OrbitPage
Back to OrbitPage
OrbitPage Legal

Privacy Policy

How personal data is collected, used, shared and protected across the OrbitPage website and managed hosted service.

Effective and last updated: 16 July 2026
Legal centerPrivacyCookiesTermsAcceptable useBilling & cancellationSubprocessorsLegal notice

1. Scope and data controller

This policy applies to orbitpage.com, OrbitPage accounts and dashboards, support channels and the managed publication service on orbitpage.net. It does not govern independent self-hosted installations of the open-source OrbitPage software.

The controller for the managed service is Paolo Ronco, operating OrbitPage from Italy. Privacy requests can be submitted through the contact page or sent to contact@orbitpage.com. Further operator information appears in the Legal Notice.

2. Roles on public pages

OrbitPage is the controller for account administration, platform security, billing and its own website analytics. A page owner decides which content, links, embeds, contact details and optional analytics appear on their public page. For those choices, the page owner may act as a separate controller and must provide any notice or consent required by law.

OrbitPage processes the page owner's hosted content and delivery data to publish the requested page. When a page owner enables newsletters, that owner determines the recipients, message content, purpose and chosen SMTP provider and normally acts as controller for the subscriber list. OrbitPage processes that list and campaign activity on the owner's instructions while remaining controller for platform security, abuse prevention and account administration.

Visitors and newsletter subscribers should contact the page owner first about content or personal data they supplied directly to that owner, while OrbitPage remains available for infrastructure privacy requests and unlawful-content reports.

3. Data we process

  • Account and identity data: name, email address, Firebase identifier, authentication method, email-verification status, username, session and account-security events.
  • Workspace and publication data: page settings, links, text, themes, uploaded images or video, connected domains, revision identifiers, publication status and plan usage.
  • Public visitor data: requested page, coarse request and delivery information, click events where the active plan includes analytics, and security signals needed to serve and protect the page.
  • Device and security data: IP address, browser and device information, request timestamps, App Check or reCAPTCHA signals, rate-limit counters, error logs and suspected-abuse events.
  • Billing data: plan, Stripe customer and subscription references, invoice and payment status, cancellation status and billing correspondence. OrbitPage does not receive or store full payment-card numbers.
  • Support and contact data: name, email, selected topic, message, reference number and information you choose to provide through support, chatbot or moderation appeals.
  • Moderation data: bounded page text submitted for safety classification, content hashes, categories returned by the moderation service, review status, temporary restrictions and appeal records.
  • Newsletter data: subscriber email address and optional name, consent and confirmation timestamps, subscription status, campaign content and schedule, SMTP acceptance or rejection, unique open and click signals, unsubscribe events, and encrypted credentials for the SMTP server chosen by the page owner.
  • Optional website analytics: consent choice, page and interaction data, approximate location and technical identifiers collected by Google Analytics only after consent and only on OrbitPage-owned platform pages.

4. Purposes and legal bases

Create and operate an accountPerformance of the service contract or steps requested before entering it.
Publish and deliver a pagePerformance of the service contract and the page owner's publication instructions.
Authenticate, prevent abuse and keep the service reliableLegitimate interests in protecting OrbitPage, its users and third parties, and compliance with legal obligations where applicable.
Take payments and maintain recordsPerformance of the contract and compliance with accounting, tax and fraud-prevention obligations.
Answer contact, support and rights requestsPerformance of the contract, legitimate interests in customer support, compliance with legal obligations or consent where the request is optional.
Moderate content and respond to reportsLegitimate interests in preventing harm and enforcing the service rules, plus compliance with applicable legal duties.
Operate owner newslettersThe page owner's documented instructions and service contract. The page owner is responsible for the legal basis used to collect subscribers and send each campaign.
Measure the OrbitPage websiteConsent. Analytics remains disabled when consent is absent or withdrawn.

5. Required and optional data

Account identity, security, workspace and billing data marked as required is necessary to provide the requested service. Without it, OrbitPage may be unable to create an account, publish a page, process a payment or investigate abuse. Optional profile content, chatbot use and website analytics are voluntary. Declining analytics does not reduce service functionality.

6. Recipients and service providers

OrbitPage uses Google Firebase and Google Cloud for authentication, database and abuse protection; Vercel for the website, dashboard, newsletter scheduling and server APIs; Cloudflare for public-page delivery, storage, caching, custom domains and the newsletter scheduler; Stripe for subscriptions and payment administration; Google Analytics for optional platform analytics; and OpenAI for server-side text moderation and, where configured, assistant processing. An operator-managed n8n service routes contact and chatbot workflows.

Newsletter email is submitted to the SMTP provider configured by the page owner. That provider is selected and instructed by the owner, can process subscriber addresses and message content, and is governed by the owner's agreement with it.

Provider purpose, data scope and official privacy documentation are listed in the Subprocessors notice. Data is also disclosed where required by law, to protect rights and safety, or in connection with a lawful business reorganisation. OrbitPage does not sell personal data.

7. International transfers

Some providers operate globally or process certain data in the United States. Where EEA personal data is transferred to a country without an adequacy decision, OrbitPage relies on the provider's data-processing terms, Standard Contractual Clauses or another valid transfer mechanism and applies supplementary safeguards where appropriate.

8. Retention

Account and workspaceFor the life of the account and then only as long as needed to complete deletion, resolve disputes, enforce agreements or meet legal duties. Restricted provider backups may take longer to expire.
Account and hosted contentUntil the account is deleted. Self-service deletion removes the Firebase login, Firestore workspace records, R2 uploads and publication, reserved username, custom-domain route and active Stripe customer relationship. A final automated storage sweep follows shortly after deletion to catch any upload URL issued immediately beforehand.
Published cacheDeleted pages may remain in OrbitPage edge cache for up to about 30 seconds. Search indexes and third-party archives are outside OrbitPage's direct control.
Security and moderationFor the period needed to investigate and prevent repeated abuse. Temporary automated holds are normally limited to the configured review period; substantiated incidents may be retained longer.
Billing recordsFor the statutory accounting, tax, chargeback and anti-fraud periods that apply to the transaction.
Support, contact and chatbotFor as long as needed to answer the request and maintain a reasonable support history, then deleted or minimised unless a dispute or legal duty requires longer retention.
Newsletter audience and reportsFor the life of the workspace or until the page owner removes the subscriber or the subscriber unsubscribes. Unsubscribed status and minimal suppression data may be retained while the newsletter remains active to prevent accidental re-mailing; campaign content and delivery reports remain until the page owner deletes that campaign or the account is deleted.
AnalyticsAccording to the configured Google Analytics retention setting and only after consent. Aggregate reports may no longer identify a visitor.

9. Automated moderation and human review

Publication text is checked using local safety rules and may be sent in a bounded form to an automated moderation service. A high-risk signal can temporarily block publication or restrict a workspace. OrbitPage does not currently claim comprehensive semantic scanning of every image or video.

You may contest a restriction and request human review through the contact page. OrbitPage considers the content, context and any supporting information before confirming, changing or removing a restriction.

10. Public content

Content published on an OrbitPage profile is intentionally public. It can be viewed without an account, linked, indexed, cached, copied or archived by third parties. Do not publish private, confidential or sensitive personal data unless you have a lawful reason and intend to make it public.

11. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier processing. Account owners can permanently delete their account and hosted workspace directly from Dashboard > Account after a fresh identity check. You may also object to processing based on legitimate interests and request human review of a moderation decision.

OrbitPage may need to verify identity before acting. Requests are answered within the period required by law. You may complain to the Italian Data Protection Authority or to the authority in your habitual EEA residence, workplace or place of the alleged infringement.

12. Children

The managed service is not directed to children and account holders must be at least 18 years old or otherwise legally able to enter the service agreement. Do not use OrbitPage to collect children's data without a valid legal basis and appropriate safeguards.

13. Security and incidents

OrbitPage applies access controls, encrypted transport, tenant isolation, signed provider requests, request limits, publication revisions and monitoring appropriate to the service. No online system is completely secure. If a personal-data breach creates a legal notification duty, OrbitPage will notify the competent authority and affected people as required.

14. Changes and contact

Material changes will be posted here and, where appropriate, communicated through the service or by email before they take effect. Questions and requests can be sent to contact@orbitpage.com.

OrbitPage
Legal centerPrivacyTerms
contact@orbitpage.com