Legal
Last updated: 25 August 2026
This Privacy Policy applies to the Omniwink service and the Omniwink app on the Meta platform, both operated by Omniwink. It explains what personal information we collect — including information we access through the Meta (Facebook and Instagram) platform — how we use, share, store, and delete it, and how you can ask us to delete it.
Want your data deleted?
You can request deletion at any time. See our Data Deletion Instructions or email hello@omniwink.com.au.
1. Who we are
Omniwink is an Australian company based in Melbourne, Victoria, Australia. We build, launch, and manage advertising campaigns inside advertising accounts that our clients own, and provide AI-driven CRM and automation software, for small and local businesses in Australia & New Zealand and other English-speaking markets.
Your contract and your invoices are with Omniwink, and the Omniwink app on the Meta platform is registered to and operated by Omniwink.
Omniwink is the entity responsible for the personal information described in this policy — the “controller” under the EU and UK General Data Protection Regulation (GDPR), and an “APP entity” handling personal information under the Australian Privacy Act 1988 and the Australian Privacy Principles.
Where we handle advertising, Page, or lead data inside a client’s own Meta Business account, we act as a service provider (a “processor” under GDPR) on that client’s instructions.
Contact for privacy matters: hello@omniwink.com.au. This is a monitored address and is the correct route for access, correction, and deletion requests.
2. What information we collect
a. Information you give us directly
- Contact details — your name, email address, phone number, business name, and website URL.
- Enquiry and qualification details — from our website quiz and enquiry forms: your business type, location and service area, what you sell, your current lead volume, your advertising goals, and your budget.
- Onboarding information — details you share when you become a client, such as your offer, target customer, brand assets, and the access you grant us to your own Meta advertising account and business assets.
- Correspondence — messages, emails, call notes, and support requests you send us.
- Billing records — the subscription, invoice, and payment-status records created when you pay our management fee.
b. Information collected automatically
- Device and usage data — IP address, browser type and version, device type, operating system, referring URL, pages viewed, time on page, and interactions with our forms.
- Cookies and similar identifiers — including Meta advertising cookies (_fbp, _fbc) and click identifiers such as fbclid, and your saved cookie preference. See section 6.
c. Information we receive from Meta
If you connect your Meta Business account to our app, or if we are granted access to your assets as a partner, we receive information from Meta. This is described in full in section 3.
d. Information we do not collect
We do not collect or store payment card numbers — card details are entered directly with our payment processor, Stripe. We do not ask for, and ask that you do not send us, sensitive information such as health data, government identifiers, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or biometric data. We do not knowingly collect information from children (section 12).
3. Meta (Facebook and Instagram) Platform Data
Omniwink operates the Omniwink app on the Meta platform. When you, as a business owner, grant our app permission — through Facebook Login, a Meta Business partner request, or an asset-sharing link — we access data from your Meta Business account (“Platform Data”) strictly to deliver the advertising service you have asked us to run.
Permissions we request, and why
We only request the permissions needed for the service, and only for the use cases below. Depending on what you ask us to do, these may include:
Creating, managing, and measuring your ads
- ads_management — to create, edit, pause, and optimise campaigns, ad sets, ads, creatives, and audiences inside the advertising account you own.
- ads_read — to read campaign performance (impressions, clicks, spend, cost per lead, conversions) so we can report results to you and optimise delivery.
- business_management — to identify the advertising accounts, Pages, pixels, and datasets you have shared with us, so we work on the correct assets.
- leads_retrieval — to retrieve the lead-form submissions generated by the campaigns we run for you and deliver them to your inbox or CRM.
Managing your Facebook Page
- pages_show_list and pages_manage_ads — to list the Pages you administer and run ads from the Page you nominate.
- pages_read_engagement and pages_read_user_content — to read your Page, its posts, and the comments and reviews people leave, so we can see what is working and moderate responses.
- pages_manage_posts, pages_manage_engagement, and pages_manage_metadata — to publish and schedule posts on your behalf, reply to or hide comments, and configure the Page settings needed to run your campaigns.
- pages_messaging — to read and reply to Messenger conversations between your business and the people who contact it, so enquiries generated by your ads get answered.
Managing messaging and content on Instagram
- instagram_basic and instagram_manage_insights — to read your Instagram profile, existing posts, and engagement metrics so we can promote well-performing organic content and report on results.
- instagram_content_publish — to publish posts, reels, and stories to your Instagram account on your behalf.
- instagram_manage_comments — to read, reply to, hide, or delete comments on your Instagram posts and ads.
- instagram_manage_messages — to read and reply to Instagram Direct conversations between your business and the people who message it, so enquiries generated by your ads get answered.
Embedding public content
- oembed_read — to embed public Facebook, Instagram, and Threads posts in web pages and landing pages we build for you. This returns only content that is already public, and we do not collect personal information about the people who view an embedded post.
What Platform Data we receive
- your Meta user ID, name, and the email address on your Meta account;
- the IDs and names of the Business accounts, advertising accounts, Pages, Instagram accounts, pixels, and datasets you share with us;
- campaign structure and settings, ad creative and copy, budgets, and targeting configuration;
- performance and billing metrics for those campaigns — impressions, reach, clicks, spend, results, and cost per result;
- Page and Instagram content and engagement insights for the accounts you share — your posts, reels, and stories, and their reach, engagement, and audience breakdowns;
- comments and reviews left on your Page posts, Instagram posts, and ads, including the commenter’s display name, profile picture, and the platform-scoped ID Meta assigns them;
- message content from Messenger and Instagram Direct — the conversations between your business and the people who contact it, including the sender’s display name, profile picture, platform-scoped ID, and the text and attachments of the messages themselves, but only for the accounts you share with us and only where you have asked us to handle enquiries;
- where you run Meta Lead Ads, the contact details and answers submitted by your prospective customers through those lead forms; and
- an access token that lets our app act on the permissions you granted, until you revoke them.
How we use Platform Data
We use Platform Data for one purpose only: to provide, manage, measure, and improve the advertising service you have engaged us for, and to support you in doing so.
Message and comment content specifically. Where you ask us to handle enquiries, we read and reply to Messenger and Instagram Direct conversations, and to comments on your posts and ads, solely to answer that person on your behalf and to pass the enquiry to you. We do not read conversations that are unrelated to the enquiries your ads generate. We do not use message or comment content to build advertising audiences, to target ads, to train artificial intelligence or machine-learning models, or for any purpose other than handling that conversation for you. If we use an automated tool to help draft a reply, that tool processes the conversation only to produce that reply and does not retain it for its own purposes. You remain the controller of your customers’ message content; we handle it on your instructions.
What we never do with Platform Data
We comply with the Meta Platform Terms and Developer Policies. We do not:
- sell, licence, rent, or otherwise monetise Platform Data;
- transfer Platform Data to any data broker, information broker, ad network, ad exchange, data-management platform, or monetisation service;
- use Platform Data to build profiles about individuals, or to enrich, augment, or cross-reference any other dataset;
- use one client’s Platform Data to benefit another client;
- use Platform Data to make, or to help anyone else make, eligibility decisions about a person — including decisions about credit, housing, employment, insurance, education, or government benefits;
- use message, comment, or lead content to train artificial intelligence or machine-learning models, or to build advertising audiences;
- send unsolicited or promotional messages to people who have not contacted the business, or message anyone outside the windows Meta’s messaging policies allow;
- use Platform Data for surveillance purposes, or place it in a search engine or directory; or
- attempt to decrypt, reverse-engineer, or de-anonymise any data Meta provides in a hashed or anonymised form.
Storage, retention, and revocation
Platform Data is stored on our secured infrastructure and access tokens are held as server-side secrets — never exposed in a browser or a public repository. Access is limited to the small number of team members who need it to run your campaigns.
You can revoke our access at any time from Facebook → Settings & Privacy → Settings → Apps and Websites (Business Integrations) by removing Omniwink, or by removing our partner access in Meta Business Settings. When you revoke access, or when our engagement ends, we stop using Platform Data immediately, and we delete it as soon as it is no longer needed for the purpose you gave it to us for — in any case no later than 90 days, except where we are required by law to retain a record. If you ask us to delete it sooner, we will: see Data Deletion Instructions.
4. Why we use your information
We use the information described above to:
- respond to your enquiry and assess whether the service is a good fit;
- deliver the service — build, launch, manage, and optimise your Meta Ads campaigns;
- set up conversion tracking and deliver leads to your inbox or CRM;
- report performance to you and support you with your account;
- measure and improve the performance of our own advertising and website;
- bill your management fee and keep records of our agreement with you;
- keep our website and systems secure and prevent fraud and abuse; and
- meet our legal, tax, and accounting obligations.
We do not sell your personal information, and we do not use it for automated decision-making that produces legal or similarly significant effects on you.
5. Our lawful basis (UK and EU visitors)
Where the GDPR or UK GDPR applies, we rely on the following lawful bases:
- Consent — for non-essential cookies and analytics, and when you submit the quiz or an enquiry form so we can contact you. You can withdraw consent at any time.
- Performance of a contract — once you become a client, to deliver the service you signed up for and to bill for it.
- Legitimate interests — to run, secure, and improve our business, in a way that does not override your rights.
- Legal obligation — to keep financial and tax records.
Australian visitors: we handle personal information in accordance with the Australian Privacy Principles, and collect only what is reasonably necessary for the functions described in this policy.
6. Cookies, tracking, and advertising measurement
Our website uses cookies and similar technologies in three categories:
- Essential — needed for the site to work and to remember your cookie choice. These cannot be switched off.
- Analytics — Microsoft Clarity, which records aggregated usage and interaction data so we can see which parts of the site are confusing.
- Advertising — the Meta Pixel, which sets the _fbp and _fbc cookies and reports page views and form submissions to Meta so we can measure and optimise our own advertising.
Your choice. If you are in the UK, EU, or EFTA, no analytics or advertising cookies load until you accept them. Elsewhere, we show a notice and you can decline at any time from the same banner. You can also clear or block cookies in your browser settings; blocking some cookies may affect how parts of the site work.
Conversions API. In addition to the browser pixel, we send some conversion events to Meta directly from our servers using Meta’s Conversions API, so that measurement still works when a browser blocks tracking. Where these events include identifiers such as your email address or phone number, those values are irreversibly hashed with SHA-256 before they leave our servers. Meta uses them only to match the event to an account and to measure ad performance. We honour the same consent choice for server-side events as for the browser pixel.
7. Who we share information with
We do not sell your personal information and we do not share it for anyone else’s marketing. We share it only with the service providers we rely on to run the service, under contract and only as far as needed:
- Meta Platforms — to build, run, and measure your ad campaigns. Campaigns run on an advertising account you own; Meta processes advertising and audience data under its own terms and Privacy Policy.
- Stripe — payment processing. Your card details go directly to Stripe; we never see or store them.
- Supabase — the database that stores leads, client records, and campaign history.
- Vercel — website and application hosting.
- Titan Email — the mail service that delivers our transactional and journey emails.
- GoHighLevel — our CRM and booking platform, which stores enquiry and appointment records.
- Microsoft Clarity — website analytics.
- Leadsie — used only if you choose it to grant us access to your Meta assets.
- Professional advisers and authorities — our accountants and lawyers, or a regulator or court, where we are legally required to disclose.
If our business is ever sold or merged, personal information may transfer to the buyer, who would remain bound by this policy or give you notice of any change.
8. International transfers
Omniwink operates from Australia, and several of the providers above are based in the United States, the European Union, or elsewhere. This means your information may be stored or processed outside your own country. Where information is transferred internationally we rely on the safeguards our providers put in place — including the European Commission’s standard contractual clauses and the UK international data transfer addendum — and we take reasonable steps to ensure it continues to be protected to the standard described in this policy.
9. How long we keep it
- Enquiries that do not become clients — up to 24 months from your last contact with us, then deleted or anonymised.
- Client account and campaign records — for as long as we work together, then up to 7 years, which is the period we are required to keep financial and tax records under Australian law.
- Meta Platform Data — deleted as soon as it is no longer needed, and no later than 90 days after you revoke access or our engagement ends (section 3).
- Message and comment content from Messenger and Instagram Direct — kept only while we are handling enquiries for you, and deleted no later than 90 days after our engagement ends. The conversation stays in your own Meta inbox, which is under your control.
- Lead-form data belonging to your customers — delivered to you and deleted from our systems no later than 90 days after our engagement ends. You remain responsible for that data in your own systems.
- Website analytics — retained by our analytics providers under their own retention schedules, typically no more than 13 months.
You can ask us to delete your information sooner — see section 11.
10. How we protect your information
We use industry-standard safeguards: encryption in transit (HTTPS/TLS), encryption at rest on our database, access controls so that only team members who need information can reach it, credentials and API tokens held as server-side secrets, and hashing of personal identifiers before any server-side event is sent to Meta. No system can be guaranteed perfectly secure, but if a data breach occurs that is likely to result in serious harm, we will notify you and the relevant regulator as required by law.
11. Your rights, including deletion
Wherever you live, you can ask us to:
- access the personal information we hold about you, and get a copy of it;
- correct information that is wrong or incomplete;
- delete your information, including any data obtained through the Meta platform;
- restrict or object to how we use it;
- receive it in a portable, machine-readable format;
- withdraw consent you previously gave, at any time; and
- opt out of marketing communications — every email we send has an unsubscribe link.
California residents have the additional rights to know what we collect, to delete, to correct, and to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we will not discriminate against you for exercising any right.
To request deletion of your data, follow the steps on our Data Deletion Instructions page, or email hello@omniwink.com.au with the subject line “Data Deletion Request”. We complete deletion requests within 30 days and confirm by email when it is done. If a request is especially complex or you have made several, we may extend this by up to a further 60 days — we will tell you inside the first 30 days if that happens, and explain why. There is no charge.
To exercise any other right, email the same address. We may need to verify your identity before we act. If you are unhappy with our response you can complain to your data-protection authority: the Office of the Australian Information Commissioner (OAIC) in Australia, the Information Commissioner’s Office in the UK, or your local supervisory authority in the EU.
12. Children
Our service is sold to businesses and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us their information, email us and we will delete it.
13. Changes to this policy
We may update this policy as our service or the law changes. The “Last updated” date at the top always reflects the current version, and this page will always be available at https://www.omniwink.com.au/privacy. If we make a material change to how we use your information, we will tell you by email or through a prominent notice on the site.
14. Contact us
Questions about this policy, or want to exercise your rights? Contact us at hello@omniwink.com.au. We respond within the timeframe required by the law that applies to you, and within 30 days at the latest.
Omniwink — Melbourne, Victoria, Australia. Operator of the Omniwink service and the Omniwink Meta app, serving Australia & New Zealand and other English-speaking markets. Company enquiries: hello@omniwink.com.au.
