Privacy Policy
This Privacy Policy explains how Omegatheme ("we", "us", or "our") collects, uses, discloses, and protects personal data in connection with the Omegatheme applications and related services provided through the Shopify platform (the "Services"), and our website.
By installing the Omegatheme app, using the Services, or visiting our website, you acknowledge that you have read and understood this Privacy Policy.
1. Scope and Our Role
1.1 Controller. We act as a "controller" (or equivalent) of personal data when we determine the purposes and means of processing, including: (a) information about merchants and their personnel who install or use the Services; (b) visitors to our website; and (c) data used for our own marketing, billing, support, security, and product-improvement purposes.
1.2 Processor. When we process personal data of a merchant's end users and store visitors on behalf of, and under the instructions of, the merchant, we act as a "processor" (or "service provider"). For that processing, the merchant is the controller/business, the merchant's own privacy policy governs, and our obligations are set out in our Data Processing Addendum ("DPA"). This Privacy Policy does not replace the merchant's privacy notice to its end users.
1.3 This Policy primarily describes our processing as a controller. Where we act as a processor, please refer to the DPA.
2. Personal Data We Collect
2.1 From merchants (as controller):
- Account and store information: store URL, store domain, store plan, store owner name, email address, country, date of installation/uninstallation.
- App usage data: operations performed inside the app (integrations, access management, professional services), preferences and settings.
- Billing information: billing history (payment card details are handled by Shopify; we do not store them).
- Support communications: information you provide when contacting support.
2.2 From end users / store visitors (as processor, on behalf of merchants):
- Identifiers and online identifiers (e.g., user/device IDs, IP address, cookie and storage values, advertising identifiers).
- Contact and order-related information provided at checkout (e.g., email, phone, address), where configured by the merchant.
- Device, browser, session, event, behavioral, location (derived from IP), and time-based data.
These categories are described in more detail in Section 5.2 of the DPA. We process this data under the merchant's instructions.
2.3 From website visitors (as controller):
- Device and usage data, IP address, cookies and similar technologies, and any information you submit through forms.
2.4 Special categories. We do not intentionally collect special categories of personal data (e.g., health, biometric, or political data) unless explicitly instructed by a merchant in its capacity as controller.
3. How We Use Personal Data and Legal Bases
As a controller, we use personal data to:
- Provide, operate, maintain, secure, and improve the Services and our website (legal basis: performance of a contract; legitimate interests).
- Process billing and manage accounts (performance of a contract; legal obligation).
- Provide customer support and communicate Service-related notices (performance of a contract; legitimate interests).
- Send marketing communications where permitted, with the ability to opt out (consent or legitimate interests).
- Detect, prevent, and address fraud, abuse, and security incidents (legitimate interests; legal obligation).
- Comply with legal obligations and enforce our agreements (legal obligation; legitimate interests).
- Create and use anonymized and aggregated data that does not identify any individual, to operate and improve our products (legitimate interests).
Where we rely on consent, you may withdraw it at any time. Where we rely on legitimate interests, you may object as described in Section 7.
5. International Data Transfers
We and our sub-processors may process personal data in countries other than your own. Where personal data is transferred internationally, we implement appropriate safeguards consistent with applicable data protection law, including contractual data protection obligations with our sub-processors and the technical and organizational measures described in the DPA. Where required, we comply with cross-border transfer obligations under applicable law, including Vietnam's Personal Data Protection Decree (Decree No. 13/2023/ND-CP).
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including providing the Services, complying with legal obligations, resolving disputes, and enforcing our agreements. Merchant account data is retained for the duration of the service relationship; end-user data is retained as configured by the merchant and in accordance with the DPA. We may retain limited data in backups, audit logs, or for fraud-prevention and security purposes, after which it is securely deleted or anonymized.
7. Your Rights
7.1 Depending on your location, you may have rights to: access; rectify; erase; restrict or object to processing; data portability; and withdraw consent. Under U.S. state privacy laws, you may have rights to know/access, delete, correct, opt out of sale/sharing, and limit the use of sensitive personal information, and not to be discriminated against for exercising these rights.
7.2 If you are a merchant's end user, please direct your request to the relevant merchant (the controller). If we receive such a request directly, we will refer it to the merchant in accordance with the DPA.
7.3 To exercise rights relating to data for which we are the controller, contact us at [email protected]. We may need to verify your identity before responding. You also have the right to lodge a complaint with a competent supervisory authority.
8. Security
We implement appropriate technical and organizational measures to protect personal data, including encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, pseudonymization of identifiers, monitoring, and personnel confidentiality obligations. Further detail is set out in the DPA. No method of transmission or storage is completely secure, and you are responsible for safeguarding your account credentials.
10. Children's Privacy
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data directly from children. Merchants are responsible for ensuring their own compliance with applicable children's privacy laws.
11. Shopify Data
As a Shopify application, we access and process certain data through the Shopify platform in accordance with Shopify's policies and the permissions you grant. We honor Shopify's mandatory privacy/compliance webhooks (including data access and deletion requests) as described in the DPA.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will provide notice of material changes by email or through a prominent notice within the Services or on our website. Your continued use of the Services after an update takes effect constitutes acceptance of the updated Policy.
13. Contact Us
Công ty Cổ phần Phần mềm Cyber (Cyber Software Joint Stock Company)
No. 3, Alley 175/55 Lac Long Quan, Tay Ho Ward, Hanoi City, Vietnam
Business Registration No. / Tax Code (MST): 0109598571
Email: [email protected]
Get started
Get in touch with us. We're here to assist you.

Subscribe to get our newest updates
Enter your email address below to get new notifications