Sync & Shop
Features Pricing Support Download

Privacy Policy

Version 2026-09-12 · Last updated 12 September 2026

1. Who we are

Sync & Shop ("the app") is operated by ALGOTECH UNLIMITED SRL, a company registered in Romania, registration number RO43636142, with its registered office at Str. Labirint Nr.43, Constanța, România ("we", "us", "our").

For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for the personal data described in this policy.

Privacy questions, requests, or complaints: support@syncnshop.com.

2. Scope

This policy covers the Sync & Shop mobile app on Android and iOS, and this website. It explains what we collect, why, how long we keep it, who else can see it, and what rights you have.

Sections marked "not yet active" describe features we are building but which are not live at the time of the version date above. They do not process any data until the feature ships and this policy's version date is updated.

3. What we collect and why

3.1 Account information

DataWhyLegal basis
Email addressTo create and identify your account, sign you in, and send password resetsContract (Art. 6(1)(b))
PasswordTo secure your account. We never see or store your password — it is handled and hashed by Google Firebase AuthenticationContract
Display name / nicknameSo other members of your group can see who added or was assigned somethingContract
Time zoneTo send daily reminders at the right local hourContract

If you sign in with Google, or with Apple, we receive your email address and name from that provider. We do not receive your Google or Apple password.

Sign in with Apple and "Hide My Email": Apple lets you hide your real address, in which case we receive a relay address ending in @privaterelay.appleid.com instead. It works as a normal address — anything we send to it reaches you — but we never learn your real one. Apple also only ever sends us your name on the very first sign-in, so if you change it later, you can update it in the app; we have no way to receive the change from Apple.

3.2 Content you create

Everything you and your group members put into the app: shopping list items, calendar events, tasks, chores, chat messages, photos sent in chat, and voice messages. This is stored so it can be shared with your group and synced across devices. Legal basis: contract.

Please note: content you add is visible to every member of that group. We cannot control what other members do with information you share with them. Do not put anything in a shared group that you would not want every member of that group to see.

3.3 Household data

If your group uses the Household section: utility meter readings you enter, bills (provider, amount, billing period, due date, and whether they are paid), and any photo you attach as proof of payment. This is stored so the household's costs can be tracked and shared with your group. Legal basis: contract.

3.4 Household Vault

The Vault is a place inside the Household section where a group can keep shared reference information — for example meter numbers, customer codes, or scans of documents. You decide entirely what goes in it. We do not inspect it, and we do not treat it as any particular category of data.

Access to the Vault is gated behind your device's own biometric or passcode check (Face ID, Touch ID, or fingerprint). That check is performed by your device and its result is all the app receives — we never receive, see, or store your biometric data. Legal basis: contract.

Please note: the biometric check controls access on your own device only. Vault contents are shared with every member of the group, exactly like the rest of the app's content, and are stored on our servers in the same way. It is not end-to-end encrypted, and it is not a password manager. Do not store anything in it that would cause you serious harm if a group member, or we, could read it.

3.5 Group information

Group names, invite codes, who belongs to which group, and who is a group administrator. Legal basis: contract.

3.6 Device and notification data

A push notification token issued by Google Firebase Cloud Messaging, so we can deliver notifications to your device. Your notification preferences (which categories you've turned on). Legal basis: consent — you choose which notifications to receive, and you can turn any of them off at any time in Settings.

3.7 Data stored on your own device

The app keeps a copy of your group's recent content in your device's local storage so it works offline. This never leaves your device except as part of the normal sync described above. Uninstalling the app removes it.

3.8 Sign-up protection

When you create an account, we use Cloudflare Turnstile, running in invisible mode, to check you are a real person and not an automated script. Cloudflare receives your IP address and technical signals from your browser for this check. Legal basis: legitimate interests (Art. 6(1)(f)) — preventing fraudulent and abusive account creation. See Cloudflare's Turnstile Privacy Addendum for details on what Cloudflare itself does with this data.

3.9 Records of your consent

When you accept these terms, we store the fact that you accepted and which version. Legal basis: legal obligation (Art. 6(1)(c)) — we must be able to demonstrate that consent was given.

3.10 Calendar import

Two calendars can be imported from, and they work differently enough to be worth describing separately.

Google Calendar

If you choose to connect a Google calendar, we will:

  • Store an access credential (OAuth refresh token) for that account, on our server, so you can import again later without signing in each time. This credential is never sent to or stored on your device.
  • Read your upcoming calendar events and import only the title, date, time, and location of each one. We deliberately do not import event descriptions or attendee lists.

The calendar on your iPhone

On iOS you can also import from the calendars already on your device, which includes iCloud and anything else your phone syncs. This works differently, and in your favour:

  • Nothing is stored on our servers to make it work. There is no credential, no token, and no connection to maintain — the app asks iOS for permission, reads the events on the device at that moment, and that is all. There is nothing to disconnect afterwards, because nothing was connected.
  • We read events in the next 180 days only, and import the same fields as above: title, date, time, and location. Descriptions and attendee lists are not imported.
  • Permission is granted by iOS, not by us, and you can withdraw it at any time in Settings › Sync & Shop › Calendars. The app reads; it never writes, changes, or deletes anything in your device's calendars.

Legal basis: consent. You initiate the connection, and you can disconnect at any time in Settings, which revokes the credential.

Imported events become ordinary events inside Sync & Shop. They are no longer linked to the source calendar, and editing them here does not change anything in Google or Apple Calendar.

Google API Limited Use disclosure: Sync & Shop's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google calendar data for advertising, we do not sell it, we do not transfer it to data brokers, and we do not use it to train artificial intelligence or machine learning models.

A limitation we want to be upfront about: a calendar event you import may incidentally contain sensitive information (for example a medical appointment). We cannot detect or filter this automatically. Only connect a calendar if you are comfortable with its contents being imported into a shared family group.

3.11 Advertising

The free version of the app shows ads served by Google AdMob. AdMob may process your device's advertising identifier, device information, and approximate location derived from your IP address.

We request non-personalised ads only, for everyone, everywhere. This means ads are chosen from general, contextual signals rather than from a profile built about you, and your advertising identifier is not used to track you across other apps and websites. We do not ask you to allow tracking, because we do not do it.

Ads are removed entirely for subscribers (see 3.12). We never use your app content — your lists, events, tasks, chats, household data, Vault contents, or imported calendar data — to target advertising. Child profiles (see section 9) likewise receive only non-personalised ads, as does everyone else.

If you are in the EU, UK, or Switzerland, we still show Google's consent notice where required, using Google's User Messaging Platform, so you can review and adjust your choices. Legal basis: legitimate interest in funding a free version of the app, limited to non-personalised advertising.

If this changes: should we ever introduce personalised advertising, it would require your explicit permission first — on iOS through Apple's own tracking permission prompt — and this policy would be updated before that happens. We would never switch it on silently.

3.12 Subscriptions

We offer a paid subscription that removes ads and unlocks additional features for a group. Payment is handled entirely by Google Play or the Apple App Store. We never receive or store your card details.

We use RevenueCat to verify and track subscription status. This involves a purchase identifier and your subscription state (active, expired, cancelled). A subscription applies to a group rather than to an individual, so the identifier we send is the group's identifier, not your personal one. Legal basis: contract for providing the paid service, and legal obligation for retaining transaction records required by tax law.

3.13 Child profiles

See section 9 for the full policy. In data terms: a child profile stores the same content data as any other member (see 3.2 and 3.5), plus a marker identifying it as belonging to a minor. It does not use a real email address — sign-in uses a system-generated placeholder that cannot receive mail, and a password set by the parent or guardian who created the profile. Legal basis: consent, given by the parent or guardian who creates the profile, on the child's behalf.

4. Who else processes your data

We do not sell your personal data. We share it only with the service providers we need to operate the app. Each acts as a data processor under contract with us.

ProviderWhat they handleWhere
Google (Firebase)Authentication, database, file storage, push notifications, server functionsDatabase and server functions: Belgium (EU). See section 5.
CloudflareSign-up bot protection (Turnstile)Global network
Google (AdMob)Advertising (non-personalised only)Global
RevenueCatSubscription verificationUnited States
AppleSign in with Apple (including Hide My Email relay), App Store payments, and push notification delivery on iOSGlobal

We may also disclose data where legally required (for example a valid court order), or to protect our rights, safety, or property.

5. Where your data is stored, and international transfers

Your account data and all group content is stored in Google's europe-west1 (Belgium) region, inside the European Union. Our server functions run in the same region.

However, Google is a US-headquartered company, and some services — notably push notification delivery — may involve processing outside the EU. Where personal data is transferred outside the European Economic Area, that transfer relies on the safeguards Google and our other providers have in place, which include the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

Our Cloud Storage bucket (used for chat photos and voice messages) is also in the europe-west1 (Belgium) region — the same region as our database, inside the EU.

6. How long we keep it

DataRetention
Account and profileUntil you delete your account
Group content (lists, events, tasks, chores)Until deleted by you or another group member, or until the group is closed
Checked-off shopping itemsAutomatically deleted 24 hours after being checked
Chat messages, photos, voice messagesUntil deleted by the sender, or until the group is closed
Household meter readings, bills, and proof-of-payment imagesUntil deleted by a group member, or until the group is closed
Household Vault contentsUntil deleted by a group member, or until the group is closed
Push notification tokensRemoved automatically when they become invalid, or when you sign out or delete your account
Calendar access credentialsUntil you disconnect the calendar or delete your account
Transaction recordsAs required by Romanian tax and accounting law

Something we want to state plainly: apart from checked-off shopping items, we do not currently delete old content automatically. Chat history and past events remain until someone deletes them or the group is closed. If you want something gone, delete it — or delete your account, which removes everything described in section 7.

7. Deleting your account and data

You can delete your account at any time: open the app, go to Settings, and tap Delete account. This immediately and permanently:

  • Deletes your sign-in credentials, so you can no longer log in
  • Deletes your profile, nickname, notification preferences, and push notification tokens
  • Removes you from every group you belong to
  • If you were a group's administrator, transfers that role to another member
  • If you were the last member of a group, deletes that entire group and everything in it
  • Revokes any connected calendar credentials
  • Deletes files uploaded by a group that is being closed — chat photos, voice messages, and household proof-of-payment images — from our file storage, not only their database records
  • If you signed in with Apple, revokes that authorisation with Apple, so the app no longer appears under Settings › Sign in & Security › Sign in with Apple on your device

Content you added to a group that still has other members — a shopping item, an event, a chat message — remains visible to those members, because it is part of their shared record too. Delete it before deleting your account if you want it gone.

You can also request deletion by emailing support@syncnshop.com. See our data deletion page for details.

8. Your rights

If you are in the EU, UK, or Switzerland, the GDPR gives you the right to:

  • Access the personal data we hold about you
  • Correct data that is wrong or incomplete
  • Delete your data ("right to be forgotten") — see section 7
  • Restrict how we process your data
  • Receive a copy of your data in a portable format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time, where processing is based on consent

We do not make automated decisions that have a legal or similarly significant effect on you, and we do not carry out profiling.

To exercise any of these rights, email support@syncnshop.com. We will respond within one month, as the GDPR requires.

If you are unhappy with how we handle your request, you can complain to the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP) — dataprotection.ro — or to the supervisory authority where you live.

8.1 If you are in California

Under the CCPA/CPRA you have the right to know what personal information we collect, to request its deletion or correction, and not to be discriminated against for exercising those rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising. The requests above cover these rights; email us using the same address.

8.2 If you are elsewhere

Other jurisdictions, including Brazil (LGPD), the UK, Canada, and Australia, grant similar rights. We apply the process in section 8 to every request we receive, wherever you are.

9. Children

Sync & Shop is not directed at children. You must be at least 13 years old to create your own account with an email and password.

Younger children do not create their own account. A parent or guardian who administers a group can create a separate child profile for them, from inside the app. A child profile:

  • is created only by the group's administrator — it cannot be self-registered by anyone, at any age, through the normal sign-up screen
  • signs in with a password the parent sets, not a real email address
  • is marked in our systems as belonging to a minor, for as long as it exists
  • never receives personalised or behaviourally-targeted advertising — only non-personalised, contextual advertising, which is what every user receives (see section 3.11)

A parent or guardian remains responsible for a child profile they create, including for reviewing what is shared inside any group the child is part of.

If you believe a child has an account or profile that was not set up by their parent or guardian, contact us at support@syncnshop.com and we will investigate and, where appropriate, delete it.

10. Security

Data is encrypted in transit (HTTPS/TLS) and encrypted at rest by Google Firebase. Passwords are hashed by Firebase Authentication and are never visible to us. Sensitive server credentials are held in Google Secret Manager, not in our application code.

Access to your group's content is restricted by database security rules, so you can only read and write data belonging to groups you are a member of.

Uploaded files — photos and voice messages sent in chat, and images attached to bills — are stored separately and require a signed-in account to reach. Each file has a long random address that the app never displays and that cannot be guessed or browsed, so a file is reachable only by someone who already had access to the conversation it came from. Payment proofs additionally cannot be overwritten once uploaded, so a record of payment cannot be replaced.

No system is perfectly secure. If a data breach occurs that is likely to affect your rights, we will notify the ANSPDCP within 72 hours of becoming aware of it, and notify you directly where the law requires.

11. Changes to this policy

If we change this policy materially — for example when we launch advertising or subscriptions — we will update the version date at the top and ask you to accept the new version inside the app. Continuing to use the app after being notified means you accept the updated policy.

12. Contact

ALGOTECH UNLIMITED SRL
Str. Labirint Nr.43, Constanța, România
support@syncnshop.com

Sync & Shop

One shared home for the list, the calendar, the chores and the chat.

ProductFeaturesPricingSupport
LegalPrivacy PolicyTerms of ServiceData Deletion
© 2026 Sync & Shop