Summary
Omnymous, LLC ("Omnymous," "we," "us") provides a marketing platform to e-commerce businesses. This Policy explains what personal information we handle, why, and what rights people have.
Two different roles. We handle personal information in two capacities, and the difference determines who is accountable:
- As a controller — for the businesses that buy Omnymous, the people who use it, people who contact us, and visitors to our websites. This Policy governs that processing.
- As a processor (service provider) — for information about our customers' shoppers, which flows into the Platform from our customers' stores, advertising accounts, and the Omnymous Pixel. Our customer decides why and how that information is used. We act on their documented instructions under our Data Processing Addendum. If you are a shopper on a store that uses Omnymous, the merchant — not Omnymous — is your point of contact. We will refer your request to them.
What we never do. We do not sell personal information. We do not share it for cross-context behavioral advertising for our own purposes. We do not train, fine-tune, or improve any generative AI model on our customers' content or on the outputs generated for them.
One thing worth knowing about our AI. Omnymous does not resell AI. Every generation runs on the customer's own API keys, against the customer's own accounts with OpenAI, Anthropic, or Google. Those providers are our customers' processors, not ours, and their handling of that content is governed by our customers' agreements with them.
This Policy is not legal advice. Our customers are responsible for their own privacy compliance, and should take their own advice on it.
1. Scope
This Policy applies to:
- omnymous.com and our other public websites;
- app.omnymous.com, the Omnymous Platform;
- docs.omnymous.com and our documentation;
- our programmatic interfaces, the Omnymous Pixel, and our Shopify application; and
- our communications with prospects, customers, applicants, and the public.
It does not apply to: our customers' own websites, stores, apps, or marketing; third-party services our customers connect; or any third-party site we link to. Those are governed by the relevant party's own policy.
Terminology. "Customer" means a business that subscribes to Omnymous. "User" means an individual authorized to use the Platform under a Customer's organization. "Shopper" means a customer, prospective customer, or website visitor of a Customer. "Visitor" means a visitor to our own websites.
2. Who We Are and How to Reach Us
Controller and contact:
Omnymous, LLC 1111b South Governors Ave, STE 94887 Dover, DE 19904 United States
| Purpose | Contact |
|---|---|
| Privacy questions, rights requests, DPAs | privacy@omnymous.com |
| Security incidents and vulnerability reports | security@omnymous.com |
| Legal notices | legal@omnymous.com |
Where we act as a processor, the relevant controller is the Customer whose organization holds the data. If you do not know which merchant holds your data, contact us and we will make reasonable efforts to identify and refer you, but we may be unable to do so without enough information to locate the record.
3. Information We Process as a Controller
3.1 Account and profile
Name, email address, password (stored only as a bcrypt hash — we never see it), Google account identifier if you sign in with Google, profile image, timezone, locale, role and permissions within an organization, onboarding and product-tour state, last login time and login count, and session and verification tokens.
3.2 Organization and business
Organization name, slug, website, logo, connected store names and domains, plan and quota configuration, and team membership and invitations (including the email addresses of people invited by a User — we process those to deliver and manage the invitation).
3.3 Billing
Subscription plan, billing cycle, status, renewal and cancellation dates, quantities, payment failure and dunning history, promotional and partner codes, and identifiers issued by our payment processor. We do not receive or store full payment card numbers, CVVs, or bank credentials — those go directly to Stripe, which is PCI DSS compliant. We receive only tokens, the card brand and last four digits, and transaction results.
3.4 Support, sales, and communications
Support ticket content and attachments, correspondence and its history, scheduled consultation and appointment details, product feedback and ratings, and the content of messages you send us.
3.5 Product usage and telemetry
Feature usage, workflow and navigation events, session duration, generation and job metadata, error and performance diagnostics, device and browser type, operating system, and approximate location inferred from IP address.
3.6 AI assistant conversations
Where a User uses our in-product assistant, we store the conversation — messages, tool results, model and token metadata, and any feedback rating or comment — so the conversation persists, can be resumed, and can be supported and debugged.
3.7 Security and audit records
Access logs, API request logs, authentication events, and audit records of security-relevant actions and configuration changes. These records include IP address and user agent in unmodified form, which is necessary for security, fraud prevention, and forensic investigation.
3.8 Credentials you entrust to us
Encrypted API keys for AI providers, encrypted OAuth tokens for connected platforms, and hashed programmatic access keys. Provider keys are encrypted with AES-256-GCM; we store only a hint (the last few characters) in clear form for display. Programmatic access keys are stored only as a SHA-256 hash — the plaintext is shown once, at creation, and cannot be recovered.
3.9 Website visitors and public features
- Analytics. Our marketing website uses Google Analytics 4, which sets cookies and collects usage information including a pseudonymous identifier, pages viewed, referrer, approximate location derived from IP, and device and browser characteristics. See Section 11.
- Public roadmap. If you vote on our public roadmap, we store your email address (normalized to lowercase) as the identity of the vote, the item voted for, and where the vote came from. We use it to prevent duplicate votes and to email you once when that item ships. You can withdraw a vote or ask us to delete it at any time.
- Forms and enquiries. Information you submit through contact, demo, careers, or waitlist forms.
3.10 Information from other sources
Publicly available business information, referral and partner information (for example, where a partner issues you a promotional code, we receive the fact of issuance and redemption), and information from our service providers such as fraud and deliverability signals.
4. Information We Process as a Processor
This Section describes personal information about Shoppers that our Customers put into, or instruct us to retrieve into, the Platform. The Customer is the controller. We process it only on their instructions.
| Category | Examples | Source |
|---|---|---|
| Shopper identity | Email address, first and last name, e-commerce platform customer identifier, tags | Customer's connected store |
| Order and transaction | Order number and value, line items, SKUs, quantities, discounts, shipping and tax amounts, refunds, currency, payment gateway, financial and fulfilment status, first-order flag and order sequence | Customer's connected store |
| Shipping and location | Shipping country and province, shipping method, carrier, package weight | Customer's connected store |
| Commercial history | Order count, total spent, first and last order dates, computed lifetime value and per-customer economics | Derived by us for the Customer |
| Behavioral events | Page views, product and collection views, cart additions and removals, checkout starts, purchases, on-site search terms, page URLs and titles, referrer | Omnymous Pixel on the Customer's storefront |
| Device and session identifiers | A persistent pseudonymous identifier stored in a first-party cookie for up to 365 days, a session identifier, user agent, and a truncated one-way hash of IP address (we do not store raw IP addresses for pixel events) | Omnymous Pixel |
| Campaign identifiers | UTM parameters and advertising click identifiers (including Meta, Google, and TikTok click IDs), landing page and creative identifiers | Omnymous Pixel and Customer's ad accounts |
| Identity linkage | A one-way SHA-256 hash of a normalized email address, used to connect a browsing session to an order | Derived by us for the Customer |
| Attribution profiles | Reconstructed customer journeys linking a Shopper's sessions and touchpoints to a specific order, with per-touch credit allocation | Derived by us for the Customer |
| Third-party content | Publicly available reviews, forum posts, and comments retrieved by research features, which may include the authors' usernames and opinions | Public web sources, at the Customer's direction |
| Workspace content | Anything a Customer or its Users upload or generate, which may contain personal information the Customer chooses to include | Customer |
Purchase events include direct identifiers. When a Shopper completes a purchase, the Pixel transmits the email address and, where available, the phone number associated with the checkout, so that the purchase can be matched to a session and an order. This is one of the most important things for our Customers to disclose in their own privacy notices.
Identity linkage is real. The Platform is designed to connect a pseudonymous browsing session to an identified purchaser and to reconstruct that person's journey across visits. Data described as "anonymous" or "hashed" in this context remains personal data under GDPR, UK GDPR, and comparable laws, and we treat it as such.
Prohibited categories. Our Terms prohibit Customers from sending us special category, sensitive, or high-risk personal data — including health, precise geolocation, government identifiers, biometric or genetic data, financial account numbers, credentials, and information about children under 16. We do not seek it, and its presence would be a breach by the Customer. We cannot practically detect or filter it, so the Customer bears responsibility for that boundary.
5. Why We Process, and Our Legal Bases
Where GDPR, UK GDPR, or a comparable law applies to our processing as a controller:
| Purpose | Categories | Legal basis |
|---|---|---|
| Create and administer accounts and organizations | 3.1, 3.2 | Performance of a contract |
| Provide, operate, and maintain the Platform | 3.1–3.3, 3.5, 3.6, 3.8 | Performance of a contract |
| Process payments, billing, dunning, and collections | 3.3 | Performance of a contract; legal obligation |
| Provide support and respond to enquiries | 3.4 | Performance of a contract; legitimate interests (responding to non-customers) |
| Secure the Platform, prevent fraud and abuse, investigate incidents | 3.5, 3.7, 3.8 | Legitimate interests (protecting our service, customers, and users); legal obligation |
| Maintain audit trails | 3.7 | Legitimate interests; legal obligation |
| Debug, monitor, and improve reliability and performance | 3.5, 3.6 | Legitimate interests (operating a functioning service) |
| Develop and improve products and features, using aggregated and de-identified data | 3.5, 3.6 | Legitimate interests (product development) |
| Send service, transactional, and administrative messages | 3.1, 3.3 | Performance of a contract; legal obligation |
| Send marketing about our own products to business contacts | 3.1, 3.9, 3.10 | Legitimate interests; consent where required by law |
| Notify roadmap voters when an item ships | 3.9 | Consent (given by voting for that purpose); legitimate interests |
| Website analytics | 3.9 | Consent where required; otherwise legitimate interests |
| Comply with law, respond to legal process, establish or defend claims | Any | Legal obligation; legitimate interests |
| Corporate transactions | Any | Legitimate interests |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by the rights and freedoms of the individuals concerned, and we limit processing accordingly. You may object — see Section 10.
Where we act as a processor (Section 4), our legal basis is our Customer's instruction. Establishing a lawful basis and obtaining any required consent for that processing is the Customer's responsibility, not ours.
6. AI Processing
6.1 Generation runs on the Customer's own AI accounts
Omnymous does not resell AI inference. When a User generates content, we transmit the request to the AI provider the Customer has configured, using the Customer's own API key, under the Customer's own agreement with that provider, billed directly to the Customer. We act as a technical conduit at the Customer's direction.
Consequence: OpenAI, Anthropic, and Google are the Customer's processors for that content, not ours. Their retention, training, abuse-monitoring, and security practices are governed by the Customer's agreement with them. Customers should review those agreements and configure their accounts accordingly. We list them in Section 8 for transparency, not because we control them.
6.2 We do not train on customer content
We do not use Customer content, workspace data, prompts, or generated outputs to train, fine-tune, retrain, or otherwise improve any generative AI model — ours or a third party's. We do not license or sell that content for model development.
We do use aggregated and de-identified operational data — counts, timings, error rates, usage patterns, and cost metrics that do not identify any Customer, User, or individual — to operate, secure, and improve the Platform. This is statistical and operational analysis, not model training on content.
6.3 Observability
We route AI requests through an observability provider to record latency, token usage, cost, and errors, and to diagnose failures. This provider sits in the request path and therefore processes prompt and response content. It is contractually bound as our sub-processor, is prohibited from using the content for its own purposes, and does not train models on it.
6.4 Research and retrieval
Research features issue queries to third-party search providers and retrieve publicly available pages, marketplace listings, and forum discussions in response to a User's request. Retrieved material may contain personal information published by third parties, including usernames and opinions. That material is placed in the Customer's workspace, where the Customer becomes responsible for it. We do not build profiles of individuals from it, and doing so is prohibited by our Acceptable Use Policy.
6.5 Automated decision-making
The Platform generates content, scores, estimates, and recommendations. It does not make decisions that produce legal or similarly significant effects concerning individuals, and it is not used for credit, employment, housing, insurance, or eligibility decisions. Content and recommendations are drafts for human review; our Terms require a User to review and approve output before use.
7. How We Share Information
We disclose personal information only as described here.
Service providers and sub-processors. To the vendors that host, secure, and operate the Platform, under written contracts limiting them to processing on our instructions, imposing confidentiality and security obligations, and prohibiting use for their own purposes. Our current list is at omnymous.com/subprocessors, which also explains how we give notice of changes.
At a Customer's instruction. Where a Customer instructs us to transmit data to a platform they have connected — most commonly, sending conversion events including hashed identifiers to advertising platforms for measurement and audience purposes. Receiving advertising platforms act as independent controllers under their own terms. The Customer is responsible for having a lawful basis for those transmissions.
Within a Customer's organization. Data in an organization's workspace is visible to that organization's Users according to the roles and permissions the Customer configures. Administrators can see the activity, content, and account details of Users in their organization.
Professional advisors. Lawyers, accountants, auditors, and insurers under duties of confidentiality.
Legal and safety. Where we believe in good faith that disclosure is required by law, regulation, subpoena, court order, or other legal process, or is reasonably necessary to enforce our Terms, investigate suspected fraud or abuse, protect the rights, property, or safety of Omnymous, our customers, or the public, or establish or defend legal claims. We will not disclose customer content in response to legal process unless legally compelled, and where legally permitted we will give the affected Customer notice and a reasonable opportunity to object.
Corporate transactions. In connection with a merger, acquisition, financing, reorganization, or sale of assets, or in bankruptcy or insolvency, subject to confidentiality obligations. Where a successor's privacy practices differ materially, we will provide notice.
Aggregated and de-identified information. We may publish or share information that has been aggregated or de-identified so that it cannot reasonably identify any individual, Customer, or organization. We do not attempt to re-identify it and require recipients not to.
We do not sell personal information, and we do not share it for cross-context behavioral advertising for our own purposes, as those terms are defined by California and other US state privacy laws. We have not done so in the preceding twelve months.
8. Categories of Recipients
The current, named list — with each recipient's function, the data it receives, and its location — is maintained at omnymous.com/subprocessors. By category, we use providers for:
| Function | What they receive |
|---|---|
| Cloud hosting, database, object storage, content delivery | All Platform data, encrypted in transit and at rest |
| Payment processing | Billing contact and transaction data; card data goes directly to them |
| Transactional email delivery | Recipient email addresses and message content |
| AI request observability | Prompt and response content, model and usage metadata |
| Advertising operations and conversion relay | Campaign structures, and conversion events including hashed identifiers |
| Web search and content retrieval for research | Search queries derived from a User's request |
| Error monitoring and performance diagnostics | Diagnostic data, which may include identifiers and request context |
| Website analytics (marketing site only) | Visitor usage data and pseudonymous identifiers |
| Authentication (sign in with Google) | Authentication assertions and basic profile data |
AI providers are listed separately on that page, because under our bring-your-own-key model they are engaged by the Customer under the Customer's own account and are the Customer's processors, not ours (Section 6.1).
9. International Transfers
We are established in the United States and our infrastructure operates principally in the United States (AWS, US East region). Personal information we process is transferred to and stored in the United States, and may be accessed from other countries where our personnel or providers operate.
For transfers from the European Economic Area, the United Kingdom, or Switzerland to countries without an adequacy decision, we rely on:
- the European Commission's Standard Contractual Clauses (Decision 2021/914), incorporated into our Data Processing Addendum and into our contracts with sub-processors;
- the UK International Data Transfer Addendum to those clauses for UK transfers; and
- the Swiss Federal Data Protection and Information Commissioner's recognized clauses for Swiss transfers, with references construed accordingly.
We carry out transfer impact assessments where required, apply supplementary technical measures including encryption in transit and at rest, and will challenge legally invalid government access requests. Copies of the relevant safeguards are available on request to privacy@omnymous.com.
10. Your Rights
10.1 Rights available
Depending on where you live and our role in the processing, you may have the right to:
- know and access the personal information we hold about you and how we use it;
- correct inaccurate or incomplete information;
- delete your information;
- port your information to another provider in a structured, machine-readable format;
- object to processing based on legitimate interests, and to direct marketing at any time;
- restrict processing in certain circumstances;
- withdraw consent where processing relies on consent, without affecting prior processing;
- opt out of the sale or sharing of personal information and of profiling for decisions with significant effects — we do none of these;
- limit the use of sensitive personal information — we do not collect it for our own purposes;
- not be discriminated against for exercising a privacy right; and
- appeal a refusal, and lodge a complaint with a supervisory authority or attorney general.
10.2 How to exercise them
Users can access, correct, export, and delete much of their information directly in the Platform, including account settings, data export, and account deletion.
Otherwise, contact privacy@omnymous.com. We will:
- acknowledge promptly and respond within 30 days, extendable by a further 45 days for complex or numerous requests, with notice;
- verify your identity proportionately to the sensitivity of the request, using information already in our possession — we will not create new accounts or collect new identity documents to verify a request where it can be avoided;
- honour requests from an authorized agent on presentation of valid written authority; and
- not charge a fee, unless a request is manifestly unfounded or excessive, in which case we will say so and explain why.
10.3 If you are a Shopper
If your information reached us because you shopped with a business that uses Omnymous, we hold it as that business's processor. Please direct your request to that business — they control the data and can act on it directly. If you contact us, we will forward your request to the relevant Customer without undue delay and assist them in responding, but we will not access, disclose, correct, or delete data in a Customer's workspace on the instruction of a third party, because we cannot verify the request or the lawfulness of acting on it. This is a deliberate safeguard, not an evasion.
10.4 Complaints
If you are in the EEA, UK, or Switzerland, you may complain to your local supervisory authority. If you are in a US state with a privacy law, you may contact your state attorney general. We ask that you contact us first so we can try to resolve it.
11. Cookies and Similar Technologies
11.1 On our own sites
| Cookie or technology | Purpose | Type | Duration |
|---|---|---|---|
| Session and authentication cookies | Keep you signed in, maintain your session, protect against cross-site request forgery | Strictly necessary | Session or until expiry / sign-out |
| Preference storage | Remember settings such as active organization, store, and interface state | Functional | Persistent until cleared |
| Security and rate-limiting | Detect and prevent abuse, credential stuffing, and automated attacks | Strictly necessary | Short-lived |
Google Analytics 4 (_ga, _ga_*) | Measure traffic and usage on our marketing website | Analytics | Up to 24 months |
Strictly necessary cookies cannot be disabled without breaking the service. You can control others through your browser, and you can opt out of Google Analytics using Google's browser add-on.
11.2 The Omnymous Pixel on Customers' storefronts
The Omnymous Pixel operates on our Customers' storefronts, not on ours. It stores identifiers in first-party cookies on the Shopper's device:
| Cookie | Purpose | Duration |
|---|---|---|
_omnymous_aid | Persistent pseudonymous visitor identifier used to connect visits over time | 365 days |
_omnymous_sid | Session identifier | 24 hours (session ends after 30 minutes of inactivity) |
_omnymous_st | Session activity timestamp used to determine when a session has ended | 24 hours |
The merchant, not Omnymous, decides whether to deploy the Pixel, on which properties, and under what consent configuration. Where a storefront platform offers consent gating for tracking, the merchant selects that setting. Any setup guidance we publish describes how the feature behaves; it is not a determination that a particular configuration is lawful for that merchant. Obtaining consent where required — including under the EU ePrivacy Directive, UK PECR, and comparable rules — providing notice, and honouring opt-outs and global privacy control signals is the merchant's responsibility. If you are a Shopper and want to opt out, use the controls the merchant provides, or clear and block cookies for that site.
11.3 Do Not Track and Global Privacy Control
We do not respond to browser "Do Not Track" signals, which lack an agreed standard. On our own websites we honour Global Privacy Control signals where legally required. On Customers' storefronts, honouring such signals is the merchant's responsibility and depends on their configuration.
12. Retention
We keep personal information only as long as we need it for the purposes described in this Policy, and then delete or de-identify it. We determine how long by reference to:
- Account lifetime. Account, organization, workspace, generated content, connected-platform data, and Shopper data are retained for as long as the organization exists. On deletion of an organization, associated records are deleted from our production systems, and encrypted credentials and access keys are destroyed.
- The 30-day export window. After termination, data is available for export for 30 days before deletion (see our Terms, Section 23.6).
- Backups. Residual copies persist in encrypted backups and are purged on our ordinary backup rotation, after which they are not restored into production.
- Legal and financial obligations. Billing, tax, and transaction records are retained for the period required by applicable tax and corporate law — generally at least seven years.
- Security and audit. Audit and security logs are retained for as long as needed for security monitoring, incident investigation, and to establish or defend claims.
- Legal holds. Anything subject to a legal hold, dispute, investigation, or regulatory request is retained until the matter is resolved.
- De-identified data. Aggregated and de-identified data is retained indefinitely, because it is no longer personal information.
Customers control retention within their workspace. A Customer can delete workspace content, disconnect stores, and delete its organization at any time. Where a Customer instructs deletion of specific Shopper records, we will action it in accordance with the DPA. Deletion is irreversible.
13. Security
We maintain administrative, technical, physical, and organizational measures appropriate to the risk, including:
- Encryption in transit — TLS 1.2 or higher for all connections.
- Encryption at rest — for databases, object storage, and backups.
- Credential protection — passwords hashed with bcrypt; third-party API keys encrypted with AES-256-GCM; programmatic access keys stored only as SHA-256 hashes; OAuth tokens encrypted.
- Tenancy isolation — every record is scoped to an organization, and access is enforced at the data layer.
- Access control — role-based permissions, least privilege, and restricted internal access to production data limited to personnel who need it for operations, support, or security.
- Access logging and audit trails — security-relevant actions and administrative access are logged and reviewable.
- Environment separation — production data is kept separate from development and test environments.
- Monitoring and incident response — error and security monitoring, and a documented incident response process covering triage, containment, notification, and remediation.
- Secure development — code review, dependency management, and security testing.
- Personnel — confidentiality obligations and security training for people with access to personal data.
We will notify affected Customers without undue delay after becoming aware of a personal data breach affecting their data, with the information they need to meet their own notification duties, and will notify individuals and regulators where we are directly required to. Notification is not an admission of fault or liability.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for protecting your credentials, managing your Users' access, and scoping the keys and permissions you grant.
Report a suspected vulnerability or incident to security@omnymous.com. We do not pursue legal action against good-faith security researchers who report responsibly and avoid privacy violations, data destruction, and service disruption.
14. Customers' Responsibilities
If you are a Customer, you are the controller for the Shopper data you process through Omnymous, and you are responsible for:
- Notice — maintaining a privacy policy that accurately describes your data practices, including the Omnymous Pixel, the identifiers it stores, the transmission of conversion data (including hashed email addresses) to advertising platforms, and your use of a processor located in the United States.
- Lawful basis and consent — establishing a lawful basis and obtaining any consent required before processing begins, including consent for cookies and device storage where required.
- Rights requests — receiving and handling requests from your Shoppers, and instructing us where our action is required.
- Opt-outs — honouring opt-outs, consent withdrawals, and global privacy control signals, and configuring your storefront accordingly.
- Data minimization — not sending us data you have no lawful basis to process, and never sending prohibited categories (Section 4).
- Your Users — managing roles, access, and offboarding within your organization.
- Your AI provider accounts — reviewing and configuring the data practices of the AI providers you connect (Section 6.1).
- Your own advice — obtaining your own legal advice. Nothing here is legal advice, and our guidance describes how features behave, not whether your use of them is lawful.
Our Data Processing Addendum applies automatically to every Customer and sets out these allocations in binding terms.
15. Children
The Platform is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16 for our own purposes, and Users must be at least 18. Customers are prohibited from sending us information about children under 16. If we learn we have collected such information without an appropriate basis, we will delete it promptly. Contact privacy@omnymous.com to report it.
16. Region-Specific Notices
16.1 European Economic Area, United Kingdom, and Switzerland
Legal bases are in Section 5; transfers in Section 9; rights in Section 10. Where we act as a processor, our controller is the Customer.
We have not appointed an Article 27 representative in the EU or UK. If you believe we are required to have one for processing that concerns you, contact privacy@omnymous.com and we will address it.
16.2 California
This Section supplements the rest of the Policy for California residents, under the CCPA as amended by the CPRA. Information we process on behalf of Customers is handled as a service provider and is excluded from these disclosures — for that data, the Customer is the business.
Categories of personal information collected in the preceding 12 months, in CCPA terms:
| CCPA category | Collected | Examples |
|---|---|---|
| Identifiers | Yes | Name, email, account identifier, IP address, cookie identifiers |
| Customer records (Cal. Civ. Code § 1798.80) | Yes | Name, contact details, billing information |
| Commercial information | Yes | Subscription, plan, purchase and usage history |
| Internet or network activity | Yes | Product usage, page views, logs, diagnostics |
| Geolocation data | Yes — coarse only | Approximate region inferred from IP address |
| Professional or employment information | Yes | Role, organization, business contact details |
| Audio, electronic, or visual information | Yes | Support attachments, profile images, message content |
| Inferences | Yes | Product interest and usage-pattern inferences |
| Sensitive personal information | Account credentials only | Password hash; API keys and tokens you entrust to us |
| Biometric information | No | — |
| Education information | No | — |
Sources are those described in Section 3: you and your organization, your use of our websites and Platform, your device, our service providers, and our partners.
Purposes are those described in Section 5: providing and operating the Platform, billing, support, security and fraud prevention, product improvement, marketing to business contacts, and legal compliance.
Disclosure for business purposes. In the preceding 12 months we disclosed each category above — other than sensitive personal information, which we disclose only to our hosting provider — to the categories of recipients in Section 8: cloud hosting and storage, payment processing, transactional email, error monitoring, website analytics, and authentication providers. Each is contractually restricted to processing on our instructions.
Sensitive personal information. The only sensitive personal information we handle is account and third-party credentials, used exclusively to authenticate you and to perform the services you request. We do not use or disclose it for inferring characteristics or any purpose requiring an option to limit, so the right to limit does not apply — but you may still ask us about it.
We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16.
Retention is described in Section 12. Rights and how to exercise them, including the right to appeal and the right against discrimination, are in Section 10.
16.3 Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, and other states with comprehensive privacy laws have rights to access, correct, delete, port, and appeal, and to opt out of targeted advertising, sale, and certain profiling. We do not sell personal information, engage in targeted advertising using it, or profile individuals for decisions with legal or similarly significant effects. Exercise rights at privacy@omnymous.com; we will respond within the period your state's law requires and will honour appeals.
16.4 Brazil
Data subjects under the Lei Geral de Proteção de Dados have rights of confirmation, access, correction, anonymization, blocking or deletion, portability, information about sharing, and revocation of consent. Contact privacy@omnymous.com.
16.5 Canada
Under PIPEDA and provincial equivalents, you may access and correct your personal information and challenge our compliance. Contact privacy@omnymous.com.
16.6 Australia
Under the Privacy Act 1988 and the Australian Privacy Principles, you may access and correct your personal information and complain about our handling of it, including to the Office of the Australian Information Commissioner. Contact privacy@omnymous.com.
17. Changes to This Policy
We may update this Policy. When we do, we will change the "Last Updated" date and post the revised version here. For changes that materially affect how we use personal information, we will provide at least 30 days' notice by email or in-Platform notice before they take effect, and where the law requires consent for the change, we will obtain it. Other changes take effect when posted. Continued use after the effective date constitutes acknowledgement of the updated Policy.
18. Contact
Privacy and data protection: privacy@omnymous.com Security: security@omnymous.com Legal: legal@omnymous.com
Omnymous, LLC 1111b South Governors Ave, STE 94887 Dover, DE 19904 United States
We aim to acknowledge privacy enquiries within five business days and to resolve them within 30 days.
Document Version: 2.0 Classification: Public
