The short version
- We collect what we need to run the website and the Omnislice platform, and nothing to sell. We do not sell personal data or use it for advertising.
- Analytics on this website only run if you say yes. You can change your mind at any time with .
- When merchants and agencies store their own customers' data in Omnislice, they decide what happens to it. We process it only on their instructions, under the data processing terms in our Terms of Service.
- You can ask for a copy of your data, a correction, or deletion by writing to [email protected]. We answer within one month.
Who we are
[Omnislice legal entity name] ([NIPC]), trading as Omnislice, with offices at Avenida D. João II, Edifício Infante 35, Piso 11A, Parque das Nações, 1990-083 Lisboa, Portugal, is the controller for the personal data described in this policy. We are based in the European Union and the General Data Protection Regulation (GDPR) and Portuguese data protection law apply to everything we do.
For any privacy question or request, write to [email protected]. Put "Privacy" in the subject and it reaches the person responsible for data protection.
Who this policy is about
- Visitors to omnislice.com, including the blog and documentation.
- People who contact us, through the contact form or by email.
- Account holders: the agencies, freelancers and merchants who sign up for Omnislice, and the team members they invite.
When we are not the controller
Omnislice is a platform that agencies and merchants use to run their stores. The products, orders, and customer records they put in it (their shoppers' names, addresses, order histories) belong to them. For that data they are the controller and we are their processor: we handle it only to provide the service, on their instructions, under the data processing terms that form part of our Terms of Service.
If you bought from a shop that runs on Omnislice, that shop's privacy policy is the one that covers you, and requests about your data should go to them first. If you write to us instead, we will pass the request on and help them answer it.
What we collect and why
Every use below has a legal basis under Article 6 of the GDPR. Where the basis is our legitimate interests, we have weighed them against yours, and you can object (see your rights).
Visiting the website
- Technical data your browser sends with every request: IP address, browser and device type, the page asked for, and the time. Our servers use it to deliver pages and to detect abuse. Basis: legitimate interests (running and securing the site). Kept in server logs for up to 30 days.
- Analytics, only with your consent: pages viewed, how you got here, approximate location derived from your IP address (country and city, not the address itself), and, if you accept, a replay of your session with anything you type masked. We use PostHog, hosted in the EU. Basis: consent. Kept for up to 12 months. The details are in the Cookie Policy.
- Sign-in state: if you are signed in to the Omnislice dashboard, the website reads the same session so it can show "Dashboard" instead of "Sign in". Basis: legitimate interests.
Contacting us
When you use the contact form or email us, we receive your name, email address, company (if you give one), the topic, and your message. We use them to reply and to keep a record of the conversation. Basis: legitimate interests (answering you), or steps before a contract if you are asking about becoming a customer. Kept for up to 24 months after the conversation ends, unless it turns into a customer relationship.
Using Omnislice
- Account data: name, email address, organisation, role, and sign-in details. We need these to create and secure your account. Basis: contract.
- Billing data: billing name and address, VAT number, plan, and invoices. Card details go directly to Stripe and never touch our servers. Basis: contract, and legal obligation for invoices. Invoices and accounting records are kept for 10 years, as Portuguese tax law requires.
- Stripe Connect: if you bill your own clients through Omnislice, Stripe collects identity and bank details to verify you and pay you out. Stripe acts as a separate controller for that verification, under its own privacy policy.
- Usage and diagnostic data: which features you use, errors you run into, and security events such as sign-ins. We use it to keep the service working, fix bugs, and protect accounts. Basis: legitimate interests. Kept for up to 12 months.
- Support conversations: whatever you tell us when asking for help. Basis: contract. Kept for the life of your account plus 24 months.
- AI features: when you use an AI feature, the text you submit is sent to a model provider through OpenRouter to produce the result. We route those requests only to providers that do not retain or train on the data. Basis: contract.
What we do not do
We do not sell personal data, share it with advertisers, build advertising profiles, or make decisions about you by automated means that have legal or similarly significant effects.
Who we share it with
We use the service providers below (sub-processors) to run the website and the platform. Each is bound by a data processing agreement and may use the data only to provide their service to us.
For the website
| Provider | What for | Where | Safeguard for transfers |
|---|---|---|---|
| Clerk | Sign-in and account authentication | United States | EU–US Data Privacy Framework and Standard Contractual Clauses |
| PostHog | Product and website analytics, session replay (only with consent on this website) | European Union (Frankfurt) | Not needed (EEA) |
| Resend | Transactional email and contact-form delivery | European Union (Ireland), company in the United States | Standard Contractual Clauses |
For the platform
| Provider | What for | Where | Safeguard for transfers |
|---|---|---|---|
| Clerk | Sign-in and account authentication | United States | EU–US Data Privacy Framework and Standard Contractual Clauses |
| PostHog | Product and website analytics, session replay (only with consent on this website) | European Union (Frankfurt) | Not needed (EEA) |
| Resend | Transactional email and contact-form delivery | European Union (Ireland), company in the United States | Standard Contractual Clauses |
| MailerSend | Transactional email sent on behalf of merchants | European Union | Not needed (EEA) |
| Stripe | Subscription billing, payments and Stripe Connect payouts | European Union (Ireland) and United States | EU–US Data Privacy Framework and Standard Contractual Clauses |
| DigitalOcean | File and image storage (Spaces) | European Union (Frankfurt) | Not needed (EEA) |
| Imgix | Image processing and delivery CDN | United States (global CDN) | Standard Contractual Clauses |
| Sentry | Error monitoring | United States | EU–US Data Privacy Framework and Standard Contractual Clauses |
| OpenRouter | Routing AI feature requests to model providers, with provider data retention disabled | United States | Standard Contractual Clauses |
We will announce new sub-processors for the platform at least 30 days before they start, so customers can object; see the data processing terms.
Connections you switch on
When you connect a sales channel, marketplace or other integration to your Omnislice project, data moves between Omnislice and that service because you asked it to. What the other service does with the data is covered by your agreement with them and their privacy policy.
When the law requires it
We disclose personal data to authorities only when legally required to, and we push back on requests that are not properly founded. Where we are allowed to, we tell the people affected.
Transfers outside the EEA
We keep data in the European Economic Area where we can. Where a provider in the table above processes data outside it, the transfer is covered by the European Commission's Standard Contractual Clauses, by the EU–US Data Privacy Framework for certified US companies, or by both. You can ask us for a copy of the relevant safeguards at [email protected].
How long we keep it
The periods are given for each use above. After them, data is deleted or anonymised. When you close your account, we delete your account data and your projects' data within 30 days, except what we must keep by law, such as invoices. Copies held in backups are deleted as those backups expire.
How we protect it
Traffic to the website and the platform is encrypted in transit. Access to production systems and customer data is limited to the people who need it to run the service. Customer data is separated by organisation and project. If a breach puts your data at risk, we will notify the supervisory authority within 72 hours and tell affected customers without undue delay, as the GDPR requires.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy of it;
- correct it if it is wrong or incomplete;
- delete it, where we have no legal reason to keep it;
- restrict how we use it while a complaint is being resolved;
- take it with you in a machine-readable format (portability);
- object to uses based on our legitimate interests;
- withdraw consent at any time, where consent is the basis. For website analytics, use . Withdrawing does not affect what happened before.
To use any of them, email [email protected] from the address linked to your data, or tell us how to confirm it is you. We answer within one month; if a request is complex we may extend that by up to two more months and will tell you why. It is free unless requests are clearly unfounded or excessive.
If you are unhappy with how we handled your data, please tell us first so we can fix it. You also have the right to complain to a supervisory authority, in the EU country where you live or work, or in Portugal to the Comissão Nacional de Proteção de Dados (CNPD).
Children
Omnislice is a business service and the website is not aimed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
When we change this policy, we update the date at the top. If a change materially affects how we use data we already hold, we will tell account holders by email before it takes effect.

