Collection, use, and protection of your personal information.
Effective: June 6, 2026
This Privacy Policy explains how Omega Tech Ventures, Inc., a corporation organized under the laws of the State of Delaware, operating as OmegaFP ("we", "us", "our") collects, uses, and protects personal information when you use our CRM and AI-powered Services.
By using the Services, you agree to the practices described in this Policy.
This Policy applies to:
If we act as a processor/service provider for your organization, our use of personal information is governed by our agreement with you and this Policy.
We collect the following categories of information, depending on how you use the Services:
When you connect or import from Third-Party CRMs, we may process:
If you (or your firm) use the AI Notetaker, we process:
Recording consent and wiretapping laws. Recording a conversation is regulated in every U.S. state and many other jurisdictions. California (Cal. Penal Code § 632), Florida, Illinois, Massachusetts, Maryland, Montana, New Hampshire, Pennsylvania, and Washington are "all-party consent" states — every participant must be informed and consent before a recording begins. The California Invasion of Privacy Act (CIPA, Cal. Penal Code § 631) further restricts the transmission of recorded content to third parties without consent.
OmegaFP provides the recording tool. Our customers (advisors and firms) are responsible for obtaining the legally required consent from every participant before enabling the AI Notetaker for any meeting that involves participants in an all-party-consent jurisdiction. If you are a meeting participant and you have questions about whether you consented, contact the firm that scheduled the meeting; OmegaFP cannot speak to the consent practices of any individual firm.
Third parties involved in transcription and analysis. Recordings and transcripts are processed through Amazon Bedrock. Depending on the selected model, Amazon Bedrock may run a model supplied by Amazon or Anthropic within the AWS service boundary. OmegaFP does not send this content directly to OpenAI or Anthropic services under the current production configuration. Only the content needed to produce the requested output is sent to Amazon Bedrock. See Section 8.1 for the current subprocessor description.
If your firm uses OmegaFP's two-way SMS feature, we may process:
See Section 17 (SMS / Text Messaging Policy) for full details on how consent is collected and how you can opt out.
If your firm uses OmegaFP Clips, a Chrome extension companion to OmegaFP, you can create short screen, tab, window, and/or camera recordings ("clips") and save them to your OmegaFP workspace. This section describes information involved in that feature in addition to the general categories above (including Section 3.3 where clips may include audio or video).
What you record becomes Customer Data. Clips can include anything visible or audible in the capture you choose (for example, shared screen content, your camera feed, and microphone audio if you enable it). You should only record content you are permitted to capture and that your firm's policies allow.
What we do not do with Clips: We do not sell clip content. We do not use clips to serve third-party ads. We do not operate the extension as a general-purpose tracker of your browsing; recording occurs only when you explicitly start a capture through the extension.
Controls. You can stop using the extension at any time, revoke browser authorization from OmegaFP where that control is offered, and manage or delete saved clips within the OmegaFP application according to your role and your firm's settings. Firm administrators may control whether Clips is available.
When you connect your Gmail or Outlook account to OmegaFP, we access and process email data to provide email management features within our CRM platform.
When you authorize Gmail access, we request the following permissions:
When you authorize Outlook access, we request the following permissions:
We use email integration data solely to:
You can disconnect your Gmail or Outlook integration at any time from your OmegaFP settings. You can also revoke access directly from your Google Account settings (Security → Third-party apps) or Microsoft Account settings (Privacy → Apps and services).
When you connect your calendar, we access event data to help you manage meetings and scheduling within OmegaFP.
When a household connects their financial accounts to OmegaFP, we use third-party account aggregation providers to retrieve account data on the household's behalf. The advisor managing the household uses this data to build and maintain the household's financial plan inside OmegaFP. We do not move money from these accounts.
OmegaFP integrates with the following aggregators. Which provider is used depends on the type of institution the household selects:
Depending on the provider and the permissions granted, we may receive:
We do not request or receive routing or full account numbers, and we do not request payment authorization permissions. OmegaFP cannot initiate transfers, debits, or other money movement from connected accounts.
Aggregation data is used solely to:
Aggregation data is shown only to the licensed advisor managing the household (and the firm-authorized administrators above them). It is not exposed to other firms, advisors, or OmegaFP customers.
Aggregation data is stored exclusively in the United States, on Amazon Web Services infrastructure (RDS, S3, ElastiCache) within U.S. AWS regions. Access tokens issued by the aggregation providers are encrypted at rest using AWS KMS-managed keys and AES-256-GCM encryption. Tokens are never logged, transmitted to client browsers, or shared outside OmegaFP and the relevant aggregation provider.
You or your advisor may disconnect a linked institution at any time:
After a connection is disconnected, the cached balances, transactions, holdings, and ownership details we previously retrieved remain stored under our retention schedule (see Section 10) until your advisor or your firm administrator removes them or your household record is deleted. Aggregation tokens are immediately invalidated on disconnect.
The aggregation providers receive and process your data under their own privacy policies and applicable Terms of Service. By choosing to connect an institution, you also agree to the relevant provider's terms:
We use personal information to:
We do not sell personal information. We do not use Customer Data for advertising or marketing to third parties.
Where applicable (e.g., in the EEA/UK), we process personal information based on:
We may share personal information with:
These providers process data on our behalf under written agreements with confidentiality and security obligations consistent with industry standards.
When you connect a Third-Party CRM, email provider (Gmail, Outlook), or other integration, we share or receive information as configured by you. Data shared with Third-Party Services is governed by their own privacy policies.
In connection with a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of the transaction, subject to appropriate safeguards.
We may disclose information if required by law or to:
9.1 We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized or unlawful access, use, disclosure, alteration, or destruction.
9.2 Our security program includes controls aligned with recognized frameworks and SOC 2–style practices, such as:
9.3 While we take these measures, no security program can guarantee absolute security. You are responsible for maintaining the security of your systems, devices, and credentials.
10.1 We retain personal information for as long as necessary to:
10.2 After termination of your account, we may:
If you require specific retention or deletion arrangements, contact us or refer to your enterprise agreement.
We may process and store personal information in countries other than where it was collected. Where required, we implement appropriate safeguards for cross-border transfers, such as contractual protections.
Depending on your jurisdiction, you may have rights such as:
To exercise rights, contact us at privacy@omegafp.com. We may need to verify your identity and coordinate with your organization (if you are an end user of a firm customer).
We use cookies and similar technologies to operate, secure, and improve the Services.
Required for authentication, session management, and security (including CSRF protection). These cookies cannot be disabled without losing access to the Services. Duration: session or up to 24 hours.
Store your settings such as theme (light/dark mode), layout preferences, and timezone selection. Duration: up to 1 year.
Help us understand usage patterns and improve the Services by collecting aggregated, non-personally-identifiable usage metrics. Duration: up to 2 years.
We do not use advertising or tracking cookies. OmegaFP does not serve advertisements and does not use cookies to track you across third-party websites.
Our payment processor (Stripe) and authentication provider (AWS Cognito) may set their own cookies when you interact with payment or login features. These cookies are subject to those providers' respective privacy policies and are outside OmegaFP's direct control.
You can control and delete cookies through your browser settings. Most browsers allow you to block or delete cookies via their privacy or settings menus. However, disabling essential cookies may prevent you from logging in or using the Services. For more information, consult your browser's help documentation.
OmegaFP does not currently respond to "Do Not Track" (DNT) browser signals because there is no universally accepted standard for how to interpret or respond to DNT signals. We will update this practice if a standard is adopted.
The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe we have collected such information, contact us so we can take appropriate action.
We may update this Privacy Policy from time to time. If changes are material, we will provide notice (e.g., via the app or email). Your continued use of the Services after the effective date of an updated Policy constitutes your acceptance.
This Privacy Policy and any dispute arising hereunder shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to its conflict-of-law principles.
OmegaFP enables financial advisors to send and receive text messages with their clients through our platform. Before any SMS messages are sent, the advisor's firm must obtain express written consent from each client. Consent is collected through the firm's OmegaFP booking page: when a client schedules a meeting, they enter their mobile number and must affirmatively check an SMS consent box (unchecked by default) that discloses the program, that message frequency varies, that message and data rates may apply, and that they can reply STOP to opt out or HELP for help at any time. The exact consent language the client agreed to, along with a UTC timestamp, is recorded with the client's meeting record. Checking the box is optional and is not a condition of booking or of receiving services; clients who do not opt in receive email-only confirmations. No SMS is sent to a client unless this consent has been recorded. Clients may manage their consent at any time by replying STOP to opt out or JOIN to opt back in.
By opting in, clients agree to receive text messages from their financial advisor's firm via OmegaFP, which may include:
Message frequency varies by firm and client relationship. Message and data rates may apply.
Clients can opt out of SMS messages at any time by replying STOP to any message. Upon receiving a STOP reply, OmegaFP will immediately cease sending messages to that phone number and record the opt-out. Clients may also reply HELP at any time to receive assistance information.
All SMS messages sent and received through OmegaFP are archived in compliance with applicable SEC and FINRA recordkeeping requirements (including SEC Rule 17a-4 and FINRA Rule 4511). Archived messages are stored in WORM (Write Once, Read Many) format for a minimum of five years. Opt-in and opt-out records are retained for the same period.
Mobile information, SMS opt-in data, and consent records will not be shared with third parties or affiliates for marketing or promotional purposes. SMS data is used solely to deliver messages, maintain compliance records, and operate the platform. The categories of data covered by this commitment include phone numbers, opt-in/opt-out timestamps, consent text the client agreed to, message content exchanged, and delivery status metadata.
We may share SMS-related information only with the limited set of sub-processors necessary to deliver the message (see Data Processing Agreement, Schedule A for the current list). These sub-processors are contractually prohibited from using mobile information for any purpose other than message delivery on our behalf.
SMS messages are delivered through Amazon Web Services End User Messaging (Pinpoint SMS Voice V2), operating under our AWS account in the United States. AWS processes recipient phone numbers, message content, opt-out registrations, and delivery-status events strictly to deliver SMS on OmegaFP's behalf. AWS is bound by its own customer agreement and AWS Acceptable Use Policy, both of which prohibit the use of customer data for AWS's own marketing purposes.
Message frequency varies depending on the firm's communication patterns and the client's engagement (typical range: 1–10 messages per month per advisor relationship; appointment reminders may add 1–4 messages around scheduled meetings). Message and data rates may apply based on the client's mobile carrier and plan. Consent to receive SMS is not a condition of receiving services from OmegaFP or the advisor's firm. SMS delivery is subject to mobile carrier delivery windows, network availability, and carrier filtering rules; OmegaFP does not guarantee delivery of any individual message.
For privacy-related questions or requests: