Legal
Privacy Policy
Effective August 14, 2026 · Last updated August 30, 2026
1. Scope and our privacy roles
This Privacy Policy explains how OrbitOmni LLC, a Georgia limited liability company operating the FounderOmni product ("FounderOmni," "we," "us," or "our"), collects, uses, discloses, and protects personal information through founderomni.com, our applications, and our nine product workspaces: Omni SEO & GEO, Omni Web Analytics, Omni Social, Omni Email, Omni Forms, Omni Schedule, Omni Sign, Omni Links, and Omni Affiliates (collectively, the "Services").
When FounderOmni is the controller
OrbitOmni LLC determines how and why information is processed for account registration, authentication, billing, security, support, waitlists, product usage, and operation of our own website. In those situations, OrbitOmni LLC acts as the controller or business through the FounderOmni service.
When FounderOmni is a processor
Customers determine why and how we process their subscriber lists, campaign recipients, website visitor information, connected social content, and similar customer-controlled data. For that data, FounderOmni acts as a processor or service provider on the customer's behalf. The customer is responsible for its own privacy notices, legal basis, consent choices, and responses to individuals. Individuals whose data was supplied by a FounderOmni customer should ordinarily contact that customer first.
2. Information we collect
Account and contact information
We collect names, email addresses, authentication identifiers, profile images, roles, organization and team information, preferences, waitlist submissions, support messages, feedback attachments, and other information you choose to provide.
Billing and transaction information
When paid plans become available, our payment provider may process billing contact details, payment method information, tax information, invoices, refunds, and transaction history. FounderOmni does not intend to store complete payment card numbers.
Content, credentials, and configuration
We process content and settings you create or import, including posts, media, email templates, subscriber records, domains, campaigns, automations, analytics projects, search prompts, agreement documents, signature fields, recipient routing, audit evidence, booking pages, availability, calendar connections, attendee details, form definitions, responses, uploaded files, reports and report recipients, destinations, Smart Links, QR codes, affiliate programs and marketplace listings, schedules, and delivery results. When you connect a provider, we receive the identifiers, permissions, OAuth tokens, app passwords, or dedicated credentials needed for that connection. Protected credentials are handled server-side and are not returned to the browser after storage.
Connected social account information
Connected-provider information may include account and profile identifiers, usernames, pages, organizations, boards, channels, permissions, and authorization credentials selected by an authorized user.
Usage, device, and security information
We collect interactions with the Services, feature usage, timestamps, browser and device type, operating system, approximate location derived from network information, referring pages, diagnostic events, IP addresses in security and server logs, and information used to prevent fraud, investigate abuse, and maintain availability.
Information from other sources
We may receive information from identity providers, connected platforms, payment providers, infrastructure vendors, public business sources, invited team members, and customers that upload or direct us to process information.
Information made public or shared by link
Information you publish through a public form, booking page, affiliate application page, approved Affiliate Marketplace listing, public report, Smart Link, or QR destination may be available to anyone with the URL and may be indexed or redistributed. Recipient signing links, partner-portal links, and booking-management links are intended for the named or intended recipient but can be used by another person who obtains the link. Do not place confidential or sensitive information on a public page or send a private management link through an insecure channel.
3. Product-specific information
Omni Social
With your authorization, we process connected profile, page, organization, channel, board, account, and permission information; content and media; publishing and scheduling instructions; provider responses; available performance metrics, comments, mentions, or engagement data; and replies or reactions made through FounderOmni where the provider supports them. We take actions on a provider only when an authorized user instructs the Services to do so or enables an automation.
Omni Email
We process customer sender identities, domains and DNS verification status, subscriber contact and consent records, groups, segments, campaign content, delivery events, opens and clicks when enabled, bounces, complaints, unsubscribe and preference records, and suppression lists. Customers are responsible for lawfully collecting subscribers and honoring their choices. We may retain suppression information after other records are deleted when necessary to prevent prohibited re-mailing.
Omni Web Analytics
Customers may install Omni Web Analytics on websites they operate. The tracker does not set HTTP cookies, but its standard configuration uses first-party browser storage for a random pseudonymous visitor identifier that rotates after 90 days and a session identifier that expires after 30 minutes of inactivity. It excludes query parameters from the current page path by default and may record page paths, page titles, referrer host and path, campaign parameters, timestamps, event and conversion data, outbound or download destinations, browser and device information, screen and viewport dimensions, language, timezone, approximate location, and network information. Heatmaps record privacy-reduced click coordinates and viewport dimensions for selected controls; the standard tracker does not record typed form values, passwords, or page screenshots. Raw visitor IP addresses are not persisted in the analytics event store: addresses are partially masked and converted into a salted one-way identifier. Supported Do Not Track and Global Privacy Control signals are honored automatically.
Omni SEO & GEO
We process websites, brands, competitors, keywords, prompts, generated outputs, search results, public domain and registration data, robots and sitemap information, page content and technical audit data, backlink or authority signals, and connected search-provider information needed to produce SEO, GEO, search-performance, and AI-visibility reports. We may crawl pages you submit and retrieve publicly available information about them. Search and generative-AI inputs may be sent to the selected provider to return the requested result.
Omni Sign
We process agreement PDFs, document titles and messages, recipient names and email addresses, routing order, assigned fields, signatures and initials, signer-confirmed names, consent text and records, timestamps, delivery status, document fingerprints, privacy-protected network evidence, audit events, and completion certificates. Customers decide which documents and recipients to use and are responsible for having authority to upload, send, and sign them. Recipient-specific signing links are private and time-limited.
Omni Schedule
We process event types, host availability and time zone, booking rules, calendar connection identifiers and protected authorization tokens, outside busy intervals used for conflict checks, attendee names and email addresses, answers to booking questions, meeting times and locations, confirmation and reminder status, and cancellation details. Public booking pages expose only the information configured for that event. Private management links should not be forwarded.
Omni Forms
We process form structure, conditional logic, theme and publication settings, response answers, optional respondent names and email addresses, uploaded files, referral and source information, completion timing, approximate country, privacy-reduced network identifiers used for abuse controls, notification status, and aggregate form activity. Form owners decide which questions to ask and are responsible for required notices, lawful collection, access controls, and retention.
Omni Affiliates
We process affiliate-program settings, partner applications and contact information, program terms and acceptance records, offers, referral links, click and conversion events, commission calculations, payout records, and related activity history. Referral clicks may include a referring hostname, user-agent information, approximate country, and salted one-way network and visitor identifiers; raw visitor IP addresses are not stored in affiliate click records. If a program owner submits a Marketplace listing, the approved company name, program title, description, logo, website, commission summary, topic, audience, region, attribution window, and application URL become public. Program owners decide whom to approve, what commissions to offer, whether a conversion is valid, and how partners are paid.
Omni Links
When a person opens a Smart Link or scans its QR code, we record the time, link and destination, high-level device and browser information, referring hostname, country or approximate region, and a privacy-reduced network prefix when supplied by our infrastructure. The network prefix masks the final portion of an IPv4 or IPv6 address before storage; Omni Links does not store the visitor's raw IP address in link engagement records. Customers must not use Smart Links for phishing, malware, deceptive redirects, or unlawful tracking.
4. Cookies and browser storage
The FounderOmni workspace uses cookies or browser storage for authentication, security, theme preferences, active organization, saved drafts, and other features you request. Our public founderomni.com pages may also run Omni Web Analytics as privacy-minimized first-party measurement. That public-site tracker uses a random first-party pseudonymous visitor identifier that rotates after 90 days and a session identifier that expires after 30 minutes of inactivity. It does not set analytics cookies, store raw visitor IP addresses in the analytics event store, or load advertising or third-party cross-site trackers, and it honors supported Do Not Track and Global Privacy Control signals.
Browser storage and similar identifiers may be regulated in the same way as cookies in some jurisdictions. Where prior consent is required for nonessential analytics storage or tracking, the site operator must prevent that processing until valid consent is obtained and must provide a way to withdraw it. The absence of an advertising cookie does not by itself remove that requirement.
A customer using Omni Web Analytics remains responsible for determining whether its own website must provide notice, a consent control, or an opt-out based on its configuration, visitors, and applicable law. FounderOmni will provide or document configuration options as they become available, but installing the tracker does not replace the customer's own compliance assessment.
5. How and why we use information
- Provide, personalize, maintain, and troubleshoot the Services.
- Authenticate users, manage organizations and permissions, and secure accounts.
- Connect providers, carry out publishing and delivery instructions, and generate requested reports.
- Process subscriptions, enforce plan limits, and maintain transaction records.
- Respond to support, privacy, security, and legal requests.
- Detect spam, malware, phishing, fraud, prohibited content, credential abuse, and threats to the Services or others.
- Measure reliability and improve features, accessibility, and user experience.
- Send service, security, legal, and account communications, and marketing communications where permitted and subject to opt-out.
- Comply with law, enforce our Terms, and establish or defend legal claims.
Where laws such as the GDPR apply, our legal bases include performing our contract to provide requested account and product functions; complying with billing, tax, legal, and regulatory obligations; our legitimate interests in securing, preventing abuse of, supporting, and improving the Services in ways that do not override individual rights; and consent for optional processing where required. You may withdraw consent without affecting processing that was lawful before withdrawal. We do not use solely automated decision-making to make decisions that produce legal or similarly significant effects about individuals.
7. U.S. state privacy disclosures
In the preceding 12 months, we have collected the categories described above, which may include identifiers and contact information; account, customer-record, and transaction information; internet or electronic-network activity; approximate geolocation; professional or employment information supplied for an organization or partner application; customer content; inferences used for security, product configuration, or reporting; and sensitive information only when a user or customer supplies it to a feature designed and authorized to process it. We collect these categories from individuals, customers, connected providers, service providers, devices and browsers, and public sources for the purposes in Section 5.
We disclose relevant categories to service providers and contractors, connected platforms at the user's direction, organization members, legal and safety recipients, and parties to a business transfer as described in Section 6. We do not sell personal information or share it for cross-context behavioral advertising, and we do not have actual knowledge that we sell or share the personal information of people under 16. We do not use sensitive personal information to infer characteristics or for purposes that require a right to limit under California law.
Where a U.S. state privacy law applies, residents may request access, correction, deletion, or portability; opt out of covered sale, targeted advertising, profiling, or sharing; limit certain uses of sensitive information; and appeal a denied request, subject to legal exceptions. Because we do not currently engage in covered sale or cross-context behavioral advertising, there is no separate “Do Not Sell or Share” link. If those practices change, we will update this Policy and provide the required choice before the change applies.
8. Connected platforms and Google user data
Your use of a connected platform remains subject to that provider's own terms and privacy policy. Permissions are requested for visible features. You can disconnect a connected account in Channel Settings. Disconnecting stops new access through FounderOmni after the provider token is revoked or expires, although records of completed actions may remain under the retention rules below.
FounderOmni's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request Google permissions in context and use Google user data only to provide or improve the user-facing features for which permission was granted, for security, to comply with law, or with the user's affirmative consent as otherwise permitted by that policy.
9. Artificial intelligence features
When you choose an AI-powered feature, relevant prompts, instructions, selected content, and context may be sent to the model provider identified in the product or supporting documentation. Do not submit sensitive personal information, regulated records, confidential information you lack authority to disclose, or credentials. We do not use customer content to train a FounderOmni general-purpose foundation model. Model providers may process data under their business or API terms. AI output may be inaccurate and should be reviewed before use.
10. Data retention and deletion
We retain information only for as long as reasonably necessary for the purposes described in this Policy. Retention depends on the type of data, the customer's plan and settings, legal requirements, security needs, and whether the account or project remains active.
- Account and organization data is generally retained while the account is active.
- Customer content, subscribers, analytics events, reports, agreement documents, signing evidence, and publishing history are retained according to the applicable plan, project settings, or until the customer deletes them.
- Connected-provider credentials are deleted or rendered unusable after disconnection, account deletion, or expiration, subject to short operational and backup periods.
- Security, abuse-prevention, and diagnostic logs may be retained for a limited period appropriate to the risk.
- Suppression, consent, signature evidence, complaint, billing, tax, dispute, and legal records may be retained longer when necessary to comply with law, prevent abuse, or establish legal claims.
After a verified eligible account-deletion request, we aim to delete or anonymize data from active systems within 30 days. Encrypted backups may retain residual copies for up to 90 additional days before ordinary rotation, unless law or security requires longer retention.
11. Account, provider, and Meta data deletion
You may delete individual projects where the product provides that control, disconnect providers in Settings, or request account or data deletion by emailing support@founderomni.com. We may verify your identity and authority over an organization before completing a request.
To remove data received from Meta products, first disconnect Facebook, Instagram, or Threads in Channel Settings. You may also email support@founderomni.com with the subject "Meta data deletion request." After verification, we delete the connected destination, stored authorization credential, associated provider identifiers, provider-derived delivery data, and exclusively owned stored media, except limited records required for security, legal compliance, or completed transactions.
To provide confirmation and safely resume an interrupted request, we retain a pseudonymous deletion-request record and confirmation code for up to 90 days after resolution; it does not contain the raw Meta user ID. If a request still has unresolved account or stored-media cleanup, the limited record may remain until reconciliation completes and is then removed by the next scheduled cleanup.
12. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, server-side credential handling, encryption in transit, security monitoring, and least-privilege practices. Customers are responsible for protecting their accounts, choosing appropriate roles, and securing data they export. No system can guarantee absolute security.
13. International data transfers and subprocessors
FounderOmni operates from the United States and may use providers in the United States and other countries. Where required, we rely on approved contractual safeguards such as the European Commission's Standard Contractual Clauses, the UK Addendum, adequacy decisions, consent, or another lawful transfer mechanism. Information about applicable safeguards and requests for a data processing agreement or current subprocessor information may be requested at support@founderomni.com.
14. Your choices and privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to know or access personal information; correct inaccurate information; delete information; obtain a portable copy; restrict or object to processing; withdraw consent; and appeal a denied request. You may also opt out of nonessential marketing emails using the unsubscribe link.
We do not sell personal information or share it for cross-context behavioral advertising. We honor Global Privacy Control where it applies to processing covered by applicable law. To exercise a right or appeal a decision, email support@founderomni.com. We may verify your identity and authority, and authorized agents may be required to provide written permission. We will not discriminate against you for exercising a privacy right. If the GDPR or UK GDPR applies, you may also lodge a complaint with the supervisory authority where you live, work, or believe an infringement occurred.
15. Children and sensitive information
The Services are intended for businesses and people age 18 or older. They are not directed to children under 13, and customers may not use FounderOmni for a child-directed site, audience, form, campaign, or service or knowingly submit personal information about a child under 13 without FounderOmni's prior written approval and all legally required parental notice and verifiable consent. If we learn that personal information was collected from a child in violation of this Policy, we will take appropriate steps to delete it. Customers must not use FounderOmni to collect sensitive personal information unless they have all necessary authority, notices, consents, safeguards, and a written agreement with FounderOmni where required.
16. Changes to this Policy
We may update this Policy as the Services or law change. We will post the updated version and revise the effective date. If a change materially reduces privacy protections, we will provide additional notice where reasonably practical or legally required.
17. Contact us
OrbitOmni LLC is located in Georgia, United States. For privacy questions, rights requests, appeals, complaints, information about transfer safeguards or subprocessors, or requests for a data processing agreement involving OrbitOmni LLC or the FounderOmni service, email support@founderomni.com. Please do not send passwords, access tokens, government identifiers, or other sensitive information by email.