Overview
Orbit PSA ("Orbit", "we", "us") operates the website at orbitpsa.com and the Orbit PSA + CRM platform (the "Service"). This policy explains what personal data we collect, why, who we share it with, and the rights you have over it.
This policy is written to be readable. It complies with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA / CPRA), and is reviewed against the Canadian PIPEDA and Australian Privacy Act. A formal Data Processing Addendum (DPA) is available on request via [email protected].
Who this applies to
- Visitors to
orbitpsa.comwho haven't signed up — we collect minimal analytics and form submissions - Prospects who request a demo, submit the contact form, or chat with us
- Customers who use the Orbit PSA application
- End users of customers' clients whose data is processed in Orbit on behalf of our customers (the customer is the data controller; Orbit is the processor)
Data we collect
From website visitors
- IP address, browser type, device type, and approximate geographic location (city-level) for analytics
- Pages visited and time on each page
- Referring URL (which site brought you here)
- Whether you've visited before (via first-party cookies)
From demo requests and contact forms
- Name, work email, company name
- Team size and current toolchain (if you tell us)
- Anything you write in a free-text field
- How you found us (UTM parameters, referrer)
From signed-in customers
- Account information (name, email, role, organization)
- Operational data you create in the platform (clients, contacts, tickets, time entries, agreements, invoices)
- Usage data — which features you use, when, performance metrics
- Support communications
- Billing information (handled by Stripe; see below)
What we don't collect
- Raw payment card numbers (Stripe handles all payment storage)
- Social security numbers, government IDs, or biometric data
- Special-category data under GDPR Article 9 (health, religion, etc.) unless our customer explicitly inputs it for their own service-delivery purposes
Legal bases for processing (GDPR)
We rely on these legal bases:
- Contract performance: processing necessary to provide the Service to signed customers
- Legitimate interests: analytics, fraud prevention, security monitoring, marketing to existing customers about Orbit features
- Consent: marketing emails to non-customers, cookie categories that aren't strictly necessary
- Legal obligation: tax records, financial accounting, responses to lawful requests
How we use data
- To provide and improve the Orbit Service
- To respond to demo requests, support questions, and inquiries
- To send service announcements and product updates to customers
- To detect and prevent fraud, abuse, and security threats
- To meet legal, accounting, and audit obligations
- To analyze aggregated, anonymized usage to improve the product
Third parties we share data with
We use sub-processors for parts of our infrastructure. See the full list with purposes, locations, and data categories on the Sub-processors page. Summary:
- Vercel — hosting + edge delivery (USA)
- Stripe — payment processing (USA)
- Resend — transactional email (USA)
- Cal.com — demo scheduling (USA)
- Tawk.to — live chat (USA)
- Google Analytics 4 — anonymized site analytics (USA, IP-anonymized)
We do not sell personal data. We do not share data with advertising networks. Anonymized, aggregated insights may be shared with partners or published as research (e.g., "MSPs running 50+ clients spend an average of X hours per week on ticket triage") — never tied to individual customers.
Cookies and similar technologies
orbitpsa.com uses first-party cookies for analytics and session management. We do not use third-party advertising cookies or cross-site tracking. Specific cookies:
- _ga, _ga_* — Google Analytics (anonymous visitor identification, IP-anonymized)
- __tawkuuid — Tawk.to live chat session
- orbit_session — keeps you signed in to the application
You can disable cookies in your browser settings. Some site features (live chat, signed-in sessions) will not work without them.
Data retention
- Demo request data: 24 months from submission, then deleted unless you become a customer
- Customer data: retained for the life of the contract; deleted within 90 days of contract termination (unless customer requests immediate deletion)
- Tax / accounting records: retained 7 years per US and UK regulations
- Anonymized analytics: retained indefinitely; no personal identifiers
- Backup copies: rotated out within 30 days of source deletion
Your rights
Depending on where you live, you have some or all of these rights over your personal data:
- Access: request a copy of the data we hold about you
- Correction: ask us to fix inaccurate data
- Deletion: ask us to delete your data (subject to legal retention obligations)
- Portability: request your data in a machine-readable format
- Restriction: ask us to stop processing while we resolve a dispute
- Objection: object to processing based on legitimate interests
- Opt-out of sale: California residents — we don't sell data, so there's nothing to opt out of, but the right exists
- Withdraw consent: where consent is the basis, withdraw it at any time
Exercise any of these rights by emailing [email protected]. We respond within 30 days (CCPA: 45 days; GDPR: 30 days).
International transfers
Orbit operates from the United States. If you're in the EU, UK, or elsewhere, your data is transferred to the US for processing. We rely on Standard Contractual Clauses (SCCs) for these transfers and have committed to the EU-US Data Privacy Framework where applicable.
Children
The Service is not directed to children under 16. We don't knowingly collect data from anyone under 16. If you believe we have, contact [email protected] and we'll delete it.
Changes to this policy
We update this policy when our practices change. The "Last updated" date at the top tracks revisions. Material changes will be announced via email to customers and a banner on orbitpsa.com for at least 30 days.
Contact
Privacy inquiries: [email protected]
Data Protection Officer: The Privacy team handles DPO responsibilities at [email protected]
EU representative: Contact via [email protected] for designated EU representative details
Supervisory authority: EU residents can also lodge complaints with their national data protection authority
