SyncRange Data Security
Last Updated: August 2026
Security
SyncRange ensures the highest level of security for your private information. We understand that when connecting your business applications, security is a top priority. The information you share with SyncRange and the data you transfer from source to destination is secured from any breaches, leaks, or unauthorized disclosures.
How we protect your data
- Transport Security: All data transferred between your services and SyncRange is protected using strong Transport Layer Security (TLS).
- Encrypted Credentials: OAuth tokens, API keys you provide for integrations, MCP access tokens, and other credentials are encrypted at rest using Fernet (AES-128-CBC with HMAC-SHA256).
- Export Data Flow: For standard data exports, your data flows through our service to your destinations (e.g. Google Sheets, BigQuery) and is not retained beyond what is needed to complete the transfer and troubleshoot failures.
- Managed Reports: When you use managed reports, we store the synced dataset in our platform-managed warehouse so you can view and refresh reports in SyncRange. That data is retained only while the report exists and is deleted when you remove the report or your account.
- Logging: Completion and error logs are retained for troubleshooting purposes.
Security, Privacy, and Compliance
Data Source Permissions
SyncRange only requests the minimum read or view permissions needed to fetch data from source applications. Our service won't be able to edit, update, or remove any records in your source applications.
Data Destination Permissions
SyncRange needs view, create, and edit permissions for destination applications (like Google Sheets) in order to write data, update data during refresh, and create new sheets when necessary.
Permission to Delete
SyncRange does not use permission to delete any existing sheets or data in your destination applications. You can revoke access to your source and destination apps at any time.
Credentials and Passwords
All logins, passwords, OAuth tokens, API keys, MCP tokens, and other credentials are classified as critical data that is securely encrypted and protected from any unauthorized access. You can revoke or rotate credentials at any time.
Authentication and Access
We provide secure authentication options:
- OAuth 2.0: Login via Google using industry-standard OAuth 2.0 protocols. Many integrations also connect via OAuth.
- API Keys: Some integrations authenticate with API keys you supply; those keys are encrypted at rest and used only to provide the requested service.
- MCP Access: If you enable SyncRange's Model Context Protocol (MCP) server, you create and manage your own MCP tokens. Those tokens grant access only to the connections and data you authorize for your team.
- Secure Sessions: All user sessions are secured with appropriate timeouts and protection measures.
- Access Controls: Users can only access their own team's data and connections.
Infrastructure Security
SyncRange's infrastructure includes:
- Secure cloud hosting with industry-standard security controls
- Regular security patches and updates
- Network protection measures including firewalls
- Monitoring for suspicious activities
Technical Security Details
Data Encryption and Protection
- In transit: All data is encrypted using TLS 1.2 or higher.
- At rest: Sensitive data (credentials, OAuth tokens, API keys, MCP tokens) is encrypted at rest using Fernet (AES-128-CBC with HMAC-SHA256). Database and application data is stored on encrypted storage.
- Key management: Encryption keys are stored securely and access is restricted to authorized personnel.
Data Storage Location
Our infrastructure is hosted in US East and Sydney, Australia. Contact us to discuss data residency requirements for your organization.
Access Control and Authentication
- Multi-factor authentication (MFA) is available for all user accounts
- MFA is required for administrative access to production systems
- Access to production systems is restricted to authorized personnel; principle of least privilege is applied
- Service account credentials are managed securely and rotated as needed
Incident Response and Monitoring
- Detection: We monitor our systems for suspicious activity and security events
- Response: We maintain an incident response process to contain and remediate security events
- Notification: In the event of a data breach affecting customer data, we will notify affected customers in accordance with applicable law and contractual obligations
- Post-incident: We conduct root cause analysis to improve our defenses following security events
Data Handling and Retention
- For standard exports, transfer data flows through our systems to your destinations and is not retained beyond completing the transfer and troubleshooting
- For managed reports, synced data is stored in our platform-managed warehouse for as long as the report (or your account) remains active
- Credentials, API keys, and MCP tokens are treated as sensitive data and protected accordingly
- Customers can request data deletion at any time; we support data subject rights including access, rectification, erasure, and portability
Business Continuity
We maintain backup and disaster recovery procedures. Our infrastructure is designed for availability, and we apply security patches and updates on a regular basis. We monitor security advisories for our technology stack.
Third-Party Data Sharing
We do not sell customer data to third parties. Data is shared only as necessary to provide our services.
Compliance and Documentation
Our Privacy Policy describes our data handling practices. We can discuss data processing agreements (DPAs) and specific compliance requirements with enterprise customers upon request.
GDPR and data protection
For customers and users in the European Economic Area (EEA), Switzerland, and the United Kingdom, we align our security practices with the expectations of the General Data Protection Regulation (GDPR) and UK GDPR where they apply.
- Technical and organizational measures: We implement appropriate measures to protect personal data, including those described on this page (encryption, access controls, monitoring, and incident response).
- Confidentiality, integrity, and availability: Our controls are designed to safeguard personal data against unauthorized access, alteration, or loss.
- Subprocessors: Where we use infrastructure or service providers that process personal data on our behalf, we assess their security and govern processing through appropriate agreements.
- Breach notification: Where we act as a processor for your organization, we will assist with notifications required under GDPR in line with our agreement with you. Where we are a controller, we will address personal data breaches in accordance with applicable law.
- Documentation: We can provide a Data Processing Agreement (DPA) and further detail on measures for customers who require it—contact us at [email protected].
Rights of individuals (access, erasure, portability, and others) and how we use personal data are set out in our Privacy Policy.
Our Commitment
At SyncRange, we're committed to maintaining the highest standards of security for your data. We regularly review and enhance our security measures to protect against emerging threats and ensure your data remains secure.
For more information about how we handle your data, please refer to our Privacy Policy and Terms and Conditions.
Security inquiries: For security concerns, enterprise security questionnaires, contact us at [email protected].