Privacy policy
Last updated: 2 October 2026
OmniText ("we") runs an online inbox that lets businesses read and answer messages their customers send through Facebook Messenger, Instagram and WhatsApp, and record the orders that come out of those conversations. This policy explains what data we handle and why.
Who this covers
Businesses that sign up for OmniText and the team members they invite, and customers of those businesses who message them on Messenger, Instagram or WhatsApp. For customer data, the business decides what to collect and why; we process it on the business's behalf.
What we collect
- Account details: business name, team members' names and email addresses, and passwords (stored only as one-way hashes).
- Connected accounts: the IDs and names of the Facebook Pages, Instagram accounts and WhatsApp numbers a business connects, and the access tokens Meta issues for them. Tokens are stored encrypted.
- Messages: messages exchanged between a business and its customers on connected accounts, the customer's name and platform ID as provided by Meta, links to attachments, and delivery status.
- Orders: details a business records for an order, such as customer name, phone number, delivery address, products and amounts.
- Technical data: basic server logs (such as IP address and time of request) used to keep the service secure and working.
How we use it
Only to provide the service: showing messages in the business's inbox, sending the business's replies back through the same platform, assigning conversations to team members, and keeping order records. We do not sell personal data, use it for advertising, or use data received from Meta for any purpose other than providing OmniText to the business that connected the account.
Who we share it with
- Meta Platforms, to receive and deliver messages on Messenger, Instagram and WhatsApp.
- Our hosting provider, which stores the data on our behalf.
- Anyone else only when the business itself exports or sends the data (for example, uploading an order list to a courier), or when required by law.
How long we keep it
For as long as the business's account is active. When a business disconnects an account, its conversations are deleted. When a business closes its account or asks for deletion, we delete its data within 30 days, except where the law requires us to keep it.
Security
Connections are encrypted with HTTPS, access tokens are encrypted at rest, passwords are hashed, and moderators only see their own customers and customers still waiting for a moderator.
Your choices
You can ask us for a copy of your data, or ask us to correct or delete it. See data deletion, or contact us at codepanthrer@gmail.com. If you are a customer of a business that uses OmniText, you can also contact that business directly.
Changes
We will post any changes to this policy on this page and update the date above.
Contact
OmniText, codepanthrer@gmail.com