Back to Omnilert

Legal

Privacy Policy

Effective July 17, 2026

This policy explains how the Omnilert app, operated by Omnilert Food and Beverages, handles information — including how it accesses, uses, stores, and shares Google user data through its optional Google Calendar integration.

How does this application access, use, store, or share Google user data?

Linking a Google account to Omnilert is optional and always initiated by the user. Omnilert requests only these scopes: openid, email, and https://www.googleapis.com/auth/calendar.events.

Access. Google user data is accessed only through Google's OAuth2 consent flow, after the user explicitly authorizes it. Omnilert receives the user's Google account email address and a refresh token scoped to calendar events.

Use. The email address is used only to identify which Google account is linked and to display that account back to the user. The calendar events permission is used only to create, update, and delete private copies of that user's own Omnilert meetings on their primary Google Calendar. Omnilert does not read, import, or index existing calendar events. It does not add Google attendees and does not send Google Calendar invitations.

Store. Omnilert stores the linked Google email address, the authorized scopes, the OAuth refresh token, the identifiers of the calendar events it created, and synchronization status. Refresh tokens are encrypted at rest using AES-256-GCM. Data is held in a PostgreSQL database accessible only to the Omnilert service.

Share. Google user data is not sold, not used for advertising, and not shared with third parties. It is transmitted only between Omnilert and Google's own APIs in order to provide the synchronization feature the user requested.

Delete. A user may disconnect Google Calendar at any time from the Meetings section of Omnilert. On disconnect, Omnilert removes the future Omnilert-created events it added, revokes the token with Google, and deletes the stored refresh token. Access may also be revoked at any time at myaccount.google.com/permissions.

Google OAuth2 Limited Use Disclosure

Omnilert's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing calendar synchronization feature, is not used for advertising, is not sold, and is not read by humans except with the user's explicit consent, to resolve a support issue the user has raised, for security purposes, or where required by law.

Who we are

Omnilert is a workforce operations platform operated by Omnilert Food and Beverages. Employers use it to coordinate branches, employees, schedules, meetings, operational requests, audits, compliance workflows, and reporting. Accounts are created by the employer; there is no public sign-up.

Privacy questions and requests may be sent to support@omnilert.app.

Other information we process

Beyond the Google integration, and depending on how an employer configures the platform, Omnilert processes account information (names, work email addresses, roles, branch assignments, authentication records); employment and workforce information (schedules, attendance, position details, payroll-related records, employee requests); operational information (verifications, audits, case reports, projects, analytics); meeting information (titles, agendas, participants, acknowledgements, messages, attachments); and technical information (device and browser details, IP address, logs, security events, notification tokens).

The employing organization administers its own workspace and determines what employee information is entered, who may access it, and how long it is retained for legitimate employment purposes.

Security

Omnilert protects information using commercially reasonable measures, including encrypted transport (HTTPS), encryption at rest for OAuth refresh tokens, hashed credentials, and role-based access controls. No method of transmission or storage is completely secure, and absolute security cannot be guaranteed.

Full platform privacy policy

This page describes Omnilert's handling of Google user data and summarizes its wider privacy practices. The complete platform privacy policy, covering all workforce and operational data, is available at https://omnilert.app/privacy.

Omnilert

The internal operations platform of Omnilert Food and Beverages — attendance, verifications, audits, and analytics for its brands, branches, and franchisees.

support@omnilert.app
Omnilert Food and Beverages