Trust center
Privacy notice
How OM Chat handles account, workspace, customer, and operational information—and where connected providers have their own responsibilities.
Effective July 16, 2026
1. Scope and roles
This notice explains how Runner Concepts handles personal information for the OM Chat website, account experience, and hosted automation service. It does not govern the independent practices of providers you connect, such as an email, AI, social, database, or payment provider.
For account, website, support, and commercial information, Runner Concepts generally acts as the business or controller. For contacts and conversation data submitted to a customer workspace, the customer determines the purpose of processing and Runner Concepts generally acts as a service provider or processor.
2. Information we collect
- Account information, such as name, email address, workspace membership, role, and authentication events.
- Commercial information, such as selected plan, subscription status, invoices, and support history when billing is enabled.
- Workspace content, such as contacts, conversation events, workflow definitions, execution logs, notes, labels, and provider metadata submitted through the service.
- Technical and security information, such as IP address, browser or device details, request timestamps, audit events, error records, and rate-limit signals.
- Communications you send when requesting a demo, support, security review, or other assistance.
3. How we use information
- Provide, authenticate, secure, maintain, and troubleshoot OM Chat.
- Create and isolate workspaces, execute configured automations, and deliver supported provider actions requested by the customer.
- Respond to requests, send service communications, and administer plans or payments.
- Detect abuse, protect users and infrastructure, enforce terms, and comply with applicable law.
- Understand product performance and improve reliability, accessibility, and user experience.
4. Customer content and connected providers
Customers choose the contacts, events, workflow content, provider accounts, and instructions submitted to a workspace. Customers are responsible for having a lawful basis, required notices, consent, and messaging permissions for that data and activity.
OM Chat supports a bring-your-own-provider model. When you connect a provider, information may be sent to and returned by that provider under your agreement with it. Provider credentials are intended to remain server-side and be represented to normal product surfaces only through redacted metadata.
5. How information is shared
We do not sell personal information for money. We may share information with infrastructure, identity, database, hosting, delivery, payment, observability, and support providers when needed to operate OM Chat; with providers you explicitly connect; with professional advisers; during a corporate transaction; or when required to protect rights or comply with law.
Each customer controls which team members can access its workspace. Workspace roles and server-side checks are designed to prevent records, credentials, and operations from crossing tenant boundaries.
6. Retention and deletion
We retain account and workspace information for as long as reasonably needed to provide the service, meet contractual or legal obligations, resolve disputes, and protect the service. Retention can differ by record type, workspace configuration, provider integration, backup lifecycle, and applicable law.
Customers may request export or deletion assistance by contacting the address below. Some records may remain for a limited period in backups, security logs, financial records, or other records we must preserve.
7. Security
OM Chat uses technical and organizational measures designed to protect personal information, including authenticated routes, workspace scoping, role checks, server-only credential access, signed ingress paths, rate limits, and release guardrails. No system is perfectly secure, and these controls do not amount to a guarantee against every risk.
OM Chat does not currently claim SOC 2, ISO 27001, HIPAA, or another formal security certification. See the Security page for the current control and certification posture.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information. You may also have the right to withdraw consent or appeal a response. We may need to verify your identity and determine whether Runner Concepts or an OM Chat customer is responsible for the request.
For information contained in a customer workspace, contact that customer first. For information controlled by Runner Concepts, email infra@runnerconcepts.com.
9. International processing and children
OM Chat and its providers may process information in countries other than where you live. Where required, appropriate contractual or legal transfer mechanisms should be used.
OM Chat is a business service and is not directed to children under 13 or the higher minimum age required by local law. Do not submit children’s personal information without an appropriate legal basis and authorization.
10. Changes and contact
We may update this notice as the service, providers, or legal requirements change. We will post the updated date here and provide additional notice when required.
Questions or requests can be sent to infra@runnerconcepts.com. Include enough information for us to understand the request, but do not email provider secrets or sensitive customer content.