1. Who We Are
Mr Syn is operated by TNAADO Labs, Inc. ("TNAADO," "we," "us") at [COMPANY_ADDRESS]. For privacy questions: [email protected].
TNAADO is the data controller (GDPR) and business (CCPA/CPRA) for the data we collect through Mr Syn.
2. What We Collect
2.1 Information you provide
- Account: name, email, password, phone number, date of birth, display name, profile photo.
- Identity verification: government ID, selfie, address, SSN or SIN last-digits (for tax), collected via Stripe Identity and stored by them on our behalf.
- Payment: card, bank account or ACH details, billing address. We never see your full card number; Stripe handles it under PCI DSS.
- Contest submissions: photos, videos, check-in proof, notes.
- Support messages: anything you send us at [email protected] or via the in-app help center.
2.2 Information we collect automatically
- Workout + sensor data: GPS coordinates, pace, distance, elevation, accelerometer / pedometer readings, heart-rate if you opt in, workout duration, route map.
- HealthKit data (iOS) and Google Fit (Android) that you explicitly authorize us to read.
- Device: device model, OS version, app version, language, time zone, IP address, device identifier, crash logs, diagnostic logs.
- Usage: pages viewed, buttons pressed, contest entries and results, session length, referrer.
2.3 Information from third parties
- Identity-verification results from Stripe Identity.
- Fraud and risk signals from Stripe, networks, and security vendors.
- Social auth providers if you sign up through them (name, email).
3. How We Use It
We use personal data to:
- Run the Service: create your account, process contests, pay winners.
- Verify identity and age, enforce eligibility, detect and prevent fraud, abuse, and prohibited conduct.
- Provide AI features (food scanner, coach). See Section 8 of the Terms and Section 15 below.
- Send transactional email and push notifications.
- Debug, monitor, and secure the Service.
- Comply with law, tax, court orders, and regulatory obligations.
- With your consent, send marketing messages about new challenges or product updates. You can unsubscribe any time.
We do not sell your personal information.
4. Legal Bases (GDPR / UK GDPR)
Where GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract: running the Service, processing contest entries, and paying out winnings.
- Legitimate interests: fraud prevention, security, product improvement, analytics.
- Legal obligation: tax, AML/KYC, sanctions screening.
- Consent: marketing, health data, optional sensor categories, cookies that are not strictly necessary.
- Vital interests: emergency safety situations during outdoor activities.
5. Sharing and Sub-Processors
We share personal data only with vendors that need it to run the Service, under written contract and confidentiality obligations. Our current sub-processors:
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Primary database, auth, storage, edge functions | US / EU |
| Stripe and Stripe Identity | Payments, payouts, KYC, tax forms | US / EU / CA |
| Anthropic (Claude) | AI coach, food scanner, submission review | US |
| xAI (Grok) | Secondary AI features | US |
| Resend | Transactional email | US / EU |
| Vercel | Website hosting | US / Global edge |
| Apple + Google | App distribution, push, in-app purchases | Global |
We may also share data with law enforcement or regulators when legally required, with professional advisers under confidentiality, or with a successor in a merger or acquisition (with notice to you).
6. International Transfers
We are based in Canada. Some of our sub-processors are in the US or EU. For transfers of EU or UK personal data outside of adequate jurisdictions we rely on Standard Contractual Clauses (SCCs) and, where available, the UK International Data Transfer Addendum. Copies are available on request.
7. Retention
- Account + activity data: for as long as your account is open, plus up to 7 years for tax, AML, and legal records.
- Contest submissions: at least 2 years after the contest to handle disputes and audits.
- Identity verification documents: retained by Stripe Identity per their terms; typically 5 years.
- Support messages: 3 years.
- Crash and diagnostic logs: up to 180 days.
You can delete your account any time from the app; we then remove or anonymize data we are not required to keep.
8. Security
We use encryption in transit (TLS 1.2+) and at rest, role-based access controls, row-level security on our database, audit logging, code review, and vendor security reviews. No system is perfectly secure. If we learn of a breach that affects you, we will notify you as required by law.
9. Your Rights
Subject to your location, you may have the right to:
- Access a copy of your data.
- Correct inaccurate data.
- Delete data we hold about you.
- Port your data to another service.
- Withdraw consent or object to processing.
- Restrict certain processing.
- Lodge a complaint with your data-protection authority.
Email [email protected] to exercise any of these rights. We will respond within 30 days (or as required by applicable law). We may need to verify your identity first.
10. US State Rights (CCPA / CPRA and similar)
If you live in California, Colorado, Connecticut, Virginia, Utah, or another US state with a comprehensive privacy law, you have the right to:
- Know what personal information we have collected about you.
- Delete personal information, subject to exceptions.
- Correct inaccurate personal information.
- Opt out of sale or sharing for cross-context behavioral advertising. We do not sell or share personal information.
- Limit use of sensitive personal information.
- Not be discriminated against for exercising these rights.
Submit requests to [email protected]. You can appeal a denial by emailing the same address with subject "Privacy Appeal".
11. Canadian Rights (PIPEDA and provincial laws)
Under PIPEDA and applicable provincial privacy laws (including Quebec's Law 25), you may access, correct, or withdraw consent to the processing of your personal information by contacting [email protected]. You can also complain to the Office of the Privacy Commissioner of Canada or to your provincial commissioner. TNAADO's designated privacy officer can be reached at the same email.
12. Health, Location, Biometrics
Mr Syn reads motion, step, and, with your permission, HealthKit or Google Fit data. We use "location: always" on iOS to record GPS during ongoing outdoor activities. You can revoke location access any time from your system settings. Disabling location will prevent us from verifying GPS-based contest entries.
The food scanner processes photos of meals. We do not use these images for facial recognition or to build a biometric profile. If you are in Illinois (BIPA) or another state with a biometric law, we do not knowingly collect biometric identifiers.
13. Children
Mr Syn is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have, contact [email protected] and we will delete it. Account holders must be 18 or older.
14. Cookies and SDKs
Our website uses a small number of strictly-necessary cookies for session, CSRF, and preferences. Our mobile app uses platform SDKs for push, analytics (counts and events only), and crash reporting. We do not use third-party advertising or cross-site tracking cookies. If this changes we will update this policy and seek consent where required.
15. Automated Decision-Making
We use automated review for contest submissions (AI plus sensor heuristics) and for fraud scoring. Automated decisions can reject a submission, place a hold, or require manual review. You can ask for a human review of any automated decision that materially affects you by emailing [email protected].
16. Changes
We may update this policy. Material changes will be announced in the app and on mrsyn.app. The "Last updated" date shows the effective version.
17. Contact
TNAADO Labs, Inc. — Attn: Privacy Officer
[COMPANY_ADDRESS]
Email: [email protected]
