1. Who We Are
This Privacy Policy (the "Policy") explains how Omnistra ("Omnistra," "we," "us," or "our") collects, uses, discloses, retains, and protects information when you interact with our products, websites, and services.
Omnistra is an Autonomous Commerce platform that provides AI-powered customer service, conversational logistics support, and commerce intelligence to e-commerce and f-commerce (Facebook-commerce) businesses. We operate the Omnistra platform (the "Service") at https://app.omnistra.io and our marketing website at https://omnistra.io, and the Omnistra application registered with Meta Platforms, Inc. for use with Facebook, Instagram, Messenger, and WhatsApp Business APIs.
Contact us: Email: privacy@omnistra.io Website: https://omnistra.io
For the purposes of the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Bangladesh Personal Data Protection framework, and other applicable data protection laws, Omnistra is the data controller for personal data we collect about our website visitors, merchant account holders, and prospects, and a data processor for personal data we process on behalf of our merchant customers (our "Clients") under a Data Processing Agreement (DPA).
2. Scope of This Policy
This Policy applies to:
- Visitors to omnistra.io, app.omnistra.io, and any subdomain we operate.
- Merchant businesses, their employees, and authorised users who register for, evaluate, or use the Omnistra Service (our "Clients").
- End-consumers who interact with Omnistra-powered AI agents on behalf of our Clients, via channels such as Facebook Messenger, Instagram Direct, WhatsApp, voice calls, SMS, email, or web chat ("End Users").
- Job applicants, vendors, and other individuals who interact with us in a business context.
Scope exclusions
This Policy does not apply to third-party websites or services linked from our Service, or to data that our Clients independently collect outside of the Omnistra Service.
When Omnistra processes personal data of End Users at the direction of a Client, the Client is the controller and Omnistra is the processor. In those cases, the Client's own privacy policy governs the collection and primary use of that data, and Omnistra processes it only to provide the Service to that Client.
3. Information We Collect
3.1 Information You Provide Directly
- Account and identity data: name, business name, job title, email address, phone number, country, login credentials.
- Payment data: when you purchase a subscription or top up tokens, our payment processor collects card or mobile-banking details. We do not store full card numbers on our servers.
- Communications: messages you send to our support, sales, or onboarding teams, including attachments.
- Content and configuration: knowledge-base articles, product catalogues, voice and text prompts, workflow definitions, and any other content you upload to the Service.
3.2 Information We Collect Automatically
- Usage data: pages viewed, features used, clicks, session duration, browser type, device type, operating system, IP address, language preference, time zone.
- Log and diagnostic data: API request and response logs, error logs, latency metrics, system events, security events.
- Cookies and similar technologies: see Section 11.
3.3 Information We Process on Behalf of Our Clients
When a Client uses Omnistra to operate an AI agent, we process data flowing through the agent on the Client's behalf. This may include:
- End-User name, phone number, email address, social handle (Facebook ID, Instagram handle, WhatsApp number).
- Order data: order ID, items, value, shipping address, payment method, delivery status, carrier, tracking ID.
- Conversation content: messages, transcripts, audio recordings, sentiment, intent classifications, AI-generated responses.
- Any other data the Client chooses to send to the Service through integrations or API calls.
3.4 Information We Receive from Meta Platforms, Inc.
When a Client connects a Facebook Page, Instagram Business Account, or WhatsApp Business Account to the Omnistra Service, and when an End User interacts with that Client through a Meta-owned surface, we receive the following data from Meta through the Pages API, Messenger Platform, Instagram Messaging API, WhatsApp Business Platform, and related products:
- Page or Instagram account ID, name, profile picture, category, and admin role information.
- End-User Page-Scoped ID (PSID), Instagram-Scoped ID (IGSID), or WhatsApp phone number, plus name, profile picture, locale, and time zone where provided by Meta.
- Message content exchanged through Messenger, Instagram Direct, or WhatsApp, including text, attachments, stickers, voice notes, and reactions.
- Conversation metadata such as timestamps, read receipts, delivery status, and message thread ID.
- Ad-related data such as ad ID, campaign ID, and click-to-message referrer data when an End User initiates a conversation from an ad.
- Comments, replies, and mentions on Page or Instagram content when a Client enables that feature.
We access Meta-provided data strictly to deliver the Service the Client has configured. We do not use Meta data for our own advertising, do not sell it, do not transfer it except as described in this Policy, and we comply with the Meta Platform Terms and Developer Policies.
3.5 Information We Receive from Other Third Parties
- E-commerce platforms our Clients connect, such as Shopify and WooCommerce.
- Logistics carriers our Clients use, such as Pathao Courier, Steadfast, RedX, Sundarban, and Paperfly, for tracking and delivery-status data.
- Payment gateways and mobile financial services for payment confirmation and refund status.
- Service providers we use for hosting, communications, and security.
- Public sources, partners, or referrers in connection with sales and marketing.
4. How We Use Information
4.1 To Provide and Operate the Service
- Authenticate users, provision accounts, and enable login through Meta or other identity providers.
- Configure, run, and monitor AI agents on the Client's behalf.
- Route, transcribe, classify, and respond to conversations across Messenger, Instagram, WhatsApp, voice, SMS, email, and web chat.
- Sync order, inventory, and customer state across the Client's connected systems.
- Generate analytics, dashboards, and reports for the Client.
4.2 To Maintain, Secure, and Improve the Service
- Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service or applicable law.
- Monitor performance, debug, and improve reliability, latency, and accuracy.
- Improve the Service using aggregated, anonymised, or de-identified data.
4.3 To Communicate with You
- Send transactional messages about the Service, including account, billing, security, and service updates.
- Respond to your support enquiries.
- Send marketing communications about Omnistra products and events, where permitted by law. You may opt out at any time.
4.4 To Comply with Law and Protect Rights
We may use information to comply with legal obligations, court orders, and lawful requests from public authorities; enforce our agreements; and protect the rights, property, or safety of Omnistra, our Clients, End Users, or others.
4.5 What We Do Not Do with Your Data
- We do not sell personal data.
- We do not share personal data for cross-context behavioural advertising as defined under the CCPA/CPRA.
- We do not use Meta-sourced messaging content to train AI models for any purpose other than serving the originating Client.
- We do not use End-User personal data to train foundational AI models that are reused across Clients.
- We do not access Client data except as needed to provide and support the Service, comply with law, or with the Client's permission.
4.6 Legal Bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing the Service to a Client | Performance of a contract (Art. 6(1)(b)) |
| Processing End-User data on behalf of a Client | Processor on the Client's lawful basis (Art. 28) |
| Marketing to prospective business customers | Legitimate interests (Art. 6(1)(f)) or consent (Art. 6(1)(a)) |
| Fraud prevention, security, network integrity | Legitimate interests (Art. 6(1)(f)) |
| Legal and regulatory compliance | Legal obligation (Art. 6(1)(c)) |
For data subjects in Bangladesh, we process personal data on the basis of consent, performance of a contract, compliance with a legal obligation, or a legitimate purpose proportionate to the rights of the data subject, as applicable.
5. How We Use Meta Platform Data — Specific Disclosures
This section is provided to satisfy the Meta Platform Terms and the Developer Policies, and identifies precisely how Omnistra processes data obtained through Meta APIs.
| Meta Product / Permission | Why Omnistra Requests It | What We Do with the Data | What We Do Not Do |
|---|---|---|---|
| pages_show_list, pages_read_engagement, pages_manage_metadata | Discover the Client's Pages and confirm admin rights so the Client can connect a Page to Omnistra. | List the Client's Pages in the Omnistra dashboard; store Page ID, name, and category. | Modify Page settings without explicit Client action. |
| pages_messaging, pages_messaging_subscriptions | Send and receive Messenger messages on the Client's behalf. | Deliver AI-generated replies, send order updates, log transcripts for the Client's review. | Message users the Client has not transacted with, outside the 24-hour standard messaging window or approved message tags. |
| instagram_basic, instagram_manage_messages, instagram_manage_comments | Reply to Instagram Direct messages and comments on Client-owned Instagram Business accounts. | Same conversational handling as Messenger; comment moderation on the Client's instruction. | Access personal Instagram accounts or content from accounts the Client does not own. |
| whatsapp_business_messaging, whatsapp_business_management | Send and receive WhatsApp Business messages and manage approved message templates on the Client's behalf. | Deliver order updates, customer-service conversations; submit and manage template messages. | Initiate WhatsApp messages outside the Client's opt-in base or outside permitted template categories. |
| public_profile, email (Facebook Login for Business) | Authenticate the Client user signing into the Omnistra dashboard. | Store name, email, and Facebook user ID for account management. | Post to your timeline or access your friends list. |
Data minimisation
We request only the permissions necessary for features the Client has enabled. Clients may disconnect a Meta asset from Omnistra at any time in the Omnistra dashboard; once disconnected, we cease processing new data from that asset.
No advertising use of Meta data by Omnistra
Omnistra does not use Meta-sourced data to build advertising profiles for our own marketing, does not sell or rent Meta data, and does not use it to create cross-site or cross-Client behavioural profiles.
Storage and retention of Meta data
Messaging content, message metadata, and Meta-issued IDs are retained as set out in Section 8 and deleted on the schedules described there or earlier on Client or End-User request.
7. International Data Transfers
Omnistra operates from Bangladesh and may transfer personal data to other countries where we, our affiliates, or our sub-processors operate, including the United States and the European Union.
When personal data is transferred outside its country of origin, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission and the UK International Data Transfer Addendum, and Data Processing Agreements with our sub-processors that incorporate technical and organisational safeguards.
You may request more information about these safeguards by writing to privacy@omnistra.io.
8. Data Retention
We retain personal data only for as long as necessary to provide the Service and fulfil the purposes set out in this Policy, then delete or anonymise it, unless a longer period is required or permitted by law.
In general:
- Client account and billing records are retained for the duration of the contract, plus any additional period required by tax and accounting law.
- Conversation transcripts, messages, and voice recordings are retained for the period the Client has configured, and are deleted within a reasonable period after a Client account closes.
- Meta-sourced identifiers are tied to the connected Meta asset and are deleted within a reasonable period after the Client disconnects the asset, or earlier on an End-User deletion request.
- Logs and security records are retained only as long as needed for operational, security, and legal purposes.
- Marketing data for prospects and leads is retained until you opt out or until it is no longer relevant.
- Backups are purged on a routine schedule.
Retention configuration
Clients can request changes to retention configuration by contacting their account representative. End Users may request earlier deletion as set out in Section 10 and via our Data Deletion Instructions at https://omnistra.io/data-deletion.
9. Security
We take the security of personal data seriously and implement reasonable administrative, technical, and physical safeguards designed to protect it against unauthorised access, alteration, disclosure, or destruction. These include:
- Encryption of personal data in transit and at rest.
- Access controls based on the principle of least privilege, with authentication required for all staff access to production systems.
- Continuous monitoring of our systems for security events.
- Incident-response procedures to investigate and respond to suspected security incidents.
- Ongoing review and improvement of our security posture as the Service evolves.
Security responsibility
No method of transmission or storage is completely secure. You are responsible for safeguarding your account credentials and for the data you choose to submit to the Service.
10. Your Rights
Depending on your location and your relationship with us, you may have the following rights regarding your personal data.
10.1 Rights Available to All Users
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your personal data, subject to legal retention requirements.
- Withdraw consent where processing is based on consent.
- Object to or restrict certain processing.
- Data portability — receive your data in a structured, machine-readable format.
- Lodge a complaint with a supervisory authority.
10.2 EU / UK Residents (GDPR)
You may contact us at privacy@omnistra.io to exercise any of the rights above. You also have the right to complain to your local data protection authority.
10.3 California Residents (CCPA/CPRA)
You have the right to know, delete, correct, limit use of sensitive personal information, and to opt out of sale or sharing for cross-context behavioural advertising. Omnistra does not sell or share personal information as those terms are defined under the CCPA/CPRA. To exercise your rights, email privacy@omnistra.io. We will not discriminate against you for exercising your rights.
10.4 Bangladesh Residents
You may contact privacy@omnistra.io to access, correct, or request erasure of your personal data, and to withdraw consent where applicable.
10.5 End Users of a Client
If you interacted with an Omnistra-powered AI agent operated by one of our Clients, you should direct your rights request to that Client in the first instance — they are the data controller. Omnistra will assist the Client in fulfilling valid requests. You may also contact us directly at privacy@omnistra.io and we will forward your request to the relevant Client and respond as a processor.
10.6 How to Exercise Your Rights
Email privacy@omnistra.io with:
- Your name and the email address or phone number associated with the data.
- The right you wish to exercise.
- If applicable, the name of the Client whose service you interacted with.
Response time
We will respond within 30 days, and may extend this period by up to 60 days for complex requests. We may need to verify your identity before fulfilling the request to protect against fraudulent requests.
10.7 Data Deletion Instructions (Meta Requirement)
Our dedicated, publicly accessible Data Deletion page is at https://omnistra.io/data-deletion. End Users may submit a deletion request via that page or by emailing privacy@omnistra.io with the subject line "Data Deletion Request." We will confirm receipt within 7 days and complete deletion within 30 days, except where retention is required by law.
12. Children's Privacy
The Omnistra Service is a business-to-business platform and is not directed to children. We do not knowingly collect personal data from children under the age of 13, or under the age of 16 in the EEA / UK, or under any other age defined by applicable law.
If we learn we have collected personal data from a child without verified parental consent, we will delete that information promptly. Parents or guardians who believe their child has provided us with personal data may contact privacy@omnistra.io.
Clients using the Service to interact with their own end-customers are responsible for ensuring their use of the Service complies with age-restriction laws.
13. Automated Decision-Making and AI
The Omnistra Service uses AI models to generate conversational replies in Bangla and English, classify intent and sentiment, and assist Clients with customer-service workflows.
AI outputs in the Service are intended to assist human decision-making, not to replace it. A Client always retains the ability to review, override, or escalate any AI-generated decision, and Omnistra provides an "ask a human" escalation route in AI-agent conversations.
Where automated processing produces a legal or similarly significant effect on an End User, the Client is responsible for providing the human-review path required by Article 22 of the GDPR or equivalent law. Omnistra provides the tooling to make this possible.
We do not use End-User personal data to train foundational AI models that are reused across Clients.
14. Changes to This Policy
We may update this Policy from time to time. The "Last Updated" date at the top reflects when the most recent changes took effect. Material changes will be notified to Clients by email or by an in-product notice before they take effect, except where a shorter period is required by law. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
15. Contact Us
If you have any questions, requests, or complaints about this Policy or our handling of personal data, please contact us:
- Omnistra Email: privacy@omnistra.io
- General: hello@omnistra.io
- Web: https://omnistra.io
- For Meta App Review purposes, the published privacy policy URL is: https://omnistra.io/privacy
- The published data-deletion instructions URL is: https://omnistra.io/data-deletion













