Privacy Policy

Effective date: July 21, 2026

1. Who We Are

This Privacy Policy explains how OmniCommerce Solutions Pte Ltd ("we", "us") collects, uses, shares, and protects personal data when you use OmniCommerce (the "Service").

2. Information We Collect

We may collect account details (name and email), authentication identifiers, usage data, marketplace integration metadata, product catalog data, order data, fulfillment data, billing-related records, and technical logs required to operate, secure, and improve the Service.

When merchants connect marketplace or commerce integrations, this can include customer personal data contained in orders—such as names, emails, phone numbers, shipping addresses, order identifiers, order totals, and line items—but only where needed for merchant-requested order, fulfillment, inventory, support, reporting, or synchronization workflows.

When you choose to connect an email provider, we also access mailbox data as described in Section 7 (Google / Gmail) and Section 9 (Microsoft Outlook).

3. How We Use Information

We use data to provide and improve user-facing product features, authenticate users, process marketplace operations, import and synchronize products and orders, support fulfillment workflows, power optional assistant/email features you enable, send service notifications, and monitor platform reliability and security.

We do not use merchant customer personal data for advertising, resale, or unrelated profiling. Use of Google user data is further limited as described in Sections 7 and 8. Use of Microsoft Outlook / Microsoft Graph data is described in Section 9.

4. Sharing of Information

We share information only with trusted service providers and infrastructure needed to operate the Service (for example hosting, storage, email delivery, observability, and AI model providers used solely to power features you request), with marketplaces and integrations you connect, or when required by law.

We do not sell personal data. We do not transfer or sell Google or Microsoft mailbox user data to data brokers, advertisers, or information resellers. Transfers of Google user data are limited as described in Sections 7 and 8. Transfers of Microsoft Outlook data are limited as described in Section 9.

5. Data Retention

We retain personal data for as long as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements. Marketplace protected customer fields are minimized by default, redacted when a supported marketplace sends a valid erasure request, and periodically redacted from retained Shopify order records after 18 months unless a longer period is legally required.

Retention and deletion practices for Google user data (including Gmail connection tokens and related data) are described in Section 7. Practices for Microsoft Outlook connections are described in Section 9.

6. Security

We apply reasonable technical and organizational safeguards to protect data, including encryption in transit (HTTPS/TLS), access controls scoped to authenticated users and their organizations, encrypted storage of OAuth refresh and access tokens for connected email accounts, and least-privilege operational practices. However, no system is completely secure.

Additional protections specific to Google user data are described in Section 7. Protections for Microsoft Outlook connections are described in Section 9.

7. Google User Data (Gmail / Google Workspace APIs)

This section applies when you connect a Google account to OmniCommerce (for example via Account → Email → Connect Gmail). Connecting Google is optional. We access Google user data only after you grant permission through Google's OAuth consent screen, and only for the scopes you approve.

Data access (what we access). Depending on the scopes granted, we may access: your Google account email address and basic identity needed to label the connection; Gmail mailbox data such as message and thread identifiers, headers (for example From, To, Cc, Subject, Date), labels, and message bodies and attachments when you or your authorized workflows read, search, or open mail; and Gmail draft and send capabilities so the Service can create drafts or send messages from your connected mailbox when you request those actions. We currently request mail-related scopes only (including gmail.readonly and gmail.compose, plus openid/email for account identity). We do not request Google Calendar scopes at this time. We may process both raw mailbox content and limited derived or aggregated signals needed to operate features (for example search results, thread summaries produced for you, or delivery status for a send you initiated).

Data use (how we use it). We use Google user data solely to provide or improve user-facing features of the Service that you enable, including: listing, searching, and reading mail in your connected mailbox; drafting and sending email on your behalf when you request it; optional assistant/AI features that help you understand or act on your own mailbox content; and reliable connection maintenance (token refresh, webhook/push notifications for new mail where configured, and troubleshooting). We do not use Google user data for targeted advertising, credit eligibility or lending decisions, or any purpose unrelated to providing or improving these features.

Data transfer (who we share it with). Google user data is not sold. We may process it using subprocessors that help us deliver the Service—such as cloud hosting and storage providers, application infrastructure, and AI model API providers—only as needed to perform the user-facing features described above (for example generating a draft reply you requested). We do not transfer Google user data to third parties for their independent advertising, data-brokerage, or model-training purposes. We may disclose data if required by law or to protect the rights, safety, and security of users and the Service.

Data protection (how we secure it). OAuth access and refresh tokens for Google connections are encrypted at rest. Access to connected mailboxes is limited to the signed-in user who connected the account (connections are user-owned, not shared organization-wide by default) and to backend systems required to fulfill your requests. We use industry-standard transport security and operational access controls. We encourage you to disconnect Google access when it is no longer needed.

Data retention and deletion. We retain Google OAuth tokens and connection metadata for as long as the connection remains active so we can continue providing the connected-email features. Message content retrieved from Gmail is processed to fulfill your requests and is not used to build advertising profiles. Operational logs may retain limited technical metadata for security and reliability for a limited period. You can disconnect Gmail at any time in Account → Email, which deletes the stored connection and associated OAuth tokens for that account. You may also revoke OmniCommerce's access in your Google Account security settings (Third-party access). For additional deletion or privacy requests regarding Google user data, contact [email protected]. We will respond in accordance with applicable law and our technical ability to identify and delete retained data.

8. Limited Use of Google User Data

Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular: (a) we use Google user data only to provide or improve user-facing features that are prominent in the Service; (b) we do not transfer Google user data to third parties except as necessary to provide or improve those features, for security, or as required by law; (c) we do not use or transfer Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising; (d) we do not allow humans to read Google user data unless you give us affirmative consent for specific messages, it is necessary for security or legal compliance, or the data has been aggregated and anonymized; and (e) we do not sell Google user data.

AI and machine learning. When optional assistant or AI features process Gmail content, that processing is only to provide personalized, user-facing features for the requesting user (for example summarizing a thread or drafting a reply). We do not use raw or derived Google Workspace / Gmail user data to develop, improve, or train generalized or non-personalized AI/ML models. We do not transfer Google Workspace / Gmail user data to third-party AI services for those services to train their models; any AI provider processing is limited to generating the feature output you requested, subject to our agreements with those providers.

The use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.

9. Microsoft Outlook User Data (Microsoft Graph)

This section applies when you connect a Microsoft account or Microsoft 365 / Outlook mailbox to OmniCommerce (for example via Account → Email → Connect Outlook). Connecting Microsoft is optional. We access Microsoft user data only after you grant permission through Microsoft's OAuth consent experience, and only for the permissions (scopes) you approve.

Data access (what we access). Depending on the permissions granted, we may access: your Microsoft account profile and primary email address (for example via openid, profile, email, and User.Read) needed to identify and label the connection; Outlook / Microsoft 365 mailbox data via Microsoft Graph such as message identifiers, conversation identifiers, headers (for example From, To, Cc, Subject, Date), folders, and message bodies and attachments when you or your authorized workflows read, search, or open mail (Mail.Read and, where granted, Mail.ReadWrite); and send capabilities so the Service can create drafts or send messages from your connected mailbox when you request those actions (Mail.Send and related write permissions). We use offline_access so we can refresh tokens and keep the connection working without repeated sign-in. We currently request mail-related Graph permissions only. We do not request Microsoft Calendar permissions (for example Calendars.ReadWrite) at this time. We may process both raw mailbox content and limited derived or aggregated signals needed to operate features (for example search results, thread summaries produced for you, or delivery status for a send you initiated).

Data use (how we use it). We use Microsoft Outlook / Graph user data solely to provide or improve user-facing features of the Service that you enable, including: listing, searching, and reading mail in your connected mailbox; drafting and sending email on your behalf when you request it; optional assistant/AI features that help you understand or act on your own mailbox content; and reliable connection maintenance (token refresh, change notifications/webhooks for new mail where configured, and troubleshooting). We do not use Microsoft mailbox data for targeted advertising, credit eligibility or lending decisions, or any purpose unrelated to providing or improving these features.

Data transfer (who we share it with). Microsoft user data accessed through Graph is not sold. We may process it using subprocessors that help us deliver the Service—such as cloud hosting and storage providers, application infrastructure, and AI model API providers—only as needed to perform the user-facing features described above (for example generating a draft reply you requested). We do not transfer Microsoft mailbox data to third parties for their independent advertising, data-brokerage, or model-training purposes. We may disclose data if required by law or to protect the rights, safety, and security of users and the Service. Microsoft’s processing of data in its own services remains subject to Microsoft’s terms and privacy statements.

Data protection (how we secure it). OAuth access and refresh tokens for Microsoft Outlook connections are encrypted at rest. Access to connected mailboxes is limited to the signed-in user who connected the account (connections are user-owned, not shared organization-wide by default) and to backend systems required to fulfill your requests. We use industry-standard transport security and operational access controls. We encourage you to disconnect Microsoft access when it is no longer needed.

Data retention and deletion. We retain Microsoft OAuth tokens and connection metadata for as long as the connection remains active so we can continue providing the connected-email features. Message content retrieved from Outlook is processed to fulfill your requests and is not used to build advertising profiles. Operational logs may retain limited technical metadata for security and reliability for a limited period. You can disconnect Outlook at any time in Account → Email, which deletes the stored connection and associated OAuth tokens for that account. You may also revoke OmniCommerce's access in your Microsoft account or Microsoft 365 admin consent settings. For additional deletion or privacy requests regarding Microsoft user data, contact [email protected]. We will respond in accordance with applicable law and our technical ability to identify and delete retained data.

AI and machine learning. When optional assistant or AI features process Outlook mailbox content, that processing is only to provide personalized, user-facing features for the requesting user (for example summarizing a thread or drafting a reply). We do not use raw or derived Microsoft mailbox data to develop, improve, or train generalized or non-personalized AI/ML models. We do not transfer Microsoft mailbox data to third-party AI services for those services to train their models; any AI provider processing is limited to generating the feature output you requested, subject to our agreements with those providers.

Our use of Microsoft APIs and data obtained through them is intended to comply with applicable Microsoft API Terms of Use, the Microsoft Services Agreement, and related Microsoft developer policies for the permissions we request.

10. Your Rights

Depending on applicable law, you may have rights to access, correct, delete, or restrict processing of your personal data. For Google-connected accounts, you can disconnect the integration in the Service or revoke access in your Google Account. For Microsoft Outlook–connected accounts, you can disconnect the integration in the Service or revoke access in your Microsoft account / organization admin settings. To exercise privacy rights, contact [email protected].

11. International Transfers

Your data may be processed in jurisdictions outside your own, including where our hosting providers and subprocessors operate. We take reasonable steps to ensure appropriate protection for cross-border transfers.

12. Policy Updates

We may update this policy periodically. Material changes will be reflected by the effective date above. Continued use of the Service after an update constitutes acceptance of the revised policy where permitted by law.

13. Contact

For privacy-related requests, including questions about Google or Microsoft user data, contact [email protected].