OmnaSense Privacy Policy
Effective Date: August 26, 2026
Last Updated: August 26, 2026
This Privacy Policy explains how OmnaSense ("OmnaSense,"
"we," "us," or "our") collects, uses, discloses, and otherwise processes personal information in
connection with the OmnaSense websites, applications, closed beta, and related support and
communications (collectively, the "Services"). It also explains the choices and rights that may
be available to individuals.
OmnaSense is a business-to-business website tracking and marketing observability service.
Customers use the Services to crawl authorized websites, replay authorized test journeys,
schedule checks, inspect tracking and event evidence, review screenshots and other artifacts,
receive alerts, and investigate incidents.
This Privacy Policy does not govern a customer's own privacy practices. When we process
monitoring data on a customer's behalf, that customer generally decides what is monitored
and why. If your information appears in monitoring data collected for one of our customers,
please contact that customer first. See Section 3, "Our Privacy Roles."
1. Scope
This Privacy Policy applies to personal information processed through:
• the OmnaSense marketing website and self-service onboarding;
• customer accounts, workspaces, dashboards, monitors, schedules, alerts, and support;
• crawl monitoring and journey monitoring, including a journey recorder and automated
replays;
• browser-side, tag-manager, server-side, and marketing-destination evidence collection;
• screenshots, request and response metadata, event evidence, incident records, and
other monitoring artifacts; and
• service-related email, beta communications, and other interactions with us.
The Services are intended for business and professional use by people who are at least 18
years old. They are not directed to consumers acting in a household capacity or to children.
2. Notice at Collection
The table below summarizes the categories of personal information we may collect, why we
use them, and the types of recipients to which we may disclose them. The examples are
illustrative; not every data element is collected from every user.
Category and Main purposes Sources Categories of recipients
examples
Account and profile Create and secure You, your organization, Authentication, database,
information: name, accounts; administer and our authentication hosting, security, support, and
business email, workspaces; provide provider. professional-service providers;
organization, support; communicate your organization.
account and about the Services.
workspace
identifiers,
authentication
status, and role.
Passwords are
handled by our
authentication
provider; we do not
receive them in
readable form.
Customer Configure, run, You, your organization, Hosting, database, monitoring,
configuration and troubleshoot, and and authorized email, and integration providers;
test instructions: improve monitors; send integrations. your organization.
monitored domains requested alerts.
and URLs,
schedules, journey
steps, selectors,
assertions, alert
recipients,
integration
settings, and
test-account
identifiers.
Monitoring Perform authorized Authorized websites, test Infrastructure, database, storage,
evidence and checks; identify tracking journeys, browsers, tag security, and integration
artifacts: page and failures; show evidence; managers, server-side providers; authorized members
network metadata, create run history, containers, marketing of the applicable customer
tag and vendor incidents, and alerts; destinations, and workspace.
identifiers, protect and debug the customer-authorized
data-layer and Services. integrations.
event information,
event parameters,
server-side
delivery evidence,
response status,
hashes of selected
identifiers,
screenshots, page
content visible
during a test,
timestamps, and
incident evidence.
Communications: Respond to requests; You and your organization. Customer-support, email,
support messages, provide support; collaboration, and
feedback, survey administer and improve professional-service providers;
responses, beta the beta and Services. your organization where
correspondence, appropriate.
and call or meeting
details.
Category and Main purposes Sources Categories of recipients
examples
Device, usage, and Operate, secure, debug, Your browser or device and Hosting, logging, authentication,
security and improve the our service infrastructure. analytics, and security providers;
information: IP Services; prevent abuse; authorities when legally required.
address, browser maintain records of
and device type, agreement and
timestamps, authorization.
referring page,
session and
authentication
events, feature
interactions, error
information, and
audit or security
logs.
Business and Administer access; fulfill You, your organization, Contracting, payment,
transaction orders; keep legal and and future payment or accounting, and professional
information: plan or business records. contracting providers. advisers, if applicable.
beta eligibility, OmnaSense does not currently
order or request payment-card details for
subscription details the free closed beta.
if paid plans are
introduced, and
records of
consents and
policy versions.
We retain each category only for as long as reasonably necessary for the purposes described
in this Policy, including to provide the Services, honor customer instructions, maintain security
and incident records, comply with law, resolve disputes, and enforce agreements. Retention
depends on the type and sensitivity of the data, workspace settings and instructions, whether
an incident is open, backup cycles, legal requirements, and the need to prevent fraud or
abuse. We do not promise a fixed retention period unless it appears in an applicable order
form or data processing agreement.
Based on the Services described in this Policy, OmnaSense does not sell personal
information for money and does not share personal information for cross-context behavioral
advertising or use it for targeted advertising. We also do not knowingly sell or share personal
information of people under 18. If our practices change, we will update this Policy and provide
any legally required choices before the change applies.
3. Our Privacy Roles
The role OmnaSense plays depends on the context.
OmnaSense as a business or controller. We determine the purposes and means of
processing for account administration, the OmnaSense website, security, support, service
communications, beta administration, and our own business operations.
OmnaSense as a service provider or processor. A customer generally determines the
purposes and means of processing Customer Monitoring Data submitted to or collected
through monitors for that customer. In that context, OmnaSense processes the data on the
customer's behalf and under the customer's instructions, subject to the Terms of Service and
any applicable data processing agreement.
Customers are responsible for providing required notices, obtaining required permissions,
choosing lawful test data, responding to requests from individuals, and configuring their
monitors appropriately. We may redirect a request concerning Customer Monitoring Data to
the relevant customer and assist that customer as required by applicable law and our
contract.
4. Information We Collect
4.1 Information You Provide
We collect information you provide when you create an account, join a workspace, configure a
monitor, record a journey, choose alert recipients, connect an integration, contact support, or
participate in the beta. Journey instructions may include typed test inputs. Customers should
use synthetic or non-sensitive test data and should not enter real payment-card data, health
information, government identifiers, biometric data, or production credentials into recorded
journeys.
Integration credentials are intended to be stored through protected secret-management
functions and referenced by the Services rather than returned to the browser or displayed in
reports. You remain responsible for using appropriately limited credentials and rotating or
revoking them when necessary.
4.2 Information Collected Through Monitoring
Authorized crawl and journey monitors may load pages and generate synthetic traffic.
Depending on customer configuration and the monitored site, evidence may include URLs,
page titles, tag and vendor identifiers, event names and parameters, data-layer values,
request and response metadata, timestamps, error details, screenshots, and content
rendered during a test. Server-side checks may poll customer-authorized systems or
providers for evidence that an event was received or forwarded.
OmnaSense is designed to favor evidence needed for observability and to redact or avoid
unnecessary raw values where practical. Selected identifiers may be hashed. However,
website pages, URLs, network events, data layers, and screenshots can contain incidental
personal or confidential information. Automated masking cannot guarantee removal of every
sensitive value, especially arbitrary text rendered on a page. Customers must configure test
environments, accounts, routes, and data accordingly.
4.3 Information Collected Automatically From the Services
We and our service providers may automatically collect device, usage, authentication, error,
and security information when you visit or use the Services. We use this information to
maintain sessions, secure accounts, diagnose problems, measure feature use, and improve
reliability.
4.4 Information From Other Sources
We may receive information from your employer or organization, an administrator who invites
you, customer-authorized integrations, service providers, public business sources, and people
who refer you to the beta.
5. How We Use Personal Information
We may use personal information to:
• provide, operate, maintain, and secure the Services;
• create accounts and workspaces and authenticate users;
• run authorized crawls, journey replays, scheduled checks, evidence polling, and incident
workflows;
• store and present evidence, screenshots, artifacts, run history, and alerts;
• send service, security, support, and beta communications;
• personalize workspace settings and improve usability and reliability;
• investigate errors, abuse, fraud, and security incidents;
• comply with law and enforce our agreements;
• protect the rights, safety, and property of OmnaSense, our customers, and others; and
• conduct internal analysis and develop the Services using aggregated or de-identified
information where reasonably possible.
We do not use Customer Monitoring Data to build advertising profiles about individuals.
6. How We Disclose Personal Information
We may disclose personal information in the following circumstances:
Service providers and subprocessors. We use providers that help with authentication,
databases, private file storage, hosting and execution, security, logging, customer support,
and email delivery. The current product uses Supabase for authentication, database, and
storage functions and Resend for transactional email. These providers process information
under their own agreements with us and, where applicable, our instructions.
Your organization and workspace. Workspace administrators and authorized members
may access account information, monitor configurations, run results, incidents, alerts, and
artifacts within that workspace. Your organization controls its workspace membership and
access decisions.
Customer-selected integrations. When a customer connects a tag manager, server-side
container, marketing destination, or other third-party service, we disclose information as
directed by the customer and receive information permitted by that integration.
Professional advisers and business operations. We may disclose information to lawyers,
auditors, insurers, accountants, and financing or transaction advisers subject to appropriate
duties of confidentiality.
Legal and safety reasons. We may disclose information if we reasonably believe it is
required by law or legal process, or necessary to protect rights, safety, property, and the
integrity of the Services. Where legally permitted, we may notify the affected customer before
disclosing Customer Monitoring Data.
Business transfers. Information may be disclosed or transferred in connection with a
merger, financing, acquisition, bankruptcy, reorganization, or sale of assets, subject to
applicable law.
At your direction or with consent. We may disclose information when you or the applicable
customer directs us to do so or provides consent.
7. Cookies and Similar Technologies
OmnaSense and its providers may use cookies, local storage, and similar technologies that
are necessary for authentication, session continuity, security, preferences, and basic service
operation. Based on the Services currently described, we do not use third-party advertising
cookies or pixels on OmnaSense properties to create profiles for cross-context behavioral
advertising.
Browser settings may allow you to block or delete cookies, but doing so may prevent account
sign-in or other essential features from working. OmnaSense does not currently respond to
browser "Do Not Track" signals because there is no uniformly accepted response standard.
Where required, we will process legally recognized opt-out preference signals for practices to
which those signals apply. Third parties may collect information about activity over time and
across different websites only if their technologies are present; OmnaSense does not
authorize such tracking for advertising on its properties under the practices described above.
8. Security
We use administrative, technical, and physical safeguards designed to protect personal
information. Depending on the data and system, these include access controls, workspace
isolation, server-side authorization, private storage, short-lived access links, protected secret
references, abuse prevention, and security logging. No method of transmission, storage, or
security is completely reliable, and we cannot guarantee absolute security.
You are responsible for maintaining the confidentiality of your credentials, using appropriately
limited test accounts and integration permissions, reviewing workspace membership, and
promptly notifying us of suspected unauthorized access.
9. Data Retention and Deletion
We retain personal information according to the criteria described in Section 2. A customer
may be able to delete monitors, artifacts, or its workspace through available product functions
or by contacting us. Some information may remain for a limited period in backups, security
records, incident records, or records we must retain by law or to resolve disputes and enforce
agreements. Deletion from active systems does not necessarily result in immediate deletion
from disaster-recovery backups.
Upon termination, Customer Monitoring Data will be handled as stated in the Terms of
Service, an applicable order form, or a data processing agreement. Customers should export
information they need before access ends.
10. Your Privacy Choices and Rights
You may update certain account information through the Services and may opt out of
non-essential marketing email by using the unsubscribe method provided. You may still
receive transactional, security, account, and beta-administration messages while you maintain
an account.
Depending on where you live and subject to legal exceptions, you may have the right to
request:
• confirmation of whether we process your personal information and access to it;
• correction of inaccurate personal information;
• deletion of personal information;
• a portable copy of certain information;
• information about categories of information, sources, purposes, and recipients;
• an appeal if we deny a privacy request; and
• opt-out of sale, targeted advertising, or certain profiling.
OmnaSense does not engage in sale, sharing for cross-context behavioral advertising, or
targeted advertising based on the practices described in this Policy, so an opt-out mechanism
for those practices is not currently offered.
To exercise a right concerning information OmnaSense controls, contact us through the in-product Help & support channel
with the subject "Privacy Request" or use https://www.omnasense.com/app/help#contact. We may
verify your identity and authority before responding. An authorized agent may submit a
request where permitted by law, but we may request proof of authorization and direct
verification with the individual. We will not discriminate against you for exercising an
applicable privacy right.
If your request concerns monitoring performed for an OmnaSense customer, identify that
customer and contact it first. We will assist the customer as required. To appeal a decision,
reply to our decision and state that you are appealing. If a state law gives you the right to
contact a regulator after an appeal, our response will provide relevant instructions.
11. Children and Teenagers
The Services are intended only for business and professional users who are at least 18. We
do not knowingly collect personal information directly from children under 13 through
OmnaSense account creation or marketing. Customers may not use the Services to monitor a
child-directed website or service, or intentionally submit children's personal information,
unless OmnaSense has expressly approved that use in writing and the customer has
documented a lawful basis and all required notices, consents, and safeguards.
If you believe a child has provided personal information directly to OmnaSense, contact
the in-product Help & support channel. We will investigate and take appropriate action.
12. United States Processing and International Use
OmnaSense is operated from the United States, and information may be processed and
stored in the United States and other locations where our providers operate. The laws in those
locations may differ from the laws where you live. Unless an applicable written agreement
states otherwise, the Services are offered as a U.S.-focused service and are not represented
as meeting every non-U.S. privacy requirement.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in the Services, law, or our practices.
We will post the updated version and revise the "Last Updated" date. If changes are material,
we will provide additional notice as required by law, such as through the Services or by email.
We will not materially change how we use previously collected Customer Monitoring Data in a
manner inconsistent with customer instructions without an appropriate legal basis and notice.
14. Contact Us
OmnaSense
Mailing address available through the in-product Help & support channel.
Privacy: the in-product Help & support channel
Legal notices: the in-product Help & support channel
Privacy request form: https://www.omnasense.com/app/help#contact
If a law requires us to identify a data-protection contact or representative, that information will
be published here or in a jurisdiction-specific notice.