Skip to main content

Legal

Privacy Policy

Last Updated: 14 July 2026

1. Who We Are

This Privacy Policy (the "Policy") explains how Omnistra (Private) Limited, a private limited company incorporated in Bangladesh with its registered office at Flat: A1, Chandrawip Tower-4, Mandy Dental Road 10, Baroikhali, Hazaribag Park, Dhaka, Bangladesh 1209 ("Omnistra," "we," "us," or "our"), collects, uses, discloses, retains, and protects information when you interact with our products, websites, and services.

Omnistra is an Autonomous Commerce platform that provides AI-powered customer service, conversational logistics support, and commerce intelligence to e-commerce and f-commerce (Facebook-commerce) businesses. We operate the Omnistra platform (the "Service") at https://app.omnistra.io and our marketing website at https://omnistra.io, and the Omnistra application registered with Meta Platforms, Inc. for use with Facebook, Instagram, Messenger, and WhatsApp Business APIs.

Contact us: Email: privacy@omnistra.io · Website: https://omnistra.io

Our Clients are the same entities defined as the Customer in our Terms of Service.

For the purposes of the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the Bangladesh Personal Data Protection Act 2026 (the "PDPA"), and other applicable data protection laws, Omnistra is the data controller (data fiduciary under the PDPA) for personal data we collect about our website visitors, merchant account holders, and prospects, and a data processor for personal data we process on behalf of our merchant customers (our "Clients") under a Data Processing Agreement (DPA).

2. Scope of This Policy

This Policy applies to:

  • Visitors to omnistra.io, app.omnistra.io, and any subdomain we operate.
  • Merchant businesses, their employees, and authorised users who register for, evaluate, or use the Omnistra Service (our "Clients").
  • End-consumers who interact with Omnistra-powered AI agents on behalf of our Clients, via channels such as Facebook Messenger, Instagram Direct, WhatsApp, voice calls, SMS, email, or web chat ("End Users").
  • Job applicants, vendors, and other individuals who interact with us in a business context.

This Policy does not apply to third-party websites or services linked from our Service, or to data that our Clients independently collect outside of the Omnistra Service.

When Omnistra processes personal data of End Users at the direction of a Client (for example, a customer of a Bangladesh online store who messages the store's Facebook Page), the Client is the controller and Omnistra is the processor. In those cases, the Client's own privacy policy governs the collection and primary use of that data, and Omnistra processes it only to provide the Service to that Client.

3. Information We Collect

3.1 Information You Provide Directly

  • Account and identity data: name, business name, job title, email address, phone number, country, login credentials.
  • Payment data: when you purchase a subscription or top up tokens, our payment processor collects card or mobile-banking details. We do not store full card numbers on our servers.
  • Communications: messages you send to our support, sales, or onboarding teams, including attachments.
  • Content and configuration: knowledge-base articles, product catalogues, voice and text prompts, workflow definitions, and any other content you upload to the Service.

3.2 Information We Collect Automatically

  • Usage data: pages viewed, features used, clicks, session duration, browser type, device type, operating system, IP address, language preference, time zone.
  • Log and diagnostic data: API request and response logs, error logs, latency metrics, system events, security events.
  • Cookies and similar technologies: see Section 11.

3.3 Information We Process on Behalf of Our Clients

When a Client uses Omnistra to operate an AI agent, we process data flowing through the agent on the Client's behalf. This may include:

  • End-User name, phone number, email address, social handle (Facebook ID, Instagram handle, WhatsApp number).
  • Order data: order ID, items, value, shipping address, payment method, delivery status, carrier, tracking ID.
  • Conversation content: messages, transcripts, audio recordings, sentiment, intent classifications, AI-generated responses.
  • Delivery-outcome signals used for the COD Buyer Reliability Score (see Section 13A).
  • Any other data the Client chooses to send to the Service through integrations or API calls.

Voice calls and recordings. Where a Client enables voice AI agents, calls may be recorded and transcribed to deliver the Service and create records for the Client. By default, our AI agents identify themselves as automated agents and state that the call is recorded at the start of the call, in line with the Bangladesh Telecommunication Act 2001 and equivalent laws elsewhere. Clients control certain call settings; where the law applicable to a call requires disclosure or recording notice, the Client is contractually prohibited from disabling it, and Omnistra logs the disclosure in the call record. We do not use voice recordings to build biometric voiceprints of End Users, and we do not use them to identify individuals across Clients. If we ever introduce a feature that uses voice characteristics to identify or verify an individual, we will update this Policy first, obtain any explicit consent the law requires (including under the PDPA's sensitive-data rules), and make the feature opt-in for Clients.

3.4 Information We Receive from Meta Platforms, Inc.

When a Client connects a Facebook Page, Instagram Business Account, or WhatsApp Business Account to the Omnistra Service, and when an End User interacts with that Client through a Meta-owned surface, we receive the following data from Meta through the Pages API, Messenger Platform, Instagram Messaging API, WhatsApp Business Platform, and related products:

  • Page or Instagram account ID, name, profile picture, category, and admin role information.
  • End-User Page-Scoped ID (PSID), Instagram-Scoped ID (IGSID), or WhatsApp phone number, plus name, profile picture, locale, and time zone where provided by Meta.
  • Message content exchanged through Messenger, Instagram Direct, or WhatsApp, including text, attachments, stickers, voice notes, and reactions.
  • Conversation metadata (timestamps, read receipts, delivery status, message thread ID).
  • Ad-related data such as ad ID, campaign ID, and click-to-message referrer data when an End User initiates a conversation from an ad.
  • Comments, replies, and mentions on Page or Instagram content when a Client enables that feature.

We access Meta-provided data strictly to deliver the Service the Client has configured (for example, replying to a customer enquiry or sending an order update). We do not use Meta data for our own advertising, do not sell it, do not transfer it except as described in this Policy, and we comply with the Meta Platform Terms and Developer Policies.

3.5 Information We Receive from Other Third Parties

  • E-commerce platforms our Clients connect (such as Shopify and WooCommerce).
  • Logistics carriers our Clients use (such as Pathao Courier, Steadfast, RedX, Sundarban, and Paperfly) for tracking and delivery-status data.
  • Payment gateways and mobile financial services for payment confirmation and refund status.
  • Service providers we use for hosting, communications, and security (see Section 6).
  • Public sources, partners, or referrers in connection with sales and marketing.

4. How We Use Information

4.1 To Provide and Operate the Service

  • Authenticate users, provision accounts, and enable login through Meta or other identity providers.
  • Configure, run, and monitor AI agents on the Client's behalf.
  • Route, transcribe, classify, and respond to conversations across Messenger, Instagram, WhatsApp, voice, SMS, email, and web chat.
  • Sync order, inventory, and customer state across the Client's connected systems.
  • Generate analytics, dashboards, and reports for the Client.

4.2 To Maintain, Secure, and Improve the Service

  • Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service or applicable law.
  • Monitor performance, debug, and improve reliability, latency, and accuracy.
  • Improve the Service using aggregated, anonymised, or de-identified data.

4.3 To Communicate with You

  • Send transactional messages about the Service (account, billing, security, service updates).
  • Respond to your support enquiries.
  • Send marketing communications about Omnistra products and events, where permitted by law. You may opt out at any time.

4.4 To Comply with Law and Protect Rights

Comply with legal obligations, court orders, and lawful requests from public authorities; enforce our agreements; protect the rights, property, or safety of Omnistra, our Clients, End Users, or others.

4.5 What We Do Not Do with Your Data

  • We do not sell personal data.
  • We do not share personal data for cross-context behavioural advertising (as defined under the CCPA/CPRA).
  • We do not use Meta-sourced messaging content to train AI models for any purpose other than serving the originating Client.
  • We do not use End-User personal data to train foundational AI models that are reused across Clients.
  • We do not access Client data except as needed to provide and support the Service, comply with law, or with the Client's permission.

The only cross-Client processing of End-User personal data we perform is the optional COD Buyer Reliability Score described in Section 13A, which uses order and delivery-outcome records only and never conversation content or Meta data.

5. How We Use Meta Platform Data: Specific Disclosures

This section is provided to satisfy the Meta Platform Terms and the Developer Policies, and identifies precisely how Omnistra processes data obtained through Meta APIs.

Meta Product / PermissionWhy Omnistra Requests ItWhat We Do with the DataWhat We Do Not Do
pages_show_list, pages_read_engagement, pages_manage_metadataDiscover the Client's Pages and confirm admin rights so the Client can connect a Page to Omnistra.List the Client's Pages in the Omnistra dashboard; store Page ID, name, and category.Modify Page settings without explicit Client action.
pages_messaging, pages_messaging_subscriptionsSend and receive Messenger messages on the Client's behalf.Deliver AI-generated replies, send order updates, log transcripts for the Client's review.Message users the Client has not transacted with, outside the 24-hour standard messaging window or approved message tags.
instagram_basic, instagram_manage_messages, instagram_manage_commentsReply to Instagram Direct messages and comments on Client-owned Instagram Business accounts.Same conversational handling as Messenger; comment moderation on the Client's instruction.Access personal Instagram accounts or content from accounts the Client does not own.
whatsapp_business_messaging, whatsapp_business_managementSend and receive WhatsApp Business messages and manage approved message templates on the Client's behalf.Deliver order updates, customer-service conversations; submit and manage template messages.Initiate WhatsApp messages outside the Client's opt-in base or outside permitted template categories.
public_profile, email (Facebook Login for Business)Authenticate the Client user signing into the Omnistra dashboard.Store name, email, and Facebook user ID for account management.Post to your timeline or access your friends list.

Data minimisation. We request only the permissions necessary for features the Client has enabled. Clients may disconnect a Meta asset from Omnistra at any time in the Omnistra dashboard; once disconnected, we cease processing new data from that asset.

No advertising use of Meta data by Omnistra. Omnistra does not use Meta-sourced data to build advertising profiles for our own marketing, does not sell or rent Meta data, and does not use it to create cross-site or cross-Client behavioural profiles.

Storage and retention of Meta data. Messaging content, message metadata, and Meta-issued IDs are retained only as long as needed to provide the Service to the originating Client. We delete Platform Data promptly when an End User or Client requests it, when it is no longer needed for the Service, when Meta requires deletion, and when the Client disconnects the Meta asset or the app connection terminates, except where the law requires retention. Our data-deletion instructions are described in Section 10.7.

6. How We Share Information

6.1 With Our Clients

When you, as an End User, interact with an AI agent built by one of our Clients, your conversation and related data are made available to that Client through their Omnistra account. The Client is the controller of that data.

6.2 With Service Providers (Sub-processors)

We rely on vetted sub-processors to operate the Service. Each sub-processor is bound by a written agreement requiring confidentiality, security, and use limited to providing services to Omnistra. Categories include:

  • Cloud hosting and storage: to host the Service and store Client data.
  • AI model providers: to generate AI responses and to transcribe and synthesise voice. We send only the data needed for the immediate request and configure these providers to retain data for the minimum period necessary to provide the service.
  • Communications infrastructure: to deliver voice, SMS, and messaging traffic, including Meta (WhatsApp Cloud API) and local Bangladesh telecom partners.
  • Payment processing: to process subscription payments and token top-ups.
  • Observability and security tools: for error tracking, performance monitoring, and security monitoring, configured to exclude the content of customer conversations where possible.

A current list of named sub-processors is published at omnistra.io/subprocessors and is also available by writing to privacy@omnistra.io.

6.3 With Meta

To operate the Service we exchange data with Meta Platforms, Inc. and its affiliates through the APIs described in Section 5. Meta's processing of WhatsApp Business data on behalf of the Client is governed by the WhatsApp Business Data Processing Terms at https://www.whatsapp.com/legal/business-data-processing-terms.

6.4 In Business Transfers

If Omnistra is involved in a merger, acquisition, financing, reorganisation, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected users where required by law.

7. International Data Transfers

Omnistra operates from Bangladesh and may transfer personal data to other countries where we, our affiliates, or our sub-processors operate, including the United States and the European Union.

When personal data is transferred outside its country of origin, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission and the UK International Data Transfer Addendum (for transfers out of the EEA and UK), and Data Processing Agreements with our sub-processors that incorporate technical and organisational safeguards.

For personal data of data subjects in Bangladesh, we transfer data outside Bangladesh only as permitted by the PDPA and its cross-border transfer rules, and we store data classified as restricted under Bangladeshi law within Bangladesh where the law requires it.

You may request more information about these safeguards by writing to privacy@omnistra.io.

8. Data Retention

We retain personal data only for as long as necessary to provide the Service and fulfil the purposes set out in this Policy, then delete or anonymise it, unless a longer period is required or permitted by law.

In general:

  • Client account and billing records are retained for the duration of the contract, plus any additional period required by tax and accounting law.
  • Conversation transcripts, messages, and voice recordings are retained for the period the Client has configured, and are deleted within a reasonable period after a Client account closes.
  • Meta-sourced identifiers (PSIDs, IGSIDs, WhatsApp numbers) are tied to the connected Meta asset and are deleted within a reasonable period after the Client disconnects the asset, or earlier on an End-User deletion request.
  • Logs and security records are retained only as long as needed for operational, security, and legal purposes.
  • Marketing data for prospects and leads is retained until you opt out or until it is no longer relevant.
  • Backups are purged on a routine schedule.

Clients can request changes to retention configuration by contacting their account representative. End Users may request earlier deletion as set out in Section 10 and via our Data Deletion Instructions at https://omnistra.io/data-deletion.

9. Security

We take the security of personal data seriously and implement reasonable administrative, technical, and physical safeguards designed to protect it against unauthorised access, alteration, disclosure, or destruction. These include:

  • Encryption of personal data in transit and at rest.
  • Access controls based on the principle of least privilege, with authentication required for all staff access to production systems.
  • Continuous monitoring of our systems for security events.
  • Incident-response procedures to investigate and respond to suspected security incidents. In the event of a personal-data breach that affects our Clients or their End Users, we will notify the affected Client without undue delay, notify the competent authority (including the authority designated under the Bangladesh PDPA) where the law requires it, and assist the Client in meeting its own notification obligations to regulators and data subjects.
  • Ongoing review and improvement of our security posture as the Service evolves.

No method of transmission or storage is completely secure. You are responsible for safeguarding your account credentials and for the data you choose to submit to the Service.

10. Your Rights

Depending on your location and your relationship with us, you may have the following rights regarding your personal data.

10.1 Rights We Support

Depending on the law that applies to you and on whether Omnistra is the controller of your data, you may have the following rights. Where a Client is the controller, we support these rights as its processor (see Section 10.5).

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your personal data, subject to legal retention requirements.
  • Withdraw consent where processing is based on consent.
  • Object to or restrict certain processing.
  • Data portability: receive your data in a structured, machine-readable format.
  • Lodge a complaint with a supervisory authority.

10.2 EU / UK Residents (GDPR)

You may contact us at privacy@omnistra.io to exercise any of the rights above. You also have the right to complain to your local data protection authority.

10.3 California Residents (CCPA/CPRA)

You have the right to know, delete, correct, limit use of sensitive personal information, and to opt out of sale or sharing for cross-context behavioural advertising. Omnistra does not sell or share personal information as those terms are defined under the CCPA/CPRA. To exercise your rights, email privacy@omnistra.io. We will not discriminate against you for exercising your rights.

10.4 Bangladesh Residents

Under the Personal Data Protection Act 2026, you have the right to access, correct, and request erasure of your personal data, to withdraw consent at any time, and to receive the disclosures described in Section 4.6 at the point of collection. You may contact privacy@omnistra.io to exercise these rights. You also have the right to lodge a complaint with the data protection authority designated under the PDPA.

10.5 End Users of a Client

If you interacted with an Omnistra-powered AI agent operated by one of our Clients (for example, a store you bought from), you should direct your rights request to that Client in the first instance; they are the data controller. Omnistra will assist the Client in fulfilling valid requests. You may also contact us directly at privacy@omnistra.io and we will forward your request to the relevant Client and respond as a processor.

10.6 How to Exercise Your Rights

Email privacy@omnistra.io with:

  • 1. Your name and the email address or phone number associated with the data;
  • 2. The right you wish to exercise;
  • 3. (If applicable) the name of the Client whose service you interacted with.

We will respond within 30 days, or any shorter period applicable law requires. For complex requests we may extend the response period, but the total will not exceed 90 days, and we will tell you about the extension within the first 30 days. We may need to verify your identity before fulfilling the request to protect against fraudulent requests.

10.7 Data Deletion Instructions (Meta Requirement)

Our dedicated, publicly accessible Data Deletion page is at https://omnistra.io/data-deletion. End Users may submit a deletion request via that page or by emailing privacy@omnistra.io with the subject line "Data Deletion Request." We will confirm receipt within 7 days. We will delete the data from our active systems within 30 days, and from encrypted backups within 90 days as those backups expire on their routine cycle, except where retention is required by law. Data awaiting backup expiry is not restored to active systems except for disaster recovery, and remains protected as described in this Policy.

11. Cookies and Similar Technologies

We use cookies, pixels, and similar technologies on our marketing website and dashboard for:

  • Strictly necessary purposes (authentication, session management, security).
  • Performance and analytics (understanding how visitors use our site).
  • Functional preferences (language, region).

You can manage your preferences by adjusting your browser settings. We do not sell or share personal information, so there is nothing to opt out of; where the Global Privacy Control (GPC) signal applies to a visitor, we treat it as a valid opt-out of any sale or sharing.

12. Children's Privacy

The Omnistra Service is a business-to-business platform and is not directed to children. We do not knowingly collect personal data from children under the age of 13 (or under the age of 16 in the EEA / UK, or under any other age defined by applicable law). If we learn we have collected personal data from a child without verified parental consent, we will delete that information promptly. Parents or guardians who believe their child has provided us with personal data may contact privacy@omnistra.io.

Clients using the Service to interact with their own end-customers are responsible for ensuring their use of the Service complies with age-restriction laws.

AI agents operated for our Clients may in practice interact with minors who shop with a Client. Clients are responsible for age screening required for their products and for lawful bases for contacting their customers. Where we learn that an End User in a conversation or in the COD Buyer Reliability Score records is a minor, we exclude that individual's records from cross-merchant scoring, do not use their data for any promotional purpose, and delete their data on request of the minor's guardian, subject to legal retention requirements.

13. Automated Decision-Making and AI

The Omnistra Service uses AI models to generate conversational replies in Bangla and English, classify intent and sentiment, and assist clients with customer-service workflows.

AI outputs in the Service are intended to assist human decision-making, not to replace it. A Client always retains the ability to review, override, or escalate any AI-generated decision, and Omnistra provides an "ask a human" escalation route in AI-agent conversations.

Where automated processing produces a legal or similarly significant effect on an End User, the Client (as the data controller) is responsible for providing the human-review path required by Article 22 of the GDPR or equivalent law. Omnistra provides the tooling to make this possible.

We do not use End-User personal data to train foundational AI models that are reused across Clients.

13A. COD Buyer Reliability Score

Some Clients enable an optional scoring feature that estimates the likelihood that a cash-on-delivery order will be accepted, based on order and delivery-outcome history contributed by participating merchants (the "Score").

  • What it uses: phone number or other order identifier, order events, and delivery outcomes (delivered, refused, unreachable). It does not use conversation content, and it does not use data from Meta messaging surfaces.
  • What it is for: helping a merchant decide how to confirm, route, or verify a cash-on-delivery order. It is a delivery-risk signal only. The Score is a decision-support signal; participating merchants must not refuse an order solely because of the Score and must offer an alternative way to order or a human review.
  • What it is not: the Score is not a credit score, and Omnistra is not a credit information bureau or consumer reporting agency. Clients are contractually prohibited from using the Score to decide eligibility for credit, insurance, employment, or housing.
  • How long it lasts: delivery-outcome events stop counting toward the Score 24 months after the event and are deleted or anonymised on that schedule. Corrected records are updated in the Score within 30 days of the correction.
  • Human review: merchants remain responsible for their own order decisions, and the Service provides a human-review path for any decision that significantly affects an End User, consistent with Article 22 of the GDPR and equivalent laws.
  • Your rights: if you believe the Score reflects inaccurate records about you, contact privacy@omnistra.io with your phone number and any order reference. We will acknowledge your dispute within 7 days and complete our review within 30 days. Where the record came from a merchant or courier, we verify it with the source. We correct records shown to be inaccurate, exclude records we cannot verify within the review period, and confirm the outcome to you. If you are in a jurisdiction that gives you a right to object to processing based on legitimate interest, you may object to inclusion in the Score at privacy@omnistra.io and we will assess your objection as the law requires.

For this feature, Omnistra acts as a data controller of the pooled delivery-outcome records. Where the GDPR or UK GDPR applies, our lawful basis is legitimate interest in fraud prevention and delivery-failure reduction, assessed and documented against the rights of the individuals concerned, and you may object at any time (see Section 10). For data subjects in Bangladesh, the Score operates on the disclosures and permissions the merchant obtains at the point of order under the Personal Data Protection Act; participating merchants are contractually required to disclose delivery-risk scoring in their order flow and privacy notices before contributing data. We do not include an individual's records in the Score where the required disclosure or permission is missing, and we will remove records on request where no valid basis exists. We do not compute or apply the Score to End Users located in the European Economic Area or the United Kingdom unless and until we publish an EEA/UK supplement to the Score terms.

14. Changes to This Policy

We may update this Policy from time to time. The "Last Updated" date at the top reflects when the most recent changes took effect. Material changes will be notified to Clients by email or by an in-product notice at least 30 days before they take effect, except where a shorter period is required by law. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

15. Contact Us

If you have any questions, requests, or complaints about this Policy or our handling of personal data, please contact us:

Omnistra (Private) Limited, Flat: A1, Chandrawip Tower-4, Mandy Dental Road 10, Baroikhali, Hazaribag Park, Dhaka, Bangladesh 1209.

Email: privacy@omnistra.io · General: hello@omnistra.io · Web: https://omnistra.io

For Meta App Review purposes, the published privacy policy URL is: https://omnistra.io/privacy-policy

The published data-deletion instructions URL is: https://omnistra.io/data-deletion