OmniConnX

Privacy Policy

Effective Date: February 17, 2026

OmniConnX ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at omniconnx.com and related services (collectively, the "Service"). Please read this policy carefully. By using OmniConnX, you agree to the terms described here.

1. Information We Collect

1.1 Information You Provide Directly

  • Account Information: When you register, we collect your name, email address, and password (hashed).
  • Billing Information: Payment card details are processed by Stripe, Inc. We receive a tokenized payment reference and billing address; we do not store full card numbers.
  • Profile Information: Optional display name, profile photo, and content niche you provide in Settings.
  • Communications: Emails or messages you send to our support team.

1.2 Platform Integration Data

When you connect a social media platform (YouTube, TikTok, Instagram, Twitter/X), we receive an OAuth access token that allows us to retrieve analytics data on your behalf. We collect:

  • Platform username and user ID (for account identification)
  • Public channel/profile metrics (views, subscribers/followers, engagement rate, impressions)
  • Content performance data (video/post-level metrics you authorize us to access)
  • Revenue and monetization data where the platform API provides it (e.g., YouTube Analytics)
  • OAuth access tokens and refresh tokens (stored encrypted at rest)

Important: We only request the minimum permissions necessary to provide the Service. We do not post on your behalf, send messages, or access private direct messages without explicit additional consent.

1.3 Usage and Technical Data

  • Log Data: IP address, browser type, operating system, referring URLs, pages viewed, and timestamps.
  • Device Data: Device type, screen resolution, and browser language.
  • Usage Data: Features used, dashboard interactions, filter selections, and session duration to improve product experience.
  • Cookies and Similar Technologies: Session identifiers, preferences, and analytics (see Section 10).

1.4 Data from Third Parties

  • Payment processing information from Stripe (subscription status, invoice history).
  • Fraud detection signals from our security service providers.
  • Single Sign-On data if you register via Google OAuth (name, email, profile picture).

2. How We Use Your Information

We use the information we collect to:

Provide and Operate the Service: Authenticate your account, sync platform metrics, generate analytics dashboards, and deliver revenue reconciliation reports.
Billing and Payments: Process subscription payments, issue invoices, handle refunds, and prevent payment fraud via Stripe.
Anomaly Detection and Health Monitoring: Analyze your metrics trends to detect unusual drops or spikes in engagement, views, or revenue, and alert you proactively.
Personalization: Tailor your dashboard, notifications, and AI-powered recommendations based on your goals and content niche.
Communication: Send transactional emails (payment receipts, health alerts, platform sync confirmations), account notifications, and — with your consent — product updates and marketing emails.
Legal Compliance: Meet obligations under applicable laws (e.g., GDPR, CCPA), respond to lawful government requests, enforce our Terms of Service, and prevent fraud or abuse.
Service Improvement: Analyze aggregated, de-identified usage patterns to improve features, fix bugs, and plan the product roadmap. We do not sell individual usage profiles.
Security: Detect and prevent unauthorized access, abuse, and other security incidents.

3. Information Sharing and Disclosure

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We share information only in the following circumstances:

Service Providers

We engage trusted third-party vendors who process data on our behalf, bound by data processing agreements:

ProviderPurposeData Shared
Stripe, Inc.Payment processingEmail, billing address, payment token
Amazon Web ServicesCloud infrastructure & data storageAll platform data (encrypted)
Confluent / Apache KafkaEvent streaming infrastructureAnonymized event data
SendGrid / AWS SESTransactional email deliveryEmail address, notification content
SentryError monitoringAnonymized error logs, device/browser info

Business Transfers

If OmniConnX is involved in a merger, acquisition, or sale of all or part of its assets, your data may be transferred as part of that transaction. We will notify you via email or prominent notice on our Service at least 30 days before any such transfer and give you the opportunity to delete your account.

Legal Requirements

We may disclose information if required by law, court order, or governmental authority, or when we believe disclosure is necessary to protect our rights, prevent fraud, or ensure the safety of our users.

Aggregated / De-identified Data

We may share aggregated, anonymized data (e.g., "creators using our platform see an average 23% improvement in engagement tracking") with partners and in public communications. This data cannot reasonably be used to identify you.


4. Data Retention

We retain your data only as long as necessary to fulfill the purposes outlined in this policy:

  • Account data: Retained for the duration of your account plus 30 days after deletion (to handle disputes), then permanently deleted.
  • Platform metrics: Raw metrics retained for 24 months. Aggregated summaries retained for up to 5 years for trend analysis.
  • Billing records: Retained for 7 years as required by financial regulations.
  • OAuth tokens: Deleted immediately upon disconnecting a platform or deleting your account.
  • Support correspondence: Retained for 2 years.
  • Log data: Retained for 90 days, then automatically purged.

To request deletion of your data before the retention period ends, contact us at info@omniconnx.com.


5. Your Privacy Rights

5.1 Rights for All Users

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your account and personal data, subject to legal retention obligations.
  • Data Portability: Receive your data in a machine-readable format (CSV/JSON).
  • Opt-Out of Marketing: Unsubscribe from marketing emails at any time via the link in each email or in Settings → Notifications.

5.2 GDPR Rights (EEA / UK Users)

If you are located in the European Economic Area or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:

  • Right to Restrict Processing: Request that we limit how we process your data.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw consent where processing is based on consent.
  • Right to Lodge a Complaint: File a complaint with your local data protection authority.

Our legal bases for processing under GDPR are: (a) performance of a contract (providing the Service), (b) legitimate interests (security, fraud prevention, product improvement), (c) compliance with legal obligations, and (d) your consent (marketing emails, optional analytics cookies).

5.3 CCPA Rights (California Residents)

Under the California Consumer Privacy Act (CCPA), California residents have the right to:

  • Know what personal information is collected, used, shared, or sold.
  • Delete personal information we have collected (with exceptions).
  • Opt-out of the sale or sharing of personal information. We do not sell personal information.
  • Non-discrimination for exercising your CCPA rights.

To exercise your rights, contact us at info@omniconnx.com or via Settings → Privacy → Data Requests. We respond within 30 days.


6. Security

We implement industry-standard technical and organizational security measures to protect your data:

  • All data transmitted between your browser and our servers is encrypted using TLS 1.2+.
  • OAuth tokens are encrypted at rest using AES-256 encryption.
  • Passwords are hashed using bcrypt with a minimum cost factor of 12.
  • Our infrastructure runs in ISO 27001-certified data centers on AWS.
  • We conduct regular vulnerability scanning and annual penetration testing.
  • Access to production systems is restricted to authorized personnel and requires multi-factor authentication.
  • We maintain a Security Incident Response Plan with a 72-hour breach notification commitment (in line with GDPR requirements).

While we strive to protect your data, no method of transmission over the Internet is 100% secure. If you discover a security vulnerability, please report it responsibly to security@omniconnx.com.


7. International Data Transfers

OmniConnX is based in the United States. If you access our Service from outside the U.S., your information may be transferred to and processed in the U.S. or other countries where our service providers operate.

For transfers from the EEA or UK to the U.S., we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Data Processing Agreements with all sub-processors incorporating appropriate transfer mechanisms.
  • The EU-U.S. Data Privacy Framework where applicable.

You may request a copy of the relevant transfer safeguards by contacting info@omniconnx.com.


8. Children's Privacy

OmniConnX is not directed to children under the age of 13 (or 16 in certain EEA countries). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at info@omniconnx.com and we will promptly delete that information.



10. Cookies and Tracking Technologies

We use cookies and similar tracking technologies. For full details, please see our Cookie Policy.

In summary, we use: (a) Essential cookies required for the Service to function (session management, CSRF protection); (b) Analytics cookies (with your consent) to understand how users interact with our product; and (c) Preference cookies to remember your settings (dark mode, language). We do not use advertising or tracking cookies for third-party ad targeting.


11. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Send an email notification to registered users at least 14 days before changes take effect.
  • Display a prominent notice on the Service for 30 days after the change.

Your continued use of the Service after changes become effective constitutes your acceptance of the updated policy. If you do not agree to the updated policy, you may delete your account before the effective date.


12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Team:

Privacy Team

info@omniconnx.com

Security Issues

security@omniconnx.com

Mailing Address

OmniConnX, Inc.
Privacy Department
548 Market Street, Suite 94103
San Francisco, CA 94104
United States

Response Time

We respond to all privacy inquiries within 30 calendar days. For GDPR requests, we aim to respond within 30 days as required by law.


13. Data Deletion

You have the right to request deletion of your data at any time. OmniConnX provides multiple ways to delete your data, including disconnecting individual platforms, deleting your entire account, or submitting a deletion request via email.

For detailed instructions on how to delete your data, including what gets deleted and retention policies, please visit our dedicated User Data Deletion page.

You can also revoke OmniConnX's access to your data directly from each connected platform's security settings (e.g., Facebook Apps and Websites, Google Account Permissions).