Privacy Policy
How personal data is collected, used, shared and protected across the OrbitPage website and managed hosted service.
Effective and last updated: 16 July 20261. Scope and data controller
This policy applies to orbitpage.com, OrbitPage accounts and dashboards, support channels and the managed publication service on orbitpage.net. It does not govern independent self-hosted installations of the open-source OrbitPage software.
The controller for the managed service is Paolo Ronco, operating OrbitPage from Italy. Privacy requests can be submitted through the contact page or sent to contact@orbitpage.com. Further operator information appears in the Legal Notice.
2. Roles on public pages
OrbitPage is the controller for account administration, platform security, billing and its own website analytics. A page owner decides which content, links, embeds, contact details and optional analytics appear on their public page. For those choices, the page owner may act as a separate controller and must provide any notice or consent required by law.
OrbitPage processes the page owner's hosted content and delivery data to publish the requested page. When a page owner enables newsletters, that owner determines the recipients, message content, purpose and chosen SMTP provider and normally acts as controller for the subscriber list. OrbitPage processes that list and campaign activity on the owner's instructions while remaining controller for platform security, abuse prevention and account administration.
Visitors and newsletter subscribers should contact the page owner first about content or personal data they supplied directly to that owner, while OrbitPage remains available for infrastructure privacy requests and unlawful-content reports.
3. Data we process
- Account and identity data: name, email address, Firebase identifier, authentication method, email-verification status, username, session and account-security events.
- Workspace and publication data: page settings, links, text, themes, uploaded images or video, connected domains, revision identifiers, publication status and plan usage.
- Public visitor data: requested page, coarse request and delivery information, click events where the active plan includes analytics, and security signals needed to serve and protect the page.
- Device and security data: IP address, browser and device information, request timestamps, App Check or reCAPTCHA signals, rate-limit counters, error logs and suspected-abuse events.
- Billing data: plan, Stripe customer and subscription references, invoice and payment status, cancellation status and billing correspondence. OrbitPage does not receive or store full payment-card numbers.
- Support and contact data: name, email, selected topic, message, reference number and information you choose to provide through support, chatbot or moderation appeals.
- Moderation data: bounded page text submitted for safety classification, content hashes, categories returned by the moderation service, review status, temporary restrictions and appeal records.
- Newsletter data: subscriber email address and optional name, consent and confirmation timestamps, subscription status, campaign content and schedule, SMTP acceptance or rejection, unique open and click signals, unsubscribe events, and encrypted credentials for the SMTP server chosen by the page owner.
- Optional website analytics: consent choice, page and interaction data, approximate location and technical identifiers collected by Google Analytics only after consent and only on OrbitPage-owned platform pages.
4. Purposes and legal bases
5. Required and optional data
Account identity, security, workspace and billing data marked as required is necessary to provide the requested service. Without it, OrbitPage may be unable to create an account, publish a page, process a payment or investigate abuse. Optional profile content, chatbot use and website analytics are voluntary. Declining analytics does not reduce service functionality.
6. Recipients and service providers
OrbitPage uses Google Firebase and Google Cloud for authentication, database and abuse protection; Vercel for the website, dashboard, newsletter scheduling and server APIs; Cloudflare for public-page delivery, storage, caching, custom domains and the newsletter scheduler; Stripe for subscriptions and payment administration; Google Analytics for optional platform analytics; and OpenAI for server-side text moderation and, where configured, assistant processing. An operator-managed n8n service routes contact and chatbot workflows.
Newsletter email is submitted to the SMTP provider configured by the page owner. That provider is selected and instructed by the owner, can process subscriber addresses and message content, and is governed by the owner's agreement with it.
Provider purpose, data scope and official privacy documentation are listed in the Subprocessors notice. Data is also disclosed where required by law, to protect rights and safety, or in connection with a lawful business reorganisation. OrbitPage does not sell personal data.
7. International transfers
Some providers operate globally or process certain data in the United States. Where EEA personal data is transferred to a country without an adequacy decision, OrbitPage relies on the provider's data-processing terms, Standard Contractual Clauses or another valid transfer mechanism and applies supplementary safeguards where appropriate.
8. Retention
9. Automated moderation and human review
Publication text is checked using local safety rules and may be sent in a bounded form to an automated moderation service. A high-risk signal can temporarily block publication or restrict a workspace. OrbitPage does not currently claim comprehensive semantic scanning of every image or video.
You may contest a restriction and request human review through the contact page. OrbitPage considers the content, context and any supporting information before confirming, changing or removing a restriction.
10. Public content
Content published on an OrbitPage profile is intentionally public. It can be viewed without an account, linked, indexed, cached, copied or archived by third parties. Do not publish private, confidential or sensitive personal data unless you have a lawful reason and intend to make it public.
11. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier processing. Account owners can permanently delete their account and hosted workspace directly from Dashboard > Account after a fresh identity check. You may also object to processing based on legitimate interests and request human review of a moderation decision.
OrbitPage may need to verify identity before acting. Requests are answered within the period required by law. You may complain to the Italian Data Protection Authority or to the authority in your habitual EEA residence, workplace or place of the alleged infringement.
12. Children
The managed service is not directed to children and account holders must be at least 18 years old or otherwise legally able to enter the service agreement. Do not use OrbitPage to collect children's data without a valid legal basis and appropriate safeguards.
13. Security and incidents
OrbitPage applies access controls, encrypted transport, tenant isolation, signed provider requests, request limits, publication revisions and monitoring appropriate to the service. No online system is completely secure. If a personal-data breach creates a legal notification duty, OrbitPage will notify the competent authority and affected people as required.
14. Changes and contact
Material changes will be posted here and, where appropriate, communicated through the service or by email before they take effect. Questions and requests can be sent to contact@orbitpage.com.