Omega CS

Privacy policy

Last updated 11 September 2026

Omega CS is a customer relationship management service operated by Source Digital, Perth, Western Australia ("we", "us"). This policy explains what personal information we collect, why, how it is stored, and the choices you have. We handle personal information in line with the Australian Privacy Act 1988 and the Australian Privacy Principles.

Who this covers

Two groups of people. Account holders: the businesses that sign up for Omega CS and the team members they invite. Their customers and enquirers: the people whose details a business stores in its workspace, for example someone who fills in an enquiry form, sends a text, or submits a Facebook lead ad. For that second group, the business is the one collecting the information and deciding how it is used; we process it on the business's behalf.

What we collect

  • Account details: name, email, mobile number, business name, ABN and address, login credentials, and the answers given during sign-up such as services offered and pricing notes.
  • Customer and enquiry data entered or received by a business: names, phone numbers, email addresses, suburbs, messages, quotes, jobs and invoices, and notes the business or its assistant adds.
  • Conversations: text messages and emails exchanged between a business's number or address and its customers, including replies written by the AI assistant.
  • Facebook and Instagram data, only when a business connects its Page: lead form submissions (the answers a person gave), the campaign, ad set, ad and form each lead came from, the Page and ad account names, and daily advertising spend and results for that business's own ad account.
  • Calendar data, only when a business connects Google Calendar or Outlook: the list of calendars on the account, the events in the calendar the business chooses, and the email address of the connected account. The calendar section below says exactly what is read and written.
  • Payment details: handled by Stripe. We store a customer reference and the plan chosen, never card or bank numbers.
  • Technical data: approximate location of a website visitor at the city level when they submit a form, browser type, and the pages of the service used, for security and to trace which advertising produced an enquiry.

Why we use it

  • To run the service: deliver enquiries to the right business, let the assistant reply, book calls, produce quotes and invoices, and show the business its pipeline and results.
  • To answer enquiries automatically. Message content is sent to an AI model provider to draft replies. Providers process it on our instructions and do not use it to train their models.
  • To send and receive text messages and emails on behalf of a business through our messaging providers.
  • To show a business what its advertising costs and produces, including sending the outcome of a lead (booked, became a customer) back to Meta when the business has switched that on.
  • To bill for the service and to meet legal obligations, including tax records.
  • To keep the service secure and to investigate misuse.

Who we share it with

We do not sell personal information. We share it only with providers that help us run the service, each bound to use it solely for that purpose:

  • Supabase, our database and file storage, hosted in Sydney, Australia.
  • Vercel, which runs the application, with servers in Sydney.
  • Twilio, for text messages, and Resend, for email.
  • Anthropic and OpenAI, to draft and classify messages and to search a business's own documents.
  • Stripe, for payments and invoices.
  • Meta Platforms, when a business connects its Facebook Page or reports lead outcomes back to its ads.
  • Xero, when a business connects its accounting.
  • Google and Microsoft, when a business connects its Google Calendar or Outlook calendar.
  • Sentry, for error reporting, which may include technical details of a request.

Some of these providers process data outside Australia, in the United States. We choose providers with recognised security practices and contractual commitments to protect personal information.

Facebook and Instagram data

Data received through Meta's platform is used only to deliver a business's own leads into its workspace, to show that business the performance of its own advertising, and, where the business enables it, to report lead outcomes back to Meta's advertising system. It is not combined across businesses, not used for our own advertising, and not shared with anyone else. A business can disconnect its Page at any time under Settings, which stops all further access. Meta data-deletion requests are honoured automatically through Meta's callback, and a business can ask us to delete Meta-sourced data at any time.

Google Calendar and Outlook data

A business can connect a Google Calendar or an Outlook calendar under Settings, Integrations, so the assistant offers times that are actually free and bookings land in the calendar the business already uses. We access a calendar only after the account holder signs in with Google or Microsoft and approves the connection.

What we ask Google for. Permission to see the list of calendars on the account, so the business can choose one; permission to see and edit the events on that calendar; and the email address of the Google account, so the workspace can show which account is connected.

What we read. The events in the chosen calendar for the days the business is looking at in its workspace, and around any time the assistant is about to offer or confirm. We use them to show the business its own calendar next to its bookings and to stop the assistant offering or booking a time that is already taken. Event details appear in the business's own workspace only. They are not stored in our database, not sent to the AI model provider, and never shown to customers.

What we write. One event for each booking made through Omega CS, holding the customer's name, contact details and enquiry notes. When the customer's email address is known they can be added as a guest, so the calendar sends them the invitation. When a booking is cancelled in Omega CS we delete that event. We do not change or delete anything else in the calendar.

How it is stored and protected. The access and refresh tokens Google issues are encrypted at rest with a key held outside the database, decrypted only at the moment of use, and never written back in plain text. We also keep the connected email address and the id of the chosen calendar, nothing else from the account.

Who sees it. No one outside the business. Calendar data is never sold, never shared with third parties, never used for advertising, never used to train AI models, and never combined with another business's data.

Disconnecting. Disconnect under Settings, Integrations, and the stored tokens, calendar choice and email address are deleted straight away. Events already in the calendar stay there, and the business can remove them in its calendar. Access can also be withdrawn from the third-party access page of the Google Account, after which our stored tokens stop working. When an account is closed, the connection is deleted with everything else within 90 days.

The Outlook connection works the same way through Microsoft Graph, with the same reading, writing, storage and disconnection rules.

Omega CS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Advertising measurement on omega-cs.com

Our own public pages (the home page and sign-up) use the Meta Pixel and Meta's Conversions API so we can tell which of our advertisements led someone to start a trial. The Pixel sets cookies (_fbp, _fbc) in your browser. When you start a trial we send Meta the fact that a sign-up happened, together with your email address and mobile number in hashed form, so the event can be matched to the advertisement without Meta receiving the readable values. This measures our advertising only; it is never applied to the customers of a business that uses Omega CS. You can block the Pixel with a browser extension or your browser's tracking settings, and the sign-up works the same without it.

How long we keep it

For as long as a business has an account, so it can run its business from its records. When an account is closed we delete or de-identify its data within 90 days, except records we must keep by law, such as tax invoices. A business can delete individual contacts and conversations at any time, and can export its data before closing.

Security

Data is encrypted in transit and at rest. Each business's workspace is isolated from every other by row-level security in the database. Access tokens for connected services are encrypted with a key held outside the database. Staff access to customer data is limited to what support requires and is logged.

Your choices and rights

  • Ask us what personal information we hold about you and to correct it.
  • Ask us to delete it, subject to records we must keep.
  • Opt out of text messages by replying STOP; the service records this and stops messaging that number.
  • Complain to us, and if you are not satisfied, to the Office of the Australian Information Commissioner at oaic.gov.au.

If you are a customer of a business that uses Omega CS, contact that business first; they control the information about you. We will help them respond.

Contact

Source Digital, Perth, Western Australia. sales@source-digital.com.au

We update this policy when the service changes. The date at the top shows the current version.