.send (permission to send email as that admin, only when they explicitly click Send inside Synctillate) and userinfo.email (the connected Gmail address itself, so we can show the admin which account they're sending as).

What we do not do: we cannot and do not read, search, list, or otherwise access the contents of an admin's existing mailbox — the mailbox itself, and every email a guard app or client has ever sent or received, stays entirely private to that Gmail account and is never visible to Synctillate.

How we use this Google user data: solely to (a) send the message an admin composed inside Synctillate, at the moment they click Send, and (b) display which Gmail address is currently connected on the Sender page. We do not use it for advertising, analytics, AI model training, or any purpose unrelated to this specific sending feature.

Third-party AI processing: the only third-party AI service Synctillate uses is OpenAI, called directly through its standard API (no aggregator, gateway, or other model hub in between) — for two purely text-generation features: "Draft with AI" / "Rewrite with AI" on the Sender page, and Sarge, an in-app assistant that can suggest email text in chat. Neither feature has any access to the Gmail connection: no Gmail API token, no mailbox content, no message metadata, and no data obtained through this Google integration is ever transmitted to OpenAI or any other third party — both tools only ever see the message text an admin is actively typing in our own editor. Per OpenAI's own API data-usage policy, data submitted through its API is not used to train or improve its models unless a customer explicitly opts in, which Synctillate does not. We do not run or rely on any self-hosted/offline AI model.

Who we share, transfer, or disclose Google user data with: nobody, except (i) Google itself, to actually transmit the message via the Gmail API — inherent to the sending feature the admin asked for — and (ii) our cloud hosting/database provider, which stores the connected account's encrypted access token and the sent-message metadata described below purely to operate this feature, under contractual confidentiality obligations, and never for its own purposes. We do not sell, rent, or otherwise transfer Google user data to any third party, data broker, or advertiser.

The Gmail access and refresh tokens are encrypted at rest. We store only what's needed to show the admin their own sending history inside Synctillate (recipient, subject, timestamp, and the attachment generated by the platform) — we do not retain a separate copy of the message body beyond what the admin composed in our editor.

An admin can revoke this access at any time from their Google Account, under Security → Third-party apps with account access. Revoking access simply turns off the "send from Gmail" feature — nothing else about the admin's account or Gmail is affected.

Synctillate's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. How we use information

  • Marking and verifying attendance, and computing payroll and statutory deductions (EPF, ESI, GST) from it.
  • Generating invoices, wage registers, payslips, appointment letters, ID cards, and other documents an agency needs to run its business and stay compliant.
  • Letting an agency send instructions, forms, and alerts to its own guards, and letting guards respond or ask for support.
  • Operating, securing, and improving the platform itself (e.g. diagnosing an error report).

We do not sell personal data, and we do not use guard or agency data to serve advertising.

6. Who can see your data

Synctillate is multi-tenant software: every agency's data is isolated from every other agency's at the database level — one agency's admin can never see another agency's guards, documents, or records, and a guard can only ever be seen by their own employer.

A small number of infrastructure providers (cloud hosting, database, and file storage) process data on our behalf under contractual confidentiality obligations, strictly to keep the platform running — they don't use the data for their own purposes.

7. Data retention

We retain account and employment records for as long as the account is active, plus the period Indian labour, tax, and DGR compliance rules require agencies to keep such records afterward. An agency admin can request deletion of a former guard's or their own organization's data, subject to those legal retention requirements.

8. Security

Sensitive fields — Aadhaar, PAN, and bank account details — are encrypted at rest. All traffic to and from the platform is encrypted in transit (HTTPS/TLS). Access to a tenant's data is restricted to that tenant's own authenticated users.

9. Your choices

  • A guard can review and update most of their own personal details directly in the guard app.
  • To request access to, correction of, or deletion of your data, contact your agency admin directly, or reach us at the email below and we'll route the request appropriately.
  • An admin can disconnect Gmail access at any time (see Section 4).

10. Children

Synctillate is a workplace tool for employed security personnel and is not directed at, or knowingly used by, children.

11. Changes to this policy

We'll update the date at the top of this page whenever this policy changes, and post the revised version here.

12. Contact us

Questions about this policy or your data can be sent to hello@synctillate.com.