Privacy Policy
Effective date: August 30, 2026
This Privacy Policy explains how Onmo for Services LLC (the "Company", "Onmo", "we", "us") collects, uses, shares, and protects personal data when you visit our websites, request a demo or pilot, use our products, or otherwise interact with us.
This policy is designed to support alignment with GDPR, CCPA/CPRA, and regional privacy laws including Saudi Arabia PDPL and Qatar Law No. 13 of 2016.
1. Who we are
Controller (for website and business contact processing):
- 1.1 Onmo for Services LLC
- 1.2 Address: Rafal Tower, Lusail, Qatar
- 1.3 Email: privacy@onmo.ai
- 1.4 Data Protection Officer (if applicable): dpo@onmo.ai
1.5 Roles under customer agreements
If you are using Onmo products under a customer agreement, the customer may be the controller for certain data you upload or submit, and Onmo may act as a processor on the customer's behalf (see Sections 4, 6, 10, and 12). In some cases, Onmo may act as an independent controller for certain security, compliance, product improvement, and aggregated analytics purposes, as described in this policy.
2. Scope
This policy applies to:
- 2.1 Website visitors (onmo.ai and related pages)
- 2.2 Sales and marketing interactions (demo requests, pilot requests, events, newsletters)
- 2.3 Product users (Onmo Platform, Onmo Signal, Onmo Go)
- 2.4 Partners and vendors with whom we interact
- 2.5 Connected advertising and measurement platform data (see Section 7)
3. Personal data we collect
3.1 Data you provide to us
- A) Contact and business details: name, work email, company, role, phone, country
- B) Commercial details: spend ranges, objectives, channels used, requested integrations
- C) Communications: emails, meeting notes, support tickets, feedback
- D) Account data: username, hashed passwords, user profile, permissions, authentication events
3.2 Data collected automatically (website and product)
- A) Device and log data: IP address, browser type, device identifiers (where applicable), timestamps, pages viewed, referral URLs
- B) Cookie and tracking data: cookie IDs, analytics events, marketing attribution (see Section 9)
- C) Usage data (product): feature usage, workflow events, performance and diagnostic logs, audit logs
3.3 Data we receive from others
- A) From customers: information your organization inputs or connects, such as campaign metadata, reporting outputs, and connected platform information
- B) From partners and vendors: integration metadata, technical logs, support context
- C) For Onmo Signal (audience data): pseudonymous identifiers and behavioral signals from third-party sources and partners, depending on scope and availability (see Section 8)
3.4 Sensitive personal data
We do not intentionally collect sensitive personal data (such as health, biometrics, or precise location) through our website. If you provide it to us, we may delete it or restrict processing.
3.5 Payment and subscription data
When you purchase a subscription, Onmo may use Tap Payments or another payment service provider disclosed at checkout to process payment-card details and the transaction. Onmo receives limited order, invoice, subscription, customer, and payment-status information needed to provide access, support billing, prevent fraud, and maintain records. Onmo does not receive or store full payment-card numbers or security codes through the marketing website.
4. How we use personal data
We use personal data to:
- 4.1 Provide and operate our products (account creation, access control, feature delivery)
- 4.2 Configure and support integrations (ad platforms, MMPs, and programmatic partners)
- 4.3 Run pilots and evaluate results (audience pilots, platform demos, success criteria)
- 4.4 Improve security and reliability (monitoring, debugging, fraud prevention)
- 4.5 Communicate with you (service notices, support responses, onboarding)
- 4.6 Sales and marketing (respond to inquiries, send updates where permitted)
- 4.7 Comply with legal obligations (audit, disputes, lawful requests)
- 4.8 Create aggregated and de-identified analytics for benchmarking and product improvement, as described in Section 13
5. Legal bases for processing (GDPR and similar frameworks)
Where GDPR applies, we process personal data under one or more legal bases:
- 5.1 Contract: to provide services you or your organization requests
- 5.2 Legitimate interests: to secure, improve, and market our services in a business context
- 5.3 Consent: where required (for example, certain cookies and marketing preferences)
- 5.4 Legal obligation: where we must comply with laws or lawful requests
6. How we share personal data
We may share personal data with:
- 6.1 Service providers (hosting, analytics, CRM, customer support tools) acting under contract
- 6.2 Integration partners when you connect them (for example, ad platforms, MMPs, and measurement partners)
- 6.3 Professional advisors (lawyers, auditors) when necessary
- 6.4 Authorities if required by law or to protect rights and safety
- 6.5 Corporate transactions (merger, acquisition, financing, restructuring), subject to safeguards
6.6 No sale of personal data
We do not sell personal information for money. If we use certain advertising technologies, some jurisdictions may treat that as "sharing" for cross-context behavioral advertising (see Sections 9 and 12).
6.7 Service provider restrictions for connected platform data
Where our service providers process connected advertising and measurement platform data on our behalf, they are contractually restricted to:
- A) Process such data solely for Onmo and at Onmo's direction to provide services Onmo requests
- B) Not use such data for their own purposes or for any other customer
- C) Apply equivalent restrictions to any sub-processors they use
- D) Delete such data when it is no longer needed for the contracted services or when we cease using the service provider, subject to lawful retention
7. Connected advertising and measurement platform data
7.1 What this section covers
This section describes how we process data obtained from or sent to third-party advertising and measurement platforms when customers connect accounts or authorize integrations through Onmo. This includes platforms such as Meta (Facebook and Instagram), TikTok, Snap, Google Ads, and other supported partners.
7.2 App and client identifiers (for transparency)
- A) Meta App ID (fb:app_id): 767004556456440
- B) TikTok App ID: 7555316967294959617
- C) Snap client ID: 882c5e36-825a-4f0b-b750-5c296349d7f7
7.3 Categories of connected platform data we may process
Depending on what a customer connects and authorizes, connected platform data may include:
- A) Account and asset identifiers (for example: ad account IDs, page IDs, pixel or tag identifiers where applicable)
- B) Campaign structure data (campaigns, ad sets, ads, creatives metadata, targeting parameters as provided via APIs)
- C) Performance and delivery reporting (impressions, clicks, conversions, spend, CPM, CPC, ROAS, attribution outputs, breakdowns)
- D) Operational metadata (sync timestamps, API responses, error logs, rate limit events)
- E) Authentication artifacts (access tokens and refresh tokens) necessary to maintain the integration
7.4 Purposes for processing connected platform data
We process connected platform data to:
- A) Enable customers to view, manage, and analyze campaigns and performance across channels within Onmo
- B) Support reporting, measurement, forecasting, optimization recommendations, and anomaly detection
- C) Support integrations, syncing, troubleshooting, and customer support
- D) Produce aggregated and de-identified analytics for benchmarking and product improvement, where permitted and as described in Section 13
7.5 Purpose limitation and consistency with this policy
We only process connected platform data for the purposes described in this policy and to provide the Services to the applicable customer, consistent with applicable platform terms, policies, and law.
7.6 Customer separation
Connected platform data is logically segregated by customer. We maintain technical and organizational controls designed to prevent one customer from accessing another customer's connected platform data.
7.7 Sharing connected platform data
We may share connected platform data only as necessary to:
- A) Provide the Services to the applicable customer
- B) Work with service providers under the restrictions described in Section 6.7
- C) Comply with lawful requests or protect rights and safety
We do not sell connected platform data.
7.8 Deletion, modification, and account disconnection
- A) Self-service deletion: Users can delete their account and associated data via the Profile Settings page within the Onmo Platform (where available and applicable).
- B) Email requests: Users may also request deletion or modification by emailing privacy@onmo.ai.
- C) Customer and client requests: If Onmo is processing connected platform data on behalf of a customer, the customer's authorized administrator may request deletion for its users or for the customer account data connected to platforms.
- D) Disconnection: When a customer disconnects an integration, we stop new collection of connected platform data for that integration and will delete or de-identify connected platform data within a reasonable period, unless retention is required for legitimate purposes (for example security, audit, dispute resolution) or by law.
7.9 Platform-specific note for Meta platform data
Where applicable, users and customers must have an easily accessible way to request deletion of Meta platform data. Onmo provides this through the Onmo Platform Profile Settings deletion controls and through privacy@onmo.ai, as described in Section 7.8.
7.10 Tokens and credentials
- A) We do not request or collect platform user passwords (including Meta passwords).
- B) Access tokens and similar authentication artifacts are stored and handled securely, with restricted access and security controls designed to prevent unauthorized use.
- C) We do not share tokens, app secrets, or similar credentials except with authorized service providers strictly for operating the Services under contract and restrictions described in Section 6.7.
7.11 Prohibited uses
We do not use connected platform data to:
- A) Make eligibility determinations about people (for example housing, employment, insurance, education, credit, government benefits, or immigration)
- B) Facilitate surveillance for law enforcement or national security purposes
- C) Discriminate or encourage discrimination in a manner that disadvantages people based on protected attributes
- D) Sell, license, or purchase connected platform data
- E) Attempt to decode, circumvent, re-identify, de-anonymize, reverse hash, or reverse engineer connected platform data
8. Onmo Signal and audience data
8.1 Overview
Onmo Signal is designed to help customers activate audience segments and improve targeting quality.
8.2 What Signal data may include (depending on scope)
- A) Pseudonymous device identifiers (such as mobile advertising IDs), hashed identifiers, or segment IDs
- B) App category or interest signals
- C) Propensity tiers (High, Medium, Low) derived from behavioral signals
8.3 How Signal data is used
- A) Build and refresh audience segments and propensity tiers
- B) Deliver audience outputs for activation through approved destinations
- C) Measure audience performance at an aggregated level
8.4 What we do not do
- A) We do not require or intend to identify individuals by name from Signal datasets
- B) We do not intentionally combine Signal identifiers with direct identifiers such as names or personal emails
8.5 Roles
Depending on the engagement structure, Onmo may act as a controller for certain Signal datasets and as a processor for certain customer-provided data. This will be reflected in the applicable agreement and, where relevant, a data processing addendum (DPA).
9. Cookies, analytics, and similar technologies
9.1 We may use cookies and similar technologies to:
- A) Operate the site and provide core functionality
- B) Understand usage and improve performance (analytics)
- C) Measure marketing effectiveness (attribution)
- D) Support advertising where enabled
9.2 Regional tracking controls
- A) In regions that require opt-in consent, optional analytics remains off until you choose to accept it
- B) In other regions, analytics may load automatically where permitted
- C) You can also block or delete cookies using your browser settings
9.3 Consent: Where required, we request consent before loading non-essential analytics. You can change that choice using the control on this page.
10. International data transfers
Your data may be processed in countries other than your own. Where required (for example under GDPR), we use appropriate safeguards for cross-border transfers such as contractual protections and vendor due diligence.
11. Data retention
11.1 General principle
We retain personal data only as long as necessary for:
- A) The purposes described in this policy
- B) Contractual requirements
- C) Legal and regulatory obligations
- D) Security, audit, and dispute resolution needs
11.2 Demo requests
We retain website demo-request details for up to 12 months from submission so our sales team can respond, manage follow-up, and measure legitimate marketing performance. We delete them sooner when required by law or after a valid deletion request, unless a lawful exception applies.
11.3 Retention for connected platform data
Unless a longer period is required by law, we will delete or de-identify connected platform data as soon as reasonably possible when:
- A) A user requests deletion of their connected platform data (subject to verification and applicable exceptions)
- B) A customer requests deletion for its account data or users, or a user no longer has an account with us (as applicable)
- C) A customer disconnects the integration and the data is no longer necessary for the purposes described in this policy
- D) We stop operating the product or service through which the data was acquired
- E) We determine the data is no longer necessary for a legitimate business purpose consistent with this policy
- F) A platform requests deletion for protection of users (where applicable)
If we are required to keep certain data under applicable law or regulation, we will retain proof of the requirement and keep the data only for the period required.
11.4 More detail
Retention periods vary by data type. We can provide additional detail on request.
12. Your rights and choices
12.1 GDPR and similar rights (where applicable)
You may have the right to:
- A) Access and receive a copy of your personal data
- B) Correct inaccurate data
- C) Delete data (in certain cases)
- D) Restrict or object to processing (in certain cases)
- E) Data portability (in certain cases)
- F) Withdraw consent where processing is based on consent
To exercise rights, contact: privacy@onmo.ai
12.2 In-product controls
Where available, you can delete your Onmo account and associated data through the Onmo Platform Profile Settings page.
12.3 California (CCPA/CPRA) notice and rights (where applicable)
California residents may have rights to:
- A) Know what personal information is collected, used, and disclosed
- B) Request deletion (subject to exceptions)
- C) Correct inaccurate information
- D) Opt out of "sale" or "sharing" (as defined by law)
- E) Limit use of sensitive personal information (if applicable)
- F) Non-discrimination for exercising rights
Notice at Collection: At or before collection, businesses must disclose categories collected and purposes. This policy is intended to support that notice, and we may also provide a separate notice at collection where required.
12.4 Saudi Arabia PDPL (where applicable)
Saudi PDPL generally emphasizes consent as a primary basis, with defined exceptions, and provides rights to individuals that are further detailed in regulations. Contact privacy@onmo.ai for PDPL-related requests.
12.5 Qatar Personal Data Protection Law (Law No. 13 of 2016) (where applicable)
Qatar's law provides a framework for personal data protection and individual rights and applies under defined conditions. Contact privacy@onmo.ai for requests.
13. Aggregated and de-identified data
We may create and use aggregated and de-identified data derived from use of the Services for product improvement, benchmarking, and analytics, provided it does not identify a customer or individuals and is not used to attempt re-identification.
14. Security
14.1 Measures
We use administrative, technical, and organizational measures designed to protect personal data, such as:
- A) Access controls and role-based permissions
- B) Encryption in transit and at rest where appropriate
- C) Logging and monitoring for security events
- D) Vendor security assessments and contractual protections
14.2 Vulnerability reporting
To report security vulnerabilities, contact: security@onmo.ai
14.3 Incident response
No system is 100% secure. We cannot guarantee absolute security. We maintain processes designed to detect, respond to, and remediate security incidents consistent with applicable law and contractual obligations.
15. Children
Our services are intended for business users and are not directed to children. We do not knowingly collect personal data from children.
16. Changes to this policy
We may update this policy from time to time. We will update the "Effective date" and, where appropriate, provide additional notice.
17. Contact
- 17.1 Privacy requests and questions: privacy@onmo.ai
- 17.2 If you are a customer end user, you may also contact your organization's administrator if they control the relevant data.