Zuppa Sync

Attio and HubSpot integration

Privacy

Privacy Policy

This policy explains how Zuppa Sync handles personal data and customer synchronization data when providing the Attio and HubSpot integration.

Last updated: July 2, 2026

1. Who we are

Zuppa Sync is operated by Lorenzo Croccolino, VAT IT04390140400, Italy (IT). This Privacy Policy explains how we collect, use, store, and protect personal data when you access the website, create an account, connect Attio or HubSpot, configure mappings, use synchronization features, contact support, or otherwise interact with the service.

For the purposes of applicable privacy laws, including the General Data Protection Regulation (GDPR) where applicable, Lorenzo Croccolino is the data controller for account, billing, support, website, and service administration data. For customer data synchronized between Attio and HubSpot, we generally act as a processor or service provider acting on your instructions.

2. Data we collect

Account data: name, email address, authentication identifiers, invited user details, account status, and session information.

Mapping and configuration data: mapping names, descriptions, selected plans, sync directions, provider connection status, profile configuration, selected objects, selected fields, matching rules, field mappings, filters, and operational preferences.

Provider connection data: OAuth identifiers, portal or workspace identifiers, scopes, token metadata, encrypted access and refresh tokens, connected account labels, and connection timestamps.

Synchronization data: record identifiers, matching values, object types, field keys, transformed payload previews, sync run status, errors, statistics, timestamps, and operational logs needed to run, debug, and report synchronization activity.

Billing data: Stripe checkout, customer, subscription, price, trial, invoice, payment status, and event metadata. Full payment card details are handled by Stripe and are not stored by us.

Support and communication data: information you submit through support forms, emails, or other contact channels, including contact details and issue descriptions.

Technical and usage data: IP address, browser and device information, timestamps, security events, server logs, diagnostics, cookies or similar technologies, and basic analytics or tracking data where enabled.

3. How we use data

We use personal data to create and manage accounts, authenticate users, provide access to dashboards and mappings, connect Attio and HubSpot accounts, run synchronization workflows, process webhooks or scheduled sync jobs, maintain logs and statistics, enforce plan limits, provide billing flows, respond to support requests, improve reliability, prevent abuse, and comply with legal obligations.

We do not sell personal data. We do not use customer synchronized data for advertising. We process connected provider data only as needed to provide, secure, maintain, debug, and improve the service, or as otherwise instructed by the customer.

4. Legal bases

Where GDPR or similar laws apply, we rely on the following legal bases: performance of a contract to provide the service, legitimate interests to secure and improve the service, consent where required for optional communications or tracking, and legal obligations for billing, tax, accounting, compliance, or security requirements.

When we process customer data from Attio or HubSpot on behalf of a customer, the customer is responsible for having an appropriate legal basis for that processing and for configuring the service in a lawful way.

5. Connected providers and third-party services

The service may use third-party providers such as Attio, HubSpot, Stripe, Firebase, MongoDB, hosting providers, email providers, analytics tools, support tools, and infrastructure providers. These providers process data only as needed for their role in operating the service, subject to their own terms, privacy policies, and data processing commitments.

When you authorize Attio or HubSpot, the service receives access according to the scopes and permissions approved during OAuth or app installation. You can revoke provider access through the provider account or by requesting deletion of your account and data.

6. International transfers

Data may be processed in countries other than your own depending on where our service providers, hosting infrastructure, or third-party platforms operate. When required, we rely on appropriate safeguards such as contractual protections, standard contractual clauses, adequacy decisions, or equivalent transfer mechanisms.

7. Data retention

We keep account, mapping, billing, support, and operational data for as long as needed to provide the service, maintain security, resolve disputes, comply with legal obligations, and preserve audit trails.

Synchronization logs, run records, and error details may be retained for operational visibility, troubleshooting, abuse prevention, and compliance. Some data may remain in backups for a limited period after deletion until those backups expire or are overwritten.

You can request account and data deletion by emailing ramen@bitzuppa.com. We will verify the request and delete or anonymize data unless we need to retain specific information for legal, billing, security, fraud prevention, or legitimate operational reasons.

8. Security

We use technical and organizational measures designed to protect data, including access controls, encrypted provider credentials where applicable, secure authentication, restricted administrative access, logging, and operational monitoring.

No system can be guaranteed to be completely secure. You are responsible for protecting your login credentials, limiting user access, reviewing connected provider permissions, and promptly informing us if you suspect unauthorized access or misuse.

9. Your privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also have the right to withdraw consent where processing is based on consent and to lodge a complaint with a supervisory authority.

To request deletion of your account and data, email ramen@bitzuppa.com. For other privacy questions, you may also contact support@bitzuppa.com. We may need to verify your identity before processing certain requests.

10. Customer responsibilities

Customers are responsible for the data they connect, sync, transform, or store through the service. This includes ensuring that provider accounts are authorized, users have appropriate permissions, data subjects have been informed when required, and the configured synchronization complies with applicable privacy, employment, marketing, and sector-specific laws.

Customers should avoid syncing unnecessary sensitive data and should configure mappings using the minimum data needed for their business purpose.

11. Cookies and tracking

The service may use cookies, local storage, or similar technologies for authentication, security, session management, embedded forms, support, analytics, and service improvement. Third-party embeds such as HubSpot forms may set their own cookies or collect technical metadata according to their policies.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the service, legal requirements, providers, or operating practices. The updated version will be posted on this page with a revised last updated date.

If changes are material, we may provide additional notice through the service or by email when appropriate.