Privacy Policy

Last updated: September 4, 2026

Syndacon LLC (“Syndacon”, “we”, “us”) built this policy to be read, not skimmed past. It explains what we collect, why we collect it, who else touches it, and what you can make us do about it.

It covers:

  • syndacon.com — our company website
  • storacle.app — the Storacle product website
  • Storacle — our managed package for Salesforce, distributed through the Salesforce AppExchange

If you reached this page from a site not listed above, this policy does not apply to it.

Who we are. Syndacon LLC, doing business as Syndacon, is a limited liability company registered in Colorado, United States. Our mailing address is 2205 W 136th Ave, Ste 106-2091, Broomfield, CO 80023, United States. You can reach us at info@syndacon.com about anything in this policy.


The short version

  • Our websites run no analytics, no advertising, no tracking pixels, and set no tracking cookies.
  • The Storacle package never sends your Salesforce data to us. Every measurement it takes stays inside your own Salesforce org.
  • We do receive two numbers from your org — how many Storacle seats are in use, and whether the nightly job is succeeding.
  • Stripe handles every payment. We never see your card number.
  • We sell nothing about you to anyone. We have never done it and we do not plan to.

What we collect and why

Website visitors

Our websites are static pages served through Cloudflare. We do not run Google Analytics or any equivalent, we do not embed advertising or social media pixels, and we do not set cookies for tracking.

Cloudflare, as our hosting provider, processes your IP address and standard request information to deliver the page and to block attacks. We do not use that data to build a profile of you.

Every font and image is served from our own domain rather than pulled from somebody else’s CDN. Reading a page involves nobody but us and Cloudflare. The Storacle support form does one thing more — see anti-bot checks below.

When you contact us

Our contact forms ask for your name, email address, company name, and your message. We use that information to answer you.

The form submission is emailed to us and stored in our Salesforce customer relationship management system, held in Syndacon’s Salesforce partner org. We keep it so we remember the conversation. Ask us to delete it and we will.

When you ask for support

The Storacle support form asks for a little more: your name, email address, company, Salesforce org name, what kind of problem it is, and how urgent it is. That becomes a support Case in our Salesforce partner org, so your request does not get lost in somebody’s inbox.

Anti-bot checks

The support form is protected by Cloudflare Turnstile, because an open form that files Cases is an open invitation to spam.

Turnstile is a Cloudflare product, and Cloudflare already hosts our sites, so this is not a new company getting your data. Your IP address reaches Cloudflare the moment you load any page here, the way it would with any web host.

What differs is what Turnstile does with it. Delivering a page is passive. Turnstile is active: your browser loads a widget from challenges.cloudflare.com that examines your IP address, your TLS fingerprint and your browser’s user agent to judge whether you are a person or a bot. It sets no cookies of any kind, and in the normal case it shows you no puzzle to solve. Cloudflare says it does not use these signals to track you across sites or for advertising. It does use them to improve its own bot detection, which is why Turnstile has a privacy policy of its own separate from our hosting arrangement.

The form also carries a hidden field that a human never sees and never fills in. If it comes back filled in, we know the submission came from a bot. No personal information is involved.

Storacle: what stays in your org

This is the most important section for Storacle customers, so we will be blunt about it.

Storacle does not transmit your Salesforce data to Syndacon. The package measures your org’s storage usage, records historical snapshots, calculates forecasts, writes log entries, and sends alert emails. All of it happens inside your own Salesforce org, under your own controls, subject to your own retention settings.

Where the package makes a web request at all, it makes it back to your own Salesforce org. It has no endpoint pointing at Syndacon and no ability to export your records to us. Object names, record counts, storage figures, forecasts and log entries are yours and stay yours.

Storacle: what we do receive

Storacle reports two values from your org to Syndacon, using the standard Salesforce Feature Management App:

WhatWhy
Number of Storacle seats currently assignedSo we can see how many of the seats an org bought are actually in use
Number of successful monitoring runs in the last 30 daysSo we can tell whether the product is working for you

Both are plain counts. Neither identifies a person, and neither contains any of your business data.

Installing Storacle from the AppExchange

When you install Storacle, Salesforce provides us with information through the standard License Management App that every AppExchange partner uses. This includes:

  • Your Salesforce organization ID, organization name, edition and instance
  • Which version of Storacle you installed, and when you install, upgrade or uninstall it
  • How many licenses you hold and how many are in use
  • The name, email address and phone number of the person who installed it

We use this to support you, to manage your licenses, and to know who to contact about the product. Salesforce collects it under its own privacy statement, and we receive it as an AppExchange partner.

Billing and payment

Storacle is listed on the AppExchange as a free app with paid seats. We collect payment ourselves, through Stripe. Salesforce is not in the middle of the transaction.

Your card details go directly to Stripe. Syndacon never sees, handles, or stores them. Checkout happens on a page Stripe hosts, and so does the billing portal where you manage or cancel your subscription. We could not read your card number if we wanted to, and we do not want to.

Here is exactly what moves, and where:

  • When you click Buy inside Storacle, we send your Salesforce organization ID to Stripe along with you. This is how we know which org to grant the seats to. It is an identifier for a company’s Salesforce instance, not for you personally.
  • You give Stripe your name, email address, billing address and payment method. Stripe processes these under its own privacy policy.
  • Stripe then notifies us that the purchase happened. That notice arrives at a small service we run on Cloudflare, which checks that the message really came from Stripe and files it in our Salesforce partner org.
  • From that record we set your license, and we report the order to Salesforce through the Channel Order App, which every AppExchange partner is required to do. The report says which org bought what, and for how much.

So we do hold your billing contact details, what you bought, what you paid, your subscription status, and your invoice history. We keep them because we need to know what you are entitled to, and because United States tax law requires it.

To change or cancel your subscription, open Manage Billing inside Storacle. That takes you to Stripe’s own customer portal.

Nonprofit discounts

If you apply for our nonprofit pricing, we will ask you for documentation of your nonprofit status. A person at Syndacon reads it, and we keep it only long enough to decide and to justify the discount if we are ever audited. We do not use it for anything else.


Support access to your Salesforce org

Salesforce lets a customer temporarily grant an AppExchange partner login access to their org for troubleshooting. If we ever ask for that access, three things will always be true:

  1. You grant it. We cannot take it.
  2. It expires on a date you set.
  3. We use it only to diagnose the problem you contacted us about.

While inside your org under granted access, we can see what a user with those permissions can see. We do not copy your records out, and we do not look at anything unrelated to your support request.


Who else touches your information

We use a small number of service providers. Each one is listed here with what it handles:

ProviderWhat it handles
StripePayment processing, checkout, and the billing portal
SalesforceOur CRM, license management, and AppExchange distribution and order reporting
CloudflareWebsite hosting and delivery, our Stripe notification service, and the Turnstile anti-bot check on the support form; sees visitor IP addresses
Google (Workspace / Gmail)Our business email, including contact form delivery

We will update this list when it changes. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.


When we disclose your information

We disclose personal information in five situations, and no others:

  • To the providers listed above, so they can do the job we hired them to do.
  • To Salesforce, for required order reporting. Every AppExchange partner must report its sales to Salesforce through the Channel Order App. We report which organization bought what, and what it actually paid.
  • To comply with a valid legal request. We assess every request. If it is overbroad or improper, we push back. Unless a court forbids it, we will tell you before we hand anything over, so you have a chance to object.
  • To protect against fraud or an imminent threat to someone’s safety.
  • If Syndacon is acquired or merges, your information transfers with the business. We will notify you before it does, and before your information becomes subject to a different privacy policy.

Marketing email

We may send occasional email about product updates, new features, or Syndacon news to people who have contacted us or installed our software.

Every one of those messages carries a working unsubscribe link. Click it and we stop. You will still receive messages we have to send you — billing notices, security notices, and replies to things you asked us.


Your rights over your information

Wherever you live, you can ask us to:

  • Tell you what personal information we hold about you
  • Correct anything that is wrong
  • Delete it
  • Give you a copy in a portable format
  • Stop using it for marketing

Email info@syndacon.com and we will respond within 30 days. We will not charge you and we will not treat you differently for asking.

If you are in the EU, the UK, or Switzerland, the GDPR gives you these rights directly, plus the right to object to processing and the right to complain to your national data protection authority. Our legal basis for processing is contract performance for anything tied to your subscription, and legitimate interests for supporting and improving our products.

If you are in California, the CCPA and CPRA give you these rights plus the right to know what categories of information we collect and who we share them with — both are answered above. We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not knowingly collect information from anyone under 16.

If you are a Storacle customer, note that we are not the controller of the data inside your Salesforce org. That is yours. If someone asks you to delete their records, you do that in your own org; we hold no copy.


How we protect your information

  • All traffic to our websites and services runs over TLS.
  • Access to our Salesforce partner org is restricted to Syndacon staff who need it, and requires multi-factor authentication.
  • We do not store payment card data anywhere, in any form.
  • We keep our software dependencies patched and our infrastructure current.

No system is perfectly secure, and we are not going to claim otherwise. If we suffer a breach that affects your personal information, we will tell you and the relevant regulators as quickly as the law requires and as soon as we usefully can.


How long we keep things

  • Contact form messages, support Cases and CRM records — until you ask us to delete them, or three years after our last contact, whichever comes first.
  • License and installation records — for as long as you are a customer, plus seven years afterward.
  • Billing, order and tax records — seven years, because United States tax law requires it.
  • Nonprofit verification documents — three years after the discount ends.
  • Cloudflare request logs — retained on Cloudflare’s own schedule, which is short.
  • Your Storacle data — we hold none of it, so there is nothing for us to keep. What lives in your org is governed by your own retention settings.

Where your information lives

Syndacon is based in the United States. Our providers store data in the United States and, for some of them, in other countries where they operate.

If you use our sites or products from outside the United States, your information is transferred to and processed in the United States. For transfers of personal data out of the EU, UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, which our providers incorporate into their agreements with us.


Changes to this policy

We may update this policy. When we do, we change the date at the top. If the change is significant, we will email customers before it takes effect.

Previous versions are kept in our public repository history, so you can see exactly what changed and when.


Questions

Email info@syndacon.com, or write to:

Syndacon LLC
2205 W 136th Ave, Ste 106-2091
Broomfield, CO 80023
United States


Adapted from the Basecamp open-source policies, used under a Creative Commons Attribution 4.0 license.