1. Scope and who is responsible
Omninal Inc operates Omninal and is responsible for deciding how and why personal information is handled for Omninal accounts, onboarding, the mobile app, website, payments and support. This Privacy Policy covers account applicants and holders, beneficial owners, directors, merchant representatives, authorized business users, transaction participants and people who contact us.
Some providers also determine how they use information for their own purposes. Their privacy notices apply to that processing. The features you use, your location and the applicable service arrangements determine which processing applies to you. Contact privacy@omninal.com with questions about Omninal's processing.
2. Information we collect
Depending on how you interact with Omninal, we may collect information directly from you, from your business or its authorized representatives, automatically from your device, from service providers, and from public or legally permitted sources.
- Identity and contact information: name, date and place of birth, nationality, citizenship, residential address, email address, phone number, signatures and other identifiers.
- Business and authority information: business name, registration and tax details, operating information, role, ownership and control structure, beneficial-owner, director and authorized-representative details.
- Verification information: government-issued identity documents and document data, proof of address, selfies, facial images, video or audio recordings, liveness results, facial geometry or other biometric identifiers and information, source-of-funds or source-of-wealth information, verification results and audit records.
- Screening and compliance information: sanctions, watchlist, politically exposed person, adverse-media and fraud-check results; risk indicators; and information needed for customer due diligence, anti-money-laundering and counter-terrorist-financing checks.
- Financial and transaction information: payment amounts, currencies, recipients, bank or payout details, order references, fees, balances, wallet addresses, transaction identifiers and related records.
- Technical and service information: IP address, timestamps, browser and device attributes, device identifiers, operating system, general location inferred from IP or device data, login and security events, diagnostics, crash reports and service activity.
- Communications and choices: support requests, complaints, attachments, survey responses and records of your instructions, notices presented and consents or acknowledgements.
3. How and why we use information
We use information to assess and open accounts; verify identity, business ownership and authority; authenticate users; conduct customer due diligence and ongoing screening; detect fraud, identity abuse and prohibited activity; comply with sanctions, AML/CFT and other legal obligations; provide and secure services; process and reconcile transactions; provide support; investigate disputes; maintain records; and improve service reliability.
Where applicable law requires a legal basis, we rely on steps requested before entering into and performance of our agreement, compliance with legal obligations, legitimate interests such as fraud prevention and service security, and consent or explicit consent where required. If information is required by law or to provide a requested service, not providing it may prevent or delay onboarding or use of that service. Optional marketing and optional device permissions are not conditions of unrelated features.
4. Identity verification through Sumsub
If identity verification is enabled and you start a verification, Omninal may use Sumsub for identification, document and database verification, liveness and facial comparison, authentication, fraud prevention, risk assessment, AML/CFT and sanctions screening, and related compliance checks. Depending on the configured checks, Sumsub and its approved subprocessors may receive the identity, document, biometric, screening, technical and other verification information described above directly from you, Omninal, your device, public records and verification or screening sources.
Omninal generally determines the purpose of its onboarding and due-diligence checks and Sumsub generally processes that information on Omninal's behalf. Sumsub may also act as an independent controller for the limited purposes described in its notice, including platform security, its own legal compliance, network-level fraud prevention, quality assurance, analytics and service development, including AI model training and testing. Sumsub may use automated document analysis, facial comparison, liveness checks, duplicate detection, database screening, device analysis and risk scoring, with human review where appropriate.
Sumsub may return verification results, alerts and risk indicators. Omninal remains responsible for its decision about your Omninal application or account and does not base a decision solely on Sumsub's automated output where prohibited by applicable law. Before any personal information is sent to Sumsub, the applicable verification flow presents Sumsub's required notice and, where required, requests an affirmative acknowledgement or consent. Reading this Privacy Policy alone does not start verification or record consent.
6. Automated checks and review
Verification and fraud-prevention providers may automatically extract information from documents, assess document authenticity, compare facial images, perform liveness and anti-spoofing checks, identify duplicate applications, screen databases and public sources, analyse device or network signals, and generate risk indicators. Authorized personnel may review results, request more information or investigate an alert.
These tools support Omninal's review. Where applicable law provides rights concerning solely automated decisions that produce legal or similarly significant effects, you may request information about the decision, ask for human review, express your point of view or contest the outcome by contacting privacy@omninal.com.
7. Device permissions and website technologies
Camera, microphone or selected photo and file access may be requested when you scan a code, upload a verification document, take a selfie or complete a liveness or video check. These verification images and recordings are different from device biometric authentication, such as Face ID or fingerprint unlock: device-authentication templates remain with the device platform and are not received by Omninal. Notifications may be used for account and transaction alerts. You can manage device permissions in device settings, although disabling a permission may prevent a feature that requires it.
Essential browser storage supports website functionality. Optional analytics, where enabled, is subject to the displayed choices and applicable consent requirements. Information you choose to send through website enquiries or support is used to respond to your request.
8. International processing
Omninal and its providers may process or allow access to information outside your state, province or country, including in countries where Omninal, Sumsub, Bridge or their approved service providers operate. Privacy laws in those locations may differ from those where you live.
Where required, international transfers use an applicable safeguard such as an adequacy decision, standard contractual clauses or another lawful transfer mechanism. Sumsub's notice describes the locations and safeguards applicable to its processing.
9. Retention and deletion
We retain information only for as long as needed for the purposes described in this policy, including to provide services, satisfy legal and regulatory requirements, prevent fraud, resolve disputes and enforce agreements. Account profile and preference information that has no continuing purpose is deleted or irreversibly de-identified after account deletion.
Identity, KYC/KYB, AML/CFT, sanctions, transaction, tax and accounting records may need to be retained after a relationship ends, commonly for five to seven years depending on the record and jurisdiction, or longer when required by a legal hold, investigation or other legal obligation. Security, fraud, dispute and consent records are retained for the period necessary for the relevant protective, evidentiary or legal purpose. We restrict retained information to those purposes and remove or de-identify it when the retention basis ends.
When a provider processes information only on our behalf, we instruct it to return, delete or de-identify the information in accordance with our agreement and applicable requirements. A provider may retain information for its own legal obligations or independent purposes under its notice. Public blockchain records, including transaction hashes and wallet addresses, cannot be removed from the blockchain by Omninal; copies held in our own systems remain subject to this policy.
10. Security
We use administrative, technical and organizational safeguards designed to protect personal information, including access controls, authentication, encryption where appropriate, vendor review and monitoring. Access is limited according to role and business need. No system is completely secure, and we cannot promise absolute security.
Never send passwords, one-time codes, recovery phrases, private keys, full payment-card details or identity documents to support unless we provide an authorized secure method for the specific request.
11. Your privacy choices and rights
Depending on applicable law, you may request access to, correction of, a copy of, portability of or deletion of your information; object to or restrict processing; withdraw consent for future processing; appeal certain refusals; or ask for review of certain automated decisions. You may also complain to your local data protection authority or attorney general. We may verify your identity and authority before responding. Exercising a right will not result in unlawful discrimination.
Email privacy@omninal.com or support@omninal.com to exercise rights concerning Omninal's processing. Requests to delete an account can be made without reinstalling or signing in to the app. If Sumsub acts as an independent controller for the processing covered by its notice, requests about that processing may also be directed to Sumsub using the contact route in its notice. Withdrawing consent does not affect processing already lawfully performed and may affect a feature that requires that information.
12. U.S. and biometric disclosures
Information described in this policy may be personal information or sensitive personal information under U.S. state privacy laws. Sensitive information may include government identifiers, account or financial information, precise location where collected, and biometric identifiers or biometric information used for identification. Omninal uses sensitive information only for the purposes described in this policy and as otherwise permitted by applicable law; it is not used to infer characteristics for advertising.
If a verification requires a selfie, facial image, video or facial-geometry analysis, the verification flow provides the notices and obtains the acknowledgement or consent required for that processing before collection. Additional biometric terms presented in the flow, including Sumsub's notice for applicable U.S. residents, control where they provide more specific protections. Biometric information is retained and destroyed in accordance with the applicable notice, Omninal's documented instructions, contractual requirements and applicable law.
13. Children and policy updates
Omninal is intended for adults aged 18 and over and is not directed to children. We do not knowingly open accounts for children. Contact privacy@omninal.com if you believe a child has provided personal information.
We update this policy when our practices or legal obligations change. Material changes will be communicated as required by law. The version and effective date appear above. For privacy questions contact privacy@omninal.com; for account help contact support@omninal.com.
