Legal

Privacy policy

Effective August 24, 2026

Who we are and what this policy covers

OmniReach is a multi-channel outreach workspace operated by Boolean and Bean from Victoria, Australia (“we”, “us”). This policy explains how we handle personal information through the OmniReach website, application, support, and related services (the “Service”). Questions and requests may be sent to hello@omnireach.com.

Our terms of use govern use of the Service. This policy is a notice about privacy practices; agreeing to the terms does not waive any privacy right.

Our role and your organisation’s role

We decide how account, billing, security, support, and product-usage information is used to operate OmniReach. For that information, we generally act as the business or controller.

A customer decides which prospects to upload or discover, which accounts to connect, and which outreach to send. For prospect records and communications processed on those instructions, the customer is generally the business or controller and OmniReach acts as its service provider or processor. The customer is responsible for required notices, consent or other lawful bases, and responding to prospects, subject to obligations the law places directly on us.

Information we collect

Depending on the features used, we collect or process:

  • Account and profile information. Email address, display name, avatar, account identifiers, sign-in and membership timestamps, workspace roles, and authentication metadata.
  • Team information. Workspace names, member roles, invitations, invitee email addresses, invitation status, and inviter details.
  • Prospect and campaign information. Names, professional roles, employers, LinkedIn URLs and identifiers, email addresses, imported fields, lists, campaign membership, notes, templates, approvals, scheduled actions, do-not-contact entries, and campaign history.
  • Connected LinkedIn information. Unipile account identifiers, account display details and status, profile and search results requested through the connected account, invitations, messages, InMail, replies, and delivery or error events. LinkedIn credentials entered in a hosted connection flow are handled by Unipile; OmniReach does not store your LinkedIn password.
  • Connected mailbox information. Email address, mailbox provider, Unipile account identifier, connection status, send limits and windows, message recipients, subjects, message content, replies, threading identifiers, and delivery or error events. Mailbox credentials are handled by the hosted connection provider and are not stored in the OmniReach database.
  • Seller and AI information. Website URL, offer, ideal-customer description, proof points, tone, prompts, excluded phrases, seller profile information, extracted website context, AI inputs and outputs, and draft status or errors.
  • Opportunity information. Targeting preferences, discovery runs and usage, public professional and company information, provider identifiers, signal evidence, scores, recommendations, source links, and feedback. We do not intentionally persist email addresses or phone numbers returned solely by Opportunities discovery.
  • Billing information. Stripe customer, subscription and price identifiers, plan quantity, billing status, invoice or payment status, and limited payment history. Stripe handles card and bank details; we do not store full payment-card numbers.
  • Usage, device, and security information. IP address, browser and device information, timestamps, pages or actions, active workspace, rate-limit events, diagnostic logs, webhook and job status, errors, and security events.
  • Communications. Support requests, privacy requests, feedback, billing communications, and transactional email delivery status.

Where information comes from

  • You and other members of your workspace.
  • Your browser, device, and use of the Service.
  • LinkedIn and connected mailboxes through Unipile when you request or enable a feature.
  • Stripe, Supabase, and other providers used to operate the Service.
  • Public websites processed through Firecrawl when you request seller-context extraction.
  • Autobound and public professional sources when you run Opportunities discovery.
  • People who communicate with us or respond to outreach sent through the Service.

We do not buy or rent bulk prospect lists. Customers may upload lists obtained elsewhere and are responsible for their source and lawful use.

How and why we use information

We use information to:

  • Create accounts, authenticate users, and administer workspaces and permissions.
  • Connect accounts and mailboxes and perform actions users configure and approve.
  • Store prospects, campaigns, messages, replies, DNC entries, and activity history.
  • Generate AI-assisted templates and prospect-specific drafts.
  • Extract seller context and provide signal-based opportunity recommendations.
  • Apply caps, approval gates, billing controls, suppression rules, and reply-based stops.
  • Process subscriptions, payments, invoices, and account changes.
  • Provide support and send authentication, team, security, billing, and service notices.
  • Monitor reliability, investigate errors or abuse, secure the Service, and enforce terms.
  • Comply with law and establish, exercise, or defend legal claims.
  • Analyse aggregated or de-identified information to understand and improve the Service.

Where laws such as the GDPR require a legal basis, we rely as appropriate on performance of our contract, legitimate interests in providing and securing a business service, compliance with legal obligations, and consent where consent is required. A customer is responsible for identifying its legal basis for prospecting and outreach it directs.

AI and automated assistance

When AI drafting is enabled, relevant seller context, campaign prompts, and prospect details such as name, role, employer, and professional profile context are sent to the AI provider configured for OmniReach. Generated drafts are returned to and stored in the workspace. A user must review and approve outreach; OmniReach does not use AI to make a legally binding decision about a prospect.

We do not use Customer Content or prospect data to train a general-purpose model offered by OmniReach to other customers. A configured AI provider handles submitted information under its own business or API terms, including any stated retention and model-improvement practices. We will not knowingly enable provider training on Customer Content without the notice or permission required by law. Contact us to identify the provider currently in use before submitting information that requires particular AI data terms.

How we disclose information

We disclose personal information only as reasonably necessary:

  • Within a workspace. Workspace members can see information made available according to their role. Owners and administrators control membership and may access or remove workspace content.
  • Service providers. Providers process information for hosting, authentication, connected accounts, sending, AI drafting, discovery, website extraction, billing, email delivery, support, and background jobs.
  • Connected platforms and recipients. We transmit messages and related details to connected accounts, LinkedIn, mailbox providers, and the recipients selected by a user.
  • Legal and safety. We may disclose information where reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate fraud or abuse, or enforce agreements.
  • Business transfers. Information may be disclosed under confidentiality safeguards in a financing, merger, acquisition, restructuring, or sale, and transferred if the recipient assumes applicable privacy obligations.
  • At your direction. We disclose information when you request an integration or otherwise direct us to do so.

We do not sell or rent personal information or prospect lists. We do not share personal information for cross-context behavioural advertising and do not use third-party advertising trackers in the product.

Service providers

Our current product is designed to use the following provider categories:

  • Supabase — authentication, account email delivery configuration, and database.
  • Vercel — application hosting, delivery, and platform logs.
  • Unipile — LinkedIn and mailbox connection, search, profile data, invitations, messaging, email, and replies.
  • Stripe — checkout, subscriptions, invoices, payment processing, and billing portal.
  • Inngest — background jobs for sends, drafting, discovery, and synchronisation.
  • Autobound — signal-based opportunity discovery and recommendations.
  • Firecrawl — extraction of public website content for seller context.
  • Brevo — transactional and team-invitation email; it may also deliver Supabase authentication email.
  • An OpenAI-compatible AI provider — AI-assisted templates and prospect drafts. The configured provider may be OpenAI or another provider disclosed in the Service or on request.

A provider is used only when the relevant feature is configured or enabled. Providers may use their own subprocessors. Contact us for the provider currently configured for a particular feature before submitting information that requires a specific processing location or contractual arrangement.

International processing

We operate from Australia and use providers that may process information in Australia, the United States, the United Kingdom, the European Union, and other countries in which they or their subprocessors operate. The likely location depends on our configured region, the connected platform, and the provider used for a feature.

Where required, we take reasonable steps to use contractual and organisational safeguards for overseas processing. Information processed elsewhere may be subject to foreign law and may not receive protections identical to those in your location. Contact us if you need more detail about a particular transfer.

Cookies and local storage

We use necessary cookies and similar browser storage for authentication sessions, active workspace selection, connected-account verification and return state, security, theme preference, and onboarding details such as a website URL you ask us to carry into signup. These are used to provide or secure requested functionality. We do not use advertising cookies, pixels, or third-party ad trackers in the product.

Outreach, opt-outs, and suppression

Customers direct outreach sent through OmniReach and are responsible for consent or other lawful authority, sender identification, and unsubscribe content. If you receive an unwanted message sent through OmniReach, use the unsubscribe method in the message, reply to the sender asking them to stop, or contact us. We may assist the relevant customer in suppressing further outreach and investigate misuse.

We may retain a minimal do-not-contact record after other prospect details are removed when necessary to honour an opt-out, prevent repeated contact, demonstrate compliance, or resolve a complaint. Suppression information is not used to send marketing.

Retention and deletion

We retain account and workspace information while the account or workspace is active and for a limited period afterwards where reasonably needed to complete deletion, provide billing records, resolve disputes, investigate security incidents, prevent abuse, or meet legal obligations. Opportunity recommendations marked available or dismissed are designed to expire after 90 days; saved records, usage ledgers, campaign history, and suppression records may remain longer for their operational purpose.

Provider logs, backups, and disaster-recovery copies are removed on their normal rotation schedules and are not restored for ordinary product use after a verified deletion. Stripe and other providers may retain records they control where required by financial, fraud, security, or legal obligations.

To request account or workspace deletion, email hello@omnireach.com. We will verify authority, explain any information that must be retained, and complete the request within the period required by applicable law. Workspace deletion may require approval from its owner and affects every member of that workspace.

Security and data breaches

We use reasonable administrative, technical, and organisational safeguards designed for the nature of the information, including access controls, workspace permissions, provider secrets, transport encryption, database row-level security, rate limits, and logging. No system is completely secure. You are responsible for protecting your email, sign-in links, devices, workspace roles, and connected accounts.

We assess suspected data breaches and will notify affected people and regulators where required by applicable law. Report a suspected security or privacy incident promptly to hello@omnireach.com.

Your privacy choices and rights

You may edit or remove prospects, pause campaigns, disconnect accounts, change workspace membership if authorised, and request account deletion. Depending on applicable law and our role, you may also request access, correction, deletion, restriction, objection, or a portable copy of personal information. You may withdraw consent where processing is based on consent, without affecting earlier lawful processing.

Send a request to hello@omnireach.com. We may verify your identity and authority, ask you to contact the customer that controls a workspace, or forward a prospect request to that customer. We will not discriminate against you for exercising a right. Some requests may be limited by another person’s rights, security needs, legal privilege, or record-retention obligations.

Australian privacy complaints

We seek to handle personal information consistently with the Australian Privacy Principles where they apply. To complain, email us with your contact details, the conduct you are concerned about, and the outcome you seek. We will acknowledge the complaint, investigate it, and aim to respond within 30 days, or tell you if we reasonably need more time.

If you are not satisfied after giving us a reasonable opportunity to respond, you may be able to complain to the Office of the Australian Information Commissioner at oaic.gov.au.

United States privacy notices

If a U.S. state privacy law applies to OmniReach and to your information, you may have the rights described above and the right to appeal a denied request. We do not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising. We do not knowingly use sensitive personal information to infer characteristics for advertising.

California categories we may process include identifiers, customer and commercial information, internet or electronic activity, professional or employment information, communications, and inferences represented by opportunity scores or AI-assisted drafts. The sources, purposes, recipients, and retention approach are described above. An authorised agent may submit a request where permitted; we may verify the agent’s authority and the identity of the person concerned. If we deny an appealable request, reply to our decision explaining why you disagree.

European and United Kingdom users

Where the GDPR or UK GDPR applies, you may have rights to access, rectification, erasure, restriction, portability, and objection, and to complain to your local data-protection authority. Where we rely on legitimate interests, those interests are operating, securing, supporting, and improving a business outreach service without overriding your rights. You may object to direct marketing at any time.

When a customer controls prospect information, that customer is the primary contact for a prospect request. We will support the customer as required by our role. Information may be transferred outside Europe using an adequacy decision, contractual safeguards, or another lawful transfer mechanism where required.

Children

The Service is for business users aged 18 or older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child’s information has been submitted, contact us so we can investigate and take appropriate action.

Changes to this policy

We may update this policy to reflect product, provider, or legal changes. We will change the date above and, for a material change, provide reasonable notice by email or a prominent notice in the Service where required. If a change requires consent under applicable law, we will seek it rather than relying only on continued use.

Contact

Privacy questions, requests, complaints, and security reports: hello@omnireach.com.