Privacy Policy
Last updated: February 12, 2026
01Introduction & Scope
Omnify Inc. (“Omnify,” “we,” “us,” or “our”) is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Omnify platform, mobile applications, APIs, and related services (collectively, the “Service”).
By using the Service, you consent to the data practices described in this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
02Information We Collect
We collect several types of information depending on which features you use and which third-party integrations you enable:
2.1 Account Information
When you create an account via Google Sign-In, Apple Sign-In, or any supported authentication method, we collect your name, email address, and profile picture (if provided). If you use Apple’s “Hide My Email” feature, we receive Apple’s private relay email address instead.
2.2 Google Services Data
When you connect your Google account, we may access the following data depending on the permissions you grant:
- Gmail: Access to send emails on your behalf. We access only the minimum data necessary to compose and send messages. We do not read, index, or mine the contents of your inbox or existing emails.
- Google Calendar: Access to read and write calendar events, including event titles, times, attendee information, and descriptions, for scheduling and availability management.
- Google Ads: Access to retrieve lead form submissions, including lead names, email addresses, phone numbers, and form responses from your Google Ads campaigns.
2.3 Microsoft / Outlook Data
When you connect your Microsoft account, we access only your Outlook calendar data, including event titles, times, attendees, and descriptions. We do not access your Outlook email, contacts, OneDrive files, or any other Microsoft services.
2.4 Meta Ads Data
When you connect your Meta Ads account, we retrieve lead form submission data from your Facebook and/or Instagram ad campaigns, including lead names, email addresses, phone numbers, and form responses. We do not access your personal social media profile, friends list, posts, or direct messages.
2.5 CRM & Communication Data
We collect and store data generated through your use of the Service, including:
- Contact information for your leads and customers (as entered by you or synced from integrations)
- Phone call recordings, transcripts, and metadata (duration, time, phone numbers)
- Text message content, delivery status, and metadata
- Email content and delivery status for messages sent through the Service
- Appointment and scheduling data
- Notes, tags, and other CRM data you create
2.6 Usage & Device Data
We automatically collect certain information when you use the Service, including your IP address, browser type, device type, operating system, referring URLs, pages viewed, features used, timestamps, and other diagnostic data. This is collected via server logs and, where applicable, cookies or similar technologies.
03How We Use Your Information
We use the information we collect for the following purposes:
- Provide the Service: To operate the CRM, make and receive AI-powered calls, send follow-up texts and emails, schedule appointments, and sync lead data.
- Account Management: To create, authenticate, and manage your account.
- Calendar Synchronization: To read your availability and create/manage appointments in your connected Google Calendar or Outlook calendar.
- Lead Management: To import, organize, and follow up on leads from Google Ads and Meta Ads campaigns.
- AI Communications: To generate phone call scripts, text messages, and email content; to improve AI accuracy and performance over time.
- Service Improvement: To analyze usage patterns, diagnose technical issues, and improve the Service.
- Compliance: To comply with legal obligations, resolve disputes, and enforce our agreements.
- Customer Support: To respond to your inquiries and provide technical assistance.
04Google API Services — Limited Use Disclosure
Omnify’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide and improve the user-facing features of Omnify that are visible and apparent to you.
- We do not transfer Google user data to third parties except as necessary to provide the Service, comply with applicable law, or as part of a merger/acquisition with adequate data protection.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data unless: (a) we have your affirmative consent; (b) it is necessary for security purposes (e.g., investigating abuse); (c) it is necessary to comply with applicable law; or (d) the data is aggregated and anonymized for internal operations.
05Third-Party Data Sharing
We do not sell your personal information to third parties. We may share your information only in the following circumstances:
- Service Providers: We share data with trusted third-party vendors who assist us in operating the Service, such as cloud hosting providers, telephony (voice/SMS) providers, email delivery services, and analytics tools. These providers are contractually obligated to use your data only for the services they perform on our behalf.
- Legal Requirements: We may disclose your information if required to do so by law, in response to a subpoena, court order, or other legal process, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.
- With Your Consent: We may share your information with third parties when you have given us explicit consent to do so.
06Text Messaging Privacy
The following disclosures apply to text messages sent through the Omnify platform:
6.1 Phone Numbers & Messaging Data
When leads and customers provide their phone numbers (via ad forms, verbal communication, direct entry, or other means), those numbers are stored in your Omnify CRM. We use these phone numbers to deliver text messages on your behalf, including follow-up messages, appointment reminders, and AI-generated communications. Phone numbers and message content are stored securely and are never sold to third parties.
6.2 Consent & Opt-In Records
Omnify requires that all text message recipients have provided valid consent before receiving messages. Consent may be given verbally (e.g., by calling the business and being informed they will receive follow-up SMS), in writing (e.g., via a web form or lead form), or through an active inquiry where a phone number is provided. All communication aligns with TCPA guidelines, and businesses using Omnify are responsible for maintaining verifiable records of consent for each recipient.
6.3 Message Logs
We retain logs of all text messages sent through the Service, including message content, recipient phone numbers, timestamps, and delivery status. These logs are retained for the purposes of providing the Service, troubleshooting, compliance, and dispute resolution. Message logs are subject to the data retention periods described in Section 8.
6.4 Opt-Out Data
When a message recipient opts out by replying STOP (or similar keywords such as UNSUBSCRIBE, CANCEL, END, or QUIT), we record their phone number on a suppression list to prevent future messages. Upon opting out, recipients receive a confirmation message. Opt-out records are retained indefinitely to ensure continued compliance. We do not share opt-out lists with third parties except as required by our telephony service providers for message filtering purposes. Recipients may re-subscribe at any time by texting START or by providing fresh consent.
6.5 Telephony Service Providers
To facilitate message delivery, we share recipient phone numbers and message content with our trusted telephony service providers. These providers are contractually obligated to handle data securely and use it solely for the purpose of delivering messages on your behalf. We do not share messaging data with any third parties for marketing or advertising purposes.
Consumer Messaging Disclosure
If you are a consumer receiving text messages from a business using Omnify, please note:
- Messages are sent by the business whose name appears in the message. Omnify is the technology platform facilitating delivery.
- Message and data rates may apply depending on your mobile carrier and plan.
- You can opt out at any time by replying STOP to any message.
- You can request help by replying HELP to any message.
- Message frequency varies by business and communication type.
- For privacy concerns, contact the business that sent you the message directly, or reach out to us at team@omnifycrm.com.
07AI & Automated Decision-Making
Omnify uses artificial intelligence and machine learning to:
- Generate natural-sounding voice calls to leads and customers.
- Compose follow-up text messages and emails based on conversation context.
- Qualify leads based on conversation data and form responses.
- Schedule appointments based on calendar availability and customer preferences.
- Provide real-time conversation recommendations and response suggestions.
AI decisions (such as lead qualification scores) are advisory in nature and are designed to assist your business operations. You retain full control over how leads are handled and can override or adjust any AI-generated actions at any time. We do not use AI to make decisions that produce legal effects or similarly significant effects on individuals without human oversight.
08Data Retention & Deletion
We retain your data for as long as your account is active or as needed to provide the Service. Specific retention periods include:
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion + 30 days |
| CRM data (contacts, notes) | Until account deletion + 30 days |
| Call recordings & transcripts | 12 months or until deletion request |
| Text message logs | 12 months or until deletion request |
| Email send logs | 12 months or until deletion request |
| Calendar event data | Synced in real-time; deleted upon disconnection |
| Opt-out / suppression records | Retained indefinitely for compliance |
| Usage & analytics data | 24 months (aggregated/anonymized) |
You may request deletion of your data at any time by contacting us at team@omnifycrm.com. Upon receiving a verified deletion request, we will delete your personal data within thirty (30) days, unless retention is required by law or for legitimate business purposes (e.g., fraud prevention, legal compliance).
09Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls limiting data access to authorized personnel only.
- Regular security audits and vulnerability assessments.
- Secure storage of authentication tokens; we never store your third-party passwords.
- Monitoring and logging of access to sensitive data.
While we strive to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.
10Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete data.
Right to Deletion
Request deletion of your personal data (subject to legal exceptions).
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Opt Out
Opt out of data processing for marketing purposes.
Right to Non-Discrimination
Exercise your rights without receiving discriminatory treatment.
To exercise any of these rights, please contact us at team@omnifycrm.com. We will respond to your request within thirty (30) days. We may require identity verification before processing your request.
California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete personal information, and the right to opt out of the sale or sharing of personal information. We do not sell your personal information. To submit a verifiable consumer request, contact us at team@omnifycrm.com.
EU/EEA Residents (GDPR)
If you are located in the European Union or European Economic Area, you have rights under the General Data Protection Regulation (GDPR), including the rights listed above. Our legal basis for processing your data includes performance of a contract (providing the Service), legitimate interests (improving the Service), and your consent (where applicable). You also have the right to lodge a complaint with your local data protection authority.
11Children’s Privacy
The Service is not directed to individuals under the age of 13 (or 16 in the EU/EEA). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at team@omnifycrm.com.
12International Data Transfers
Your information may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from those of your country. When we transfer data internationally, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure your data receives adequate protection regardless of where it is processed.
13Cookies & Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience, analyze usage, and support the Service. The types of cookies we use include:
- Essential Cookies: Required for the Service to function (e.g., authentication, session management).
- Analytics Cookies: Help us understand how users interact with the Service to improve performance and usability.
You can control cookies through your browser settings. Disabling essential cookies may impact the functionality of the Service.
14Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on our website and/or sending a notification via email at least thirty (30) days before the changes take effect. The “Last updated” date at the top of this policy indicates when the latest revision was made. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.
15Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Omnify Inc.
Privacy Inquiries: team@omnifycrm.com
General Inquiries: team@omnifycrm.com
Website: omnifycrm.com
© 2026 Omnify Inc. All rights reserved.