Scope and roles
OmniReach is a multi-tenant communications platform available at canwe.tech. This policy applies to our website, dashboard, APIs and connected services. For customer content processed on behalf of a business workspace, that business is the data controller or data fiduciary and OmniReach acts as its processor or data processor. Each workspace is responsible for having a lawful basis and required consent to contact its customers.
Data we collect
We collect account details such as name, business email, authentication records and workspace membership; business configuration such as organization, channel and billing settings; customer records and conversation content submitted by a workspace; integration identifiers such as WhatsApp Business Account, phone-number and Google Business Profile identifiers; webhook events, message delivery status and template metadata; and security or usage information such as timestamps, request identifiers, IP address and user agent where available.
Payment card or UPI credentials are handled by the selected payment provider. OmniReach receives transaction references and payment status, not the customer’s complete payment credentials.
How we use data
We use data to authenticate users, provide tenant-isolated workspaces, send and receive authorized communications, synchronize connected accounts, generate review links and QR codes, provide analytics, process payments, prevent abuse, maintain security, troubleshoot incidents and comply with legal obligations.
AI-assisted features may process the text a user deliberately submits to generate drafts, summaries or review responses. AI output is a suggestion and should be reviewed before publishing. We do not sell personal data or use customer message content for third-party advertising.
Meta, Google and other integrations
When a workspace connects Meta or WhatsApp, we process the authorization token, app-scoped user mapping, WhatsApp Business Account ID, phone-number ID and related status data needed to operate the Cloud API. Meta independently processes data under its own terms and privacy policy.
When a workspace connects Google Business Profile or Maps, we process OAuth authorization and the selected location identifiers needed to retrieve permitted business information and manage authorized review workflows. Google independently processes data under its own terms and privacy policy. Access tokens are encrypted at rest and are not displayed after connection.
Retention and security
We retain data while an account or workspace is active and for the period reasonably needed to provide the service, resolve disputes, prevent fraud, meet financial or legal obligations and maintain backups. Retention can vary by data type and workspace configuration. Connected-channel tokens are removed when the connection is deleted, subject to short-lived encrypted backups and legal holds.
We use HTTPS, access controls, tenant isolation, encrypted integration credentials, restricted production access, logging and backups. No internet service is risk-free; users should protect their credentials, enable available account security controls and report suspected compromise promptly.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, withdrawal of consent or information about processing. Workspace members should first contact their workspace owner for customer content controlled by that business. You may disconnect an integration from Settings → Channels and may also remove access through the connected provider.
For Meta-related deletion, use our data deletion instructions. We may verify identity and authority before completing a request.
International processing and children
Service providers may process data in countries other than the user’s location, subject to appropriate contractual and legal safeguards. OmniReach is a business service and is not directed to children. Workspaces must not knowingly submit children’s personal data without the authority and safeguards required by law.
Policy updates
We may update this policy to reflect product, legal or operational changes. The effective date above will change when updates become effective. Material changes may also be communicated through the service or by email.
Contact and grievances
For privacy questions, rights requests or grievances, contact the OmniReach privacy team at [email protected]. Include the relevant workspace name and use the workspace-owner email where possible. We will acknowledge and handle requests according to applicable law.