Privacy Policy

Your privacy, by design.

How DeepSync collects, uses, and protects information—built around masking, consent, and data minimization.

Last updated: July 28, 2026

1. Overview

DeepSync (“we,” “us,” or “our”) provides an AI-powered website analytics and user behavior platform, including session replay, heatmaps, conversion funnels, user journeys, and AI-generated insights (the “Service”). This Privacy Policy explains what information we collect, how we use and share it, and the choices available to you, whether you are a customer using our dashboard (“Customer,” “you”) or a visitor to a website or app on which our Service is deployed (“Visitor”).

We are built privacy-first. Sensitive input fields are masked by default, our customers control consent and retention settings, and we do not sell personal information.

This Privacy Policy applies to deepsync.in, our dashboard and application (app.deepsync.in), our tracking script and mobile SDKs, and related services. It does not apply to third-party websites or services that we do not control, even if linked from our Service.

2. Roles: controller and processor

When you create a DeepSync account, we act as the data controller (or equivalent) of your account information (described in the Information We Collect section below) and are responsible for how we handle that data.

When our Service captures behavioral data from a Customer's website or app visitors (clicks, scrolls, page views, form interactions, and similar signals) on that Customer's instruction, DeepSync acts as a data processor (or service provider, as applicable) and the Customer acts as the data controller responsible for the lawfulness of that data collection, including providing notice and obtaining consent from its own Visitors. If you are a Visitor and have questions about data collected on a particular website, you should contact the operator of that website directly.

3. Information we collect

Depending on how you interact with DeepSync, we may process:

  • ·Account information: name, email address, password (hashed), company name, job title, phone number, and billing details you provide when creating an account or subscribing to a plan.
  • ·Payment information: our payment processor (Razorpay) collects and processes card, UPI, or bank details directly; DeepSync does not store full payment card numbers.
  • ·Usage data: how you interact with the DeepSync dashboard, including pages viewed, features used, clicks, and session duration, collected to help us improve the product and provide support.
  • ·Behavioral/Visitor data captured on Customer websites and apps on behalf of our Customers (who act as data controllers for this data), which may include: page views and navigation paths, clicks, taps, scrolls, and mouse or touch movement; form field interaction metadata (with sensitive field values masked by default); rage clicks, dead clicks, and error signals; approximate location derived from IP address; and device, browser, and operating system information.
  • ·Technical data: IP address, browser type and version, device type, operating system, referring/exit pages, and timestamps, collected automatically when you or a Visitor interacts with our website, dashboard, or the Service embedded on a Customer property.
  • ·Communications: information you provide when you contact support, respond to surveys, or otherwise communicate with us.
  • ·Cookies and similar technologies: as described in the Cookies and tracking technologies section below.

4. What we do not intentionally collect

DeepSync's tracking script is designed to mask sensitive input fields (such as passwords, payment card numbers, and other fields marked as sensitive by the Customer or detected by our automatic masking heuristics) by default, so that their values are not transmitted to or stored by DeepSync.

We do not intend to collect government identification numbers, health information, financial account numbers, or other special categories of personal data through the Service, and Customers are responsible for configuring masking, exclusion rules, and consent controls to prevent such data from being captured.

5. Legal bases for processing (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • ·Performance of a contract, to provide the Service to Customers and manage their accounts.
  • ·Legitimate interests, to secure, maintain, and improve the Service, prevent fraud and abuse, and communicate with Customers about their accounts, provided those interests are not overridden by your rights.
  • ·Consent, where required by applicable law for certain cookies, tracking technologies, or marketing communications, or where a Customer relies on Visitor consent to enable behavioral data capture.
  • ·Compliance with legal obligations, where we are required to process or retain data to comply with applicable law.

6. How we use information

  • ·To provide, operate, maintain, and support the DeepSync dashboard and Service.
  • ·To generate session replays, heatmaps, funnels, journeys, and AI-generated insights and summaries for our Customers.
  • ·To process payments and manage subscriptions, billing, and invoicing.
  • ·To communicate with you about your account, service updates, security notices, and (where permitted) product news; you can opt out of non-essential marketing communications at any time.
  • ·To monitor, detect, investigate, and prevent fraud, abuse, security incidents, and technical issues.
  • ·To comply with legal obligations, respond to lawful requests from authorities, and enforce our Terms of Service.
  • ·To develop and improve our products, including using aggregated or de-identified data for analytics, benchmarking, and machine-learning model improvement, in each case in a manner that does not identify an individual Visitor.

7. Cookies and tracking technologies

DeepSync and our Customers may use cookies, local storage, and similar technologies to enable core Service functionality (such as recognizing returning Visitors within a session), remember preferences, and, where applicable and permitted, measure and improve the Service.

Categories of cookies used include: strictly necessary cookies required for the Service to function; functional cookies that remember settings; and analytics cookies used to understand aggregate usage patterns. We do not use cookies for third-party behavioral advertising.

You can control cookies through your browser settings, and, where our Customers implement a consent management or cookie banner, through those controls. Disabling certain cookies may affect the functionality of websites that use the Service.

8. Data masking and minimization

DeepSync masks sensitive fields such as passwords and payment details by default. Customers can configure additional masking rules, exclude specific pages, elements, or user segments from capture, and set retention periods to minimize the data collected and stored to what is necessary for their use case.

9. AI-generated insights

DeepSync uses large language models and other automated analysis to generate summaries, insights, and recommendations from Customer Data (for example, identifying friction points in a session or summarizing trends across sessions). These AI features process Customer Data solely to generate outputs for the Customer that requested them and are not used to train third-party foundation models on Customer Data without a separate agreement.

10. Data sharing and subprocessors

We do not sell personal information, and we do not share Visitor data with third parties for their own advertising purposes.

We share data with the following categories of service providers, each bound by contractual confidentiality and data protection obligations, solely to help us operate the Service:

  • ·Cloud hosting and infrastructure providers (for example, Microsoft Azure), to store and process Customer Data and Visitor data.
  • ·Payment processors (currently Razorpay), to process subscription payments.
  • ·Customer support, analytics, and communication tools used to operate our business.
  • ·AI model providers, to generate AI insights from Customer Data, subject to contractual restrictions on further use of that data.
  • ·Professional advisors (legal, accounting) and, where necessary, law enforcement or regulators, to comply with legal obligations or protect our rights.
  • ·A successor entity, in the event of a merger, acquisition, financing, or sale of assets, subject to this Privacy Policy or a substantially similar policy.

11. International data transfers

DeepSync's infrastructure may process and store data in India and other countries where our hosting and service providers operate. Where personal data originating in the EEA, UK, or Switzerland is transferred to a country that has not been deemed to provide an adequate level of protection, we rely on appropriate safeguards, such as Standard Contractual Clauses or equivalent mechanisms, to protect that data.

12. Data retention

We retain account information for as long as your account remains active and for a reasonable period afterward to comply with legal, accounting, or reporting obligations, resolve disputes, and enforce our agreements.

Behavioral/Visitor data (session recordings, heatmap data, and related analytics) is retained according to the retention period configured by the applicable Customer for their plan; by default this does not exceed the retention period associated with the Customer's subscription tier. Customers can configure shorter retention periods and request deletion of specific sessions or data sets at any time.

Upon account cancellation or termination, we delete or anonymize Customer Data within a commercially reasonable period, except where retention is required to comply with legal obligations, resolve disputes, or enforce agreements.

13. Data security

We use enterprise-grade security controls, including encryption of data in transit (TLS) and at rest, access controls and authentication, network segmentation, tenant isolation between Customer accounts, and regular security reviews, to protect data against unauthorized access, disclosure, alteration, or destruction.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal data, we will notify you and applicable regulators as required by law.

14. Your privacy rights

Subject to applicable law (including the GDPR, UK GDPR, India's Digital Personal Data Protection Act, and U.S. state privacy laws such as the CCPA/CPRA), you may have the right to:

  • ·Access the personal data we hold about you and receive a copy of it.
  • ·Correct or update inaccurate or incomplete personal data.
  • ·Request deletion of your personal data, subject to certain legal exceptions.
  • ·Object to or request restriction of certain processing activities, including processing based on legitimate interests.
  • ·Request portability of personal data you have provided to us, in a structured, commonly used format.
  • ·Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
  • ·Not be discriminated against for exercising any of these rights.

15. California privacy rights

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, use, and disclose, to request deletion or correction of your personal information, and to opt out of the “sale” or “sharing” of personal information. DeepSync does not sell or share personal information for cross-context behavioral advertising. To exercise your California privacy rights, contact us at m@drema.in.

16. How to exercise your rights

To exercise any of the rights described above, contact us at m@drema.in. We may need to verify your identity before fulfilling your request. If you are a Visitor to a Customer's website and wish to exercise rights over data collected there, we recommend contacting that Customer directly, as they control the purposes and means of that data collection; we will also assist Customers in responding to such requests as required by our data processing terms.

17. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal data directly from children through our own website or account registration. If you believe a child has provided us with personal data, contact us at m@drema.in so we can take appropriate action.

18. Do Not Track signals

Some browsers offer a “Do Not Track” (DNT) signal. Because there is no common industry standard for DNT, our Service does not currently respond differently to browser DNT signals, though our Customers may configure their own consent controls to honor such preferences.

19. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. Material changes will be reflected by updating the “Last updated” date above, and, where required by law or where the changes are significant, we will provide additional notice such as an email or in-product notification.

20. Contact us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at m@drema.in.

Ready to understand
users like never before?

Join thousands of teams who use DeepSync to uncover insights,improve experiences, and build better products—faster.

Quick & easy onboarding
See results in real time
Enterprise-grade security