OrbitPage
Back to OrbitPage
OrbitPage Legal

Subprocessors

The principal providers that support OrbitPage managed hosting and the purposes for which they receive data.

Effective and last updated: 16 July 2026
Legal centerPrivacyCookiesTermsAcceptable useBilling & cancellationSubprocessorsLegal notice

1. How to read this list

A provider can act as a processor, subprocessor or independent controller depending on the product and data involved. The list below covers the principal hosted-service providers. A self-hosted OrbitPage operator chooses and is responsible for their own providers.

2. Current providers

Google Firebase and Google Cloud

Authentication, email verification, Firestore database, Firebase App Check, reCAPTCHA Enterprise and related security infrastructure. Account, workspace, request and attestation data may be processed. Firebase Authentication processing is documented by Google as US-only; other locations depend on the configured service.

Firebase privacy and security Google Cloud Data Processing Addendum

Vercel

Hosts the OrbitPage marketing site, authentication UI, dashboard and server-side API routes. Processes HTTP request information, application logs and data handled by those functions.

Privacy Notice Data Processing Addendum

Cloudflare

Provides R2 object storage, Worker delivery, edge caching, DNS, TLS, custom hostnames and abuse protection for public pages and media. Processes public content, media and network request data.

Privacy Policy Customer DPA

Stripe

Provides Checkout, recurring subscriptions, invoice and payment administration, fraud prevention and Customer Portal. Processes billing contact, transaction and payment-method data. Stripe can act as both processor and independent controller for different payment functions.

Privacy Center Data Processing Agreement

Google Analytics

Measures use of OrbitPage-owned platform pages only after consent. Processes online identifiers and page or interaction information. Advertising signals and personalisation are disabled, and OrbitPage does not use its platform property on hosted user pages.

Google Privacy Policy Ads Data Processing Terms

OpenAI

Receives bounded text for server-side content-safety classification and may process public-site assistant prompts when configured in the workflow. API credentials remain server-side; full payment data and account passwords are not intentionally sent.

Privacy Policy Data Processing Addendum

3. Operator-managed workflow automation

OrbitPage uses an operator-managed n8n deployment to route contact-form and chatbot requests. n8n is the workflow software rather than an independent recipient in that configuration. The workflow may pass the minimum necessary data to a provider listed above according to the purpose disclosed in the Privacy Policy.

4. Customer-selected SMTP providers

When a workspace enables newsletters, its owner supplies and controls the SMTP account. OrbitPage submits recipient addresses and campaign content to that provider on the owner's instructions. Because OrbitPage does not select or contract with one shared newsletter provider for this feature, the customer's SMTP provider is not listed as an OrbitPage platform subprocessor; the customer must assess its terms, processing locations and safeguards.

5. Transfers and safeguards

Providers may operate from the EEA, United States and other service locations. OrbitPage uses provider data-processing agreements, Standard Contractual Clauses, adequacy decisions or other lawful transfer mechanisms where required. Provider links above contain the latest location and transfer details.

6. Changes

OrbitPage may add or replace a provider as the service evolves. This page will be updated before a material new processing purpose takes effect where required. Organisations that need notice of subprocessor changes can request it at contact@orbitpage.com.

OrbitPage
Legal centerPrivacyTerms
contact@orbitpage.com