Privacy Policy
What personal data we handle when you use OmniMessage, why, and the choices and rights you have.
OmniMessage is a GridStudio product.
Last updated: 5 October 2026
1.Who we are and what this policy covers
OmniMessage is a messaging gateway offered under the GridStudio brand and provided by the GridStudio group company named on your invoice (we, us). This policy explains how we handle personal data in connection with the OmniMessage website, console and API.
We act in two different roles, and the difference matters for your rights:
- As a controller, we decide how and why personal data is used when we run our own business: the data of people who visit the website, create an account, are members of an account, pay us or write to us. Sections 2 to 9 describe this.
- As a processor, we handle the messages our customers send and receive, and the identifiers of the people they message, only on the customer’s instructions. The customer is the controller of that data. Section 4 describes this.
2.Data we collect as a controller
- Account data: your name, email address, password if you set one (stored only as a hash), the name of your workspace and company, your country and time zone, your role in the account, your interface language and, if you tell us, what you plan to use the service for.
- Sign-in data from Google, Apple or Facebook, only if you choose to sign in with one of them: the identifier that provider assigns to you for our service, your name, your email address and whether the provider has verified it. Apple may give us a private relay address in place of your own. We do not receive your password with that provider, your contacts or anything you post, and we do not keep the provider’s access tokens.
- Billing data: your billing email address, your payment history, invoice numbers and receipts, and the identifiers our payment processor gives us for your customer record and payments. Card details are entered on the payment processor’s pages; we do not receive or store full card numbers.
- Usage and security data: the IP address and browser type of your sessions, sign-in times, the time an API key was last used, records of failed sign-in attempts, and an audit log of the actions that members take in the account.
- Technical data: the cookies and similar storage described in the Cookie Policy, and the information a browser sends with every request.
- Correspondence: what you send us when you ask for support or sales information.
We receive this data from you, from the other members of your account, for example when one of them invites you, from a sign-in provider you choose to use, and from our payment processor.
3.How we use it and on what basis
- To provide the service: creating and securing your account, authenticating requests, processing payments, showing balances and usage, sending service emails such as verification links, low-balance alerts and receipts, and giving support. The basis is our contract with you or with the organisation you belong to.
- To keep the service secure and working: preventing fraud and abuse, enforcing rate limits, investigating incidents, keeping audit records and improving reliability. The basis is our legitimate interest in running a secure service.
- To meet legal obligations: keeping accounting and tax records and answering lawful requests from authorities.
We do not sell personal data, we do not use it for advertising, and we do not take decisions about you by automated means that have legal or similarly significant effects.
The website and the console use no analytics or advertising trackers.
4.Data we process for our customers
When a customer sends or receives messages through OmniMessage, we process on the customer’s behalf: the content of the messages, including any media they refer to; the identifiers of senders and recipients, such as phone numbers, chat IDs and platform user IDs; delivery and read statuses; the references and metadata the customer attaches; and the webhook events that carry this information to the customer.
We use this data only to deliver and receive the messages, to report their status, to bill the customer, to keep the service secure and to comply with the law. The terms are set out in the Data Processing Addendum.
The credentials, access tokens and authorisation codes a customer uses to connect a channel are forwarded to our delivery platform and are not stored or logged by the gateway.
If you received a message from a business that uses OmniMessage and want to know how your data is used, to stop receiving messages or to exercise your rights, please contact that business. If you contact us, we pass your request on to the customer concerned where we can identify it.
5.Who we share data with
We share personal data only with the following categories of recipients, and only as far as each needs it:
- Payment processing: Stripe, which processes card payments and issues receipts.
- Hosting and infrastructure: the providers that host our servers, databases and backups.
- Email delivery: the provider that sends our service emails.
- Sign-in providers: Google, Apple or Meta (Facebook), only if you choose to sign in with one of them. The provider learns that you signed in to OmniMessage and when, and acts under its own terms and privacy policy.
- Messaging networks: the channel providers a customer connects, such as Meta for WhatsApp, Messenger and Instagram, Telegram, TikTok, Twilio and other SMS providers and carriers. They receive the messages the customer sends and act under their own terms and privacy policies.
- GridStudio group companies that operate the delivery platform and support the service.
- Advisers and authorities: professional advisers, and courts, regulators or law-enforcement bodies where the law requires it or where it is needed to establish or defend legal claims.
If the business is reorganised or transferred, personal data may pass to the successor, which remains bound by this policy.
6.International transfers
Messaging is international by nature, and some of the recipients listed above are located outside the country where you live. Where the law restricts transfers of personal data to another country, we rely on a mechanism it recognises, such as an adequacy decision or standard contractual clauses approved by the competent authority, together with additional safeguards where they are needed. You can ask us for details at support@omnimessage.co.
7.How long we keep data
We keep personal data for as long as it is needed for the purposes described above, and then delete or anonymise it:
- Account data is kept for as long as the account is open, and afterwards for as long as needed to close the account properly and to handle claims.
- The link between your account and a Google, Apple or Facebook sign-in is kept until you unlink it in the settings, until you ask the provider to end it (Apple and Facebook then tell us to remove it), or until the account is closed.
- Billing and accounting records are kept for the period that tax and accounting laws require.
- Message records and delivery history that we process for customers are kept for as long as the customer’s account is open, so that the message log and usage reports work, unless the customer asks for earlier deletion.
- Security and audit records are kept for as long as needed to investigate incidents and to show how the account was used.
- A sign-in session ends when you sign out and expires after 30 days without use. Idempotency keys sent with API requests are kept for 24 hours.
8.How we protect data
The measures we apply include:
- encryption of data in transit with TLS;
- passwords stored only as salted hashes using Argon2id, session tokens and API keys stored only as hashes, and sign-in with Google, Apple or Facebook completed on our servers with the provider’s signed confirmation;
- encryption at rest, with AES-256-GCM, of secrets such as webhook signing secrets and the keys that link an account to the delivery platform;
- channel credentials and tokens passed through to the delivery platform without being stored or logged by the gateway;
- role-based access within an account, API keys limited by scope and by IP address, rate limits and temporary lockout after repeated failed sign-ins;
- an audit log of administrative actions and of billing-relevant actions;
- signed webhooks, and checks that stop webhook addresses from pointing at private networks.
No system is perfectly secure. If a personal-data breach affects you, we notify you and the competent authorities as the law requires.
9.Your rights
Depending on where you live, data protection law gives you rights over the personal data we hold as a controller. Under the EU and UK General Data Protection Regulation, the Turkish Law on the Protection of Personal Data (KVKK), the UAE Personal Data Protection Law and similar laws, these generally include the right to:
- know whether we process your personal data and obtain a copy of it;
- have inaccurate or incomplete data corrected;
- have data deleted where there is no longer a reason for us to keep it;
- restrict or object to processing, in particular processing based on our legitimate interests;
- receive the data you gave us in a portable format, or have it sent to another provider;
- lodge a complaint with the data protection authority of the country where you live or work.
To exercise a right, write to support@omnimessage.co. We may need to confirm your identity before we act. Members of an account can correct most account data themselves in the console.
Where we process your data on behalf of a customer, please address your request to that customer, as explained in section 4.
10.Children
The service is intended for businesses. It is not directed at children, and we do not knowingly collect personal data from anyone under 18 as a controller.
11.Changes to this policy
We update this policy when our practices change. The date at the top shows the latest version, and we tell account owners by email when a change is significant.
12.Contact
The controller is the GridStudio group company named on your invoice. For privacy questions and requests, write to support@omnimessage.co.
Our postal address is stated on your invoices and is available on request.
Questions about this document: support@omnimessage.co