Omni AI operates the Omni AI OEM app. This policy explains what personal data we collect, why, who we share it with, and what you can do about it. It is written to meet Malaysia's Personal Data Protection Act 2010 (PDPA).
1. What we collect
Information you give us
- Name, email address and mobile number
- Date of birth, if you choose to provide it, used only to send a birthday reward
- Delivery addresses and recipient names
- Anything you write to us in feedback or support messages
Information created by using the app
- Orders: what you bought, when, how much you paid, and where it was sent
- Loyalty activity: points earned and spent, your tier, vouchers claimed, referral code and who referred you
- If you are a member of staff: your staff points balance and its history
- A device token, if you turn on notifications, so we can send them
- The date you last opened the app
Information from our retail systems
- A membership or card number, if your account is linked to one of our in-store systems, so purchases made in person can earn points
2. What we do not collect
- We never see or store your card number. Payments are taken on a page hosted by Stripe; your card details go to them, not to us. We receive only whether the payment succeeded.
- Photographs you take with the product scanner are not stored. The image is sent to our AI provider to identify the product and is discarded once the answer comes back.
- Conversations with the AI assistant are not saved to your account. They exist only for the length of the conversation.
- We do not track your location.
- We do not use advertising trackers, and we do not build advertising profiles.
3. Why we use it
- To take, deliver and support your orders
- To run the loyalty programme: awarding points, applying your tier, issuing and validating vouchers
- To answer product questions through the AI assistant
- To send you notifications you have asked for, and messages about your orders
- To keep records we are required by law to keep, including for tax
- To detect and prevent fraud and abuse of the loyalty programme
Under the PDPA we process your data because it is necessary to perform the contract you enter into when you place an order, to comply with our legal obligations, and — for optional notifications and marketing messages — on the basis of your consent, which you can withdraw at any time.
4. Who we share it with
We do not sell your personal data, and we do not share it for anyone else's marketing. We share the minimum necessary with:
- Stripe, Inc. — to take payment. They receive your payment details and order amount directly.
- Google LLC — the AI assistant and product scanner run on Google's Gemini models. Your question, and any photograph you scan, are sent to Google to produce a reply.
- Google LLC (Firebase Cloud Messaging) — to deliver push notifications, if you have enabled them.
- Delivery partners — the recipient name, address and phone number needed to deliver your order.
We may also disclose data where the law requires it, or to establish or defend a legal claim.
5. Transfers outside Malaysia
Stripe and Google process data on servers outside Malaysia. Where that happens, we rely on the contractual protections those providers offer, and we send only what the service needs to function.
6. How long we keep it
- Your account and profile — until you delete your account.
- Orders — kept after your account is deleted, because they are financial records we are required to retain. They are anonymised first: your name, phone number, email and street address are removed, leaving the transaction and the town it went to.
- Points and voucher history — deleted with your account.
- Device tokens — removed when you sign out or delete your account.
7. Deleting your account
You can delete your account from inside the app: Profile, then Delete Account. It happens immediately and cannot be undone.
Deleting removes your profile, addresses, points balance and points history, saved vouchers, notifications and device tokens. Orders remain as anonymised financial records, as described above. Any unpaid order is cancelled.
8. Your rights
Under the PDPA you may:
- ask what personal data we hold about you and request a copy
- ask us to correct anything inaccurate
- withdraw consent to marketing messages and notifications
- limit how we process your data
- delete your account, as described above
To exercise any of these, email privacy@omniai.app. We will respond within 21 days, as the PDPA requires.
9. Security
Data is encrypted in transit. Passwords are stored hashed and are never readable by us or by our staff. Access to member data is restricted to staff who need it, and every administrative action is recorded in an audit log.
No system is perfectly secure. If a breach affects your data, we will tell you and the relevant authority.
10. Children
The app is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us their data, contact us and we will delete it.
11. Changes
We may update this policy. If a change materially affects how we use your data, we will tell you in the app before it takes effect. The date at the top shows when this version was published.
12. Contact
Questions or complaints: privacy@omniai.app
If you are not satisfied with our response, you may complain to the Personal Data Protection Commissioner, Malaysia.