July 2026
Privacy Policy
Sygna helps WooCommerce merchants track and optimize their conversion signals. This policy explains what data we collect, how we use it, and your rights. We have written it in plain language. Questions? Email us at [email protected].
Sygna is currently an early-access pilot operated from Israel, built to serve merchants and their customers worldwide — including users in the European Union, United Kingdom, Israel, and beyond. We apply the same data protection standards to everyone, regardless of where they are located. As Sygna moves out of pilot, we will update this page with our registered legal entity and address.
Who this policy covers
Merchants (our customers) — site owners who connect their WooCommerce store to Sygna. This policy governs our handling of your account data.
Site visitors (end-customers of merchants)— site visitors on stores that use Sygna. The merchant is the data controller for your personal information; Sygna acts as a data processor on the merchant's behalf. We do not use your data for our own advertising or profiling.
Our role: controller vs. processor
When we handle merchant account data (your name, email, business details), we are the data controller. When we process conversion events from your site on your behalf, you (the merchant) are the controller and we are the processor — acting only on your instructions to deliver the service.
Data we collect
Merchant account data
- Name, email address, business name, and site URL.
- Business profile (industry, sales channels, ad platforms, revenue range).
- Ad platform credentials — Meta Pixel ID and access token, GA4 Measurement ID and API secret, Google Ads customer/conversion-action IDs and OAuth tokens, TikTok pixel and access token. Stored AES-256-GCM encrypted. Never returned in plain text after saving.
- Notification email addresses for health alerts.
- Support messages.
- Free-text business-profile notes, if you choose to add them — see "AI processing" below for how these are handled.
- Product journey records such as pages viewed, important actions, safe summaries of inputs and outputs, request status, and test-scenario identifiers. We do not record mouse movement, screen video, passwords, access tokens, or arbitrary form fields. Exact assistant prompts and answers are retained only while an internal scenario run is explicitly active; normal customer usage stores lengths and outcome metadata only.
Conversion event data (from your site)
Sygna Connect for WooCommerce forwards normalized events to our API. Each event may include:
- Event type (purchase, add to cart, WhatsApp click, form submit, etc.).
- SHA-256 hashed email, phone, first name, and last name when available and consent permits. Hashing is one-way, but a platform that already knows a possible value can hash it and compare the result; we therefore still treat these hashes as personal data.
- Order value, currency, and product identifiers. No card numbers or payment data.
- UTM parameters and ad click IDs (fbclid, gclid, ttclid) from the URL.
- Browser-generated session ID and event ID for deduplication.
- Consent state set by your site's cookie solution.
- IP address for geolocation context.
We do not collect raw (unhashed) email addresses, phone numbers, payment card data, passwords, or special category data.
How we use this data
| Purpose | Legal basis |
|---|---|
| Forward conversion events to the ad and analytics platforms you connect (Meta CAPI, GA4, Google Ads, TikTok) | Contract performance |
| Analyze business-profile notes and account context with a hosted AI model to suggest strategy and recommendations | Contract performance / Legitimate interest |
| Provide strategy recommendations and health monitoring | Contract performance |
| Diagnose product journeys, support test scenarios, and improve Sygna workflows | Legitimate interests and contract performance |
| Maintain your account and provide support | Contract performance / Legitimate interest |
| Send service notifications and alerts | Contract performance / Legitimate interest |
| Improve the product using aggregated, anonymized data | Legitimate interest |
| Comply with legal obligations | Legal obligation |
We do notsell your data. We do not use your customers' data for cross-site advertising or to build profiles for our own marketing.
Third-party services we send data to
- Meta (Facebook) CAPI— if you connect your Pixel, we forward events to Meta's Conversions API on your behalf. Meta's own privacy policy governs their use of that data.
- Google Analytics 4— if you connect your GA4 property, we forward events via the Measurement Protocol. Google's privacy policy applies.
- Google Ads— if you connect a Google Ads account, we forward offline conversions via Google's conversion import APIs. Google's privacy policy applies.
- TikTok— if you connect a TikTok Pixel, we forward events to TikTok's Events API. TikTok's own privacy policy governs their use of that data.
- Hosted AI / large-language-model providers — Sygna uses one or more hosted AI providers to parse business-profile notes into suggested settings, explain health alerts, and draft strategy recommendations. We currently use models from Anthropic and/or Google, and may add, remove, or switch providers over time; the current provider(s) are listed on our sub-processor page. Depending on the feature, the context sent may include your business-profile notes, account/site configuration, alert diagnostics, or strategy context. Sygna does not intentionally include customer-event contact fields, payment data, or hashed customer identifiers in AI context. We also remove recognizable email, phone, credential, and opaque-identifier patterns at the final provider boundary. Pattern matching cannot identify every possible name, address, or personal detail, so do not place customer personal data in profile notes or assistant questions. We select provider plans and configurations intended to exclude your data from model training, and we will give notice before switching to a provider or plan that does not offer this. Exact prompts sent for a given feature are retained only while an internal scenario run is explicitly active; normal usage retains outcome metadata only, per the retention table below.
- Cloud infrastructure — the application runs on a Hetzner Cloud server, uses Supabase for the production PostgreSQL database, and is reached through Cloudflare for DNS, TLS, and secure tunnelling. Sentry receives scrubbed application-error telemetry. The current providers and purposes are listed on our sub-processor page.
- Resend — used for transactional emails (health alert notifications). Only the recipient address and email content are shared.
We share data with the platforms you explicitly connect and with infrastructure sub-processors needed to operate the service. See our Sub-processors page for the current, up-to-date list — we will update it whenever a sub-processor is added, removed, or changed.
Consent and suppression
Sygna Connect for WooCommerce reads the consent state from your site's cookie solution. What happens next depends on the consent posture you choose in Settings:
- Require granted consent (default) — an event is only forwarded to ad platforms when the visitor has explicitly granted analytics/ad consent. Denied or not-yet-specified consent is suppressed and not forwarded.
- Merchant-managed consent — an event is forwarded unless the visitor has explicitly denied consent, but only while Sygna has fresh scan evidence that no consent layer is present and you have accepted the current acknowledgement. If a consent layer is detected, an unanswered or not-yet-specified choice remains blocked. Stale, failed, unsupported, or inconclusive detection also falls back to the safer require-granted behavior. Choosing this mode means you are relying on another lawful basis for a site without a consent layer; it is a merchant responsibility, not a Sygna guarantee of compliance.
Denied consent is always respected and never forwarded, in both modes. You are responsible for implementing a compliant consent mechanism on your site and for choosing the posture that matches your legal basis.
Data retention
- Conversion event data — retained for up to 12 months, then deleted automatically.
- Lead records — retained until you remove the site or close your account.
- Business profile and strategy — retained until you remove the site or close your account.
- Encrypted credentials — retained until you disconnect the destination or remove the site or delete your account.
- Audit and delivery history — retained for up to 12 months.
- Aggregated, anonymized data — may be retained indefinitely. Cannot identify you or your customers.
International data transfers
Sygna is operated from Israel. The European Commission has recognized Israel as providing an adequate level of data protection, so transfers of personal data from the European Economic Area (EEA) or United Kingdom to Sygna in Israel do not require Standard Contractual Clauses (SCCs) or another additional transfer mechanism. Where we use sub-processors located outside Israel and the EEA/UK (for example, in the United States — see our Sub-processors page), we put appropriate safeguards in place, such as SCCs or the sub-processor's own certified transfer mechanism.
Security
Ad platform credentials are encrypted at rest (AES-256-GCM). All data in transit uses HTTPS/TLS. Our logging infrastructure is configured to redact sensitive fields (tokens, API secrets, passwords) automatically. Sygna team members access customer data only when necessary for support or operations.
Cookies
The Sygna dashboard uses only essential session cookies. The WooCommerce plugin may set session-scoped identifiers on your site front-end for deduplication and attribution — you are responsible for disclosing this in your site's cookie policy and obtaining consent where required.
Your rights
Depending on where you are located, you have the right to access, correct, delete, and port your data, object to certain processing, and withdraw consent where it applies. See our Data Deletion page for how to submit requests. We respond within 30 days.
- EU / EEA and UK users — you have rights under the GDPR and UK GDPR, including the right to lodge a complaint with your local supervisory authority.
- California residents — you have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt-out of certain sharing. We do not sell personal information. To exercise your rights, email [email protected].
- Israeli users— you have rights under Israel's Privacy Protection Law and Amendment 13 (effective August 2025), including the right to file a complaint with the Privacy Protection Authority (Reshut HaGana al HaPratiut).
Your responsibilities as a merchant
You are the data controller for your customers' data. You are responsible for having a lawful basis to collect and forward their data to ad platforms, disclosing your use of server-side conversion tracking in your site's privacy policy, and obtaining any required consent. We cannot take on legal responsibility for your site's own data practices.
Children
Sygna is a business tool for adults. We do not knowingly collect data from anyone under 16. Contact [email protected] if you believe we have done so and we will delete it promptly.
Changes
We will update this page when our practices change and update the "Last updated" date above. For material changes we will notify active accounts by email.
