Privacy Policy

Last updated: 1 August 2026

1. Who we are

Omnitik is a customer-messaging platform operated by Transit International Tours and Travel (trading as Omnitik). It lets a business receive and answer messages from its own customers across WhatsApp, Instagram, Facebook Messenger and other channels in one shared inbox.

For questions about this policy or your data, contact support@techeffic.com.

2. Our role

Omnitik is used by businesses to talk to their customers. Where a business uses Omnitik to handle its own conversations, that business decides what is collected and why (it is the data controller) and Omnitik processes the data on its behalf (we are the data processor). Where we handle the accounts of the people who log in to Omnitik, we act on our own behalf.

3. What we collect

DataWhy we hold it
Account details — name, email address, role, password (stored only as a one-way hash, never in readable form) To sign you in and apply your permissions
Messages and attachments — the content of conversations between a business and its customers, including images, documents and voice notes This is the service: showing a business its conversations and letting it reply
Customer contact details — the phone number or platform ID and profile name supplied by the messaging platform To identify who a conversation belongs to and keep its history together
Activity records — who replied, who a conversation was assigned to, status changes, timestamps Accountability inside the business, and reporting on response times
Technical logs — IP address, browser type, error and request logs Security, abuse prevention and diagnosing faults

We do not use conversation content for advertising, we do not sell it, and we do not use it to train machine-learning models.

4. Where the data comes from

Most of it reaches us from the messaging platform a customer chose to write on. When a customer messages a business on WhatsApp, Instagram or Facebook Messenger, Meta delivers that message to Omnitik through its official APIs so the business can answer it. We only receive data for accounts and Pages the business has explicitly connected and authorised.

5. Meta platform data

For data obtained through Meta's APIs — the WhatsApp Business Platform, Instagram Messaging, and the Messenger Platform for Facebook Pages — this is what we receive and what we do with it:

Meta sourceWhat we receiveWhat we do with it
WhatsApp Business Platform Message content and attachments, the customer's phone number and WhatsApp profile name, delivery and read receipts Show the conversation in the business's inbox and send its replies
Instagram Messaging Message content and attachments, the sender's Instagram-scoped ID, username, profile name and picture, message reactions Show the conversation in the business's inbox and send its replies
Messenger Platform (Facebook Pages) Message content and attachments sent to the business's Page, the sender's Page-scoped ID, public profile name and picture, message reactions; and the Page's own name and ID so the owner can pick which Page to connect Show the conversation in the business's inbox, show the agent who they are talking to, and send the agent's reply back in Messenger

A Page-scoped ID identifies a person only in relation to that one Page. We cannot use it to identify them anywhere else, and we do not try to.

For all of it we additionally commit that we:

6. Who can see it

Inside a business, a conversation is visible only to members whose role and permissions allow it — Omnitik enforces this on the server, not just in the interface. Each business's data is isolated from every other business on the platform.

Outside the business, data is shared only with:

Every third party named above is bound, by contract, to protect this data to the same or an equal standard as this policy sets out, and to use it only to provide the service we have asked them for. None of them may use it for their own purposes, sell it, or pass it to anyone else. Where a provider cannot meet that standard, we do not use them.

7. Security

All traffic is encrypted in transit (HTTPS). Passwords are stored as one-way hashes. Incoming platform messages are cryptographically verified before being accepted, so forged traffic is rejected. Access to production systems is restricted and logged.

No system is perfectly secure, but if a breach affects your data we will notify affected businesses without undue delay.

8. How long we keep it

Conversations and their attachments are retained while the business's account is active, because their value is the history itself. Deleted conversations are held briefly in a recoverable trash and then removed. When an account is closed, its data is deleted within 90 days, except where the law requires us to keep records (for example, billing).

9. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to how it is used. If you are a customer messaging a business that uses Omnitik, contact that business first — it decides what happens to your conversation. You can also write to us and we will help route the request.

To request deletion, email support@techeffic.com with the subject "Data deletion request". We will confirm and complete verified requests within 30 days. Full instructions, including what to send us and what happens to each kind of data, are on the data deletion page.

10. The mobile app

Omnitik is also available as an app for iPhone and Android. The app is the same product as the website and holds no data of its own: everything it shows is read from, and written to, the same servers described above, and nothing is kept on the phone except your sign-in token, which is stored in the device's own secure keystore and removed when you sign out.

The app asks for two permissions, and only ever when you use the feature that needs them:

PermissionWhat it is for
Camera To take a photo and send it to a customer inside a conversation, or to set your own profile picture. The camera is never opened by the app on its own.
Photo library To choose an existing picture for the same two purposes. The app reads only the single image you pick; it does not scan, index or upload your library.

A picture you send is stored on our servers as part of that conversation, exactly as it would be if you had sent it from the website, and is kept and deleted under the same rules set out in section 8. It is not stored anywhere else, and it is not shared with anyone outside the company that employs you, other than the customer you deliberately sent it to.

The app collects no analytics, contains no advertising, uses no third-party tracking, and does not read your contacts, your location, your calendar or your microphone.

You can withdraw either permission at any time in your phone's own settings. The rest of the app carries on working; only sending a picture stops.

To delete your data, see Data deletion — the same route applies whether you use the app or the website.

11. International transfers

Our servers are hosted in the European Union. If your data moves between countries, we rely on legally recognised safeguards for that transfer.

12. Children

Omnitik is a business tool and is not directed at children under 16. We do not knowingly collect their data.

13. Changes

If we change this policy we will update the date at the top, and we will tell account holders directly when a change is significant.