Privacy Policy

Last updated: 1 July 2026

1. Who We Are

Omnistream (“we”, “our”, “us”) is a B2B financial intelligence platform that helps Indian businesses analyse bank statements, identify cost-recovery opportunities, and manage invoices. We act as the Data Fiduciary for the personal data described below and are committed to protecting it in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act).

2. Data We Collect

  • Email address (for sign-in via Google or an email magic link)
  • Business name, GSTIN, PAN, owner email (optional, set in Settings)
  • Bank statements and vendor bills (payables) you upload (PDF files)
  • Parsed transaction data, X-Ray findings, and spend/business intelligence results
  • Invoice and buyer-contact data you create, and payment references (e.g. UPI transaction/UTR IDs) you submit
  • Your questions to the AI assistant and the resulting conversation history
  • Limited technical/usage logs, email open events, and invoice-portal interaction events (see Section 8)

3. How We Use Your Data

  • To provide bank statement analysis and X-Ray findings
  • To produce business/spend intelligence and vendor payment-timing guidance
  • To answer your questions in the AI assistant using your own data
  • To generate, send, track, and collect on invoices (including UPI/QR links) and manage vendor bills
  • To calculate financial impact and queue actionable items
  • To authenticate your sign-in and send transactional emails
  • To operate, secure, and improve the service

We process this data to perform our contract with you and for our legitimate business purposes of operating the service. We do not sell your data or use it for third-party advertising.

4. AI Processing of Your Data

To generate X-Ray findings, extract invoice/bill details, and answer your questions in the AI assistant, relevant transaction text and a summary of your own figures are processed by our AI sub-processor, Anthropic (Claude API). When you use the assistant, your question and a grounded summary of your financial data are sent so it can answer from your numbers. This processing may occur on infrastructure located outside India. Anthropic processes this content only to return results to us and does not use your data to train its models under our API terms. We send only the data needed for the task.

5. Data Storage

Your records are stored in Supabase infrastructure in the Mumbai (ap-south-1) region. Bank statement PDFs are held in encrypted object storage, and database records are encrypted at rest. Access is isolated per organisation using row-level security.

6. Data Retention

Your uploaded statement PDF is deleted from storage immediately after a successful parse. If a parse fails, the file is retained for no more than 72 hours to allow re-processing, after which it is removed; as a backstop, any residual statement files are purged within 90 days. Parsed transaction data, findings, invoices, and your AI-assistant conversation history are retained while your account is active and are removed when you delete your data or close your account.

7. Your Rights Under the DPDP Act

As a Data Principal you have the right to access, correct, and erase your personal data, to withdraw consent, to nominate another person to exercise your rights, and to grievance redressal. You can permanently delete all your data at any time using Settings → Delete All My Data — this is immediate and irreversible. For any other request, contact our Grievance Officer (Section 9).

8. Cookies, Tracking & Analytics

We use essential session cookies required for authentication. We may use privacy-respecting product analytics (such as PostHog) to understand feature usage and improve the service; we do not use third-party advertising or cross-site tracking cookies. Our invoice and collection emails include a standard 1×1 open-tracking pixel so we can show you whether an invoice email was opened; you can block remote images in your email client to opt out. When you share an invoice payment link, we also record basic interaction events on that page (such as views and downloads) so we can show you delivery, opened, and downloaded status in your invoice Money Tracker.

9. Third-Party Sub-Processors

  • Supabase — database, auth, and encrypted storage (Mumbai region).
  • Anthropic — AI processing of statement/invoice text (see Section 4).
  • Razorpay — payment processing. We never store card details; Razorpay is PCI-DSS Level 1 certified.
  • Google — sign-in (OAuth) when you choose “Continue with Google”.
  • Resend — sign-in magic links, transactional and collection email delivery.
  • Vercel — application hosting.
  • Sentry — error monitoring and reliability diagnostics.
  • PostHog — privacy-respecting product analytics (feature usage).

10. Grievance Officer & Contact

In accordance with the DPDP Act 2023, our Grievance Officer is Tarun Krishna. For privacy questions, data requests, or complaints, contact privacy@omnistream.co.in (we aim to respond within the timelines required by law). You may also reach us via our Contact page.