Legal and data practices

Privacy Policy

This policy explains how OmniChat handles information when businesses use our omnichannel inbox, including data received through Meta products such as WhatsApp, Messenger, Facebook Pages, and Instagram.

Last updated: August 23, 2026

1. Scope and our role

This policy applies to the OmniChat website, applications, APIs, and related support services. OmniChat directly controls account, security, and service-administration data for its workspace users.

A business that connects its customer channels to OmniChat generally determines why and how its customer communications are handled. For that customer data, the business is the controller and OmniChat acts as its service provider or processor. Customers of an OmniChat business should direct privacy requests to the business they contacted.

2. Information we process

  • Workspace information, including names, work email addresses, organization details, roles, authentication records, preferences, and support communications.
  • Customer-service content, including messages, comments, contact details, attachments, conversation history, assignments, tags, internal notes, and audit events.
  • Connected-channel information, including account and Page identifiers, business phone identifiers, access tokens, webhook events, delivery status, and connector health.
  • Technical and security information, including device and browser details, IP-derived security signals, session records, request logs, error data, and service metrics.
  • Subscription and billing administration information when paid services are enabled. We do not ask users to place payment-card details in messages or demo workspaces.

3. Meta Platform data

When an authorized business user connects Meta products, OmniChat requests only the permissions used by the selected product features. Depending on the products enabled, this can include the Meta user ID used to authorize the connection, Facebook Page IDs and names, Page access tokens, Instagram professional account IDs and profile details, WhatsApp Business Account and phone-number IDs, messages, delivery events, posts, comments, public profile details associated with a conversation, and media needed to provide customer support.

Access tokens are treated as credentials and are encrypted at rest. OmniChat does not sell Meta Platform data or use it to build advertising profiles. We use it to connect channels, display and route conversations, send authorized replies, manage customer service activity, provide requested automation, and protect the service.

4. Why we use information

  • Provide, operate, troubleshoot, and improve the omnichannel service.
  • Authenticate users, enforce workspace permissions, and prevent abuse.
  • Route conversations and deliver messages, notifications, and requested automation.
  • Maintain auditability, reliability, backups, and incident response.
  • Comply with law, valid legal process, and platform obligations.

If a workspace enables an AI feature, the minimum necessary content may be sent to the AI provider configured for that workspace to generate the requested output. Workspace administrators are responsible for choosing whether to enable those features and for providing appropriate notice to their customers.

5. How information is shared

We disclose information only as needed:

  • To authorized members and administrators of the relevant workspace.
  • To connected providers such as Meta or email services when sending, receiving, or managing communications at the business's direction.
  • To infrastructure, storage, security, email, monitoring, and optional AI service providers operating under service and confidentiality obligations.
  • When required by law, to protect rights and safety, or as part of a properly governed business transaction.

6. Retention and deletion

We retain information while it is needed to provide the service, meet the connected business's documented instructions, protect the platform, resolve disputes, and comply with applicable obligations. Retention can differ by data type and workspace settings. Data that is no longer needed is deleted or de-identified; limited copies can remain in protected backups or records required by law until their retention period ends.

Removing a Meta app authorization triggers our signed deletion callback. OmniChat verifies Meta's request, removes the authorizing Meta user ID and associated access tokens, disconnects matching OAuth integrations, and returns a confirmation code with a public status page. See our data deletion instructions.

7. Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection. Workspace users can update profile information and authorized administrators can remove channel connectors. To request deletion, follow the public data deletion instructions or email us. We may need to verify the requester's identity and authority before acting.

8. Security

We use safeguards appropriate to the service, including encrypted transport, encrypted connector credentials, access controls, tenant isolation, signed webhook validation, logging, malware scanning for supported uploads, backups, and operational monitoring. No internet service is completely secure, so users should protect their credentials and promptly report suspected misuse.

9. International processing and children

Information may be processed where OmniChat and its service providers operate, subject to contractual and legal safeguards where required. OmniChat is a business service and is not directed to children under 13 or the higher minimum age required in their jurisdiction.

10. Changes and contact

We may update this policy when our service or legal obligations change. We will publish the revised policy here and update the date above. Material changes may also be communicated in the service.

Privacy questions and verified requests can be sent to privacy@srv1179701.hstgr.cloud. Do not send passwords, access tokens, or sensitive message content by email.