Privacy

Privacy Policy
Your data stays yours.

This policy explains what information Omnikyo collects, why, who it is shared with, how long it is kept and how to have it deleted. It applies to the Omnikyo website, dashboard and mobile app, to the online stores businesses build with Omnikyo, and to the Facebook, Instagram and WhatsApp accounts businesses connect to Omnikyo.

  • Last updated September 29, 2026
  • Operated by Avraano, Dhaka
Never soldWe do not sell data or use it to profile anyone for advertising.
Only what you connectWe see only the Pages and accounts a business chooses to connect.
Deleted in 30 daysAsk for deletion and it is erased within 30 days of your request.
Disconnect anytimeIn Omnikyo, or from your Facebook and Instagram settings.

Who we are

Omnikyo is a commerce software platform operated by Avraano (এভ্রানো), a sole proprietorship registered in Bangladesh (trade licence TRAD/DNCC/010405/2026). In this policy, “Omnikyo”, “we” and “us” mean Avraano providing the Omnikyo service.

Avraano is responsible for the personal information described here. Contact: [email protected], 01644399607, Plot-4, The Address, Lakeview Road, Block-D, Sector-2, Aftabnagar, Dhaka 1212, Bangladesh.

Who uses Omnikyo

Omnikyo is used by businesses (“merchants”) to run their online sales. Merchants add their own products, orders and customers, and choose which of their own Facebook Pages, Instagram accounts, WhatsApp Business numbers, ad accounts, datasets and product catalogs to connect.

Information about a merchant’s customers (for example, a shopper who places an order or a person who messages a merchant’s Page) belongs to that merchant. We process it on the merchant’s behalf and on their instructions, only to provide Omnikyo to them. Each merchant can only see its own data. If you are a customer of a business that uses Omnikyo, you can also contact that business about your information.

Information we collect

Account information. Name, email address, phone number, password (stored hashed), business name and details, team members you invite, and billing details for Omnikyo fees.

Business data you add. Products, prices, stock, orders, customer names, phone numbers and delivery addresses, payments, expenses, store content and settings.

Data from connected Meta accounts (Facebook, Instagram, WhatsApp). When you log in with Facebook or Instagram and connect your accounts, we receive, only for the accounts you select:

  • Your Facebook user ID, name and the list of Pages, Instagram accounts, business portfolios, ad accounts, datasets and catalogs you have access to;
  • Page, Instagram and WhatsApp Business account details (name, ID, profile picture, phone number);
  • Messages, photos, videos, audio, files and reactions sent to and from your Page, Instagram account and WhatsApp number, including the sender’s name, profile picture and account ID, and any phone number or address a customer shares in a conversation;
  • Comments and replies on your Facebook and Instagram posts and ads;
  • WhatsApp call records (time, duration, participants) when calling is enabled;
  • Referral information that tells you which ad or post a conversation started from;
  • Posts and media you publish through Omnikyo, and their engagement;
  • Ad account data: campaigns, ad sets, ads, creatives, budgets, spend, results and insights;
  • WhatsApp message templates and their review status, and message delivery status;
  • Access tokens that let Omnikyo act on the accounts you connected.

Data from other services you connect. For example, Shopify products and orders, courier booking and tracking status, and payment status from your payment provider.

Store visitors and shoppers. On stores built with Omnikyo we collect what a shopper enters at checkout (name, phone, address, order details) and basic browsing data (pages viewed, device and browser type, IP address, referring link) used for the store’s analytics and to protect it from fraud. If the merchant enables the Meta Pixel, the Pixel sets cookies in the shopper’s browser (see section 5).

Technical and usage data. Log data, device and browser information, IP address and how features are used, to run, secure and fix the service.

How we use data from Facebook, Instagram and WhatsApp

We use data from connected Meta accounts only to provide the features the merchant chose to use:

  • Showing messages and comments from Messenger, Instagram and WhatsApp in one inbox, and sending the merchant’s replies, media and product details;
  • Handling WhatsApp calls between the merchant and their customers;
  • Creating orders and customer records from conversations, and showing each customer’s history to the merchant;
  • Creating WhatsApp message templates, submitting them to Meta for review, and sending template and marketing messages to customers who opted in;
  • Publishing the merchant’s posts to their Facebook Page and Instagram account;
  • Creating and syncing the merchant’s product catalog, and creating or selecting their dataset (Pixel);
  • Creating, editing, running and reporting on the merchant’s ad campaigns, and showing which ads led to conversations and orders;
  • AI features the merchant turns on, such as suggested replies and summaries (section 7).

We do not sell this data, use it to build profiles for advertising, share it with other merchants, or use it for any purpose unrelated to providing Omnikyo to the merchant who connected it. We handle it in line with Meta’s Platform Terms and Developer Policies.

Data we send to Meta on a merchant’s behalf

When a merchant uses these features, Omnikyo sends data to Meta for them:

  • Messages, comments, posts and ads the merchant writes or approves, and the media attached to them.
  • Product catalog: product names, descriptions, prices, availability, images and links.
  • Conversions API: when an order is placed and when cash on delivery is collected, the event name, time, order value, currency and product IDs, the shopper’s email address and phone number in hashed (SHA-256) form, IP address, browser user agent and Meta browser and click identifiers (fbp, fbc). Meta uses this to measure and improve the merchant’s ads.
  • Meta Pixel: on stores where the merchant enables it, the Pixel runs in the shopper’s browser, sets cookies and sends page views and shopping events to Meta.

Meta’s use of this data is governed by Meta’s own policies. Merchants are responsible for telling their shoppers about the Pixel and Conversions API in their store’s privacy notice.

WhatsApp messaging

Merchants may only send WhatsApp marketing messages to customers who have opted in to receive them. Customers can opt out at any time by replying STOP or using the opt-out option in the message, and Omnikyo stops marketing messages to that number for that merchant. Meta charges its WhatsApp messaging fees to the merchant’s own WhatsApp Business account.

AI features

Omnikyo’s AI features (such as drafting replies, summarising conversations, answering questions about a business and generating product content) send the relevant messages and business data to AI model providers, or to models we host ourselves, only to produce that result for the merchant. We do not sell this data. Merchants control whether AI replies are sent automatically or only as drafts.

Service providers and sharing

We share data only with providers that help us run Omnikyo, under agreements that limit their use of it, and with services the merchant chooses to connect:

  • Hosting and network: Vercel, Cloudflare
  • Database and file storage: Supabase
  • AI model providers, and models we host ourselves
  • Meta Platforms (Facebook, Instagram, WhatsApp), for the features in sections 4 and 5
  • Couriers the merchant books through Omnikyo, such as Pathao and Steadfast (recipient name, phone, address, cash-on-delivery amount)
  • Payment providers the merchant connects, such as bKash (payment amount and reference)
  • SMS gateway in Bangladesh, for order updates the merchant sends by SMS (phone number and message)
  • Shopify and other stores the merchant connects

We may also disclose information when required by law, to protect people’s safety or rights, or to a company that takes over operating Omnikyo (including a company formed to operate Omnikyo), which would remain bound by this policy. We never sell personal information.

How long we keep data

  • We keep a merchant’s data while their account is active, so the service works.
  • When a merchant disconnects a Facebook, Instagram or WhatsApp account, we stop receiving data from it and delete its access tokens immediately. Messages and records already in Omnikyo remain available to the merchant until they request deletion.
  • When a merchant or user requests deletion, we delete the data within 30 days of the request.
  • We may keep limited records longer where the law requires it (for example, invoices for Omnikyo fees), and encrypted backups are overwritten on a rolling basis.

Disconnecting and deleting your data

You can stop Omnikyo’s access at any time:

  • In Omnikyo: Settings → Integrations, then disconnect Facebook, Instagram or WhatsApp.
  • On Facebook: Settings & privacy → Settings → Business integrations, then remove Omnikyo.
  • On Instagram: Settings → Website permissions → Apps and websites, then remove Omnikyo.

To have your data deleted, follow the steps on our data deletion page or email [email protected]. When you remove Omnikyo in Facebook, Meta notifies us and we disconnect the account and delete its access tokens. If you also ask Facebook to delete your data, Meta passes that request to us and we delete it within 30 days.

Security

Data is encrypted in transit and at rest, access tokens are never shown in the browser, and each merchant’s data is isolated so it can only be accessed by that merchant’s team. Staff access is limited to what is needed to operate and support the service. No online service is completely secure, and we will notify affected merchants of a breach that affects their data as required by law.

Where data is stored

Our providers store and process data on servers that may be outside Bangladesh. We use providers that protect data with industry-standard security.

Your choices and rights

You can view and correct your account information in Omnikyo, ask us for a copy of your data, disconnect connected accounts, and request access to or deletion of your personal information by emailing [email protected]. We reply within 30 days.

Children

Omnikyo is a business service and is not intended for children under 13. We do not knowingly collect their personal information.

Changes to this policy

We will post any changes on this page and update the date above. If a change materially affects how we use merchants’ data, we will also notify them by email or in Omnikyo before it takes effect.

Questions about your data or these terms?

Write to us. A person reads every email.