Privacy Policy
Effective 2026-07-10
This Privacy Policy describes how RefSource ("we," "us," or "our"), operated by Synctek LLC, collects, uses, and protects information when you use the RefSource iOS app or web applications. RefSource is a referral-management tool for professional service businesses.
Two kinds of data flow through RefSource. Account Data is information about you as a RefSource user. Customer Data is information you enter about your own customers and jobs in order to create and track referrals. For Customer Data, your organization (your "tenant") is the data controller and RefSource acts as a processor / service provider — we process it only to provide the Service on your organization's behalf, and never for our own independent purposes.
1. Information we collect
Account Data (about you)
- Name. The name you provide when you set up or are invited to an account.
- Email address. Collected when you accept an invite or sign in via magic-link OTP. Used to authenticate you and to send service-related email (invite confirmations, notifications you opt into). Not used for marketing.
- Role and organization. Your role and the shop or company you belong to, used to scope your access within your tenant.
- User identifier. An internal user ID that associates your activity within your tenant. Not shared across organizations.
Customer Data (entered by you about your customers and jobs)
- Customer contact information. The name, phone number, and physical or service address of the customers and jobs you enter to create and track a referral.
- Referral and commission content. Referral notes, commission figures, job details, and other content you create or that is shared with you.
- Photos and videos. Attachments you add to a referral or thread message. Stored in our object storage, scoped to your tenant, and visible only to authorized members of that tenant.
Technical and diagnostic data
- Device and usage data. A device identifier and basic information such as app version, used to operate the Service and diagnose issues.
- Crash and error data. We use Sentry to capture crash reports and error events from the app and backend services. Sentry events do not include attachment contents, OTP codes, or other secrets. We have configured Sentry to strip personally identifiable information from breadcrumbs and to never send default PII.
2. Information we do NOT collect
- We do not track your activity across other apps or websites.
- We do not sell, rent, or share your personal information with third parties for marketing or advertising purposes.
- We do not use third-party analytics or advertising/tracking SDKs.
- We do not collect device location.
3. Required-reason APIs (Apple)
The iOS app uses the following Apple APIs for the listed legitimate purposes:
UserDefaults(reason:CA92.1) — to persist user-selected app preferences across launches.FileTimestamp(reason:C617.1) — to display creation and modification timestamps on user-attached files.SystemBootTime(reason:35F9.1) — to compute elapsed time for diagnostic measurements.DiskSpace(reason:E174.1) — to verify available storage before downloading attachments.
4. How we use information
- To authenticate you and authorize your access to your tenant's data.
- To provide the referral-management features you use — create and track referrals, record commissions, and store the documents tied to a job.
- To deliver service-related transactional email and one-time passcodes.
- To diagnose and fix crashes and errors.
- To comply with legal obligations.
5. Subprocessors
We share data with a limited set of subprocessors that process it on our behalf under contract:
- Amazon Web Services (AWS). Cloud hosting, database, object storage, and transactional email / one-time-passcode delivery (Amazon SES). United States region.
- Sentry. Crash and error diagnostics.
We use additional infrastructure providers for communications where needed (for example, email and SMS delivery). A current list of subprocessors is available on request at [email protected]. We do not authorize any subprocessor to use your data for its own purposes.
6. Cookies and local storage
Our web applications use strictly necessary cookies and browser local/session storage to keep you signed in and remember your preferences. We do not use advertising or cross-site tracking cookies.
7. Your privacy rights
Depending on where you live, you may have rights over your personal information, including the right to access or know what we hold, to delete it, to correct it, and to receive a portable copy (export). Residents of California (CCPA/CPRA) and individuals in the EEA and UK (GDPR) have these rights among others, including the right to restrict or object to certain processing.
We do not sell your personal information and do not share it for cross-context behavioral advertising. We will not discriminate against you for exercising your rights.
To exercise a right, email [email protected]; we will respond within the timeframe required by applicable law. Where the request concerns Customer Data, your organization is the controller — please direct the request to your tenant administrator, and we will assist them as processor. For EEA/UK users, we process personal data to perform our contract with your organization, to pursue our legitimate interests in operating and securing the Service, and with consent where required.
8. Data retention
We retain Account Data and tenant data while your account or tenant remains active. Referral and commission records may be retained longer where we need them to meet legal, tax, or audit obligations, or to resolve disputes. Media attachments (photos and videos) that are no longer referenced by an active thread are automatically deleted after 90 days. You can request export or deletion of your personal data at any time by emailing [email protected]; we will complete verified requests within 30 days.
9. Data security
Data is encrypted in transit (TLS 1.2+) and at rest. Row-level security policies in our database isolate each tenant's data. Access to production systems is restricted to a small operations team.
10. Children's privacy
RefSource is intended for use by professional service operators. We do not knowingly collect information from children under 13. If you believe a child has provided information, contact us and we will delete it.
11. Changes to this policy
We may update this policy. The effective date at the top reflects the most recent revision. Material changes will be communicated by email or in-app notice.
12. Contact
Privacy inquiries: [email protected]
General support: [email protected]
Postal mail: Synctek LLC, attn: RefSource Privacy