Privacy Policy
Last updated: July 27, 2026
This Privacy Policy explains how Orbitra ("Orbitra", "we", "us", or "our"), the provider of the Orbitra platform available at orbitra.app (the "Service"), collects, uses, discloses, and protects personal data when you visit our website, create an account, or use the Service.
We are committed to protecting your privacy and handling your data in an open and transparent manner, in accordance with the EU General Data Protection Regulation ("GDPR") and other applicable data protection laws.
1. Who we are (Data Controller)
Orbitra is the data controller responsible for your personal data collected through the Service. For any questions about this Policy or our data practices, contact us at privacy@orbitra.app.
2. What data we collect
We collect the following categories of data:
- Account data: name, email address, password (hashed), company name, and role, provided when you sign up or log in.
- Billing data: billing address, payment method details, and transaction history, processed on our behalf by our payment processor (Stripe). We do not store full payment card numbers on our own servers.
- Outreach and campaign data: prospect lists, lead information, message templates, and conversation content that you upload, generate, or connect to the Service (including data synced from connected Email, LinkedIn, or WhatsApp accounts) in order to provide the Service's core functionality.
- Connected account credentials/tokens: authentication tokens required to send and receive messages on your behalf through connected channels.
- Usage data: log data, device and browser information, IP address, pages visited, features used, and interaction timestamps.
- Cookies and similar technologies: as described in our Cookie Policy.
- Communications: information you provide when you contact support, request access, or respond to surveys.
3. How we use your data
We use personal data to:
- Provide, operate, and maintain the Service, including AI-generated outreach messages, the unified inbox, and lead discovery features;
- Create and manage your account and process subscription payments;
- Send transactional communications (e.g. account, billing, and security notices);
- Send product updates or marketing communications, where you have consented or where permitted by law, with an option to opt out at any time;
- Monitor, analyze, and improve the performance, security, and functionality of the Service;
- Detect, investigate, and prevent fraudulent, unauthorized, or illegal activity;
- Comply with legal obligations and enforce our Terms of Service.
4. Legal basis for processing (EU/UK users)
Where the GDPR applies, we rely on the following legal bases:
- Contract: processing necessary to provide the Service you subscribed to.
- Legitimate interests: improving and securing the Service, preventing fraud, and direct marketing to existing customers, balanced against your rights.
- Consent: non-essential cookies, marketing communications to prospects, and any processing where consent is required by law. You may withdraw consent at any time.
- Legal obligation: processing required to comply with tax, accounting, or other applicable laws.
5. Cookies and tracking technologies
The Service uses cookies and similar tracking technologies to operate the website, remember preferences, and analyze usage. Full details, including how to manage or disable cookies, are set out in our Cookie Policy.
6. Third-party services
We share personal data with the following categories of third parties, solely to operate the Service:
- Payment processing: Stripe, Inc. (subscription billing and payment processing).
- Cloud infrastructure and hosting: DigitalOcean (VPS hosting) and Cloudflare (DNS, CDN, email routing).
- Database and authentication: Supabase (PostgreSQL database, user authentication, and file storage).
- Messaging channel providers: Unipile (unified API for LinkedIn and WhatsApp outreach and inbox). Email is sent via your own SMTP credentials — we do not relay your emails through our own servers.
- AI/language model providers: Google (Gemini 2.0 Flash) for generating outreach copy, AI replies, and running the conversation agent. Prompts and relevant context from your brief and conversation history are transmitted to generate outputs.
- Analytics tools: PostHog (product analytics, pseudonymized usage data).
These third parties are only permitted to process personal data for the purposes we specify and are bound by appropriate data processing agreements. We do not sell your personal data.
7. Data retention
We retain personal data for as long as your account is active and as necessary to provide the Service. Following account closure, we retain data for up to 90 days to allow for account recovery, and thereafter delete or anonymize it, unless a longer retention period is required to comply with legal, tax, or accounting obligations, or to resolve disputes. Billing records may be retained for up to 7 years as required by applicable tax law.
8. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request deletion of your personal data ("right to be forgotten");
- Request restriction of, or object to, certain processing;
- Request a portable copy of your data;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at privacy@orbitra.app. We will respond within the timeframe required by applicable law (generally within 30 days under GDPR).
9. Security
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or alteration, including encryption in transit, access controls, and regular security reviews. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. International data transfers
Your data may be transferred to, and processed in, countries other than your country of residence, including the United States, where our sub-processors are located. Where such transfers occur from the EEA/UK, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to ensure an adequate level of protection for your data.
11. Children's privacy
The Service is intended for business use by individuals who are at least 18 years old. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will take reasonable steps to delete it promptly.
12. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will post the updated version on this page and revise the "Last updated" date above. Material changes will be communicated via email or an in-product notice where required.
13. Contact us
If you have questions about this Privacy Policy or our data practices, contact us at:
Orbitra
Email: privacy@orbitra.app