Privacy Policy

Last updated: August 30, 2026

1. Introduction

Cyndr ("we", "us", or "the Service") is a construction lead and project management platform. This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have. By using the Service you agree to the practices described here.

2. Information We Collect

  • Account information — name, email address, phone number, business name, and address you provide when registering or configuring your organization.
  • Business content — projects, contacts, estimates, change orders, invoices, line items, documents, and signatures you create or upload.
  • Payment-related information — records of payments made against your documents (amounts, dates, status, and a reference to the processor's transaction). We do not collect or store full card numbers or bank account numbers; those are entered directly on the payment processor's secure pages.
  • Connected-service data — when you connect a third-party account such as QuickBooks Online, we access and store limited data from that account as described in Section 5.
  • Usage and device data — log data, IP address, and basic analytics used to operate and secure the Service.
  • On-duty location & work-activity data — if your employer enables location tracking: while auto clock-in is on, we check your device location so the app can clock you in and out automatically when you arrive at or leave a job site; and while you are clocked in, we also record your device location and a log of the work actions you take in the app (such as creating tasks, uploading photos, or adding notes) so your employer can see where and how on-site work happened. This runs only while auto clock-in is on or you are clocked in (you can pause it) and is not intended to run on your personal time. It requires your in-app consent before it begins and is visible only to your organization's administrators (never shown in chat). Raw location history is automatically deleted after your organization's retention period (see Section 8).

3. How We Use Information

  • To provide, maintain, and improve the Service.
  • To create and manage estimates, change orders, invoices, and payment requests on your behalf.
  • To process and reconcile payments through your chosen payment provider.
  • To communicate with you about your account, documents, and support requests.
  • To protect against fraud and to comply with legal obligations.

We do not sell your personal information or your connected-service data.

4. Payment Processing

Online payments are handled by third-party payment processors — Stripe and Intuit QuickBooks Payments, depending on the option your service provider has enabled. When you pay online, your card or bank details are entered directly on the processor's secure, hosted pages and are never transmitted to or stored on Cyndr's servers. Each processor's handling of your data is governed by its own privacy policy.

5. QuickBooks Online / Intuit Integration

If your organization connects a QuickBooks Online account, Cyndr integrates with Intuit's services to create invoices and collect and reconcile payments. This section describes that integration specifically.

Data we access

With your authorization (OAuth 2.0, scope com.intuit.quickbooks.accounting), we access only what is needed to bill and reconcile payments, which may include: customers, items/products and services, income accounts, and invoices and their payment status and balances in your connected QuickBooks company.

How we use it

  • To find or create a customer record for the person being billed.
  • To create an invoice for a progress payment, deposit, or change order and to enable Intuit's hosted online card/ACH payment page for it.
  • To read an invoice's balance so we can mark the corresponding payment as paid in Cyndr once it clears.

What we store

  • The OAuth access and refresh tokens and your QuickBooks company (realm) identifier, used to maintain the connection on your behalf.
  • A mapping between each QuickBooks invoice we create and the corresponding Cyndr payment, plus that invoice's identifier and status.
  • We do not store cardholder data or bank-account numbers. Payment card and bank details are collected solely on Intuit's PCI-compliant hosted pages.

How we protect it

Connection tokens are stored with restricted access and transmitted only over encrypted (TLS) connections to Intuit's APIs. Access is limited to the functions described above.

Disconnecting and deletion

An organization owner can disconnect QuickBooks at any time from Organization Settings → Online Payment Provider → Disconnect, or by removing Cyndr from the Apps section of QuickBooks. Disconnecting revokes our access and stops further data exchange. Upon disconnection or upon written request to support@cyndr.app, we delete the stored QuickBooks tokens and company identifier. Our use and transfer of information received from Intuit APIs adheres to the Intuit Developer Services Agreement and applicable API rules.

6. Google Account Integration (Calendar & Sheets)

If you connect a Google account, Cyndr uses Google APIs to power two optional features: exporting your Cyndr data to Google Sheets, and checking your team's availability using Google Calendar. Connecting Google is entirely optional; the rest of the Service works without it.

Data we access

  • Google Sheets export (scope https://www.googleapis.com/auth/drive.file) — a per-file scope that lets Cyndr create and manage only the spreadsheets it creates for you. Cyndr cannot see, open, or access any other file in your Google Drive.
  • Calendar availability (scope https://www.googleapis.com/auth/calendar.freebusy) — lets Cyndr read only free/busy time ranges (whether a person is busy, not the title, attendees, or any other detail of their events) for organization members who choose to enable it.
  • Basic account identifier (openid, email) — so the app can show which Google account is connected.

How we use it

  • When you choose "Open in Google Sheet," we create a spreadsheet in your own Google Drive, owned by you, and populate it with the Cyndr data you exported (for example a project, estimate, or contact list).
  • When cross-member availability is enabled, we read free/busy windows for the relevant members to help schedule jobs. This is off by default and is turned on per organization and per member.

What we store

  • The OAuth access and refresh tokens for your Google connection, and which scopes you granted, so the connection works on your behalf.
  • We do not copy the contents of your Google Drive or Google Calendar into Cyndr. Exported spreadsheets live in your Drive under your ownership, and free/busy results are used only at the moment of scheduling — we do not retain your calendar events.

Limited Use

Cyndr's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide and improve the features described above. We do not use it for advertising, and we do not sell it or transfer it to third parties except as needed to provide these features at your request or as required by law. Cyndr does not allow humans to read this data, and does not use it to train generalized artificial intelligence or machine-learning models.

Disconnecting and deletion

You can revoke Cyndr's access at any time from your Google Account permissions page, or by disconnecting Google from within Cyndr. Doing so revokes our access and deletes the stored Google tokens. Spreadsheets already created in your Drive remain yours to keep or delete.

7. How We Share Information

We share information only as needed to operate the Service:

  • With payment processors (Stripe, Intuit) to process and reconcile payments you initiate.
  • With infrastructure and service providers (e.g., cloud hosting, email delivery) that process data on our behalf under appropriate safeguards.
  • With people you choose to share documents with (for example, a customer who receives a signable estimate sees the signer's name and email).
  • When required by law, or to protect the rights, safety, and security of Cyndr and its users.

8. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your data as described below.

On-duty location history is retained only for a limited window set by your organization (60 days by default), after which raw location points are automatically and permanently deleted; only aggregate summaries (such as hours worked per project) are kept beyond that window. You may ask to see or delete your own on-duty location and activity data at any time.

9. Security

We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and restricted access to credentials. No method of transmission or storage is completely secure, but we work to protect your information and continually improve our safeguards.

10. Your Choices and Rights

  • Access, update, or correct your account information at any time within the Service.
  • Disconnect connected services such as QuickBooks at any time.
  • Request a copy or deletion of your personal data by contacting us.

11. Children's Privacy

The Service is intended for business use and is not directed to individuals under 18. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page with a new "Last updated" date. Material changes may be communicated through the Service.

13. Contact Us

If you have questions about this Privacy Policy or your data, contact us at:

Cyndr
Email: support@cyndr.app

By using Cyndr, you acknowledge that you have read and understood this Privacy Policy.