هذه مسودات، نُشرت لتعمل الروابط. ليست الصيغة النهائية، وكل خانة مُعلَّمة هي قيمة لم تُملأ بعد.
Sincro Privacy Policy
Draft for legal review. Not published. Version: draft 1 — 7 September 2026. Effective date: [POLICY EFFECTIVE DATE].
1. Who we are
Sincro is operated by زين ليبيا للتدريب وخدمات تقنية المعلومات (Zain Libya for Training and Information Technology Services), registered at [REGISTERED ADDRESS].
زين ليبيا للتدريب وخدمات تقنية المعلومات (Zain Libya for Training and Information Technology Services) is the data controller for Account data — everything about the Owner and their use of Sincro.
For the content of a Page — Comments, Conversations, Messages, Orders, and the people who wrote them — زين ليبيا للتدريب وخدمات تقنية المعلومات (Zain Libya for Training and Information Technology Services) is a processor. The Owner of the Page is the controller. See section 9.
You can reach us at [CONTACT EMAIL on sincro.ly].
2. What Sincro does
Sincro replies to comments and private messages on a Facebook Page on behalf of the person who runs it. The person who signs up and links their Page is the Owner. Anyone who writes a Comment or a Message on that Page is a Customer. The AI is Sincro's automated agent that writes the replies.
To do this, Sincro reads and writes data on the Page through Meta's APIs, using permissions the Owner grants through Facebook Login.
3. What we store about Owners
- Sign-in identity. Which method was used — Google, Facebook, or email and password — and the identifier that method gives us. For email and password, the password is stored only as a hash.
- Email address. Optional. It is required only for the email-and-password method and for password reset. An Owner who signs in with Facebook and has no email on Facebook can use Sincro without one.
- Phone number. Optional. Used only so support can contact the Owner.
- Display name and dashboard settings: language, light or dark appearance, notification switches.
- Pages linked. The Facebook Page identifier, the Page name, and an access token that lets Sincro act on the Page. Access tokens are encrypted.
- Settings the Owner writes for each Page. Business Type, Catalogue and Products, Business File (shop facts such as address, hours, delivery, payment, returns), AI instructions, Delivery Cities and fees, Discount Rules.
- Subscription and Payments. Plan, period, message usage, and a record of each Payment: amount, method, reference, and time. Card details are never seen or stored by Sincro. They are handled by EzonePay.
- Technical records. Sign-in times, request logs, and error reports, used to keep the service running and secure.
4. What we store about Customers
A Customer is a person who writes to a linked Page. For each Page, Sincro stores:
- Comments. The text of a public Comment on a Post, when it was written, and which Post it sits under.
- Messages. The text and attachments of the private Conversation between the Customer and the Page: what the Customer sent, what the AI sent, and what the Owner sent.
- Name and Meta identifiers. The Customer's public name and profile picture as Meta provides them, and the Meta identifiers Meta gives us for that person on that Page.
- Orders. When a Customer places an Order, Sincro stores the name, phone number, city, area or landmark, notes, the items ordered, prices, delivery fee, and the Order's status.
- A phone number given inside a Conversation when a Customer provides one without placing an Order.
Sincro does not ask a Customer for a password, a card number, or a national identity number, and the AI is instructed never to request them.
A Customer belongs to one Page. The same person writing to two different Pages is two separate Customer records, and they are never joined.
5. Where data is stored
Sincro's servers are in Europe, hosted by [HOSTING PROVIDER, COUNTRY]. Everything described in sections 3 and 4 is stored there. Backups are encrypted and also kept in Europe.
Traffic between your device and Sincro is encrypted in transit. Page access tokens and AI provider keys are encrypted at rest.
The text of Comments and Messages is sent to the AI providers named in section 6 so that the AI can write a reply. Some of those providers process that text outside Europe. Section 6 names each one and its processing region.
6. Sub-processors
The companies below process data on our behalf. Each AI provider is bound by terms that forbid using the data to train their models and that cap how long they keep it at 30 days.
| Name | Purpose | Processing region | Terms |
|---|---|---|---|
[PROVIDER NAME] | [what it does — for example writing replies, classifying Comments, embeddings] | [region] | [terms URL] |
This table is generated from the AI providers Sincro has enabled. Whenever that list changes, this policy is republished with the new list.
Other service providers, outside the AI list:
| Name | Purpose | Processing region | Terms |
|---|---|---|---|
[HOSTING PROVIDER, COUNTRY] | Servers, storage, backups | Europe | [HOSTING TERMS URL] |
| EzonePay | Taking Payments from Owners | Libya | [EZONEPAY TERMS URL] |
[TRANSACTIONAL EMAIL PROVIDER] | Verification and password-reset emails | [region] | [terms URL] |
[ERROR TRACKING PROVIDER] | Error reports from the application | [region] | [terms URL] |
Meta is not a sub-processor. Meta is the platform Sincro reads from and writes to, under Meta's own terms and its own privacy policy.
7. How long we keep data
| What | How long |
|---|---|
| Conversations and the Messages inside them | 12 months, then deleted |
| Comments | 12 months, then deleted |
| Orders | For the life of the Account |
| A Customer record | Deleted once that Customer has no Conversation, Comment, or Order still inside its retention period |
| A phone number a Customer gave in a Conversation but not in an Order | Deleted with the Conversation that captured it |
| Data of a Page the Owner unlinks | 30 days, then deleted. If the Owner relinks the same Page within 30 days, the data is restored |
| Account data after the Owner deletes the Account | Deleted within 30 days |
| Data covered by a deletion request from Meta or from a Customer | Deleted within 30 days |
| Payment records and usage history | For the life of the Account |
| Webhook delivery records from Meta | 7 days |
| Notifications shown in the dashboard | 90 days |
| Records of AI calls (which provider, which model, cost — no message text) | 13 months |
| Encrypted backups | 30 days |
| Text sent to an AI provider | At most 30 days at that provider, and never used to train their models |
Two things outlive everything else, and neither contains personal data:
- Trial grant records. A note that a particular Facebook Page identifier has used its one free Trial. It holds a Page identifier and a date, nothing about a person.
- Aggregated statistics that cannot identify anyone.
When a Customer asks to be erased, Sincro erases the Customer record, their Conversations, and their Comments, and removes the personal fields from their Orders. The Orders' amounts and items are kept without personal fields, because the Owner needs their sales records.
8. Meta data: what we use and why
Sincro asks the Owner for permissions through Facebook Login. The Owner sees the list in Facebook's own dialog and can refuse it, or withdraw it later in their Facebook settings.
Page permissions granted through Facebook Login. Sincro requests only the permissions its features use, and only for the Pages the Owner chooses to link.
| Permission | What it lets Sincro see or do | What Sincro uses it for |
|---|---|---|
[PAGE PERMISSION NAME] | [what Meta grants] | [the Sincro feature that needs it] |
Sign-in permissions:
| Permission | What it lets Sincro see or do | What Sincro uses it for |
|---|---|---|
[SIGN-IN PERMISSION NAME] | [what Meta grants] | [the Sincro feature that needs it] |
Sincro uses Meta data only to run the features described in this policy. Sincro does not sell Meta data, does not use it for advertising, does not build profiles across Pages, and does not use it to train AI models.
If the Owner removes a permission or unlinks a Page, the AI stops acting on that Page and the data follows the retention rules in section 7.
9. Roles: who is responsible for what
- Account data — the Owner's identity, settings, Subscription, and Payments.
زين ليبيا للتدريب وخدمات تقنية المعلومات (Zain Libya for Training and Information Technology Services)is the controller. - Page content — Comments, Conversations, Messages, Customers, and Orders. The Owner of the Page is the controller.
زين ليبيا للتدريب وخدمات تقنية المعلومات (Zain Libya for Training and Information Technology Services)is the processor and acts on the Owner's instructions.
A Customer who wants their data corrected or erased can ask either the Owner of the Page or Sincro. Sincro acts on the request and tells the Owner.
10. Automated replies
Replies on a linked Page are written by the AI on the Owner's behalf. This is not hidden.
- The first Message the AI sends in a private Conversation begins with a line saying the reply is automated. Sincro writes that line, in the Customer's language. The Owner cannot switch it off or edit it. It is repeated when a Conversation reopens after a long gap, and when the AI starts replying again after the Owner has been replying personally.
- A Customer can always reach the Owner. When the AI cannot answer, it stops and hands the Conversation to the Owner, who replies as themselves. A Customer who asks for a person is handed to the Owner.
- The Owner can pause the AI in any Conversation and reply personally at any time.
The AI writes replies from the Owner's Catalogue, Business File, and instructions. It does not make decisions that have a legal or similarly significant effect on a Customer.
11. Deleting data
There are three ways to have data deleted.
An Owner deleting their Account. Settings has a Delete Account action, behind a confirmation. It unlinks every Page, cancels the Subscription without a refund, and deletes all Account data within 30 days. Trial grant records and aggregated statistics are kept; neither holds personal data.
A deletion request through Facebook. When someone removes Sincro in their Facebook settings, Facebook can send Sincro a deletion request. Sincro receives it at its data deletion callback, deletes that person's data within 30 days, and returns a confirmation code together with a status URL where the request can be checked.
Written instructions. Anyone can also ask us directly. The instructions are published at [DATA DELETION INSTRUCTIONS URL]. Send an email to [CONTACT EMAIL on sincro.ly] naming the Facebook Page and the name used. We complete the deletion within 30 days and confirm it.
A Customer may ask the Owner of the Page instead. Either route works.
12. Owners' rights
An Owner may:
- see and correct their profile and settings in the dashboard;
- ask
[CONTACT EMAIL on sincro.ly]for a copy of their Account data; - delete their Account, and with it all its data, in Settings;
- withdraw Meta permissions at any time in their Facebook settings;
- object to how Sincro processes their Account data, or complain to a supervisory authority where one has jurisdiction.
We answer within 30 days.
13. Customers' rights
A Customer who has written to a Page running Sincro may ask for:
- a copy of what is stored about them;
- correction of anything wrong;
- erasure of their Customer record, their Conversations, and their Comments, and of the personal fields of their Orders.
Ask the Owner of the Page, or write to [CONTACT EMAIL on sincro.ly]. We complete the request within 30 days. Because the Owner is the controller of Page content, we tell the Owner about the request.
14. Security
- All traffic uses TLS.
- Page access tokens, AI provider keys, and administrator two-factor secrets are encrypted at rest.
- An Owner can only ever read or write data belonging to their own Account.
- Sincro's own staff see Customer data only where support or a quality review needs it, and every such view is logged.
- Backups are encrypted, and a restore is tested before the service is offered to sellers.
15. Children
Sincro is a tool for businesses. It is not directed at children, and we do not knowingly collect data from a child. Sincro does not ask for or record a Customer's age.
16. Changes to this policy
We update this policy when what we do changes. The sub-processor list in section 6 is republished automatically whenever the set of enabled AI providers changes. The version and date are at the top of this page. Material changes are announced in the dashboard before they take effect.
17. Contact
زين ليبيا للتدريب وخدمات تقنية المعلومات (Zain Libya for Training and Information Technology Services) [REGISTERED ADDRESS] [CONTACT EMAIL on sincro.ly]