300Sync is built to sync your data between systems — not to collect or monetize it. This policy explains exactly what we collect, how we use it, and what rights you have.
Effective date: March 11, 2026
No passwords stored
We use OAuth for all integrations. Credentials are encrypted at rest with AES-256-GCM.
No raw data stored
We pass your records directly between systems. We don’t retain the content of synced data.
No tracking cookies
We use cookies only for authentication sessions — never for advertising or cross-site tracking.
You stay in control
Email privacy@300sync.com at any time to request data export, correction, or deletion.
When you create a 300Sync account or install 300Sync from the HubSpot Marketplace, we collect the email address and name associated with your HubSpot portal. We also store your HubSpot portal ID and, where applicable, the organization ID from your connected third-party software.
To sync data on your behalf, we store the OAuth access and refresh tokens issued by HubSpot and your connected integration (e.g., Clio, ServiceTitan, Jobber). For integrations that use API key or credential-based authentication rather than OAuth, we store only the encrypted form of those credentials. All tokens and credentials are encrypted at rest using AES-256-GCM. We never store your passwords.
We store the sync settings you configure: which object types to sync, field mapping rules, sync direction preferences, and conflict resolution strategy. This configuration is necessary to operate the service.
We log the outcome of each sync run: timestamp, number of records processed, number of records created or updated, and any errors encountered. Log entries reference record counts and error codes — they do not contain the content of your records (names, contact details, case information, etc.).
Payments are processed by Stripe. We do not store credit card numbers, CVV codes, or full payment card details on our servers. We receive and store a Stripe customer ID, your current subscription plan, and billing status from Stripe.
We collect aggregate usage metrics: monthly record sync counts per portal, API request counts, and feature usage flags. This data is tied to your portal ID and is used to enforce plan limits and to understand how the product is used at an aggregate level. We do not build individual behavioral profiles.
We use the information we collect only to operate and improve 300Sync. Specifically:
300Sync is designed as a pass-through integration platform. During a sync run, we fetch records from your source system (e.g., Clio contacts), transform them according to your field mapping configuration, and write them to the destination system (e.g., HubSpot contacts). The record data exists in memory only for the duration of that operation and is not persisted to our database.
Our database (Neon PostgreSQL, hosted in the United States) stores:
Integrations with healthcare-adjacent platforms (Open Dental, Boulevard) apply a data classification filter during sync. Clinical notes, medical history, treatment plans, diagnosis codes, and other protected health information (PHI) are explicitly excluded from sync operations and are never transmitted to HubSpot. Only administrative and contact data (names, appointment schedules, practice metadata) is processed.
All data stored by 300Sync is hosted in the United States. Our application is deployed on Vercel (US regions). Our database runs on Neon PostgreSQL (AWS us-east-1). Background jobs are processed by Inngest (US). If you are located outside the United States and connect to 300Sync, your account data will be transferred to and stored in the United States.
300Sync uses a small set of trusted third-party services to operate. Each service receives only the data necessary for its specific function.
| Service | Purpose |
|---|---|
| HubSpot | CRM destination for synced data |
| Stripe | Payment processing and subscription management |
| Vercel | Application hosting and edge delivery |
| Neon PostgreSQL | Primary database |
| Inngest | Background job processing (sync scheduling, retry logic) |
We do not use Google Analytics, Facebook Pixel, Segment, Mixpanel, or any other third-party tracking or analytics service. We do not share your data with advertising networks.
When you connect a third-party integration (e.g., Clio, ServiceTitan, Jobber, Buildium, etc.), 300Sync acts as a conduit. Data from your connected system is transmitted to HubSpot according to your configuration. Your use of those third-party platforms is governed by their own terms of service and privacy policies — not this one.
Security is a core design principle of 300Sync, not an afterthought. We implement the following controls:
No system is perfectly secure. If you discover a security vulnerability in 300Sync, please disclose it responsibly by emailing privacy@300sync.com. We will respond promptly and work with you to address the issue.
We retain your data for as long as your account is active and for a reasonable period after account termination to allow for dispute resolution and legal compliance.
Depending on your location, you may have the following rights regarding your personal data. We honor these rights for all users, regardless of jurisdiction.
Right to access
You can request a copy of the personal data we hold about you, including your account information, sync configuration, and log summaries.
Right to rectification
If any data we hold about you is inaccurate or incomplete, you can request that we correct it.
Right to erasure
You can request deletion of your account and all associated data ("right to be forgotten"). We will complete deletion within 30 days, subject to legal retention obligations.
Right to data portability
You can request an export of your personal data in a machine-readable format (JSON or CSV).
Right to restrict processing
You can request that we limit how we use your data while we address a complaint or verify accuracy.
Right to object
You can object to our processing of your data. We do not process data for direct marketing, so this right primarily applies to any future use we may introduce.
CCPA — Right to opt out of sale
We do not sell personal information. There is nothing to opt out of, but you have the right to know this explicitly.
Right to withdraw consent
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing that occurred before the withdrawal.
To exercise any of these rights, email privacy@300sync.com with a description of your request. We will respond within 30 days. We may ask you to verify your identity before processing the request. There is no charge for submitting a rights request.
For users in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on the following legal bases:
300Sync is a business-to-business software service designed for use by organizations and business professionals. It is not directed at children under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at privacy@300sync.com and we will promptly delete the information.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you by email or via an in-app notification.
Your continued use of 300Sync after a policy update constitutes your acceptance of the revised policy. If you do not agree with the changes, you may discontinue use of the service and request deletion of your account.
We encourage you to review this page periodically. The current effective date is always displayed at the top of this policy.
If you have questions, concerns, or requests related to this Privacy Policy or the handling of your personal data, please contact us:
Mailing address: 300Sync, Inc. · Privacy Team · www.300sync.com
We aim to respond to all privacy inquiries within 5 business days and will complete any rights requests within 30 days.
We take privacy seriously. If anything in this policy is unclear or if you want to exercise your rights, reach out to our privacy team directly.