The short version
Omnix is desktop software. Your business data — customers, products, sales, prescriptions, employees — is written to a local database on your machine and does not leave it unless you turn on cloud backup or share an export with support.
This policy covers the account data we hold to run your licence, the optional diagnostics you can send us, optional cloud backup, and the third parties involved.
Data that stays on your device
Business data (local by default): customer names, product names, sale amounts, prescriptions, employee details, and bank transactions live in a SQLite database file on your Windows machine. We never see this data unless you contact support and choose to share an export.
Omnix does not encrypt the local database file itself. Access to it depends on your Windows account, physical access to the computer, and any full-disk encryption you configure. Securing the device is your responsibility; the software keeps the record local so that responsibility stays with you.
Account data we hold
To operate your account and licence we store your name, email, phone, business name, KRA PIN (if you provide one), licence keys, activated machines, and payment history. This is the minimum needed to issue a licence, bind it to a device, and support you.
We do not sell your data to anyone.
Telemetry and diagnostics
Diagnostics are opt-in. If you enable them, Omnix may send the app version, the operating-system version, the active module, error logs, and aggregated counts such as the number of branches, users, and sales — plus a random session identifier that is not tied to your identity. You can turn this off at any time in Settings → Privacy.
What is never sent: customer names, product names, sale amounts, prescriptions, employee names, national IDs, KRA PINs, bank account numbers, M-Pesa till numbers, or any free-text you type. Diagnostics are used to fix bugs and prioritise work — never sold or shared with third parties.
Website analytics (optional, opt-in)
This website can measure anonymous page visits with Google Analytics, but only if you choose “Accept analytics” in the notice we show you. Until you accept, no analytics script loads and no request is made to Google. If you never accept, nothing is measured.
Your choice is stored on your device in local storage, not in a cookie, and it is not tied to any identifier we could use to recognise you. If your browser sends a Do Not Track or Global Privacy Control signal, analytics stays off and we do not ask.
What a page view records: a normalised page path drawn from a fixed allowlist of public pages (for example /ke/pharmacy) and the site origin — nothing more. Article, guide, and location pages are recorded by a generic template such as /ke/blog/article, never the specific slug, and any path we do not recognise is recorded as /ke/not-found. We do not send the page title, the query string, the fragment after a #, the page you came from, or the full address. Checkout, account, and admin pages sit outside this measurement, so a payment, order, or licence reference can never reach it.
What a conversion records: for a small set of actions (a completed demo request, a WhatsApp click, starting a product video), we send the event name plus up to three fixed labels: which product, which country, and which control. No name, email, phone, business name, message, amount, or reference is ever included.
You can change your mind at any time with Analytics preferences in the site footer, without clearing your browser storage. Turning analytics off does not affect the product, your purchase, or the support you receive. This is our own practice, not a certification or a legal guarantee.
Cloud backup (optional)
Cloud backup is an optional add-on (KES 500 per month per branch). When it is on, each snapshot of your local database is encrypted on your device with AES-256-GCM before it is uploaded to Cloudflare R2 storage we operate from London. The encryption key is derived from your password plus your licence key, so the Omnix team cannot decrypt your backup.
You can delete your cloud backups at any time from your dashboard.
Third parties we rely on
Paystackprocesses payments. We share the name, email, phone, and amount needed to take payment; Paystack’s own privacy terms apply.
Resend sends transactional email such as a licence key or a compliance-renewal reminder. We share your name and email for that purpose.
Cloudflare R2 stores cloud backups if you enable them. Data is encrypted on your device before it reaches Cloudflare.
Google Analyticsmeasures anonymous page visits on this website, and only after you opt in. Before you accept, no request reaches Google. See “Website analytics” above for exactly what is sent.
If you connect an AI provider, you supply your own key and requests go directly from your machine to that provider — we do not see your prompts, responses, or keys.
Your choices
You can:
- Ask for a copy of the account data we hold — email support@omnix.co.ke.
- Ask us to delete your account; we remove account data within 30 days.
- Turn diagnostics off in Settings → Privacy.
- Export your business data from within Omnix at any time.
- Delete your cloud backups from your dashboard.
Contact
Questions about this policy? Email support@omnix.co.ke, or reach us on WhatsApp at +254740455200.