Polityka prywatności
W jaki sposób dane osobowe są gromadzone, wykorzystywane, udostępniane i chronione w witrynie OrbitPage i zarządzanej usłudze hostingowej.
Obowiązuje i jest aktualizowany pod adresem: 31 sierpnia 2026To tłumaczenie udostępniamy dla wygody. Wersja angielska pozostaje wersją nadrzędną.
1. Scope and data controller
This policy applies to orbitpage.com, OrbitPage accounts and dashboards, support channels and the managed publication service on orbitpage.net. It does not govern independent self-hosted installations of the open-source OrbitPage software.
The controller for the managed service is Paolo Ronco, operating OrbitPage from Italy. Privacy requests can be submitted through the contact page or sent to contact@orbitpage.com. Further operator information appears in the Legal Notice.
2. Roles on public pages
OrbitPage is the controller for account administration, platform security, billing and its own website analytics. A page owner decides which content, links, embeds, contact details and optional analytics appear on their public page. For those choices, the page owner may act as a separate controller and must provide any notice or consent required by law.
OrbitPage processes the page owner's hosted content and delivery data to publish the requested page. When a page owner enables newsletters, that owner determines the recipients, message content, purpose and chosen SMTP provider and normally acts as controller for the subscriber list. OrbitPage processes that list and campaign activity on the owner's instructions while remaining controller for platform security, abuse prevention and account administration.
When a page owner enables Shop, that owner is the seller and controller for customer and fulfilment data used for the sale. The seller must publish their identity, contact details and policies. OrbitPage processes catalog, order, consent, delivery and optional booking data to provide the Shop, while Stripe independently processes payment, identity and payout information under its connected-account terms. A seller that connects Cal.com also instructs OrbitPage to exchange the minimum booking lifecycle data with that account.
When a page owner adds a partner block, booking tool, form, map, player or other external service, the page owner selects that recipient and decides the purpose of the integration. OrbitPage keeps consent-gated content blocked until the visitor grants the relevant category, but the external provider independently processes data once its content is loaded or its link is opened.
Visitors and newsletter subscribers should contact the page owner first about content or personal data they supplied directly to that owner, while OrbitPage remains available for infrastructure privacy requests and unlawful-content reports. The Data Processing Agreement governs processing carried out by OrbitPage on the page owner's behalf.
3. Data we process
- Account, team and identity data: name, email address, Firebase identifier, authentication method, email-verification status, username, workspace memberships, invitations, roles, session and account-security events.
- Workspace and publication data: page settings, links, text, themes, uploaded images or video, connected domains, revision identifiers, publication status and plan usage.
- Public visitor and consent data: requested page, coarse request and delivery information, click events where the active plan includes analytics, security signals, and category choices, policy version, timestamp and random receipt identifier for a public-page consent receipt. The receipt does not intentionally contain a name or email address.
- Device and security data: IP address, browser and device information, request timestamps, App Check or reCAPTCHA signals, rate-limit counters, error logs and suspected-abuse events. With analytics consent, OrbitPage also computes a pseudonymous browser identifier locally and stores only a purpose-bound server-side hash with a signed-in account to recognize returning customers.
- Billing data: plan, Stripe customer and subscription references, invoice and payment status, cancellation status and billing correspondence. OrbitPage does not receive or store full payment-card numbers.
- Support, contact and service-request data: name, email, selected topic, message, reference number, linked workspace, delivery status and information you provide through support, chatbot, moderation appeals or privacy requests. Online withdrawal declarations additionally contain the contract identifier, declaration, legal version, date, time and email-receipt status.
- Business relationship data: prospect, demo, onboarding, promotion-code and customer-care records entered by the operator, including business contact details, category, notes, follow-up status and communications.
- Moderation data: bounded page text submitted for safety classification, content hashes, categories returned by the moderation service, review status, temporary restrictions and appeal records.
- Newsletter data: subscriber email address and optional name, consent and confirmation timestamps, subscription status, campaign content and schedule, SMTP acceptance or rejection, unique open and click signals, unsubscribe events, and encrypted credentials for the SMTP server chosen by the page owner.
- Connected-service configuration: the selected provider, public content or share URL, display settings and consent category for partner blocks, players, maps, booking tools and forms. OrbitPage does not ask for the visitor's third-party account password to display these public integrations.
- AI page-editing data: your instruction, recent assistant conversation, current page context and, when you use Launch Kit, the screenshot you submit and any later corrections are sent to OpenAI to generate an answer or proposed edit. OrbitPage requests non-persistent response handling with
store: false; Launch Kit screenshots are re-encoded and not stored by OrbitPage. OrbitPage keeps the submitted instruction with the account, workspace, outcome and timestamp for support and quality review, but does not keep the recent conversation history or screenshot in its operational event log. A validated proposal, including any visible or subsequently supplied destinations, remains available for up to ten minutes and becomes page content only if you confirm it; operational records can also include model, token counts, request identifier and estimated cost. Unless a separately approved zero-data-retention setting applies, OpenAI may retain API inputs, outputs and safety metadata for a limited abuse-monitoring period under its published data controls. - Automation API and connected-app data: personal token name, scope, prefix, one-way hash, expiry, creation, last-use and revocation details; and OAuth client name and identifier, registered return address, selected workspace, granted scopes, connection and last-use timestamps and one-way credential hashes. Raw personal tokens, authorization codes and connected-app credentials are not recoverable after issue.
- Tenant Shop and booking data: public seller identity and policy links, connected Stripe account reference and capability status, product catalog, private delivery files, order and application-fee references, buyer email, seller-terms and digital-delivery consent timestamps and versions, payment, refund and dispute status, delivery expiry, download count, intake answers, booking provider identifier, status, scheduled times and meeting URL where a seller connects Cal.com, and limited request-security signals. OrbitPage does not store full payment-card, Stripe identity-verification or payout-account details.
- Wallet data: pass identifiers, signing and delivery status and the public page title, username and URL used to create an Apple Wallet pass locally or a Google Wallet Save URL. Google receives the public pass object when Google Wallet is selected; OrbitPage does not send an Apple pass to Apple merely to build the package.
- Contract evidence: Stripe Checkout references, accepted legal version, terms acceptance and immediate-performance request for paid plans, plus the Shop consent evidence and withdrawal records described above.
- Optional website analytics: consent choice, page and interaction data, approximate location and technical identifiers collected by Google Analytics only after consent and only on OrbitPage-owned platform pages. A separate same-origin returning-customer lookup uses the hashed browser identifier described above and sends only a boolean returning-customer event to Google Analytics.
4. Purposes and legal bases
5. Required and optional data
Account identity, security, workspace and billing data marked as required is necessary to provide the requested service. Seller identity and policy details are required before a Shop can be published, seller-terms acceptance is required for every Shop checkout and separate express consent is required before immediate digital delivery. Without required data, OrbitPage may be unable to create an account, publish a page, process a subscription or Shop order, deliver a digital purchase or investigate abuse. Optional profile content, partner blocks, AI editing, connected AI apps, wallet passes, chatbot use and website analytics are voluntary.
6. Recipients and service providers
OrbitPage uses Google Firebase and Google Cloud for authentication, database and abuse protection; Vercel for the website, dashboard, scheduling and server APIs; Cloudflare for public-page delivery, private Shop files, storage, caching and custom domains; Stripe for subscriptions, connected seller onboarding, Checkout, consent evidence, refunds, disputes and payment administration; Google Analytics for optional platform analytics; OpenAI for server-side text moderation and authenticated AI page editing; and the operator-configured transactional SMTP provider or providers for account, security, support, withdrawal and Shop messages. An operator-managed n8n service routes contact and chatbot workflows.
Newsletter email is submitted to the SMTP provider configured by the page owner. That provider is selected and instructed by the owner, can process subscriber addresses and message content, and is governed by the owner's agreement with it.
A Shop seller may connect Cal.com for booking lifecycle updates; the seller's Cal.com account then receives buyer and order-linked booking data. Selecting Google Wallet sends the public page identity needed for the pass to Google. Apple Wallet packages are built by OrbitPage and handed to the user's device. A page owner may also select an external consent-management platform; that provider receives consent and device data according to the owner's configuration.
When an account holder connects ChatGPT or another MCP client, that selected service receives the workspace data returned by the tools the holder authorises. The client operates under the holder's account and the provider's terms; OrbitPage supplies a revocable, workspace-bound OAuth grant and does not disclose the holder's Firebase password or personal API tokens.
Partner blocks can connect a visitor to independent services such as Instagram, Facebook, YouTube, Spotify, Apple Music, Deezer, SoundCloud, Mixcloud, Vimeo, Loom, TikTok, Giphy, Google Maps, Google Calendar, Calendly, Typeform and Google Forms. Depending on the block, data is disclosed only when the visitor opens the link or after the required consent allows embedded content to load. The provider can then receive the visitor's IP address, browser information, referring page and provider-specific identifiers under its own privacy terms.
Provider purpose, data scope and official privacy documentation are listed in the Subprocessors notice. Data is also disclosed where required by law, to protect rights and safety, or in connection with a lawful business reorganisation. OrbitPage does not sell personal data.
7. International transfers
Some providers operate globally or process certain data in the United States. Where EEA personal data is transferred to a country without an adequacy decision, OrbitPage relies on the provider's data-processing terms, Standard Contractual Clauses or another valid transfer mechanism and applies supplementary safeguards where appropriate.
8. Retention
9. Automated moderation and human review
Publication text is checked using local safety rules and may be sent in a bounded form to an automated moderation service. A high-risk signal can temporarily block publication or restrict a workspace. OrbitPage does not currently claim comprehensive semantic scanning of every image or video.
You may contest a restriction and request human review through the contact page. OrbitPage considers the content, context and any supporting information before confirming, changing or removing a restriction.
10. Public content
Content published on an OrbitPage profile is intentionally public. It can be viewed without an account, linked, indexed, cached, copied or archived by third parties. Do not publish private, confidential or sensitive personal data unless you have a lawful reason and intend to make it public.
11. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier processing. Account owners can permanently delete their account and hosted workspace directly from Dashboard > Account after a fresh identity check. You may also object to processing based on legitimate interests and request human review of a moderation decision.
Personal API tokens and connected AI apps can be reviewed and revoked from Dashboard > Account. Consumer withdrawal is separate from data-protection rights and can be exercised through the online withdrawal function. OrbitPage may need to verify identity before acting on other requests. Requests are answered within the period required by law. You may complain to the Italian Data Protection Authority or to the authority in your habitual EEA residence, workplace or place of the alleged infringement.
12. Children
The managed service is not directed to children and account holders must be at least 18 years old or otherwise legally able to enter the service agreement. Do not use OrbitPage to collect children's data without a valid legal basis and appropriate safeguards.
13. Security and incidents
OrbitPage applies access controls, encrypted transport, tenant isolation, signed provider requests, request limits, publication revisions and monitoring appropriate to the service. No online system is completely secure. If a personal-data breach creates a legal notification duty, OrbitPage will notify the competent authority and affected people as required.
14. Changes and contact
Material changes will be posted here and, where appropriate, communicated through the service or by email before they take effect. Questions and requests can be sent to contact@orbitpage.com.