Privacy Policy.
Last updated September 14, 2026.
OrbitOps Pro ("OrbitOps Pro," "we," "us"), operated by OrbitOps Pro, LLC, provides field-service-management software to service businesses ("Operators"). This policy explains what personal information we handle, how, and why. It covers both our marketing site (orbitopspro.com) and our application (app.orbitopspro.com).
Two kinds of data, two roles
OrbitOps Pro handles personal information in two distinct roles, and it's important to understand the difference:
- Data about Operators (we are the controller). When you sign up for and use OrbitOps Pro as a service business, we collect and control certain information about you and your business directly.
- Data about an Operator's customers (we are the processor). When an Operator uses OrbitOps Pro to manage their own customers, that customer information belongs to the Operator. We process it on the Operator's behalf and under their instructions — we do not own it, sell it, or use it for our own purposes. If you are a customer of a business that uses OrbitOps Pro and you have questions about your data, contact that business directly; they are the controller of that information.
Information we collect
From Operators (account and business data): business name, business email and phone, business address, your name, username, role, and login credentials, your business logo, tax settings, your payment-processor connection details (see Payments below), and — if you choose to connect QuickBooks Online — your QuickBooks connection details and accounting preferences (see QuickBooks Online Integration below).
From Operators, about their customers (processed on the Operator's behalf): customer or household names, service addresses, contact name/phone/email, service locations and their geolocation coordinates, on-site equipment records, service history and job notes, and invoice and payment records. OrbitOps Pro does not decide what customer data an Operator enters; the Operator does.
From technicians using the mobile field application: when a technician chooses to optimize their route, the application reads the device's location at that moment and transmits it to the Service solely to order that day's stops from the technician's current position. This location is not stored, is not retained after the route is ordered, and is not made available to the Operator or any other user. When a technician chooses to take a photo, the application accesses the device camera; photos the technician takes or selects are stored with the associated property or visit record and are visible to the Operator. The application also registers a device notification token so the Operator's office can send work-related notifications to that device.
From our marketing site: if you submit an interest or contact form, we collect the email address, name, and any details you provide.
Automatically: our hosting provider logs standard technical request data (such as IP address and timestamps) for security and reliability. Our product analytics (see below) record how Operators use the application.
We do not collect Social Security numbers, health data, or biometric data, and we do not store payment card numbers (see Payments).
Payments
Payment card processing is handled entirely by Stripe. When a payment is made, card details are entered on Stripe's own hosted checkout — OrbitOps Pro never receives, sees, or stores card numbers or security codes. Our systems store only non-sensitive references such as payment amounts, status, method, and Stripe transaction identifiers. Operators connect their own Stripe accounts to receive funds directly; Stripe handles Operator identity and payout verification through its own onboarding. Stripe's handling of this data is governed by Stripe's privacy policy.
QuickBooks Online Integration
An Operator may connect their own QuickBooks Online company to OrbitOps Pro so that summary accounting entries can be posted into their books. The integration is optional, is initiated by the Operator, and works as described below.
What we access. The connection uses Intuit's OAuth 2.0 authorization with a single scope — com.intuit.quickbooks.accounting, the Accounting API. We do not request or use the QuickBooks Payments API or the QuickBooks Payroll API. Within that scope:
- We read the chart of accounts only — account id, name, type, and classification — so the Operator can map which accounts OrbitOps Pro posts to.
- We write summary journal entries. Journal entries are the only records OrbitOps Pro creates in QuickBooks.
- We do not read or import QuickBooks customers, invoices, transactions, or any other financial records. Apart from reading the chart of accounts, data flows in one direction only: from OrbitOps Pro into QuickBooks.
What we store. For a connected company we store only:
- The OAuth access token, refresh token, and QuickBooks company (realm) id — each encrypted at rest with AES-256-GCM, with the encryption key held as a platform secret separate from the database.
- The Operator's account mapping — which of their accounts revenue, sales tax, receivables, and cash post to.
- A record of the journal entries we posted: the period, the QuickBooks entry id, and the amounts.
We store no customer financial data retrieved from QuickBooks.
How it is used. This information is used solely to post monthly summary journal entries that the Operator triggers manually — nothing is automated or scheduled. Tokens are used only server-side and are never sent to the browser. Each connected company's data is isolated from every other company's.
What we never do with QuickBooks data. We do not sell it, share it, or make it available to any third party. We do not use it for marketing or advertising, and we do not send it to our product analytics provider. It is not used for any purpose other than the accounting-posting function described above. The stored connection record lives in our own hosted database, encrypted at rest, and is not disclosed to anyone else.
Disconnecting. An Operator can disconnect QuickBooks at any time from Settings in the application. Disconnecting deletes the stored connection outright — access token, refresh token, realm id, and account mapping are all removed. Journal entries already posted remain in the Operator's QuickBooks company, because that data belongs to the Operator.
Questions about this integration can be sent to support@orbitopspro.com.
Service providers we share data with
We use a small set of trusted providers to operate OrbitOps Pro. Each processes data only as needed to provide their service:
- Supabase — our database and authentication provider; stores account and application data.
- Stripe — payment processing (see Payments).
- Resend — delivery of transactional emails (invoices, estimates, statements, and similar), which may include attached documents containing customer names, addresses, and line items.
- PostHog — product analytics, configured to identify only Operators and their organizations. It is deliberately configured so that an Operator's customer personal information is not sent to it.
- Cloudflare — hosting and request logging.
- Google Maps Platform — where enabled, customer service addresses are sent to Google's geocoding and routing services to validate addresses and optimize technician routes. Where a technician optimizes their route from their current position, that technician's device location is sent as the route's starting point.
- Apple and Google — delivery of push notifications to the technician's device. Notification content is limited to work-related information and does not include an Operator's customer personal information.
- Google (Gemini API) — where an Operator uses an AI drafting feature, the text or document for that draft is sent to Google's Gemini API and a suggested draft is returned. This applies to rewriting a technician's visit note into customer-readable text, and to drafting a marketing post about a completed job, which carries the trade and the work performed, not the customer; in both cases customer and property names, service addresses, phone numbers and email addresses, and any line referring to a gate, lockbox, alarm or code, are replaced or removed before the text is sent. It will shortly apply to reading a photographed purchase receipt or supplier bill in order to pre-fill an expense entry, which is the Operator's own purchase document rather than customer information. Nothing is sent unless an Operator uses the feature, and what comes back is a draft the Operator accepts or discards. We use the paid Gemini API, whose terms exclude using data submitted through it to train Google's models. There is no customer-facing AI in OrbitOps Pro: no model speaks to, writes to, or generates anything sent to an Operator's customer.
None of these providers receive data from an Operator's connected QuickBooks Online company, and none of them are given access to it.
We do not sell personal information, we do not share it with third parties for their own marketing, and we do not share it with anyone beyond the providers listed above, except where required by law.
Analytics and tracking
Our marketing site uses no analytics, advertising, or tracking cookies. Our application uses PostHog for product analytics, configured privacy-first: no automatic capture of page content, no session recording, and an enforced filter that prevents Operator customer personal information from being sent to analytics. We measure how Operators use features, not who their customers are. No QuickBooks Online data is sent to analytics. We do not use any of the data described in this policy for advertising, and we do not run advertising on our site or in our application.
How we protect data
Access to the application requires authentication. Each Operator organization's data is logically separated, and our application enforces that separation on every request so that one Operator cannot access another Operator's data. Sessions use secure, HTTP-only cookies. We work to protect information but no method of transmission or storage is completely secure.
Data retention and your choices
We retain Operator account data for as long as an account is active. Operators can remove or archive customer records within the application. QuickBooks Online connection data is retained only while the connection is active and is deleted when an Operator disconnects, as described under QuickBooks Online Integration above. To request deletion of your Operator account data, or if you are an Operator with questions about customer-data handling, contact us at support@orbitopspro.com — we handle deletion requests as an operational process. If you are an Operator's customer, direct data requests to the business that serves you, as they control that data.
Requesting deletion
If you are a technician or other staff user, your OrbitOps Pro login belongs to the business that employs you — that business created it and administers it. Ask your employer to delete your account; they can remove your access and your user record from within the application. We do not delete a staff account on request without the Operator's instruction, because the account is theirs to administer.
If you are an Operator, email support@orbitopspro.com from the address on your account to request deletion of your company's data. We confirm the request with you, then delete your organization's records — your account and user logins, your customer records, service history, job notes and photos, and any stored integration connections, including the QuickBooks Online connection described above.
If you are a customer of a business that uses OrbitOps Pro, send your deletion request to that business. They control that information; we process it on their behalf and act on their instruction.
What is retained after deletion. We retain invoice, payment and tax records for as long as applicable law requires us or the Operator to keep them, and our hosting provider's standard security and request logs expire on their own schedule. Records already posted into an Operator's own QuickBooks Online company remain there, because that data belongs to the Operator. Routine backups are overwritten on their normal cycle.
Children
OrbitOps Pro is a business tool not directed to children and is not intended for anyone under 18.
Scope
OrbitOps Pro currently serves businesses in the United States. This policy is written accordingly; if we expand internationally, we will update it to address additional obligations.
Changes and contact
We may update this policy; material changes will be reflected in the "last updated" date. Questions about this policy, or about privacy and data handling generally: support@orbitopspro.com.
Mailing address: OrbitOps Pro, LLC · 6650 Rivers Ave STE 100, Charleston, SC 29406