Privacy Policy
Last updated 29 August 2026 · Sympl Analytics LLC, Utah, United States
1. Who we are
Sympl Analytics LLC (“Sympl”, “we”, “us”) is a limited liability company registered in Utah, United States. We provide a marketing and sales analytics dashboard that connects to systems our customers already use, standardises the data, and reports on it.
For any question about this policy, or to make a request about your data, contact symplanalytics@gmail.com.
2. Two different roles
We handle two kinds of data and our responsibilities differ between them. This distinction matters legally, so we state it plainly rather than blurring the two.
Business data belonging to our customers. When a customer connects HubSpot, Google Search Console or an advertising account, we process that data on their instructions, as a processor. The customer decides what is connected and why. If you are an individual whose details appear in a customer’s CRM, that customer is the controller of your data — contact them, and we will support them in responding.
Data we collect ourselves. Account details and fit-check submissions made on our website are collected by us for our own purposes, and for those we are the controller.
3. What we collect
Account data. Email address, password (stored only as a hash by our authentication provider — we never see or store it in readable form), company name, and the data areas you choose to switch on.
Connected platform data. Only from the platforms you connect, and only what the relevant report needs:
- HubSpot — contact records (first name, last name, email address, lead source) and deal records (name, amount, stage, pipeline, close date).
- Google Search Console — search queries, page URLs, clicks, impressions, click-through rate and average position for the property you select.
- Advertising platforms via Windsor.ai — campaign name, channel, date, spend, impressions, clicks and conversions.
Fit-check submissions. If you complete the questionnaire on our website, we store the email address and answers you provide.
Operational data. Access credentials for connected platforms (encrypted, see section 5), a daily count of assistant requests per account, and — for the two pages that accept submissions without a login — the originating IP address, kept only long enough to enforce rate limits and deleted after 48 hours.
What we do not collect. We run no advertising trackers, no analytics pixels and no third-party cookies. The only cookies we set are the ones that keep you signed in and a short-lived token that protects the Google connection flow from interference.
4. Google user data
When you connect Google Search Console we request a single scope, webmasters.readonly, which is read-only. We never request permission to change or delete anything in your Search Console account, and we do not have it.
How we use it. Solely to produce the search performance reports, recommendations and answers shown inside your own dashboard. Nothing else.
Where it goes. Search Console data is stored in our database (see section 5). When you ask the built-in assistant a question, the relevant portion of your data is sent to Anthropic’s API to generate your answer, and the answer is returned to you. We state this explicitly because it is a transfer to a third party: it happens only to deliver the feature you asked for, only for your own account’s data, and Anthropic acts as our service provider under contract.
What we never do. We do not use Google user data for advertising. We do not sell it, rent it, or share it with data brokers. We do not use it to train general-purpose AI or machine-learning models, and we do not permit our service providers to do so. We do not allow humans to read it except where you have explicitly asked us to help with a support issue, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can revoke our access at any time at myaccount.google.com/permissions, or by removing the connection in your Sympl settings.
5. How we protect it
Access tokens and API keys for connected platforms are encrypted with AES-256-GCM before being written to the database. The encryption key is held only in our server environment, so the database alone never contains a usable credential.
Every account’s data is scoped to that account. Queries are filtered by account identifier resolved from your logged-in session, and the database enforces the same separation independently through row-level security policies.
Credentials for connected platforms are held only on our servers and are never sent to your browser. All traffic to our site and to the platforms we connect to runs over HTTPS.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your data, we will notify affected customers without undue delay and, where we act as a processor, will support the customer in meeting their own notification obligations.
6. Who else processes your data
We use a small number of service providers, each under contract and each with access limited to what their function requires:
- Supabase — database hosting and user authentication.
- Vercel — application hosting and delivery.
- Anthropic — generates the answers given by the in-product assistant, as described in section 4.
- Windsor.ai — retrieves advertising performance data, for customers who connect an advertising platform.
HubSpot and Google are not our service providers — they are your own systems, which you authorise us to read.
We will give notice before adding a new service provider that processes customer data. We do not sell personal information, and we have not done so.
7. How long we keep it
Connected platform data is retained for as long as your account is active, so that period-on-period reporting works. Rate-limiting records are deleted after 48 hours. Fit-check submissions are kept until you ask us to delete them.
When an account is closed we delete its data, including its stored credentials, within 30 days of the request, except where we are required to retain something by law.
8. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to object to or restrict how we use it, to receive a copy in a portable format, and to withdraw consent. Residents of California and other US states with comparable laws have equivalent rights, including the right not to be discriminated against for exercising them.
Email symplanalytics@gmail.com and we will respond within 30 days. Where the data belongs to one of our customers’ connected systems, we will refer you to that customer, who controls it, and assist them in responding.
Our servers are located in the United States. If you are outside the United States, using Sympl involves transferring your data there.
9. Children
Sympl is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.
10. Changes to this policy
If we change how we handle data we will update this page and revise the date at the top. For changes that materially affect how we use data you have already given us, we will notify account holders by email before the change takes effect.