Omni Store
PricingCustomersDocsContact
Sign in Start free
EN FR
Omni Store
PricingCustomersDocsContact Sign in
Start free
EN FR
Omni Store / Legal

OmniStore Privacy Policy

Version 1.1.8 · Effective 2026-06-01 · Updated 2026-07-05

All policies

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use Policy
  • Refund Policy
  • Data Processing Agreement
  • DMCA / Copyright Policy
  • Imprint
  • Subprocessors

OmniStore Privacy Policy

Effective Date: June 1, 2026 Last Updated: May 24, 2026 Version: 1.0.0


1. Who we are

OmniStore is a software-as-a-service platform that lets retail merchants run their inventory, point-of-sale, sales tracking, and customer-facing online store. OmniStore is operated by Harold Voufack, an unincorporated individual operator trading under the name “OmniStore”, based in Cameroon. We are reachable at legal@useomnistore.com.

For the purposes of the EU General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act / California Privacy Rights Act (“CCPA/CPRA”), and the Cameroonian Loi N° 2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité, the data controller for the personal data described in this Privacy Policy is Harold Voufack, contactable at legal@useomnistore.com.

For data that OmniStore processes on behalf of a merchant (the merchant’s own customers’ personal data, hosted on the merchant’s storefront), OmniStore acts as the data processor and the merchant is the data controller. That processing is governed by the OmniStore Data Processing Agreement, available at useomnistore.com/legal/dpa.

We have not appointed a Data Protection Officer. Data-protection inquiries should be sent to legal@useomnistore.com.


2. Who this Privacy Policy applies to

This Privacy Policy describes how OmniStore handles personal data of:

  • Merchants who register an OmniStore account to run their retail business through the platform (the OWNER of a store and any team member they invite - ADMIN, MANAGER, SELLER, INVENTORY_HANDLER, VIEWER).
  • Visitors to the OmniStore marketing pages at useomnistore.com and the admin app at app.useomnistore.com.
  • Visitors to a merchant’s storefront at {merchant-slug}.useomnistore.com, only insofar as the OmniStore platform itself collects data (e.g. abuse-prevention logs). The merchant’s own privacy policy - which the merchant is responsible for providing - governs how the merchant handles their customers’ data.
  • Anyone who contacts us through email, support channels, or social media.

If you are a customer of a merchant who uses OmniStore, your primary relationship is with that merchant, not with OmniStore. The merchant’s own privacy policy governs their use of your data. This Privacy Policy explains only the limited platform-level data OmniStore itself processes.


3. What personal data we collect, and why

We collect and process the following categories of personal data:

3.1 Account data (merchants and their team members)

  • What: email address, first name, last name, password (stored hashed using BCrypt with a cost factor of 12, never in plaintext), role within the store, store affiliation.
  • Why: to create and operate your OmniStore account, authenticate you, send you transactional emails (verification, password reset, billing, abuse notifications), enforce role-based permissions.
  • Legal basis (GDPR Art. 6): contract (Art. 6(1)(b)) - we cannot provide the service without this data.
  • Retention: for the lifetime of your account, plus 90 days after deletion for safety net against accidental deletion. Audit-log entries related to your account are retained indefinitely as a system-of-record for security and legal purposes.

3.2 Store data

  • What: store name, slug (the leftmost part of your storefront URL), address, timezone, currency, country, locale, settings JSON (branding colors, hours, tagline, hero image URL, contact details). Logo and product images stored in Cloudflare R2 object storage.
  • Why: to display your storefront to customers; to localise the admin interface; to power features like multi-currency display, store-hours-based “open now” indicators, and the per-tenant subdomain routing.
  • Legal basis: contract (GDPR Art. 6(1)(b)).
  • Retention: for the lifetime of your account; deletion follows account deletion within 90 days.

3.3 Subscription and billing data

  • What: subscription tier (MICRO/SOLO/TEAM/PRO/ENTERPRISE), status (TRIAL/ACTIVE/PAST_DUE/SUSPENDED/CANCELLED), billing country, pricing band, currency, billing-period dates, invoice history, payment-method metadata. Actual payment-card numbers and full bank details are NEVER handled by OmniStore; they are tokenised by our payment processors (Stripe, Campay, Monetbil) and we only store the resulting opaque tokens.
  • Why: to charge you the right amount on the right date, send invoices, manage trial expiry, run dunning (automated retry on failed mobile-money charges), comply with tax-reporting obligations.
  • Legal basis: contract (GDPR Art. 6(1)(b)) and legal obligation (GDPR Art. 6(1)(c)) for tax-related retention.
  • Retention: invoices retained for ten years after issuance to satisfy Cameroonian and EU tax-record obligations. Payment-method tokens retained for the lifetime of the subscription plus 90 days.

3.4 Operational data (“how you use the product”)

  • What: product entries you create, sales transactions you record, inventory adjustments, staff invitations sent, audit-log rows recording mutations you make to your store. IP addresses, user-agent strings, and approximate location (derived from IP, country-level only) for requests to the admin app.
  • Why: the product is this data - without it the platform has nothing to show you. The audit log is required for security forensics, dispute resolution, and (in some cases) tax-reporting compliance.
  • Legal basis: contract (Art. 6(1)(b)) for the product data; legitimate interest (Art. 6(1)(f)) for the audit log and IP-based abuse prevention. Our legitimate interest is the secure operation of a multi-tenant platform where one merchant’s actions cannot be allowed to compromise another’s data.
  • Retention: product and sales data for the lifetime of your account. Audit-log entries retained indefinitely. IP addresses in access logs are retained for 90 days.

3.5 Customer data (your storefront’s visitors and purchasers)

When a customer interacts with your OmniStore storefront - browses products, places an order, contacts you - any personal data they provide is YOUR responsibility as the data controller. OmniStore stores this data on your behalf as your processor, under the terms of the Data Processing Agreement. We do not use your customer data for our own purposes.

  • What we hold on your behalf: customer name, email, phone, address (if you add the customer to your customer list), order line items (product, quantity, price, timestamp), payment-method metadata tokens.
  • What we never hold: full payment-card numbers, full bank-account numbers, government-ID numbers (we never ask for these).
  • Retention: for the lifetime of your account. You can export and delete individual customer records through the admin’s Customers page at any time.

3.6 Communications

  • What: the contents of emails you send to legal@useomnistore.com, support@useomnistore.com, harold@useomnistore.com, or any other OmniStore inbox; any support tickets you open; any feedback you submit through in-app forms.
  • Why: to respond to you, improve the product, retain a record of issues raised.
  • Legal basis: contract (Art. 6(1)(b)) for support inquiries that relate to your account; legitimate interest (Art. 6(1)(f)) for general feedback. Our legitimate interest is improving the product.
  • Retention: support correspondence retained for the lifetime of your account plus 90 days. Aggregate, anonymised feedback may be retained indefinitely.

3.7 Cookies and analogous technologies

See the separate Cookie Policy at useomnistore.com/legal/cookies. In summary: as of the date of this Privacy Policy, OmniStore uses exactly one cookie - a strictly-necessary HttpOnly authentication-refresh cookie named os_refresh - and does not deploy any analytics, advertising, or tracking pixels on the platform. If we add such tracking in the future, this Privacy Policy and the Cookie Policy will be updated and (where required) a consent banner will appear.


4. Who we share your personal data with

We share your personal data only with the parties below, only for the purposes stated, and only to the minimum extent required. None of these parties may use your data for their own purposes.

4.1 Subprocessors

A subprocessor is a third party that helps us run the platform and that has access to personal data we control or process. The current list of subprocessors, their purposes, locations, and the data categories they handle is maintained at useomnistore.com/legal/subprocessors. We give merchants 30 days’ notice before adding a new subprocessor.

4.2 Legal disclosures

We may disclose your personal data to government authorities, courts, or law-enforcement agencies when we are legally required to do so (e.g. by a court order from a court with jurisdiction over us). We will challenge improper requests and where legally permitted will notify you of the request before complying.

4.3 Business transfers

If OmniStore is acquired by, merges with, or transfers its assets to another entity, your personal data may be transferred as part of that transaction. We will notify affected merchants by email at least 30 days before such a transfer, and the receiving entity will be bound by terms no less protective than this Privacy Policy.

4.4 What we DO NOT do

We do not sell your personal data. We do not share it with advertising networks. We do not use it to build profiles for marketing other products. We do not provide it to data brokers.

For CCPA/CPRA purposes: OmniStore has not sold or shared personal information of California residents in the preceding 12 months. We do not have a “Do Not Sell or Share My Personal Information” mechanism because there is no selling or sharing to opt out of.


5. International transfers

OmniStore operates from Cameroon. Some of our subprocessors are located in the United States (Stripe, AWS for SES email), Canada / global (Cloudflare for R2 object storage and CDN). When we transfer personal data outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914), incorporated by reference into our agreements with the recipient subprocessor. For Cameroonian-data transfers outside Cameroon, we comply with Loi N° 2010/012’s transfer requirements; in practice this means the same SCC mechanism plus disclosure to the affected merchant.

A copy of the SCCs used for any specific transfer is available on request to legal@useomnistore.com.


6. Your rights

You have the following rights regarding your personal data. We will honour these requests within 30 days of receipt at legal@useomnistore.com, free of charge unless the request is manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse, as permitted under GDPR Art. 12(5)).

6.1 Rights under GDPR (if you are in the EU or EEA)

  • Right of access (Art. 15) - to know what personal data we hold about you and to receive a copy.
  • Right to rectification (Art. 16) - to correct inaccurate data.
  • Right to erasure (Art. 17, “right to be forgotten”) - to have your data deleted in certain circumstances (e.g. when it’s no longer necessary for the purposes for which it was collected). Note that some data (audit logs, billing records, tax records) is retained as required by law and cannot be erased on request.
  • Right to restriction of processing (Art. 18) - to temporarily halt processing while a dispute is resolved.
  • Right to data portability (Art. 20) - to receive your data in a machine-readable format and to have it transmitted to another controller. The OmniStore admin provides an export of your product, customer, and sales data on the Reports page.
  • Right to object (Art. 21) - to object to processing based on our legitimate interests (Art. 6(1)(f)).
  • Right not to be subject to automated decision-making (Art. 22) - we don’t make automated decisions with legal or similarly significant effects on you.
  • Right to lodge a complaint with a supervisory authority - typically the Data Protection Authority of your EU Member State.

6.2 Rights under CCPA/CPRA (if you are a California resident)

  • Right to know what personal information we collect, the purposes, and the categories of third parties we share with - this Privacy Policy provides that information; further detail available on request.
  • Right to delete personal information we hold, subject to the same legal-retention exceptions noted above.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing - not applicable, because we don’t sell or share. We do not provide a “Do Not Sell or Share” link for this reason.
  • Right to limit use of sensitive personal information - we do not use sensitive personal information for purposes beyond providing the service requested.
  • Right to non-discrimination for exercising any of the above rights.

To exercise California rights, email legal@useomnistore.com. We will verify your identity (via the email associated with your OmniStore account or another reasonable verification method) before responding.

6.3 Rights under Cameroonian law

Under Loi N° 2010/012, you have substantially similar rights of access, rectification, opposition, and deletion. Exercise these by emailing legal@useomnistore.com. The supervisory authority for data-protection matters in Cameroon is the Agence Nationale des Technologies de l’Information et de la Communication (ANTIC); you may lodge a complaint with ANTIC if you believe we have not handled your data lawfully.


7. How we protect your data

We apply industry-standard technical and organisational measures, including:

  • Encryption in transit: all connections between you, the platform, and our subprocessors use TLS 1.2+ (HTTPS).
  • Encryption at rest: the Cloudflare R2 object store encrypts uploaded files at rest by default. The PostgreSQL database hosting personal data uses encrypted backups; live disk encryption is provided by the underlying hosting infrastructure.
  • Password hashing: passwords are stored as BCrypt hashes with a cost factor of 12. Plaintext passwords are never written to disk or logs.
  • Authentication tokens: access tokens are held in-memory in the SPA only (never localStorage); refresh tokens are stored in HttpOnly + Secure + SameSite cookies and rotated on use.
  • Audit logging: every security-relevant action (login, password change, role change, account closure, slug rename, etc.) is recorded in an immutable audit log retained indefinitely.
  • Subprocessor access controls: each subprocessor’s credentials are scoped per environment (alpha, prod) and per resource (e.g. R2 tokens scoped to a single bucket).
  • Per-tenant data isolation: the platform’s database schema is multi-tenant by row. Every tenant-scoped query is automatically filtered by store ID via a TenantContext mechanism + per-table composite foreign-key constraints that the database enforces.

No system is perfect. If we become aware of a personal-data breach affecting your data, we will notify you and (if applicable) the relevant supervisory authority within 72 hours of becoming aware, in line with GDPR Art. 33-34 and equivalent obligations elsewhere.


8. Children’s data

OmniStore is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, contact us at legal@useomnistore.com and we will delete it.

This is not a service designed for minors. Storefront customers shopping at a merchant’s store may be of any age permitted by the merchant’s local law; the merchant is responsible for any age-restriction enforcement.


9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The current version, effective date, and “last updated” date appear at the top of this page. Version history is maintained in CHANGELOG.md in the OmniStore legal documents repository.

For material changes (new categories of personal data, new subprocessors, new purposes of processing, new disclosures), we will notify affected account holders by email at least 30 days before the change takes effect. You will see an in-app banner during the 30-day notice window. After the 30 days, continued use of the service constitutes acceptance of the updated Privacy Policy; if you do not agree, you can cancel your subscription and delete your account before the change takes effect, in which case the prior version of the Privacy Policy applies to your historical data.


10. Contact

For any privacy-related question - exercising a right, asking how we handle something, lodging a complaint before going to a supervisory authority, requesting a copy of an SCC - email legal@useomnistore.com.

For data-subject requests, please include enough information for us to verify your identity (the email on your OmniStore account is usually sufficient) and to identify the data you’re asking about.

Omni Store Omni Store

The operating system for independent shops.

EN FR

Product

  • Counter
  • Stockroom
  • Storefront
  • Pricing

Company

  • About
  • Customers
  • Contact
  • Help Center

Legal

  • Privacy
  • Terms
  • Cookies
  • Refunds
  • Imprint

© 2026 Omni Store. Built for independent shops.

Omni Store uses cookies to understand how the site is used and improve it. Analytics is optional - essential cookies are always on. See the privacy policy.