Back to Omnilert

Legal · Privacy

Privacy Policy

Effective July 17, 2026

Omnilert is the internal operations platform of Omnilert Food and Beverages. Because it manages employment and branch records, it necessarily holds personal information about the people who work in and with our branches. This policy describes — specifically and plainly — what that information is, why we process it, and the rights you hold under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173).

No ads, no data sales

Your information is used to run branch operations — never for advertising, and it is never sold.

Role-scoped visibility

People see only what their role, branch, and permissions require. Nothing more.

Your DPA rights apply

The Philippine Data Privacy Act (RA 10173) gives you rights over your data — and a path to exercise them.

01Who we are

Omnilert Food and Beverages runs the Omnilert platform for its own brands, branches, and franchisees in the Philippines. The platform is not offered to the public — every person with an account works in or with one of those branches.

For most information in the platform, Omnilert Food and Beverages — or the franchisee that employs you — acts as the personal information controller. Privacy questions and requests may be sent to support@omnilert.app.

02Information we keep

Omnilert holds the records an operating branch needs. Depending on your role, that includes:

  • Account information — name, work or login email, role, branch assignment, and authentication records.
  • Employee personal information — full name, address, birthday, gender, contact details, emergency contacts, profile photo, government-issued IDs, and bank details used for payroll.
  • Employment requirements — documents you submit to complete your employment file, and their verification status.
  • Attendance and shift records — scheduled shifts, clock-ins and clock-outs, and shift exchanges.
  • Operational records — case reports, violation notices, POS verification and session records (including discount and non-cash order verifications), purchase order tracking, petty cash fund (PCF) verifications, cash and authorization requests, peer evaluations, and inventory variance records.
  • Store audit media — CCTV footage, screenshots, and photos uploaded as part of store audits and case investigations, stored in secured cloud storage (AWS S3).
  • Technical records — device and browser details, IP address, application logs, and notification tokens.
  • Google Calendar integration data — if you link a Google account: the linked email address, authorized scopes, an encrypted OAuth refresh token, and the identifiers of calendar events Omnilert creates.

03Why we process it

Under the Data Privacy Act, we process personal information on these bases:

  • Employment administration — running attendance, payroll-related records, employment requirements, and HR workflows is necessary to carry out the employment relationship.
  • Legitimate business interests — verifying orders and cash counts, auditing stores, investigating cases, and producing operational analytics protect the business and the people working in it.
  • Consent — optional features, such as the Google Calendar integration, run only when you choose to enable them.
  • Legal obligations — we keep records where Philippine labor, tax, or other law requires it.

We do not use your information for advertising, and we do not sell it.

04CCTV and store audit media

Store audits may include CCTV footage, screenshots, and photos taken at a branch. This media exists to verify audit findings and case reports — it documents the state of a store or an incident, and people appearing in it may be identifiable.

Audit media is uploaded to secured cloud storage, is visible only to roles with audit or case permissions, and is attached to the specific audit or case it supports. It is not published, reused for other purposes, or shared outside the workflows described here.

05Google Calendar integration

Linking Google Calendar is optional and happens only through Google's own consent screen. When linked, Omnilert uses the granted permission solely to create, update, and remove private copies of your Omnilert meetings on your primary Google Calendar. Omnilert never adds attendees to those events and never sends Google Calendar invitations.

We store only what the integration needs: your linked Google email, the scopes you authorized, an OAuth refresh token encrypted at rest, and the identifiers of events we created. You can disconnect at any time from the Meetings section — Omnilert will remove the future events it created and discard the stored connection — or revoke access from your Google Account settings.

Google user data is used only to provide this synchronization feature. It is not sold, not used for advertising, and not shared beyond what the feature requires, consistent with the Google API Services User Data Policy, including its Limited Use requirements.

06Who can see your information

Visibility inside Omnilert follows roles and permissions: your branch managers, HR, and administrators see what their role requires. A service crew member cannot open another employee's file, and audit media is limited to audit and case roles.

Outside the platform, information reaches only: service providers that run our infrastructure (cloud hosting, database, file storage on AWS S3, and email delivery), acting under our instructions; and authorities, where disclosure is required by Philippine law or necessary to protect our people or the service. There are no advertising or data-brokerage recipients.

07Security

Access to Omnilert requires authenticated accounts with role-based permissions. Sensitive credentials, including integration tokens, are encrypted at rest; connections are encrypted in transit. Administrative actions and verifications leave audit trails.

No system is immune to every incident. If a breach affecting your personal information occurs, we will notify affected people and the National Privacy Commission as the Data Privacy Act requires.

08Retention

Employment and operational records are kept for the duration of the employment or franchise relationship, plus the periods Philippine labor, tax, and audit rules require. Audit media and case records are kept for as long as the audit or case they support remains relevant. When a record is no longer needed, it is deleted or anonymized.

09Your rights under the Data Privacy Act

As a data subject under RA 10173, you may: be informed about how your information is processed; access it; correct inaccurate entries; object to processing that isn't required by law or your employment; request erasure or blocking of unlawfully processed data; request a copy in a portable format; and claim damages for violations. You may also lodge a complaint with the National Privacy Commission.

Because most records in Omnilert are employment records controlled by your employer, start with your HR or branch administrator — or write to support@omnilert.app and we will route your request to the right controller.

10Changes and contact

Omnilert is a workplace system for people authorized by Omnilert Food and Beverages or its franchisees; it is not directed to children. When this policy changes, we will publish the revised version here with a new effective date and flag material changes inside the platform.

Omnilert Food and Beverages · support@omnilert.app

Omnilert

The internal operations platform of Omnilert Food and Beverages — attendance, verifications, audits, and analytics for its brands, branches, and franchisees.

support@omnilert.app
Omnilert Food and Beverages