Privacy Policy

Last updated: August 22, 2026

1. Who we are

Sentalong is operated by Symphonic Grow ("Sentalong", "we", "us"). We operate sentalong.com, the Sentalong application, and branded affiliate portals configured by our customers. This policy explains what personal data we collect, why, how long we keep it, and the choices available to you.

For affiliate partners ("affiliates") using a customer's portal: that customer controls their program and its data. We process affiliate data on their behalf as a service provider — direct your rights requests to the company whose program you participate in, or to us at [email protected] and we will route them appropriately.

2. Data we collect

Depending on your relationship with us:

  • Account data: name, email, password hash, workspace details you provide at signup.
  • Billing data: subscription status managed via our payment processors; we do not store full card numbers.
  • Program data our customers upload or connect: affiliate contact details, referral link activity, commission records, payout history.
  • Tracking data for attribution: first-party cookies and server-side session records connecting referral clicks to conversions on our customers' sites (60-day default window).
  • Usage data: pages visited, features used, approximate location derived from IP, device/browser type, logs.
  • Communications: emails you send us and records of support interactions.

3. Why we use it

We process personal data to:

  • Provide the service: accounts, tracking, commission calculation, payouts, program reporting.
  • Operate attribution accurately for our customers' affiliate programs.
  • Secure the service, prevent fraud and abuse, and enforce our terms.
  • Communicate about your account, service changes, billing, and (with consent) product updates.
  • Meet legal obligations, including tax documentation requirements for payouts.

4. Sharing

We sell no personal data and run no ad-network trackers. We share data only with:

  • Infrastructure and sub-processors necessary to run the service (cloud hosting, email delivery, error monitoring), bound by confidentiality obligations.
  • Payment processors (e.g., Stripe) strictly to execute subscriptions and affiliate payouts.
  • The Sentalong customer who operates the program an affiliate participates in.
  • Authorities where legally required, with notice to you when permitted.

5. Cookies

We use strictly necessary cookies for authentication and first-party referral-attribution cookies (set only on our customers' domains for affiliate tracking). We do not use third-party advertising cookies. You can clear or block cookies in your browser; blocking authentication cookies will prevent sign-in, and blocking attribution cookies may prevent affiliates from receiving credit for visits from your browser.

6. Retention

Account and program data are retained while a workspace is active. After account closure, data is deleted or anonymized within 90 days, except where law requires longer retention (e.g., financial and tax records, which follow statutory retention periods). Backup copies age out within a further 30 days.

7. Your rights

Where applicable law provides rights of access, correction, deletion, portability, restriction, or objection — including rights under the EU/UK GDPR, California's CCPA/CPRA (knowing, deleting, correcting, and opting out of any 'sale' or 'share' of personal information, which we do not engage in), and India's Digital Personal Data Protection Act, 2023 (access, correction, erasure, grievance redressal, and nomination) — contact us and we will respond within the legally required timeframe. Authorized agents may submit requests with proof of authorization.

8. Security & international transfers

We protect data with encryption in transit and at rest, access controls, least-privilege internal access, and audit logging. No system is perfectly secure; we also maintain incident response practices and will notify affected customers and regulators as required by law. Data may be processed in the United States and other countries where our sub-processors operate; where required, transfers rely on appropriate safeguards such as standard contractual clauses.

9. Changes & contact

We update this policy when practices change; material changes are announced in-app or by email before taking effect. This version applies from its "last updated" date. For data-privacy questions or grievances — including under India's DPDP Act — write to [email protected] (Symphonic Grow); we acknowledge grievances promptly and resolve them per applicable timelines.

Questions about this document? Email [email protected].