Privacy Policy
Last updated: July 18, 2026
1. Who this applies to
This policy covers everyone who interacts with CapitalSync: business owners and teams who sign up as clients, investors/founders using the investor-facing features, agencies, developers, influencers, and referral partners across every portal, and visitors to our public pages. It also covers a narrower category: prospective business contacts our lead-generation feature discovers from public sources (see Β§4) before they ever sign up.
2. What we collect directly from you
- Account information: name, email address, business name, phone number (if you provide one β used for WhatsApp/SMS alerts, see Β§6), business vertical/industry, and password (stored as a salted hash, never in plain text).
- Content you create: social media captions, hashtags, and media you generate or upload through the platform, plus the topics/prompts you give our AI content tools.
- Billing information: if you subscribe to a paid plan, payment details are collected and processed directly by our payment processors (Stripe or Razorpay, depending on your region) β we do not store your full card number on our own servers.
- Usage data: which features you use, how many AI-generated posts you request, login timestamps, and similar activity β used to operate the product (e.g. detecting inactivity to send a re-engagement message, or usage approaching your AI credit limit).
3. Cookies and similar technology
We use one first-party authentication cookie (auth_token), set when you log in, expiring after 24 hours, and marked SameSite=Lax so it isn't sent on cross-site requests. It exists solely to keep you signed in β it is not used for advertising or cross-site tracking. We also use your browser's local storage for the same session-keeping purpose. See our Cookie Policy for the full, itemized list.
4. Prospect data β a category most privacy policies don't mention
Part of CapitalSync's product is a lead-generation feature that identifies potential clients for social-media-management services by scanning publicly available business information (public Instagram business profiles, Google Maps/Places listings, and public LinkedIn company pages) via third-party data providers (Apify, Google Maps Platform). This processes business/public-profile data about people and companies who are not yet CapitalSync users. If you believe your public business information was processed this way and want it removed from our lead database, contact us using Β§9 below and we will honor the request.
5. AI processing β where your content actually goes
When you use AI content generation, your prompt and relevant business context are sent to one of the following providers, depending on the complexity of the request (chosen automatically to balance quality and cost) or a specific feature's explicit choice: Groq, Anthropic (Claude), and OpenAI. Each provider processes the request under its own data-use terms; we do not use your content to train our own models, and we route every AI call through a single internal service specifically so this policy stays accurate without having to track it separately per feature.
6. Other third parties we actually use
We share the minimum data necessary with the following providers, only for the purpose stated, and only for features you actually use:
- Resend β sends transactional emails (welcome emails, outreach you send through the platform, notifications).
- Twilio β sends SMS alerts, if configured for your account.
- Meta (WhatsApp Business Platform) β sends WhatsApp alerts (account activity, churn/upsell notices, publish-failure alerts), if you've provided a phone number and this channel is configured.
- Telegram β sends bot-based alerts, if configured.
- Firebase Cloud Messaging β sends mobile/web push notifications, if you've enabled them on a device.
- Stripe / Razorpay β processes payments and subscriptions.
- Railway and Vercel β our infrastructure hosts (backend/database and frontend, respectively) β all data described in this policy is stored on their infrastructure.
We do not sell your personal data to anyone, for any purpose.
7. How long we keep data
Account and content data is kept for as long as your account is active, plus a reasonable period afterward to handle billing disputes and legal obligations. One specific exception: for clients in the finance/investment-advisory vertical, content compliance review records are kept for a minimum of three years without modification or deletion, to meet financial-industry recordkeeping requirements (see our Compliance page for the regulatory background). You can request deletion of your other data at any time (Β§9).
8. Your rights
Depending on where you're located, you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. We honor these requests regardless of which specific law grants them, including under the GDPR (EU/ UK), the CCPA/CPRA (California), India's DPDPA, Brazil's LGPD, and comparable laws in other jurisdictions our Compliance page lists. To exercise any of these rights, use the contact in Β§9.
9. Contact
For any privacy question, data request, or concern, email privacy@capitalsync.net or hello@capitalsync.net. We aim to respond to legitimate requests within a reasonable time and in line with whichever data-protection law applies to you.
10. Changes to this policy
If our data practices change in a way that affects this policy, we'll update this page and change the βLast updatedβ date above. For material changes, we'll make a reasonable effort to notify active account holders directly.