Privacy Policy.
Preliminary — under review. Last updated [DATE].
OrbitOps Pro ("OrbitOps Pro," "we," "us"), operated by OrbitOps Pro, LLC, provides field-service-management software to service businesses ("Operators"). This policy explains what personal information we handle, how, and why. It covers both our marketing site (orbitopspro.com) and our application (app.orbitopspro.com).
Two kinds of data, two roles
OrbitOps Pro handles personal information in two distinct roles, and it's important to understand the difference:
- Data about Operators (we are the controller). When you sign up for and use OrbitOps Pro as a service business, we collect and control certain information about you and your business directly.
- Data about an Operator's customers (we are the processor). When an Operator uses OrbitOps Pro to manage their own customers, that customer information belongs to the Operator. We process it on the Operator's behalf and under their instructions — we do not own it, sell it, or use it for our own purposes. If you are a customer of a business that uses OrbitOps Pro and you have questions about your data, contact that business directly; they are the controller of that information.
Information we collect
From Operators (account and business data): business name, business email and phone, business address, your name, username, role, and login credentials, your business logo, tax settings, and your payment-processor connection details (see Payments below).
From Operators, about their customers (processed on the Operator's behalf): customer or household names, service addresses, contact name/phone/email, service locations and their geolocation coordinates, on-site equipment records, service history and job notes, and invoice and payment records. OrbitOps Pro does not decide what customer data an Operator enters; the Operator does.
From our marketing site: if you submit an interest or contact form, we collect the email address, name, and any details you provide.
Automatically: our hosting provider logs standard technical request data (such as IP address and timestamps) for security and reliability. Our product analytics (see below) record how Operators use the application.
We do not collect Social Security numbers, health data, or biometric data, and we do not store payment card numbers (see Payments).
Payments
Payment card processing is handled entirely by Stripe. When a payment is made, card details are entered on Stripe's own hosted checkout — OrbitOps Pro never receives, sees, or stores card numbers or security codes. Our systems store only non-sensitive references such as payment amounts, status, method, and Stripe transaction identifiers. Operators connect their own Stripe accounts to receive funds directly; Stripe handles Operator identity and payout verification through its own onboarding. Stripe's handling of this data is governed by Stripe's privacy policy.
Service providers we share data with
We use a small set of trusted providers to operate OrbitOps Pro. Each processes data only as needed to provide their service:
- Supabase — our database and authentication provider; stores account and application data.
- Stripe — payment processing (see Payments).
- Resend — delivery of transactional emails (invoices, estimates, statements, and similar), which may include attached documents containing customer names, addresses, and line items.
- PostHog — product analytics, configured to identify only Operators and their organizations. It is deliberately configured so that an Operator's customer personal information is not sent to it.
- Cloudflare — hosting and request logging.
- Google Maps Platform — where enabled, customer service addresses are sent to Google's geocoding and routing services to validate addresses and optimize technician routes.
We do not sell personal information, and we do not share it with third parties for their own marketing.
Analytics and tracking
Our marketing site uses no analytics, advertising, or tracking cookies. Our application uses PostHog for product analytics, configured privacy-first: no automatic capture of page content, no session recording, and an enforced filter that prevents Operator customer personal information from being sent to analytics. We measure how Operators use features, not who their customers are.
How we protect data
Access to the application requires authentication. Each Operator organization's data is logically separated, and our application enforces that separation on every request so that one Operator cannot access another Operator's data. Sessions use secure, HTTP-only cookies. We work to protect information but no method of transmission or storage is completely secure.
Data retention and your choices
We retain Operator account data for as long as an account is active. Operators can remove or archive customer records within the application. To request deletion of your Operator account data, or if you are an Operator with questions about customer-data handling, contact us at support@orbitopspro.com — we handle deletion requests as an operational process. If you are an Operator's customer, direct data requests to the business that serves you, as they control that data.
Children
OrbitOps Pro is a business tool not directed to children and is not intended for anyone under 18.
Scope
OrbitOps Pro currently serves businesses in the United States. This policy is written accordingly; if we expand internationally, we will update it to address additional obligations.
Changes and contact
We may update this policy; material changes will be reflected in the "last updated" date. Questions: support@orbitopspro.com.