Privacy Policy
Last updated October 6, 2026
This policy explains what information Ometz (“Ometz,” “we,” “us”) collects through ometz.co, our client portal, and the services we provide, how we use it, and the choices you have. By using our site or services you agree to this policy.
Information we collect
Information you give us. When you fill out a form (Start Your Build, onboarding, or support), we collect what you enter, such as your name, business name, email, phone number, website, industry, timeline, and the details you share about your project. Onboarding may also include brand colors, logo files or links, page lists, and notes about your customers and services.
Client portal accounts. If you are a client, we collect your login email, name, role, notification preferences, messages you send, files you upload, approvals and comments, support requests, and a record of portal activity. Your password is stored only as a secure hash by our authentication provider; we never see it. Two-factor authentication secrets are stored by that provider, not by us.
Payment information. Payments are processed by Stripe. Card and bank details go directly to Stripe and are never stored on our servers. We receive confirmation of payment, the amount, and basic billing details.
Automatically collected information. Our hosting and database providers record standard technical data such as IP address, browser type, pages requested, and timestamps, for security and reliability. The client portal stores a login session in your browser so you stay signed in. We do not use advertising cookies or sell data to advertisers.
How we use information
- To respond to inquiries and prepare proposals.
- To design, build, host, maintain, and support your website and back-office system.
- To run the client portal, including messages, files, approvals, invoices, and reports.
- To send service emails such as confirmations, project updates, invoices, payment reminders, and monthly reports. You can turn off most portal notifications in your portal settings; essential account and billing messages may still be sent.
- To process payments, keep accounting records, and meet legal obligations.
- To protect our services, prevent fraud and abuse, and fix problems.
We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising.
Service providers we use
We share information only with providers that help us run our services, under agreements that limit their use of it:
- Supabase: database, authentication, file storage, and server functions.
- Netlify: website hosting and delivery.
- Stripe: payment processing.
- Resend and Google Workspace: email delivery and correspondence.
We may also disclose information if required by law, to protect our rights or the safety of others, or as part of a merger, acquisition, or sale of assets, in which case this policy will continue to apply.
Data we handle for our clients
When we build and host a system for a client, that client’s own customer data (for example leads, bookings, or invoices) belongs to the client. We process it only on the client’s instructions to provide our services. Questions about that data should go to the business you dealt with; we will help them respond.
How we protect information
Connections to our site, portal, and admin systems are encrypted with HTTPS. Data is encrypted at rest by our infrastructure providers. The client portal requires two-factor authentication, signs out inactive sessions, and uses database-level access rules so each client can see only their own records. Files are stored in a private bucket and shared through short-lived links. No system is perfectly secure, but we work to protect your information and will notify affected clients of a breach as required by law.
How long we keep information
We keep inquiry and lead information for up to 3 years unless you ask us to delete it sooner. We keep client project, portal, and billing records for as long as you are a client and for up to 7 years afterward for accounting and legal purposes. Backups are overwritten on a rolling schedule.
Your rights and choices
You can ask us to access, correct, export, or delete your personal information, and you can opt out of any non-essential emails. Depending on where you live (for example California, Colorado, Virginia, Texas, or the EU/UK), you may have additional rights under local law. We will not discriminate against you for exercising them. To make a request, email us from the address on file; we may need to verify your identity and will respond within 45 days.
Children
Our services are for businesses and are not directed to children under 13. We do not knowingly collect information from children.
Where information is processed
Our providers store and process data in the United States. If you access our services from outside the U.S., your information will be transferred to and processed in the U.S.
Changes to this policy
We may update this policy. When we do, we will change the date above, and for material changes we will notify clients by email or in the portal.
Contact
Questions or requests: admin@ometz.co