Privacy Policy

Last Updated: August 12, 2026

1. Introduction

Welcome to OMOBL SSO Platform ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Single Sign-On (SSO) authentication service.

By using OMOBL SSO, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Personal Information

We collect information that you provide directly to us, including:

  • Name and email address
  • Profile information (photo, display name)
  • Organization and group memberships
  • Role and permission assignments
  • Authentication credentials (securely hashed)

2.2 Usage Information

We automatically collect certain information when you use our service:

  • Session data (login times, duration, IP addresses)
  • Device information (browser type, operating system)
  • Application access logs
  • Analytics data (usage patterns, feature interactions)
  • Audit trail information for security purposes

2.3 OAuth/OIDC Token Information

When you authenticate with third-party applications through our SSO service, we temporarily store OAuth tokens and related authentication data to facilitate secure access.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our SSO authentication service
  • Authenticate and authorize your access to applications
  • Manage user accounts, groups, and permissions
  • Monitor and analyze usage patterns and trends
  • Detect and prevent security incidents and fraud
  • Maintain audit logs for compliance and security
  • Send important service notifications and updates
  • Respond to your support requests and communications

4. Information Sharing and Disclosure

4.1 With Third-Party Applications

When you use our SSO service to access third-party applications, we share necessary authentication information (such as your identity and authorized scopes) with those applications in accordance with OAuth/OIDC protocols.

4.2 Within Your Organization

Group Admins and Master Admins in your organization may have access to certain information about users within their managed groups, including:

  • User profiles and group memberships
  • Application access permissions
  • Usage analytics and activity logs

4.3 Legal Requirements

We may disclose your information if required by law, court order, or governmental request, or to protect our rights, property, or safety.

5. Data Security

We implement industry-standard security measures to protect your information:

  • AES-256-GCM encryption for sensitive data (OAuth secrets, API keys)
  • Secure password hashing using bcrypt
  • TLS/SSL encryption for data in transit
  • Regular security audits and monitoring
  • Role-based access controls (RBAC)
  • Comprehensive audit logging

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Data Retention

We retain your information for as long as necessary to:

  • Provide our services to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain security and audit trails

Specifically:

  • Raw session data: 90 days
  • Aggregated analytics data: 2 years
  • Audit logs: As required by applicable regulations
  • User accounts: Until deletion requested or account inactivity exceeds policy limits

7. Your Rights and Choices

Depending on your jurisdiction, you may have certain rights regarding your personal information:

  • Access: Request access to your personal information
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and data
  • Data Portability: Request a copy of your data in a portable format
  • Opt-Out: Unsubscribe from non-essential communications

To exercise these rights, please contact your organization's administrator or reach out to us directly.

8. Third-Party Authentication

We use Clerk (clerk.com) as our authentication infrastructure provider. Clerk processes authentication data on our behalf in accordance with their privacy policy. We recommend reviewing Clerk's privacy policy to understand how they handle authentication data.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws different from your jurisdiction. We ensure appropriate safeguards are in place for such transfers.

10. Children's Privacy

Our service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date. Your continued use of our service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

OMOBL SSO Platform

Email: privacy@omobl.com

Website: https://sso.omobl.com