Untermanager
Die Infrastruktur und Dienstanbieter, die OrbitPage zur Bereitstellung des verwalteten Dienstes verwendet.
In Kraft und aktualisiert unter: 31. August 2026Diese Übersetzung dient der besseren Verständlichkeit. Maßgeblich bleibt die englische Fassung.
1. How to read this list
A provider can act as a processor, subprocessor or independent controller depending on the product and data involved. The list below covers the principal hosted-service providers. A self-hosted OrbitPage operator chooses and is responsible for their own providers.
2. Current providers
Google Firebase and Google Cloud
Authentication, email verification, Firestore database, Firebase App Check, reCAPTCHA Enterprise and related security infrastructure. Account, workspace, request and attestation data may be processed. Firebase Authentication processing is documented by Google as US-only; other locations depend on the configured service.
Firebase privacy and security Google Cloud Data Processing Addendum
Vercel
Hosts the OrbitPage marketing site, authentication UI, dashboard and server-side API routes. Processes HTTP request information, application logs and data handled by those functions.
Cloudflare
Provides R2 object storage, Worker delivery, edge caching, DNS, TLS, custom hostnames and abuse protection for public pages and media. Processes public content, media and network request data.
Stripe
Provides hosted-plan Checkout, recurring subscriptions, invoices, Customer Portal, connected seller onboarding, Shop Checkout, application fees, refunds, disputes, fraud prevention and payouts. It processes billing contacts, connected-business verification, transaction and payment-method data and acts as processor or independent controller depending on the function.
Privacy Center Data Processing Agreement Connected Account Agreement
Google Analytics
Measures use of OrbitPage-owned platform pages only after consent. Processes online identifiers and page or interaction information. Advertising signals and personalisation are disabled, and OrbitPage does not use its platform property on hosted user pages.
OpenAI
Receives bounded text for server-side content-safety classification. For authenticated AI page editing it receives the account holder's instruction, recent conversation and current page context needed to answer or propose a validated edit. OrbitPage sends store: false, does not create provider application state for the response and retains the submitted instruction with its account, workspace, outcome and timestamp, but not the recent conversation history. It also retains the short-lived proposal and bounded operational metadata. Unless OrbitPage's API project has separately approved zero-data-retention controls, OpenAI may retain API inputs, outputs and safety metadata for its published abuse-monitoring period. API credentials remain server-side, and payment data, authentication secrets and personal API tokens are not intentionally sent.
3. Operator-managed workflow automation
OrbitPage uses an operator-managed n8n deployment to route contact-form and chatbot requests. n8n is the workflow software rather than an independent recipient in that configuration. The workflow may pass the minimum necessary data to a provider listed above according to the purpose disclosed in the Privacy Policy.
4. Customer-selected SMTP providers
When a workspace enables newsletters, its owner supplies and controls the SMTP account. OrbitPage submits recipient addresses and campaign content to that provider on the owner's instructions. Because OrbitPage does not select or contract with one shared newsletter provider for this feature, the customer's SMTP provider is not listed as an OrbitPage platform subprocessor; the customer must assess its terms, processing locations and safeguards.
5. Page-owner selected partner services
A page owner can add external links and consent-gated content from services such as Instagram, Facebook, YouTube, Spotify, Apple Music, Deezer, SoundCloud, Mixcloud, Vimeo, Loom, TikTok, Giphy, Google Maps, Google Calendar, Calendly, Cal.com, Typeform and Google Forms. A Shop seller can connect Cal.com for booking lifecycle updates. A page owner can also choose iubenda, Cookiebot, CookieYes, OneTrust or an approved custom consent manager, and can offer Google Wallet or Apple Wallet passes. These providers are selected by the page owner or visitor, not appointed by OrbitPage to process the platform's own data, so they are not OrbitPage subprocessors for that use.
When a visitor opens a link or consents to load an embed, the selected provider can independently receive network and browser information and use its own identifiers. The page owner must assess the provider, configure the correct consent category and explain the integration in their own privacy and cookie notices. Compatibility with a partner block does not mean that the provider sponsors, endorses or has a commercial partnership with OrbitPage.
For a connected Cal.com account, OrbitPage sends order-linked booking data such as buyer email, booking identifier, status and scheduled times on the seller's instructions. Google receives the public page identity needed when a user chooses a Google Wallet pass. Apple Wallet packages are generated by OrbitPage and handed to the user's device. Official policies: Cal.com privacy, Google privacy and Apple privacy.
6. Transfers and safeguards
Providers may operate from the EEA, United States and other service locations. OrbitPage uses provider data-processing agreements, Standard Contractual Clauses, adequacy decisions or other lawful transfer mechanisms where required. Provider links above contain the latest location and transfer details.
7. Changes
OrbitPage may add or replace a provider as the service evolves. This page will be updated before a material new processing purpose takes effect where required. Organisations that need notice of subprocessor changes can request it at contact@orbitpage.com.