Subprocessors
The principal providers that support OrbitPage managed hosting and the purposes for which they receive data.
Effective and last updated: 16 July 20261. How to read this list
A provider can act as a processor, subprocessor or independent controller depending on the product and data involved. The list below covers the principal hosted-service providers. A self-hosted OrbitPage operator chooses and is responsible for their own providers.
2. Current providers
Google Firebase and Google Cloud
Authentication, email verification, Firestore database, Firebase App Check, reCAPTCHA Enterprise and related security infrastructure. Account, workspace, request and attestation data may be processed. Firebase Authentication processing is documented by Google as US-only; other locations depend on the configured service.
Firebase privacy and security Google Cloud Data Processing Addendum
Vercel
Hosts the OrbitPage marketing site, authentication UI, dashboard and server-side API routes. Processes HTTP request information, application logs and data handled by those functions.
Cloudflare
Provides R2 object storage, Worker delivery, edge caching, DNS, TLS, custom hostnames and abuse protection for public pages and media. Processes public content, media and network request data.
Stripe
Provides Checkout, recurring subscriptions, invoice and payment administration, fraud prevention and Customer Portal. Processes billing contact, transaction and payment-method data. Stripe can act as both processor and independent controller for different payment functions.
Google Analytics
Measures use of OrbitPage-owned platform pages only after consent. Processes online identifiers and page or interaction information. Advertising signals and personalisation are disabled, and OrbitPage does not use its platform property on hosted user pages.
OpenAI
Receives bounded text for server-side content-safety classification and may process public-site assistant prompts when configured in the workflow. API credentials remain server-side; full payment data and account passwords are not intentionally sent.
3. Operator-managed workflow automation
OrbitPage uses an operator-managed n8n deployment to route contact-form and chatbot requests. n8n is the workflow software rather than an independent recipient in that configuration. The workflow may pass the minimum necessary data to a provider listed above according to the purpose disclosed in the Privacy Policy.
4. Customer-selected SMTP providers
When a workspace enables newsletters, its owner supplies and controls the SMTP account. OrbitPage submits recipient addresses and campaign content to that provider on the owner's instructions. Because OrbitPage does not select or contract with one shared newsletter provider for this feature, the customer's SMTP provider is not listed as an OrbitPage platform subprocessor; the customer must assess its terms, processing locations and safeguards.
5. Transfers and safeguards
Providers may operate from the EEA, United States and other service locations. OrbitPage uses provider data-processing agreements, Standard Contractual Clauses, adequacy decisions or other lawful transfer mechanisms where required. Provider links above contain the latest location and transfer details.
6. Changes
OrbitPage may add or replace a provider as the service evolves. This page will be updated before a material new processing purpose takes effect where required. Organisations that need notice of subprocessor changes can request it at contact@orbitpage.com.