OmniInvariably Digital
PricingFeaturesWho it’s forLearnContact
Log InStart free for 7 days
PricingFeaturesWho it’s forLearnContactLog In

Privacy Policy

Effective Date: March 7, 2026
Last Updated: March 7, 2026

Invariably Digital Group (“Company”, “we”, “us”) operates the Omni platform (“Platform”, “Service”). This Privacy Policy describes how we collect, use, store, and protect personal information when you use our Service.

1. Scope

This Privacy Policy applies to:

  • Platform users — Individuals who create accounts and use the Platform (tenant administrators, staff, and other authorized users).
  • Public site visitors — Individuals who visit our public website, pricing pages, or contact forms.
  • Applicants — Individuals who submit signup applications for new tenant accounts.

This policy does not cover personal data that our merchant customers enter about their end customers. Merchants are the data controllers for their customer records; our processing of that data is governed by our Data Processing Agreement.

2. Information We Collect

2.1 Information You Provide

  • Account information: Name, email address, business name, phone number, and billing address when you register for an Account.
  • Billing information: Payment method details are collected and processed by our payment processors (Stripe, Square, or Authorize.Net). We store only tokenized payment references — we never store raw credit card numbers.
  • Contact form submissions: Name, email, and message content when you submit a public inquiry.
  • Support requests: Information you provide when contacting support.

2.2 Information Collected Automatically

  • Usage data: Pages visited, features used, and actions taken within the Platform.
  • Device and browser information: IP address, browser type, operating system, and device identifiers.
  • Security events: Login attempts (successful and failed), session activity, permission changes, and MFA events, logged for security audit purposes.

2.3 Information from Third-Party Integrations

When you enable third-party integrations (e.g., Shopify, Square), we receive data from those services as configured by you. The categories of data imported depend on the integration type and your sync settings. Enabling customer data sync from third-party platforms requires your explicit acknowledgment.

3. How We Use Your Information

We use personal information for the following purposes:

  • Providing the Service: Account management, billing, feature delivery, and customer support.
  • Security: Fraud detection, rate limiting, audit logging, and incident response.
  • Communication: Transactional emails (billing confirmations, security alerts, password resets), service announcements, and responses to your inquiries.
  • Improvement: Usage analytics to improve Platform features and performance. We do not use your data for advertising or sell it to third parties.

4. How We Share Your Information

We do not sell, rent, or trade your personal information. We share data only in these limited circumstances:

  • Service providers (sub-processors): Payment processors, email delivery providers, hosting providers, and object storage providers — each bound by data processing agreements. See our DPA for the current list.
  • Legal requirements: When required by law, subpoena, court order, or to protect our rights, property, or safety.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with advance notice to affected users.

5. Data Storage and Security

5.1 Tenant Isolation

Customer data is stored in isolated, per-tenant database schemas. This architecture ensures that one tenant’s data is physically separated from another’s — queries cannot cross tenant boundaries.

5.2 Encryption

  • In transit: All connections use TLS 1.2 or higher.
  • At rest: Database-level encryption provided by our hosting provider. Sensitive fields (MFA secrets, integration credentials) use AES-GCM application-level encryption.

5.3 Access Control

Access to production systems follows least-privilege principles. The Platform enforces role-based access control with 6 default roles and tenant-customizable permission matrices across 19 resource areas.

5.4 Monitoring

We log 10 categories of security events (login, logout, password changes, MFA events, permission changes, session revocations, and more) and retain security audit logs for 2 years.

6. Data Retention

Data CategoryRetention Period
Tenant data (customers, orders, inventory, users)Duration of subscription + 30 days
Security audit logs2 years
Billing records7 years (tax/accounting compliance)
Support ticketsDuration of subscription + 90 days
Signup applications1 year after resolution
GDPR/privacy data exports24 hours after generation

Upon account cancellation, tenant data is retained for 30 days (grace period for reactivation or data export), then permanently deleted. Full details are in our Data Retention Policy.

7. Your Privacy Rights

Depending on your jurisdiction, you may have the following rights:

7.1 All Users

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Update inaccurate or incomplete personal data via your Account settings.
  • Deletion: Request deletion of your Account and associated data.
  • Export: Export your data using the Platform’s built-in export tools at any time.

7.2 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose.
  • Request deletion of your personal information.
  • Opt out of the sale of personal information. We do not sell personal information.
  • Non-discrimination for exercising your privacy rights.

To exercise these rights, contact us at privacy@idomni.app.

7.3 Other US State Privacy Laws

We comply with applicable state privacy laws including those in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA). Residents of these states may exercise equivalent rights by contacting us at the address above.

8. Cookies and Tracking

The Platform uses the following cookies:

CookiePurposeType
Authentication token (httpOnly)Session authenticationEssential
Refresh token (httpOnly)Token rotationEssential
Locale preferenceLanguage selectionFunctional
Theme preferenceLight/dark modeFunctional

We do not use third-party advertising cookies or cross-site tracking. Our public site may use basic analytics to measure page views; no personal data is shared with analytics providers.

For full details on the cookies we use, their purposes, durations, and how to manage them, please see our Cookie Policy.

9. Children’s Privacy

The Service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe we have collected information from a child under 13, contact us immediately at privacy@idomni.app.

10. International Users

The Service is primarily intended for users in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes at least 30 days before they take effect via email or in-platform announcement. The “Last Updated” date at the top reflects the most recent revision.

12. Contact Us

For privacy-related questions or to exercise your rights:

  • Email: privacy@idomni.app
PricingFeaturesWho it’s forLearnTri-StateContactAboutTerms of ServicePrivacy PolicyCookie Policy
CompareOmni vs LightspeedOmni vs ZohoOmni vs SquareOmni vs OdooOmni for ShopifyOmni for BigCommerce

© 2026 Omni by Invariably Digital. All rights reserved.

An Invariably Digital product