Effective Date: March 15, 2026 · Last Updated: March 15, 2026
Synqline ("we," "us," or "our") operates as a business automation and messaging consultancy. This Privacy Policy describes how we collect, use, protect, and disclose information in connection with our services, including WhatsApp Business API integration, SMS campaign management, chatbot development, and systems integration.
This policy applies to:
By using our services or website, you agree to the practices described in this policy. If you do not agree, please discontinue use of our services.
Note: This policy is intended to satisfy the requirements of Meta (Facebook) Business Verification, Twilio Messaging Services, PCI DSS, HIPAA, TCPA, CAN-SPAM, GDPR, and CCPA. If you have compliance-specific questions, contact us at info@synqline.io.
When we build or manage messaging systems for clients, we may process:
This data is processed under a data processing agreement with the client and is used solely to deliver the contracted service.
We do not intentionally collect sensitive personal data (Social Security numbers, government IDs, biometric data, financial account numbers, or health information) unless explicitly required and agreed upon in writing for a specific engagement — in which case HIPAA and applicable security controls apply.
We do not sell, rent, or trade personal data to third parties for their own marketing purposes.
Synqline is a WhatsApp Business Solution Provider (BSP) partner operating under Meta's WhatsApp Business Policy and Meta Platform Terms. All messaging conducted through our platform must comply with these terms.
We only send WhatsApp messages to end-users who have explicitly opted in to receive communications. Opt-in must be:
Messages sent via WhatsApp Business API are limited to Meta-approved categories, including: utility messages, authentication messages, and marketing messages (where a valid opt-in exists). Prohibited content includes spam, illegal content, misleading information, and unsolicited commercial messages.
End-users may opt out of WhatsApp communications at any time by:
Opt-out requests are honored within 24 hours. Once opted out, the user will not receive further messages from that campaign.
Synqline maintains verified business status with Meta. This verification confirms our legal business identity and ensures compliance with Meta's commercial messaging policies. Client businesses operating under our BSP umbrella must also complete Meta's Business Verification process before accessing WhatsApp Business API.
WhatsApp message metadata is processed via Meta's infrastructure. Message content may transit Meta's servers in accordance with Meta's Privacy Policy. We recommend clients review Meta's data residency policies for regional compliance requirements.
TCPA Disclosure: By providing your phone number and consenting to receive SMS messages, you agree to receive automated text messages from us or our clients. Message and data rates may apply. Message frequency varies.
We operate SMS campaigns in compliance with the Telephone Consumer Protection Act (TCPA), CAN-SPAM Act, and carrier requirements under The Campaign Registry (TCR) 10DLC program. SMS messages are only sent to individuals who have:
All SMS campaigns utilizing 10-digit long codes (10DLC) are registered with The Campaign Registry through our Twilio account. Registration includes:
Unregistered or improperly registered traffic may be filtered by mobile carriers. We do not operate campaigns that violate carrier guidelines or TCR policies.
The following standard keywords are supported on all SMS campaigns:
Opt-out is immediate. Confirmation of opt-out is sent within one message. Re-opt-in is permitted at any time by texting START.
Mobile phone numbers and SMS consent information will not be shared with or sold to third parties or affiliates for their own marketing or promotional purposes. This data is used solely to operate the specific SMS campaign for which consent was granted.
We strictly prohibit and do not facilitate the following content categories (SHAFT):
Synqline is a messaging and automation services company. We do not directly process, store, or transmit payment card data. All payment transactions are handled by PCI DSS Level 1 certified third-party payment processors. Our PCI DSS obligations are governed by SAQ-A (Self-Assessment Questionnaire A) as a merchant that fully outsources payment processing.
If Synqline builds or integrates a payment workflow within a messaging automation system for a client, the following conditions apply:
In the event of a suspected breach involving payment data, we will notify affected parties within 72 hours in accordance with applicable breach notification laws and PCI DSS Requirement 12.10.
Important: Synqline's standard services are not designed for the transmission or storage of Protected Health Information (PHI). Engagements involving PHI require a signed Business Associate Agreement (BAA) prior to project commencement.
HIPAA obligations apply when Synqline is engaged by a Covered Entity (healthcare provider, health plan, or healthcare clearinghouse) or their Business Associates to build or manage communication systems that may involve PHI. In such cases:
For HIPAA-covered engagements, Synqline implements:
WhatsApp and standard SMS channels are not considered HIPAA-compliant by default due to the absence of BAAs with Meta and carriers. If a healthcare client requires messaging automation:
For HIPAA-covered engagements, individuals retain all rights under the HIPAA Privacy Rule, including the right to access, amend, and receive an accounting of disclosures of their PHI. Requests should be directed to the Covered Entity (your healthcare provider), who will coordinate with Synqline as required under the BAA.
We implement industry-standard technical, administrative, and physical safeguards to protect data against unauthorized access, alteration, disclosure, or destruction:
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Upon expiration of the applicable retention period, data is securely deleted or anonymized.
Our lawful basis for processing is: contract performance (for service delivery), legitimate interests (for security and analytics), and consent (for marketing communications).
California residents have the right to know what personal information is collected, the right to delete, the right to opt out of sale (we do not sell data), and the right to non-discrimination for exercising privacy rights. To submit a request, email info@synqline.io with the subject line "CCPA Request."
To exercise any of the above rights, contact us at info@synqline.io. We will respond within 30 days (or as required by applicable law). We may verify your identity before fulfilling the request.
Our services are directed to businesses and are not intended for individuals under the age of 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, contact us immediately at info@synqline.io and we will delete it.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform policies. When we make material changes, we will update the "Last Updated" date at the top of this page. Continued use of our services after changes are posted constitutes acceptance of the revised policy.
For significant changes affecting messaging consent or data rights, we will provide direct notice to active clients via email.
For privacy requests, compliance questions, BAA inquiries, or to report a concern:
Synqline
Privacy & Compliance
info@synqline.io
synqline.io/contact
For HIPAA-specific requests or to request a Business Associate Agreement, please email with the subject line "BAA Request".
For TCPA / SMS opt-out issues not resolved through keyword reply, email with the subject line "SMS Opt-Out" and include your phone number.