CROXSYNC
Legal

PRIVACY
POLICY.

CROXSYNC is committed to protecting your personal information and complying with UK GDPR, EU GDPR, and all applicable privacy and data protection laws.

Last updated: May 2026

Zero Credential Storage

OAuth 2.0 only — your passwords never touch our servers.

No File Content Stored

Files stream directly between Procore and SharePoint in 5 MiB chunks. We never buffer or retain file content.

EU Data Storage

All data stored in the EU. Tokens encrypted at rest with AES-256-GCM.

Beta Stage Notice

CROXSYNC is currently in closed beta. The platform is available exclusively to users who have received a direct invitation or submitted a specific access request. It is not publicly listed on the Procore Marketplace nor available for general download or use. This Privacy Policy accurately and completely reflects our data practices during this beta period.

As development progresses toward public launch, this policy will be updated to reflect any changes in data practices. Beta participants will be notified by email of any material updates before they take effect. Continued use of the Service following notification constitutes acceptance of the revised policy.

Data Responsibility

CROXSYNC — and not Procore Technologies, Inc. or Microsoft Corporation — is solely and exclusively responsible for the privacy, security, and integrity of any Customer Data accessed, processed, or stored by CROXSYNC or the CROXSYNC application.

CROXSYNC is an independent software application developed and operated by Croxsoft Ltd. Procore Technologies, Inc. and Microsoft Corporation are third-party platform providers whose APIs CROXSYNC integrates with. Neither Procore nor Microsoft is a party to this Privacy Policy, and neither bears any responsibility or liability for how CROXSYNC accesses, handles, stores, or processes your data.

By using CROXSYNC, you acknowledge and agree that all data protection obligations relating to your use of this application rest solely with Croxsoft Ltd (trading as CROXSYNC), and not with Procore or Microsoft.

What Personal Information We Collect

We collect and process the minimum personal information strictly necessary to provide the synchronisation Service. This includes:

Full name
Email address
Organisation name
File metadata (names, sizes, timestamps, IDs)
OAuth access tokens (encrypted at rest)
Sync activity and audit logs
Metadata only — never file content. CROXSYNC records file names, sizes, last-modified timestamps, and platform-assigned identifiers. This is the strict minimum required to compare and synchronise files between Procore and SharePoint. Under no circumstances do we access, copy, store, or process the content of your files.

What We Do Not Collect

CROXSYNC explicitly does not collect, store, or process the following:

  • File content — all documents, drawings, photos, and other files remain exclusively within your Procore and SharePoint accounts at all times
  • Passwords or credentials — CROXSYNC uses OAuth 2.0 exclusively; no third-party credentials are ever entered into or stored by CROXSYNC
  • Payment card details — no billing system is active during beta; no payment or financial data of any kind is collected or stored
  • SMS opt-in data or phone numbers — CROXSYNC does not operate any SMS messaging service
  • Biometric data, health data, or any special category data as defined under UK/EU GDPR
  • Data in excess of what is strictly necessary for the delivery of synchronisation functionality
  • Customer Data for the purpose of training, fine-tuning, benchmarking, or otherwise improving any machine learning or artificial intelligence system

How We Use Personal Information

Personal information collected by CROXSYNC is used solely for the following purposes:

  • Authenticating your account and maintaining a secure session
  • Establishing and maintaining OAuth 2.0 connections to your Procore and Microsoft SharePoint accounts
  • Comparing file metadata across connected platforms to identify synchronisation actions required
  • Performing authorised file transfers between Procore and SharePoint on your behalf
  • Maintaining sync history and audit logs accessible to you as the account holder
  • Responding to support requests and communicating material service updates
  • Monitoring and improving platform reliability, security, and performance during the beta phase
Customer Data and API Data obtained via the Procore or Microsoft APIs is used solely and exclusively to deliver CROXSYNC synchronisation functionality to the organisation that provided it. It is not used for any secondary purpose, is not shared with other organisations, is not sold, and is not used to train, fine-tune, benchmark, or otherwise develop any machine learning or artificial intelligence model or system.

Data Transfer Architecture

CROXSYNC employs a streaming-first architecture specifically designed to ensure that file content never persists on our infrastructure. When a file transfer is performed:

  • Files are transferred incrementally — each segment is downloaded from the source and immediately uploaded to the destination without being held in full
  • No complete file is assembled, buffered, or retained on CROXSYNC servers at any point during or after a transfer
  • Upon completion of each transfer, no file data whatsoever remains on CROXSYNC infrastructure
  • Only the metadata record (file name, size, timestamp, platform-assigned ID) is retained for sync state management and audit purposes
CROXSYNC operates as a synchronisation conduit, not a storage service. Your files reside exclusively within your own Procore and Microsoft SharePoint accounts at all times.

Third-Party Integrations

CROXSYNC currently integrates with the following third-party platforms:

  • Procore — a construction management platform operated by Procore Technologies, Inc. CROXSYNC is a verified Procore Connected App.
  • Microsoft SharePoint — a cloud collaboration platform forming part of Microsoft 365, operated by Microsoft Corporation. CROXSYNC is a verified Microsoft publisher.

By connecting a third-party service through CROXSYNC, you:

  • Expressly authorise CROXSYNC to access and interact with that service on your behalf via its OAuth 2.0 authorisation flow
  • Confirm that you are a duly authorised user of that third-party platform and hold a valid subscription or licence to use it
  • Acknowledge that the third-party platform's own terms of service and privacy policy govern that platform's handling of your data independently of CROXSYNC
  • Acknowledge that OAuth access tokens are stored by CROXSYNC in encrypted form
  • Acknowledge that CROXSYNC requests only the minimum API scopes and permissions strictly required to perform synchronisation
CROXSYNC is an independent application and is not affiliated with, endorsed by, sponsored by, or in any way formally associated with Procore Technologies, Inc. or Microsoft Corporation. CROXSYNC does not represent or warrant that either platform will maintain API availability, and is not liable for any disruption to the Service caused by changes to third-party APIs.

Data Storage & Location

All personal data and Customer Data processed by CROXSYNC is stored exclusively within the European Union.

  • No Customer Data is stored, replicated, or transferred outside the European Union without prior explicit disclosure and, where required, your consent
  • All data in transit between CROXSYNC and third-party APIs (Procore, Microsoft) is encrypted via TLS 1.2 or higher
  • All data at rest is encrypted at the infrastructure level in addition to application-level encryption of OAuth tokens
CROXSYNC's data residency in the EU is maintained in compliance with UK GDPR and EU GDPR requirements. You will be notified in advance of any change to data storage location or residency arrangements.

Protection of Personal Information

CROXSYNC employs reasonable and appropriate technical, administrative, and organisational safeguards to protect personal information and Customer Data against misuse, interference, loss, unauthorised access, modification, and disclosure:

  • OAuth 2.0 authentication exclusively — no third-party passwords, credentials, or secrets are stored by CROXSYNC
  • OAuth access tokens encrypted at rest using AES-256-GCM
  • TLS encryption enforced on all connections — no data is transmitted in plaintext
  • Role-based access controls — Customer Data is accessible only to the authenticated account holder
  • Technical controls to prevent unauthorised webhook access and sync loop exploitation
  • API credentials maintained in strict confidence and not exposed in any public-facing system
  • Ongoing security review and vulnerability assessment as part of the beta development process

Disclosure of Personal Information

CROXSYNC will not disclose your personal information or Customer Data to any third party except in the following limited circumstances:

  • Authorised cloud infrastructure providers acting as data processors under our instruction, bound by data processing agreements and EU data protection standards
  • Professional or legal advisers — where strictly necessary for legal compliance or the defence of legal claims
  • Regulatory authorities — where disclosure is required by applicable law or court order
CROXSYNC does not sell personal information or Customer Data under any circumstances. We do not share data with third parties for marketing, advertising, or profiling purposes. We do not use data obtained from one organisation to benefit any other organisation or third party.

Cookies & Analytics

CROXSYNC uses cookies for two distinct purposes:

  • Session management (essential) — strictly necessary cookies used to authenticate your session and maintain your login state. These cannot be disabled without impairing core platform functionality.
  • Analytics (non-essential) — Google Analytics 4 is used to understand platform usage, identify performance issues, and guide product improvements. Analytics cookies are loaded only after you provide explicit informed consent via the cookie consent banner displayed on first visit.

You may withdraw consent for analytics cookies at any time without affecting your ability to use the Service. Declining analytics has no impact on synchronisation functionality or your account.

Retention of Personal Information

Personal information and Customer Data is retained only for as long as is necessary for the purpose for which it was collected:

  • Account data (name, email, organisation) — retained for the duration your account remains active
  • OAuth access tokens — retained only while the relevant integration connection is active; deleted immediately and permanently upon disconnection
  • File metadata and sync logs — retained for the duration of the relevant sync bridge to support audit trail and operational continuity
  • Following account deletion — all personal data, Customer Data, OAuth tokens, and associated metadata will be permanently purged from all systems within 30 days of the deletion request

Security Incidents

In the event of any actual or reasonably suspected security incident involving unauthorised access to, disclosure of, or loss of Customer Data, CROXSYNC will:

  • Notify Procore Technologies, Inc. at security@procore.com within 24 hours of becoming aware of the incident, as required under the Procore API Terms of Use
  • Notify affected users and, where required by applicable law, the relevant supervisory authority (including the ICO for UK data subjects), within legally mandated timeframes
  • Preserve all available evidence relating to the incident and provide a full written report including: nature and root cause of the incident, categories and approximate number of affected individuals and organisations, categories and approximate volume of affected records, likely consequences, and corrective and remediation actions taken
  • Bear sole responsibility, at our expense, for investigating, containing, and remediating the incident and for all required notifications to affected customers and regulatory authorities
CROXSYNC is solely responsible for all security incidents arising from the use of the CROXSYNC application. Procore Technologies, Inc. and Microsoft Corporation bear no responsibility or liability in connection with any such incident.

Access and Correction

You may at any time request access to, correction of, restriction of processing of, or deletion of your personal information by contacting us at support@croxsync.com. We will respond to all verifiable requests within 10 business days. No fee will be charged for a request unless it is manifestly unfounded, excessive, or repetitive.

GDPR (EU & UK Residents)

CROXSYNC acts as data controller in respect of account information and file metadata. All data is stored in EU-region infrastructure. Where CROXSYNC processes Customer Data on your behalf as part of the Service, it acts as a data processor subject to your instructions.

If you are located in the EU or UK, you have the following rights under EU GDPR and UK GDPR respectively:

  • Right of access — to obtain a copy of your personal data we hold
  • Right to rectification — to have inaccurate personal data corrected without undue delay
  • Right to erasure — to have personal data deleted where there is no compelling reason for its continued processing
  • Right to restriction of processing — to limit how we use your data in certain circumstances
  • Right to data portability — to receive your data in a structured, commonly used, machine-readable format
  • Right to object — to processing of your personal data on grounds of legitimate interests

Our lawful basis for processing is: (a) performance of a contract — to deliver the synchronisation Service you have requested; and (b) legitimate interests — for platform security, fraud prevention, and service improvement. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data rights have been infringed.

Contact Us

For privacy questions, data rights requests, or to report a security concern:

General Enquiries

support@croxsync.com

Security Incidents

support@croxsync.com

Subject: Security Incident

Post

Privacy Officer, CROXSYNC
(a product of Croxsoft Ltd)
85 Great Portland Street
London, England, W1W 7LT
Company No: 16174351

© 2026 CROXSYNC. All rights reserved. CROXSYNC is a product of Croxsoft Ltd, a company registered in England and Wales (Company No. 16174351).