Privacy Policy
We collect the minimum needed to sell and run a mentorship: who you are, what you bought, and how you use the site. We never sell your data, and we never ask for anything that touches your trading account.
Scope
This policy explains what personal data Synflow (“Synflow”, “we”, “us”) collects when you visit our website, buy the mentorship, or take part in our community, why we collect it, who we share it with, and what control you have over it. It applies to the website and to the paid program.
What we collect
- Details you give us: name, email address, and anything you send us in a message, application, or support request.
- Purchase data: the products you bought, amount, currency, date, and the outcome of the transaction. Our payment processor handles your card details — we never see or store full card numbers.
- Community data: your account identifier and display name on the platform hosting our community, plus the messages and material you post there.
- Technical data: IP address, browser and device type, operating system, referring page, and the pages you view, collected automatically through server logs and analytics.
- Anything you choose to share: charts, screenshots, or account context you send a mentor for review.
What we never ask for
We do not need — and will never ask for — your brokerage login credentials, API keys with trading permissions, bank passwords, or account numbers. We do not place trades for you and we do not access your trading account. Treat any request that appears to come from us asking for these as fraudulent and report it.
Why we use it
- To deliver what you bought: granting access, running sessions, answering questions, and reviewing your work.
- To take payment, issue receipts, and keep the financial records the law requires.
- To operate and moderate the community.
- To support you and respond to enquiries.
- To improve the program and the site, using aggregated usage data.
- To send service messages about your access, and — only if you opt in — occasional marketing email you can unsubscribe from at any time.
- To detect fraud, enforce our terms, and comply with legal obligations.
Legal basis (UK/EU users)
Where the UK GDPR or EU GDPR applies, we rely on: performance of a contract (delivering the program you paid for); legitimate interests (securing and improving the Service, preventing fraud); consent (marketing email, non-essential cookies — withdrawable at any time); and legal obligation (tax and accounting records).
Who we share it with
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We share only what is needed, with providers who process it on our behalf:
- Payment processor — to take payment and handle billing.
- Community platform — to host the private community and grant access.
- Email provider — to send service and, where you consented, marketing messages.
- Analytics and hosting providers — to run and measure the site.
- Professional advisers, and authorities where we are legally required to disclose.
- A buyer or successor, if the business is sold or reorganised.
International transfers
Our providers may process data in countries outside your own, including the United States. Where data leaves the UK or EEA, we rely on appropriate safeguards such as the provider's standard contractual clauses or an approved adequacy mechanism.
How long we keep it
Account and access data: for as long as you have access, then up to two years afterwards. Transaction records: for the period tax and accounting law requires, typically six to seven years. Community posts: until you or we delete them, or the platform's own retention applies. Analytics: in aggregated form, up to 26 months. Support messages: up to two years.
Cookies and analytics
We use essential cookies to make the site work and, where applicable, analytics cookies to understand traffic. You can block or delete cookies in your browser; essential cookies are required for the site to function. We honour Global Privacy Control and “Do Not Track” signals where our providers support them.
Security
We use HTTPS, reputable providers, access controls, and the principle of least privilege. No system is perfectly secure, and we cannot guarantee absolute security, but we will notify you and any relevant regulator of a breach affecting your data where the law requires it.
Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, withdraw consent, receive it in a portable format, and — under US state laws such as the CCPA/CPRA — to know what is collected, to delete it, to correct it, and to opt out of sale or sharing (we do neither).
To exercise any right, email us at [SUPPORT EMAIL]. We will verify your identity and respond within the statutory period, normally one month. We will not discriminate against you for exercising these rights. Deleting your data may end your access to the program, and doing so does not entitle you to a refund.
If you are in the UK or EEA and are unhappy with our response, you may complain to your data protection authority.
Children
The Service is for adults aged 18 and over. We do not knowingly collect data from children. If you believe a minor has given us data, contact us and we will delete it.
Changes to this policy
We may update this policy as the program or the law changes. The effective date above shows the current version, and material changes will be posted here before they take effect.
