1. Introduction
Welcome to Orbit! We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about our policy, or our practices with regards to your personal information, please contact us at support@orbitaim.io.
Orbit by OrbitAIM is an AI-native marketing superapp that helps small and mid-sized businesses unify strategy, content, lead generation, and automation into a single intelligent platform. Rather than forcing teams to stitch together 8–10 separate tools for email, CRM, content, and reporting, Orbit acts as a central business brain that codifies best practices, executes campaigns, and optimizes performance with minimal human intervention.
About OrbitAIM and Our Platform
OrbitAIM is operated and managed by HEMANT GADODIA. Our mission is to enable growth-focused teams and SMEs to run advanced, multi-channel marketing without deep in-house expertise. We embed strategy and repeatable processes inside automation so every campaign is rooted in a shared brand playbook rather than ad-hoc prompts or disconnected slides.
We specifically target SMEs, startups, and mid-market teams—business owners, marketing managers, and employer-branding leads who want a guided, scalable system without the complexity of enterprise suites. Orbit is built for teams that are resource-constrained, forward-looking on AI, and tired of juggling many disconnected tools.
Our Five Integrated Modules
Orbit provides five core modules that work together as a unified marketing automation platform. Understanding these modules helps clarify what data we collect and why:
- Strategy & Knowledge Hub: The "Brain" of Orbit. This module stores your brand guidelines, Ideal Customer Profiles (ICPs), tone of voice settings, and messaging pillars. It ensures every AI-generated output remains on-brand and consistent across all channels. Data stored here directly influences content quality.
- Content & Creation: AI-powered writers for LinkedIn posts, blog articles, and cold emails. This module includes "Assisted Ideation" to generate hooks, angles, and content frameworks instantly. Your usage patterns help us improve AI recommendations.
- Lead Engine: A complete lead generation machine featuring prospecting, data enrichment, list management, and full lifecycle tracking from first touch to conversion. This module processes prospect data to help you build and manage your sales pipeline effectively.
- Automation & Workflows: Curated, pre-built workflows with trigger-based sequences. For example, LinkedIn engagement can automatically trigger email follow-ups. These workflows are executed by autonomous AI agents that process your campaign data.
- Analytics & Dashboards: Actionable metrics for SMEs including ROI tracking, engagement rates, open rates, and "AI Usage" transparency. This module aggregates your campaign data to provide insights and help you close the loop from activity to outcome.
Our Business Model & Credits System
Orbit operates on a Membership + Credits model designed for teams. A base subscription covers your platform access and team seats (optimized for teams of 3-10+), while our "Orbit Credits" currency powers AI-driven features. Understanding this model is important for knowing how we track and process usage data:
- Subscription Credits: Included monthly with your plan (Starter, Pro, or Growth tiers). These refresh each billing cycle and do not roll over.
- Top-up Credits: Additional credit packs you can purchase. These never expire and remain in your account until used.
- Credit Consumption: Different features consume different amounts of credits. For example, generating a cold email may cost 1 credit, while deep web research may cost 2 credits. All consumption is transparently tracked in your dashboard.
- Company Credit Pool: Credits are shared across your entire team/company, allowing flexible allocation based on who needs AI assistance most.
Scope of This Privacy Policy
This privacy policy describes how and why we collect, store, use, and share your information when you use our services, including when you:
- Register on the platform and create your company workspace
- Connect third-party services like Gmail for email automation
- Input brand guidelines and ICPs into the Strategy Hub
- Utilize our AI-powered content writers for LinkedIn, blogs, and emails
- Access the Lead Engine for prospecting and data enrichment
- Set up and run Automation Workflows with AI agents
- Purchase subscriptions or top-up credit packs
- View Analytics & Dashboards for campaign performance
Our Privacy Commitment
At OrbitAIM, we believe that trust is the foundation of any successful business relationship. We are committed to:
- Transparency: Being clear about what data we collect, why we collect it, and how it is used
- Security: Implementing robust technical and organizational measures to protect your data
- Control: Giving you meaningful control over your personal information and how it is processed
- Minimal Collection: Only collecting data that is necessary to provide and improve our services
- No Data Selling: We never sell your personal data or Gmail data to third parties for advertising purposes
By using Orbit, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
Orbit's use of information received from Gmail APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
Technology Stack: Orbit runs on a modern stack (Next.js frontend; Python/Express backend; TypeScript) and uses LLMs, autonomous AI agents, and LangChain to orchestrate workflows. All data processing is performed on secure, encrypted infrastructure.
3. How We Use Your Information
We use personal information collected via our platform for a variety of business purposes described below. We process your personal information for these purposes in reliance on our legitimate business interests, in order to enter into or perform a contract with you, with your consent, and/or for compliance with our legal obligations.
Orbit is designed to be your "central business brain" for marketing operations. Below we explain in detail how we use your information across each of our five integrated modules.
Account Management & Platform Access
- Account Creation & Authentication: We use your name, email, and credentials to create your account, verify your identity, and provide secure access to the platform.
- Workspace Setup: We use company information to configure your shared workspace, assign team seats (optimized for teams of 3-10+), and set up role-based permissions.
- Administrative Communications: We send product updates, security alerts, credit balance notifications, subscription renewal reminders, and important policy changes.
- Team Collaboration: We facilitate team messaging, shared access to campaigns, and collaborative features within your company workspace.
Strategy & Knowledge Hub Usage
The Strategy Hub is the "Brain of Orbit. We use the data you store here to power personalized AI experiences across all modules:
- Brand Consistency: We use your brand guidelines, core values, and visual identity information to ensure all AI-generated content remains on-brand across LinkedIn posts, blogs, and emails.
- ICP Targeting: Your Ideal Customer Profiles (ICPs) inform lead targeting in the Lead Engine and help personalize cold outreach messaging to resonate with specific audience segments.
- Tone Calibration: Tone of voice settings (formal/casual, technical/simple, persuasive/informative) are applied to all AI content generation to match your communication style.
- Messaging Alignment: Your messaging pillars and value propositions are woven into generated content to maintain consistent positioning across all channels.
- Competitive Differentiation: Competitor information helps the AI emphasize your unique selling points and avoid messaging that overlaps with competitors.
Content & Creation Module Usage
When you use our AI-powered content writers and Assisted Ideation features, we use your data to:
- Generate LinkedIn Posts: Create engaging, on-brand LinkedIn content using your Strategy Hub data, topic preferences, and content style guidelines.
- Write Blog Articles: Produce long-form content that reflects your brand voice, targets your ICP, and incorporates your messaging pillars.
- Craft Cold Emails: Generate personalized outreach emails that align with your ICP definitions and incorporate proven cold email frameworks.
- Power Assisted Ideation: Generate hooks, angles, subject lines, and content frameworks to accelerate your creative process.
- Learn From Feedback: Use your edits, ratings, and content performance feedback to improve future AI recommendations and better align with your preferences.
- Save Templates: Store your custom templates and formatting preferences for efficient reuse across campaigns.
Lead Engine Usage
The Lead Engine is a complete lead generation machine. We use your data to support your full sales pipeline:
- Prospecting: Match your ICP criteria against prospect databases to identify and surface relevant leads for your outreach campaigns.
- Data Enrichment: Enhance prospect records with additional information like LinkedIn profiles, company size, industry, and contact details to improve targeting accuracy.
- List Management: Organize prospects using tags, segments, and custom fields to enable targeted campaign execution.
- Lifecycle Tracking: Monitor lead progression from first touch through qualification to conversion, providing visibility into your sales funnel.
- Lead Scoring: Use engagement signals (email opens, clicks, responses) to automatically prioritize high-intent leads for follow-up.
- Interaction History: Maintain a complete record of all touchpoints with each lead for context in follow-up conversations.
Automation & Workflow Usage
We process your data to execute automation workflows powered by autonomous AI agents:
- Trigger-Based Sequences: Execute automated actions based on events like email opens, link clicks, LinkedIn engagement, or time-based triggers.
- Multi-Channel Campaigns: Run coordinated campaigns across channels (e.g., LinkedIn engagement automatically triggers email follow-up sequences).
- AI Agent Execution: Deploy autonomous AI agents to execute complex workflow sequences with minimal human intervention.
- Scheduled Sending: Queue emails, posts, and other actions for optimal delivery times based on your preferences.
- Workflow Optimization: Analyze workflow performance data to identify bottlenecks and suggest improvements.
Analytics & Dashboard Usage
We aggregate and analyze your data to provide actionable insights:
- Campaign Performance: Calculate and display open rates, click-through rates, response rates, and conversion metrics for all your campaigns.
- ROI Tracking: Track revenue attribution, cost-per-lead, and return on investment to help you understand marketing effectiveness.
- AI Usage Transparency: Provide detailed breakdowns of how AI features contributed to your results, including credit consumption by feature type.
- Engagement Analytics: Monitor LinkedIn post performance, blog traffic, email engagement, and overall channel effectiveness.
- Custom Reporting: Generate and save custom reports based on your specific KPIs and business objectives.
Credits & Subscription Management
We track and manage your Orbit Credits to ensure transparent, predictable billing:
- Credit Allocation: Allocate monthly subscription credits based on your plan tier (Starter, Pro, or Growth) and track consumption across all AI-powered features.
- Usage Tracking: Log credit usage per action (e.g., 1 credit for cold email generation, 2 credits for deep web research) with full transparency.
- Balance Notifications: Alert you when credit balance is running low or when subscription renewal is approaching.
- Top-up Processing: Process purchases of additional credit packs that never expire and add to your company pool.
- Company Pool Management: Manage shared credit allocation across team members within your company workspace.
Platform Improvement & Support
- Product Development: Analyze aggregated usage patterns to identify popular features, pain points, and opportunities for improvement.
- Customer Support: Use your account and usage data to provide faster, more accurate support when you contact our team.
- Onboarding Assistance: Guide new users through platform setup based on their company profile and goals.
- Feature Recommendations: Suggest relevant features and workflows based on your usage patterns and business objectives.
- Quality Assurance: Monitor platform performance, identify bugs, and ensure reliable service delivery.
Legal & Compliance Usage
- Terms Enforcement: Monitor compliance with our Terms of Service and Acceptable Use Policy, including fair use of AI credits.
- Fraud Prevention: Detect and prevent fraudulent activity, unauthorized access, and abuse of platform features.
- Legal Compliance: Respond to valid legal requests, subpoenas, and regulatory inquiries as required by law.
- Dispute Resolution: Use transaction and usage records to resolve billing disputes or service-related issues.
How We Use Your Gmail Data
We use information received from Gmail APIs specifically for the following purposes related to our Cold Emailer and automation features:
- Email Composition & Sending: Compose, read, send, and organize emails through our platform interface using your connected Gmail account.
- Cold Email Campaigns: Send personalized cold outreach emails to prospects in your Lead Engine lists with tracking and follow-up automation.
- Email Automation: Execute scheduled sending, email sequences, and automated follow-ups as part of your workflow configurations.
- Delivery Tracking: Track email delivery status, opens, and clicks to measure campaign effectiveness and trigger follow-up actions.
- Response Detection: Identify and categorize responses to automatically update lead status and pause automation when appropriate.
- Sync & Backup: Synchronize email data within our platform for seamless access and backup purposes.
We do NOT use your Gmail data for:
- Sending unsolicited commercial emails or spam
- Advertising, retargeting, or serving ads to you or others
- Training general AI/machine learning models (your data is only used to personalize your own experience)
- Selling, renting, or trading your data to third parties
- Any purpose not explicitly disclosed in this privacy policy
Our Commitment to Ethical AI Use
Orbit uses LLMs, autonomous AI agents, and LangChain to orchestrate workflows. We are committed to using AI responsibly: your Strategy Hub data trains personalization for your account only, not shared models. We provide full "AI Usage" transparency in dashboards so you can see exactly how automation aids your growth.
4. How We Share Your Information
We only share information with your consent, to comply with laws, to provide you with services, to protect your rights, or to fulfill business obligations. As a marketing automation platform, Orbit integrates with various third-party services to deliver comprehensive functionality. Below we explain in detail how and when we share your information.
Sharing Within Your Organization
Orbit is designed for teams of 3-10+ members. Your data may be shared within your organization in the following ways:
- Team Workspace Access: Team members in your shared workspace can access campaigns, leads, content, and analytics based on their assigned roles and permissions.
- Company Credit Pool: Orbit Credits are shared across your team, so credit consumption is visible to administrators and tracked at the company level.
- Strategy Hub Data: Brand guidelines, ICPs, tone settings, and messaging pillars are shared across all team members to ensure brand consistency.
- Lead Engine Lists: Prospect lists and lead data can be shared among team members for collaborative sales and marketing efforts.
- Campaign Collaboration: Multiple team members can collaborate on campaigns, workflows, and content creation.
Service Providers & Infrastructure Partners
We work with trusted third-party service providers who help us operate and improve the Orbit platform:
- Cloud Hosting Providers: We use secure cloud infrastructure (AWS, Google Cloud, or similar) to host our platform and store your data with enterprise-grade security.
- Database Services: Your data is stored in secure, encrypted databases managed by trusted providers with SOC 2 compliance.
- AI/LLM Providers: We use large language model providers to power our AI content writers, Assisted Ideation, and autonomous AI agents. Your prompts and generated content pass through these services.
- Email Delivery Services: For cold email campaigns, we may use email delivery infrastructure to ensure high deliverability rates.
- Payment Processors: Subscription payments and credit top-up purchases are processed by PCI-compliant payment providers. We never store full credit card numbers.
- Analytics Services: We use analytics tools to understand platform usage and improve performance. This data is aggregated and anonymized.
Data Enrichment & Lead Services
The Lead Engine module may share limited data with enrichment services:
- Prospect Enrichment: When you use our data enrichment features, basic prospect information (name, email, company) may be sent to enrichment providers to retrieve additional details like LinkedIn profiles and company data.
- Lead Verification: Email addresses may be verified through third-party services to ensure deliverability and reduce bounces.
- Web Research: When you use our AI-powered web research features (2 credits), we may query external data sources to gather publicly available information.
Third-Party Integrations
When you connect Orbit with third-party services, data flows between our platform and those services:
- Gmail Integration: Email content, contacts, and settings are accessed via Gmail APIs for cold email campaigns and automation (see Section 5 for details).
- LinkedIn Integration: For LinkedIn content posting and engagement tracking, we may connect with LinkedIn APIs to publish posts and retrieve analytics.
- CRM Integrations: If you connect external CRM tools, lead data may be synchronized bidirectionally based on your configuration.
- Webhook Integrations: Custom workflow triggers may send data to external services you configure.
Business Circumstances
- With Your Consent: We may share your information when you have given us explicit permission to do so, such as when publishing testimonials or case studies.
- Business Transfers: In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. In such cases involving Google user data, we will obtain your explicit prior consent.
- Legal Requirements: When we believe disclosure is necessary to comply with applicable law, regulation, legal process, or governmental request.
- To Protect Rights: When we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to safety, or as evidence in litigation.
- Aggregated/Anonymized Data: We may share aggregated, anonymized data that cannot identify you for research, benchmarking, or marketing purposes.
Sharing of Google User Data
We share, transfer, or disclose your Google user data only in the following limited circumstances, in strict compliance with Google API Services User Data Policy:
Third-Party Service Providers
We may share your Google user data with carefully vetted third-party service providers who assist in delivering our services (such as cloud hosting providers and database management services). These providers are contractually obligated to:
- Keep your information confidential and secure
- Use it only for the specific purposes we define
- Comply with Google API Services User Data Policy
- Implement appropriate security measures
- Delete data upon termination of their service relationship
Email Automation Services
When you use our Cold Emailer and Automation Workflows, email content may be processed by our email delivery infrastructure to ensure reliable sending and tracking. All providers adhere to strict data protection standards.
Legal Compliance
We may disclose your Google user data when required by law, regulation, legal process, governmental request, or court order. We will notify you of such requests when legally permitted.
With Your Explicit Consent
We may share your Google user data with other third parties when you have provided explicit permission for us to do so, such as when connecting additional integrations or services.
We do NOT:
- Sell, rent, or trade your Google user data or any personal data to any third parties
- Share your Google user data with advertisers or marketing companies for their own purposes
- Use your Google user data for purposes unrelated to providing our core services
- Share your Strategy Hub data, ICPs, or brand guidelines with competitors or third parties
- Allow third parties to use your data for AI model training
Our Data Protection Commitment
All third-party providers we work with are carefully vetted for security practices and sign data processing agreements (DPAs) that require them to protect your data to the same standards we maintain. We regularly audit our providers to ensure compliance.
5. Gmail API Services
Orbit uses Gmail API services to power our Cold Emailer and Automation Workflow features. This section explains in detail how we use Gmail APIs, what data we access, and how we protect your email data in compliance with Google API Services User Data Policy.
Gmail integration is a core component of Orbit's multi-channel marketing capabilities, enabling you to execute personalized cold outreach campaigns, automate follow-up sequences, and track email engagement—all from within the platform.
Why We Need Gmail Access
Orbit's Gmail integration enables the following platform features:
- Cold Emailer Campaigns: Send personalized outreach emails to prospects in your Lead Engine lists with AI-generated content that matches your Strategy Hub settings.
- Email Sequences: Execute multi-step email sequences with automated follow-ups based on recipient behavior.
- Multi-Channel Automation: Trigger email sends based on LinkedIn engagement or other workflow events.
- Delivery Tracking: Monitor email delivery, opens, and clicks to measure campaign effectiveness.
- Response Detection: Automatically detect replies to pause automation and update lead status.
- Unified Inbox: View and manage email conversations alongside your Lead Engine data.
Scopes We Request
We request the following Gmail API scopes to provide our services. Each scope is necessary for specific functionality:
- Read, compose, send, and permanently delete all your email from Gmail
Required for: Comprehensive email management, sending cold emails, managing sent/received messages, and cleaning up draft emails created during campaigns. - View your email messages and settings
Required for: Displaying your emails within Orbit, syncing account configurations, and reading email threads for response detection. - Send email on your behalf
Required for: Sending cold outreach emails and automated follow-up sequences through your Gmail account. - Read, compose, and send emails from your Gmail account
Required for: Creating email drafts, personalizing content with AI, and executing email campaigns.
How We Use Gmail Data in Orbit Features
Cold Emailer Module
- Send personalized cold emails with AI-generated content aligned to your ICP and tone settings
- Execute multi-step email sequences with configurable delays and triggers
- Track email opens, clicks, and replies for analytics
- Automatically pause sequences when recipients respond
Automation Workflows
- Trigger email sends based on workflow events (e.g., LinkedIn engagement → Email follow-up)
- Schedule emails for optimal delivery times
- Integrate with autonomous AI agents for complex sequence execution
- Coordinate multi-channel campaigns across LinkedIn and email
Lead Engine Integration
- Update lead status based on email engagement (opens, clicks, replies)
- Track interaction history for each prospect
- Score leads based on email response behavior
- Move leads through lifecycle stages automatically
Analytics & Dashboards
- Calculate email campaign metrics (open rates, CTR, response rates)
- Provide AI Usage transparency for email-related credit consumption
- Track ROI from email campaigns through to conversion
- Generate reports on email performance by campaign, segment, or time period
Legitimate Use Case
Orbit is an email management and productivity platform designed to enhance your email experience for business purposes. We fall under Google's approved use case for "applications that enhance the email experience for productivity purposes (such as applications for customer relationship management, delayed sending of email, or mail merge)."
Specifically, Orbit provides:
- CRM-like Functionality: Lead management with email tracking and engagement history
- Delayed/Scheduled Sending: Queue emails for optimal delivery times
- Mail Merge Capabilities: Personalized mass outreach with dynamic content fields
- Email Templates: AI-generated templates based on your Strategy Hub settings
- Sequence Automation: Multi-step email campaigns with conditional logic
Anti-Spam Commitment
All emails sent through Orbit require your explicit consent and action. We only send emails to recipients that you personally specify. We require users to confirm that recipients have opted in to receive emails, and we provide mechanisms for recipients to unsubscribe. We strictly prohibit the use of our platform for spam or unsolicited commercial emails. Violations may result in immediate account termination.
Security Measures for Gmail Data
We implement robust security measures to protect your Gmail data:
- Encryption in Transit: All data transmitted between Gmail and Orbit uses TLS 1.2 or higher
- Encryption at Rest: Email data stored on our servers is encrypted using AES-256
- Secure Token Storage: OAuth tokens are stored in encrypted, access-controlled environments
- Access Controls: Only authorized services can access Gmail data, with strict role-based permissions
- Audit Logging: All access to Gmail data is logged for security monitoring
- Regular Security Audits: We conduct regular security assessments of our Gmail integration
Human Access to Your Gmail Data
Our employees do not access or read your emails except in the following strictly limited circumstances:
- With Your Explicit Consent: You have specifically requested technical support and granted permission for troubleshooting email-related issues
- Security Investigations: It is necessary to investigate abuse, unauthorized access, security incidents, or violations of our Terms of Service
- Legal Compliance: Required by applicable law, regulation, or valid legal process (subpoena, court order)
All employee access is logged, monitored, and subject to strict confidentiality agreements. Employees who access user data undergo additional privacy training.
Data Retention and Deletion
Gmail data accessed through our platform is handled as follows:
- Secure Storage: Stored securely using industry-standard encryption (both in transit and at rest)
- Minimal Retention: Retained only as long as necessary to provide our services to you
- Automatic Deletion: Automatically deleted within 30 days after you revoke our access or delete your account (unless retention is required by law)
- Campaign Data: Email campaign analytics (aggregated metrics) may be retained for your historical reporting needs
- Purpose Limitation: Never used for purposes beyond those disclosed in this policy
How to Revoke Access
You can revoke Orbit's access to your Gmail account at any time:
- Visit: https://myaccount.google.com/permissions
- Find "Orbit" or "OrbitAIM" in the list of connected apps
- Click "Remove Access" to immediately revoke permissions
- We will cease all access and begin data deletion immediately
Access Review Requirements
Google will ask you to review Orbit's access to your Gmail data every 6 months, unless you choose to allow ongoing access during the initial authorization process. This is a Google security feature designed to ensure you remain in control of your data.
Limited Use Disclosure
Orbit's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. This means we:
- Only use Gmail data for the purposes described in this policy
- Do not use Gmail data for advertising purposes
- Do not allow humans to read your email content except in limited circumstances with your consent
- Do not transfer Gmail data to third parties except as necessary to provide our services or as required by law
6. How Long We Keep Your Information
We will retain your personal information only for as long as necessary to fulfill the purposes outlined in this privacy policy, unless a longer retention period is required or permitted by law. This section provides detailed information about our retention practices for each type of data we collect.
Our retention policies are designed to balance your right to data minimization with our need to maintain service quality, comply with legal obligations, and support your business continuity needs.
Retention by Data Category
General Account Data
Active Account: Retained for as long as your account is active or as needed to provide you services.
Post-Deletion: After account deletion, we retain certain information for up to 90 days for backup and recovery purposes. This includes your profile, team settings, and workspace configurations.
Includes: Name, email, company information, team member data, profile preferences, language settings, and timezone configurations.
Strategy Hub & Brand Data
Active Subscription: Your brand guidelines, ICPs, tone of voice settings, and messaging pillars stored in the Strategy & Knowledge Hub are retained for the duration of your active subscription.
Post-Deletion: This data is permanently deleted within 30 days after account deletion.
Rationale: This data serves as the "Brain" of Orbit, powering personalized AI content generation across all modules. Immediate deletion upon account closure ensures your proprietary brand information is not retained.
Orbit Credits & Billing Data
Subscription Credits: Monthly allocation that refreshes each billing cycle. Unused subscription credits do not roll over to the next month.
Top-up Credits: One-time purchases that never expire and remain associated with your company account until used or the account is deleted.
Transaction History: Credit consumption logs, purchase records, and billing information are retained for 7 years as required by financial regulations and tax compliance.
Includes: Credit balance history, feature usage logs (e.g., 1 credit for cold email, 2 credits for web research), subscription plan changes, invoices, and payment method metadata (not full card numbers).
Lead Engine Data
Active Subscription: Prospect lists, enrichment data, lead scoring, and lifecycle records are retained for the duration of your active subscription.
Post-Deletion: All lead data is permanently deleted within 30 days after account closure.
Rationale: This data is essential for maintaining your sales pipeline and tracking conversions from first touch to closure. We retain it to ensure uninterrupted access to your prospect database.
Content & Campaign History
AI-Generated Content: LinkedIn posts, blog drafts, cold emails, and other content created through our AI writers are retained for as long as your account is active.
Campaign Analytics: Open rates, CTR, response rates, and conversion metrics are retained to support our Analytics & Dashboards module.
Post-Deletion: All content and campaign data is permanently deleted within 30 days after account deletion.
Automation Workflow Data
Workflow Configurations: Your custom automation sequences, trigger conditions, and action steps are retained for the duration of your subscription.
AI Agent Logs: Execution logs from autonomous AI agents are retained for 90 days for debugging and performance analysis, then automatically purged.
Scheduled Actions: Future-scheduled emails and posts are retained until execution or cancellation.
Gmail Data
Active Connection: Email data accessed via Gmail APIs is retained only as long as necessary to provide Cold Emailer and automation services.
Post-Revocation: As described in Section 5, Gmail data is permanently deleted within 30 days after you revoke access or delete your account.
Campaign Metrics: Aggregated email analytics (open rates, clicks) may be retained separately for your historical reporting needs.
Technical & Usage Data
Session Data: Login timestamps, IP addresses, and browser information are retained for 90 days for security monitoring.
Error Logs: Application errors and crash reports are retained for 30 days for debugging purposes.
Aggregated Analytics: Anonymized usage patterns may be retained indefinitely for product improvement.
Support & Communication Data
Support Tickets: Customer support conversations are retained for 2 years after resolution for quality assurance and training purposes.
Feedback & Surveys: Product feedback is retained indefinitely in anonymized form for product improvement.
Onboarding Data: Initial setup information is retained for the duration of your subscription.
Legal and Compliance Data
Legal Holds: We may retain certain data longer when required to comply with legal obligations, resolve disputes, or enforce agreements.
Fraud Prevention: Data related to suspected fraud or abuse may be retained for investigation purposes.
Audit Trails: Security-related logs and access records may be retained for up to 3 years for compliance and audit purposes.
Data Deletion Upon Request
You may request deletion of your data at any time by contacting us at support@orbitaim.io or through your account settings. Upon receiving a valid deletion request:
- Standard Deletion: Most data is deleted within 30 days of your request.
- Backup Purge: Backup copies are purged within 90 days.
- Legal Holds: Certain data may be retained if required by law or ongoing legal proceedings.
- Aggregated Data: Anonymized, aggregated data that cannot identify you may be retained for analytical purposes.
Retention Summary Table
| Account & Profile Data | Active subscription + 90 days |
| Strategy Hub Data | Active subscription + 30 days |
| Billing & Credits History | 7 years (legal requirement) |
| Lead Engine Data | Active subscription + 30 days |
| Content & Campaigns | Active subscription + 30 days |
| Gmail Data | Until revocation + 30 days |
| AI Agent Logs | 90 days (auto-purge) |
7. How We Keep Your Information Safe
We implement robust organizational and technical security measures to protect your personal information and Google user data. As an AI-native marketing platform handling sensitive business data, security is fundamental to our architecture and operations.
OrbitAIM, managed by HEMANT GADODIA, is committed to maintaining the highest security standards to protect your Strategy Hub data, Lead Engine prospects, content, and Gmail integrations.
Technical Security Measures
Encryption
- In Transit: All data transmitted between your device and our servers is encrypted using HTTPS/TLS protocols (TLS 1.2 or higher)
- At Rest: User data, including Gmail data, OAuth tokens, and refresh tokens, is encrypted using industry-standard encryption (AES-256)
- API Communications: All API calls between Orbit modules and third-party services use encrypted channels
Access Controls
- Strict role-based access controls (RBAC) limit access to user data to authorized personnel only
- Multi-factor authentication (MFA) required for all administrative and employee access
- Regular access reviews and immediate revocation upon employee departure
- Principle of least privilege applied across all systems
Secure Storage
- OAuth access tokens and refresh tokens are stored encrypted in secure, isolated databases
- Database access is logged and monitored for suspicious activity
- Regular automated backups with encrypted storage
- Data segregation between customer accounts
Security Monitoring
- Continuous monitoring for potential security threats and vulnerabilities
- Automated intrusion detection and prevention systems (IDS/IPS)
- Real-time alerting for suspicious activities
- 24/7 security operations monitoring
Infrastructure Security
- Cloud Infrastructure: Hosted on enterprise-grade cloud platforms with SOC 2 Type II compliance
- Network Security: Firewalls, DDoS protection, and network segmentation protect our infrastructure
- Vulnerability Management: Regular vulnerability scanning and patching of all systems
- Penetration Testing: Annual third-party penetration testing to identify security weaknesses
- Disaster Recovery: Geo-redundant backups and documented disaster recovery procedures
AI & LLM Security
As an AI-native platform using LLMs, autonomous AI agents, and LangChain for workflow orchestration, we implement specific security measures for AI components:
- Data Isolation: Your Strategy Hub data is used only to personalize your own AI experiences, not to train shared models
- Prompt Security: Input validation and filtering to prevent prompt injection attacks
- Output Monitoring: AI-generated content is monitored for compliance with platform policies
- Audit Trails: Full logging of AI agent activities for transparency and debugging
- Third-Party LLM Providers: We use vetted LLM providers with enterprise security agreements
Gmail Integration Security
- OAuth 2.0: Secure authentication using Google's OAuth 2.0 protocol—we never see your Google password
- Token Security: OAuth tokens are encrypted at rest and in transit, with automatic refresh handling
- Scope Minimization: We only request the Gmail API scopes necessary for Cold Emailer and automation features
- Access Revocation: You can revoke access instantly via Google Account settings
Organizational Security
- Employee Training: All employees undergo security awareness training, with additional training for those handling user data
- Background Checks: Security-sensitive roles require background verification
- Confidentiality Agreements: All employees sign NDAs and confidentiality agreements
- Security Policies: Documented security policies and procedures reviewed annually
- Vendor Management: Third-party vendors are vetted for security practices and sign data processing agreements
Compliance & Standards
- Google API Services User Data Policy: Full compliance with Google's requirements for Gmail API access
- Data Protection: Alignment with GDPR principles for data protection and privacy
- Industry Best Practices: Following OWASP guidelines for web application security
- Regular Audits: Internal and external security audits to verify compliance
Incident Response
In the event of a security incident, we have established procedures to respond quickly and effectively:
- Detection: Automated systems and manual monitoring to detect potential incidents
- Response Team: Dedicated incident response team with defined roles and responsibilities
- Containment: Rapid containment procedures to limit impact
- User Notification: Affected users will be notified within 72 hours of confirmed data breaches, as required by applicable laws
- Root Cause Analysis: Post-incident analysis to prevent recurrence
Your Role in Security
Security is a shared responsibility. We recommend the following best practices for your Orbit account:
- Use strong, unique passwords for your Orbit account
- Enable multi-factor authentication when available
- Review team member access regularly and remove inactive users
- Report suspicious activity to support@orbitaim.io immediately
- Regularly review third-party app permissions in your Google Account
Important Notice: Despite our comprehensive security measures, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. We continuously improve our security posture and promptly address any identified vulnerabilities.
8. Do We Collect Information From Minors?
We do not knowingly solicit data from or market to children under 18 years of age. Orbit is designed exclusively as a B2B (business-to-business) marketing automation platform for SMEs, startups, and marketing professionals—not for personal or consumer use by minors.
Age Requirements
- Minimum Age: You must be at least 18 years old to create an Orbit account and use our services.
- Business Representation: By registering, you represent that you are authorized to act on behalf of your company and have the legal capacity to enter into binding agreements.
- Team Members: All team members added to your company workspace must also be at least 18 years of age.
- Parental Consent: If you are the parent or guardian of a minor who has created an account without authorization, please contact us immediately.
Why Age 18?
The 18-year age requirement reflects the nature of our platform:
- Professional Use: Orbit is designed for marketing professionals, business owners, and startup founders making strategic business decisions.
- Financial Transactions: Our subscription plans (Starter, Pro, Growth) and Orbit Credits system require the ability to enter into financial agreements.
- Third-Party Integrations: Use of Gmail APIs, LinkedIn integrations, and other connected services require users to have their own authorized accounts.
- Data Responsibility: Users handle prospect data in the Lead Engine and are responsible for compliance with outreach regulations.
If We Discover Minor Users
If we learn that we have collected personal information from a user under the age of 18 without verification of proper authorization, we will take the following steps:
- Immediate Account Suspension: The account will be temporarily suspended pending verification.
- Parental Notification: If contact information for a parent or guardian is available, we will notify them.
- Data Deletion: All personal data, Strategy Hub configurations, Lead Engine data, content, and Gmail connections will be permanently deleted.
- Credit Refund: Any unused Top-up Credits will be refunded where applicable.
- Documentation: We will document the incident for compliance purposes.
Reporting Underage Users
If you become aware of any data we have collected from children under 18, or if you believe someone under 18 is using our platform, please contact us immediately:
Email: support@orbitaim.io
Subject Line: "Minor User Report"
Please include any relevant information that will help us identify and address the situation promptly. We treat all such reports with urgency and confidentiality.
Compliance Statement
OrbitAIM, managed by HEMANT GADODIA, complies with applicable laws regarding the protection of children's data, including the Children's Online Privacy Protection Act (COPPA) in the United States and similar regulations in other jurisdictions. We do not knowingly collect, use, or disclose personal information from children under 13 (or applicable age in your jurisdiction) without verifiable parental consent.
9. What Are Your Privacy Rights?
OrbitAIM, managed by HEMANT GADODIA, is committed to respecting your privacy rights. Depending on your location and applicable laws, you have several rights regarding your personal information and how we process it.
We make it easy for you to exercise these rights through your account dashboard, direct email requests, or by managing your third-party app permissions (for Gmail data).
General Privacy Rights
✓Right to Access: Request access to and obtain a copy of your personal information
✓Right to Rectification: Request correction of inaccurate or incomplete personal data
✓Right to Erasure: Request deletion of your personal information (subject to certain legal exceptions)
✓Right to Restriction: Request restriction of processing of your personal information
✓Right to Data Portability: Request transfer of your data to another service in a structured, commonly used format
✓Right to Object: Object to our processing of your personal information
✓Right to Withdraw Consent: Withdraw your consent at any time where we rely on consent as the legal basis for processing
Rights Specific to Orbit Platform Features
Given the nature of our AI-native marketing platform, you have specific rights related to each module:
Strategy & Knowledge Hub Data
You can view, edit, or delete your brand guidelines, ICPs, tone settings, and messaging pillars at any time from your dashboard. Request a full export of your Strategy Hub data in JSON or CSV format.
Content & Creation Data
Access, edit, or delete all AI-generated content including LinkedIn posts, blog articles, cold emails, and ideation outputs. Export your content history for migration or archival purposes.
Lead Engine Data
Export your prospect lists, enrichment data, lead scores, and interaction history. Delete individual leads or entire lists. Request information about how leads were scored or categorized by our AI.
Automation & Workflow Data
Pause, modify, or delete any active automation workflows. Cancel scheduled emails or posts. Request logs of AI agent activities related to your account.
Analytics & Dashboard Data
Export campaign analytics, performance metrics, and ROI reports. Request an AI Usage transparency report showing credit consumption by feature.
Orbit Credits & Billing Data
View your complete credit transaction history, subscription details, and invoices. Request detailed billing records for accounting purposes. Note: Financial records are retained for 7 years per legal requirements.
Managing Your Gmail Data
You have complete control over your Gmail data:
- Revoke Access: You can revoke Orbit's access to your Gmail account at any time by visiting: https://myaccount.google.com/permissions
- View Connected Data: See which Gmail data is being accessed through your Orbit dashboard
- Export Your Data: Request a copy of your data stored in our platform, including email campaign metrics and send history
- Delete Your Data: Request deletion of all your data, including Gmail data, by contacting us at support@orbitaim.io or using the account deletion feature in your dashboard
- Pause Integration: Temporarily disconnect Gmail without deleting your account
Upon receiving a valid deletion request, we will delete your Gmail data within 30 days. Aggregated, anonymized campaign metrics (not containing personal information) may be retained for your historical reporting needs.
Team Member Rights
If you are a team member in a company workspace (rather than the account owner):
- Contact Your Admin: Some data management requests may need to be processed by your company's Orbit administrator
- Personal Profile Data: You can directly access and modify your own profile information
- Gmail Connection: If you connected your personal Gmail, you maintain full control over that integration
- Leave Workspace: You can request to be removed from a company workspace at any time
Regional Privacy Considerations
Depending on your location, you may have additional rights:
- European Union (GDPR): Full data subject rights including access, rectification, erasure, restriction, portability, and objection. Right to lodge a complaint with your local data protection authority.
- California (CCPA/CPRA): Right to know what personal information is collected, right to delete, right to opt-out of sale (note: we do not sell personal information), and right to non-discrimination for exercising your rights.
- India (DPDP Act): Rights including access, correction, erasure, and the right to nominate another person to exercise rights on your behalf.
- Other Jurisdictions: We comply with applicable data protection laws in all jurisdictions where we operate.
How to Exercise Your Rights
To exercise any of your privacy rights, you have multiple options:
Self-Service Options
- Account Dashboard: Access, edit, and delete most data directly through your Orbit dashboard
- Profile Settings: Update your personal information and preferences
- Export Tools: Download your data using built-in export features
- Google Account: Manage Gmail permissions directly at myaccount.google.com/permissions
Contact Us Directly
Email: support@orbitaim.io
Subject Line: "Privacy Rights Request - [Type of Request]"
Please include your account email address and specify which rights you wish to exercise. For security purposes, we may need to verify your identity before processing certain requests.
Response Timeline
- Acknowledgment: We will acknowledge your request within 48 business hours
- Standard Response: Most requests are completed within 30 days
- Complex Requests: If your request is complex or if we receive many requests, we may extend this period by up to 60 additional days (we will notify you if this is necessary)
- No Fee: We do not charge a fee for exercising your privacy rights unless requests are manifestly unfounded or excessive
Exceptions to Deletion Requests
We may need to retain certain information even after a deletion request in the following circumstances:
- Legal obligations requiring data retention
- Ongoing legal disputes or investigations
- Prevention of fraud or abuse
- Billing records required for tax compliance (7 years)
- Anonymized, aggregated data that cannot identify you
10. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected.
Our Current DNT Response
At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.
If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy policy.
Tracking Technologies We Use
Understanding what tracking technologies we use helps you make informed decisions about your privacy:
Essential Cookies
Required for platform functionality including authentication, session management, and security. These cannot be disabled without affecting your ability to use Orbit. They maintain your login state and workspace preferences.
Functional Cookies
Store your preferences such as language, timezone, and dashboard layout. These enhance your experience but are not strictly necessary. They remember your Strategy Hub settings and content editor preferences.
Analytics Cookies
Help us understand how users interact with our platform, which features are most popular, and how we can improve. This data is used to enhance our AI-native marketing tools and optimize the user experience across all five modules.
Performance Cookies
Monitor platform performance, load times, and error rates. This helps us maintain a fast, reliable service for your Cold Emailer campaigns, automation workflows, and content generation tasks.
What We Do NOT Track
OrbitAIM is committed to minimal data collection. We do NOT:
- Track your activity across other websites (no cross-site tracking)
- Sell or share tracking data with advertisers
- Use tracking pixels for advertising purposes
- Build behavioral profiles for ad targeting
- Share Analytics data with third-party marketing networks
Email Tracking in Cold Emailer
Our Cold Emailer feature includes tracking capabilities for emails you send through the platform:
- Open Tracking: We may include a small transparent pixel to detect when recipients open your emails
- Click Tracking: Links in your emails may be routed through our servers to track click-through rates
- Optional Feature: You can disable email tracking for individual campaigns or globally in your account settings
- Recipient Choice: Email recipients can use email clients that block tracking pixels
Note on Campaign Analytics
The tracking in Cold Emailer is used to provide you with campaign analytics in your Analytics & Dashboards module. This data helps you understand open rates, click rates, and response rates to optimize your outreach campaigns. Your leads are NOT tracked for advertising purposes—only for your own business insights.
Your Tracking Controls
You have multiple options to manage tracking:
- Browser Settings: Adjust your browser settings to refuse cookies or alert you when cookies are being sent
- Account Preferences: Manage analytics and tracking preferences in your Orbit dashboard settings
- Campaign Settings: Disable open and click tracking for individual Cold Emailer campaigns
- Private Browsing: Use private/incognito mode to limit cookie storage
- Third-Party Tools: Use browser extensions designed to block tracking
Important Notice
Disabling certain cookies may impact your ability to use some features of our platform. Essential cookies are required for authentication and basic functionality. If you have questions about our tracking practices, contact us at support@orbitaim.io.
11. International Data Transfers
Your information, including personal data and Gmail data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction.
OrbitAIM, managed by HEMANT GADODIA, operates globally and may transfer data internationally to provide our AI-native marketing platform services. This section explains how we handle such transfers and the safeguards we implement.
Where Your Data May Be Processed
Depending on how you use our platform, your data may be processed in the following locations:
India (Primary Data Center)
Our primary operations and data processing facilities are located in India. Account information, Strategy Hub data, Lead Engine records, content, and billing information are primarily stored and processed here.
Cloud Infrastructure Regions
Our cloud hosting providers maintain data centers in multiple regions. Your data may be replicated across regions for redundancy, disaster recovery, and performance optimization.
Third-Party Service Providers
Some of our service providers (LLM providers, email delivery services, analytics tools) may process data in the United States, European Union, or other jurisdictions. These providers are contractually bound to protect your data.
Google Services
When you connect your Gmail account, data is also processed by Google in accordance with their data processing locations and policies. Gmail data accessed through our platform may pass through Google's infrastructure.
Safeguards for International Transfers
When we transfer data internationally, we implement the following safeguards:
- Standard Contractual Clauses (SCCs): When transferring data from the EEA to countries without adequate data protection, we use EU-approved Standard Contractual Clauses.
- Data Processing Agreements: All service providers who process data on our behalf sign comprehensive data processing agreements with security and confidentiality obligations.
- Encryption: All data transfers are encrypted using TLS 1.2 or higher, and data at rest is encrypted using AES-256.
- Access Controls: Strict role-based access controls limit who can access your data, regardless of location.
- Vendor Assessment: We vet all vendors for their security practices before engaging them and periodically review their compliance.
Regional Considerations
European Union / EEA Users
Data transferred outside the EEA is protected by Standard Contractual Clauses or other approved mechanisms. You have the right to obtain a copy of the safeguards we use by contacting us.
United Kingdom Users
Post-Brexit, we use UK-approved International Data Transfer Agreements (IDTAs) or UK Addendum to EU SCCs for transfers from the UK to non-adequate countries.
California Users
We comply with CCPA/CPRA requirements regarding the transfer of California residents' personal information. We do not sell your personal information.
India Users
For users based in India, data is primarily processed domestically. We comply with the Digital Personal Data Protection Act (DPDP Act) and its requirements.
Data Categories and Transfer Purposes
The following types of data may be transferred internationally:
- Strategy Hub Data: Transferred to AI/LLM providers for content personalization and generation
- Lead Engine Data: May be processed by enrichment services to enhance prospect information
- Content Data: Processed by AI services for LinkedIn posts, blog articles, and cold email generation
- Gmail Data: Processed through Google's infrastructure and our Cold Emailer services
- Billing Data: Processed by payment providers for subscription and credit transactions
- Analytics Data: May be processed by analytics providers to improve platform performance
Gmail Data and International Transfers
When you connect your Gmail account, additional considerations apply:
- Gmail data passes through Google's global infrastructure as part of their service
- Our access to Gmail data is governed by Google API Services User Data Policy
- Cold Emailer campaign data may be processed by email delivery partners
- Email tracking data (open rates, clicks) may be processed in various regions
Your Consent to Transfers
If you are located outside India and choose to provide information to us, please note that we transfer the data, including personal data, to India and process it there.
Your consent to this privacy policy followed by your submission of such information represents your agreement to that transfer. You may withdraw consent by deleting your account, though this may affect your ability to use our services.
Our Commitment
We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy and applicable data protection laws, regardless of where it is processed. This includes implementing appropriate technical and organizational measures to protect your data during and after transfer.
Questions About Data Transfers
If you have questions about international data transfers or would like to obtain a copy of the safeguards we use, please contact us:
Email: support@orbitaim.io
Subject Line: "International Data Transfer Inquiry"
12. Third-Party Services and Links
Our platform may contain links to third-party websites, services, or applications that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the privacy policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Third-Party Service Providers We Use
OrbitAIM, managed by HEMANT GADODIA, integrates with various third-party services to power our AI-native marketing platform. These providers are carefully vetted and contractually bound to protect your data:
| Cloud Hosting Providers | For secure data storage and platform infrastructure (SOC 2 Type II certified) |
| Payment Processors | For processing subscription payments and Orbit Credits purchases (PCI DSS compliant) |
| AI/LLM Providers | For powering content generation, ideation, and AI agents across all modules |
| Analytics Services | For understanding platform usage, performance tracking, and improving our services |
| Email Delivery Services | For Cold Emailer campaign delivery, platform notifications, and transactional emails |
| Lead Enrichment Services | For enhancing prospect data in the Lead Engine with company and contact information |
| Security Services | For fraud prevention, DDoS protection, and security monitoring |
| Customer Support Tools | For managing support tickets, live chat, and customer communications |
Platform-Specific Third-Party Integrations
Different Orbit modules utilize specific third-party services:
Strategy & Knowledge Hub
AI/LLM providers access your brand data to generate personalized guidance and recommendations. Your Strategy Hub data is sent to these providers for processing but is not stored or used to train their models.
Content Creation (LinkedIn, Blog, Cold Email)
AI/LLM providers power all content generation. Your prompts, inputs, and Strategy Hub context are sent to generate personalized content. Each content generation task consumes Orbit Credits based on complexity.
Lead Engine
Lead enrichment services verify and enhance prospect data. AI services analyze and score leads based on your ICP. Lead discovery may pull from third-party B2B databases with appropriate licensing.
Cold Emailer & Automation
Email delivery services send campaigns on your behalf. Email verification services check recipient addresses. AI services personalize email content and subject lines based on prospect data.
Gmail Integration
Google APIs are used to access your Gmail account for sending campaigns, reading responses, and managing threads. All access is governed by the Google API Services User Data Policy.
Analytics & Dashboards
Analytics providers help aggregate performance data across campaigns. Data visualization libraries render your dashboard charts and reports. AI services provide insights and recommendations.
What Data We Share with Third Parties
We only share the minimum data necessary for each service to function:
- AI/LLM Providers: Content prompts, Strategy Hub context (brand voice, ICP, messaging pillars), and input data for generation tasks
- Email Delivery Services: Recipient email addresses, subject lines, and email content for campaign delivery
- Lead Enrichment: Company names, job titles, and email addresses for verification and enhancement
- Payment Processors: Transaction details (amount, plan, credit quantity) — they collect payment information directly
- Analytics Services: Anonymized usage data, feature engagement, and performance metrics
- Cloud Providers: All platform data is stored with encrypted cloud infrastructure providers
Our Data Sharing Principles
- Data Minimization: We only share the minimum data necessary for each third-party service to function
- No Selling of Data: We never sell your personal information or business data to third parties
- Contractual Protections: All third-party providers are bound by data processing agreements with confidentiality and security requirements
- No Model Training: Your data is NOT used to train third-party AI models — it is only processed for your specific requests
- Regular Audits: We periodically review third-party providers for their security and privacy practices
External Links
Our platform may contain links to external websites:
- Blog Content: Links included in AI-generated blog articles
- LinkedIn Posts: Links to external resources in your LinkedIn content
- Lead Profiles: Links to LinkedIn profiles and company websites in Lead Engine
- Cold Emails: Your custom links and resources in email campaigns
- Help & Support: Links to documentation, tutorials, and external resources
We are not responsible for the privacy practices or content of these external sites. We recommend reviewing their privacy policies before providing any personal information.
Your Control Over Third-Party Access
- Gmail Integration: You can revoke access at any time through your Google Account settings
- LinkedIn Integration: Disconnecting LinkedIn stops data flow to LinkedIn-related services
- Lead Engine Data: You can delete leads to remove them from enrichment services
- Content Generation: Your data is only sent to AI providers when you actively use content generation features
- Account Deletion: Deleting your account terminates all third-party data processing on your behalf
Questions About Third-Party Services?
If you have questions about the specific third-party services we use or how your data is shared, please contact us at support@orbitaim.io. We can provide additional details about our data processing partners upon request.
13. Do We Make Updates to This Policy?
Yes, we will update this policy as necessary to stay compliant with relevant laws and to reflect changes in our practices. OrbitAIM, managed by HEMANT GADODIA, is committed to keeping you informed about any changes that may affect how your data is processed.
Reasons We May Update This Policy
We may revise this privacy policy in response to:
- New Features: When we introduce new modules, features, or capabilities (such as new content types, AI agents, or integrations) that affect how we collect or process data
- Legal Requirements: Changes in data protection laws, regulations, or guidance in jurisdictions where we operate (GDPR, CCPA, DPDP Act, etc.)
- Business Changes: Mergers, acquisitions, reorganizations, or changes to our service offerings
- Third-Party Services: Changes to the third-party services we use, such as new AI/LLM providers, payment processors, or cloud infrastructure
- Security Updates: Enhanced security measures or changes to our data protection practices
- Google API Compliance: Updates to Google API Services User Data Policy that affect our Gmail integration
- User Feedback: Clarifications based on user questions or feedback about our privacy practices
How We Will Notify You of Changes
We use different notification methods depending on the significance of the changes:
For All Changes
- Posting the updated policy on this page
- Updating the "Last Updated" date at the top of this policy
For Minor Changes
- Displaying an in-app notification in your Orbit dashboard
- Brief summary of changes in the notification
For Material Changes
- Email notification to your registered email address
- Prominent banner on the platform
- Advance notice (typically 30 days before effective date)
- Highlighted summary of what has changed
What Constitutes a "Material Change"
We consider the following types of changes to be material and will provide additional notice:
- New categories of personal data collected
- New purposes for processing your data
- Changes to how we share data with third parties
- Modifications to your privacy rights
- Changes to our Gmail data handling practices
- New AI/LLM providers processing your content
- Changes to data retention periods
Version History
We maintain a record of policy updates:
| Version | Effective Date | Summary of Changes |
|---|
| 1.0 | December 2024 | Initial privacy policy publication |
Previous versions of this policy are available upon request. Contact support@orbitaim.io to request archived versions.
Your Options When We Update
When we make changes to this privacy policy, you have the following options:
- Review the Changes: Read the updated policy and any summary we provide
- Contact Us: If you have questions about the changes, reach out to support@orbitaim.io
- Continue Using: Your continued use of Orbit after the changes take effect indicates your acceptance
- Export Your Data: If you disagree with changes, you can export your data before closing your account
- Delete Your Account: You can delete your account if you do not agree with the updated terms
We Encourage Regular Review
We recommend reviewing this privacy policy periodically to stay informed about how we protect your data. The "Last Updated" date at the top of this page indicates when changes were last made. Changes are effective immediately upon posting unless otherwise stated.
Important Notice
Your continued use of our platform (including Strategy Hub, Lead Engine, Content Creation, Cold Emailer, and Analytics modules) after any modifications to the privacy policy constitutes your acceptance of such changes. If you do not agree with any updates, you should stop using the platform and contact us to delete your account.
15. Additional Disclosures for Specific Jurisdictions
OrbitAIM, managed by HEMANT GADODIA, is committed to complying with data protection laws across all jurisdictions where we operate. This section provides additional information required by specific regional regulations.
For Users in the European Economic Area (EEA) — GDPR
If you are located in the EEA, you have certain rights under the General Data Protection Regulation (GDPR). This section provides specific disclosures required under GDPR.
Data Controller Information
Controller Identity: OrbitAIM, managed by HEMANT GADODIA, is the data controller responsible for your personal information.
Contact for EEA Users: support@orbitaim.io
Representative: Contact us for information about our EEA representative.
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent (Article 6(1)(a)): For Gmail API access, email communications, and optional analytics
- Contract Performance (Article 6(1)(b)): To provide Orbit services, process Orbit Credits, manage your subscription (Starter, Growth, Pro plans)
- Legitimate Interests (Article 6(1)(f)): To improve our platform, prevent fraud, ensure security, and provide customer support
- Legal Obligations (Article 6(1)(c)): To comply with tax, accounting, and other legal requirements
Your GDPR Rights
- Right of Access (Article 15): Request a copy of your personal data across all Orbit modules
- Right to Rectification (Article 16): Correct inaccurate or incomplete data in your Strategy Hub, profile, or Lead Engine
- Right to Erasure (Article 17): Request deletion of your data ("Right to be Forgotten")
- Right to Restriction (Article 18): Limit processing while disputes are resolved
- Right to Data Portability (Article 20): Export your data in a structured, machine-readable format (JSON, CSV)
- Right to Object (Article 21): Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for Gmail access or marketing communications at any time
Right to Lodge a Complaint
You have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated. A list of EEA data protection authorities is available at: https://edpb.europa.eu
For Users in the United Kingdom — UK GDPR
If you are located in the United Kingdom, you have rights under the UK General Data Protection Regulation and the Data Protection Act 2018. Your rights are substantially similar to those under EU GDPR.
Supervisory Authority: UK Information Commissioner's Office (ICO)
ICO Website: https://ico.org.uk
International Transfers: We use UK-approved International Data Transfer Agreements (IDTAs) or the UK Addendum to EU SCCs for transfers outside the UK.
For California Residents — CCPA/CPRA
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Your California Privacy Rights
- Right to Know: What personal information we collect, use, disclose, and sell
- Right to Delete: Request deletion of your personal information
- Right to Correct: Correct inaccurate personal information
- Right to Opt-Out of Sale: We do NOT sell personal information
- Right to Limit Use of Sensitive Information: Control how sensitive data is used
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
Categories of Personal Information Collected
In the preceding 12 months, we have collected the following categories of personal information:
- Identifiers (name, email, account ID)
- Commercial information (subscription plans, Orbit Credits purchases, transaction history)
- Internet activity (usage data, feature interactions, Cold Emailer analytics)
- Professional information (company, job title, business data in Strategy Hub)
- Inferences (lead scoring, content recommendations, AI-generated insights)
Notice Regarding Sale of Personal Information
OrbitAIM does NOT sell personal information as defined by CCPA. We do not sell your name, email, Strategy Hub data, Lead Engine prospects, content, or any other personal information to third parties for monetary consideration.
For Users in India — DPDP Act
OrbitAIM is based in India and fully complies with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian data protection laws.
Data Fiduciary Information
Data Fiduciary: OrbitAIM, managed by HEMANT GADODIA
Contact for Indian Users: support@orbitaim.io
Your Rights Under DPDP Act
- Right to Access: Obtain confirmation of whether your data is being processed and access to your data
- Right to Correction: Request correction of inaccurate, incomplete, or outdated personal data
- Right to Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Right to Withdraw Consent: Withdraw previously given consent at any time
- Right to Nomination: Nominate another person to exercise your rights on your behalf
Grievance Redressal
For any grievances related to the processing of your personal data:
- Email: support@orbitaim.io
- Subject Line: "DPDP Act Grievance - [Your Concern]"
- Response Time: We will acknowledge your grievance within 48 hours and resolve within 30 days
Data Categories Summary by Regulation
| Data Category | Orbit Features | Legal Basis |
|---|
| Account Information | Profile, Authentication | Contract Performance |
| Strategy Hub Data | Brand, ICP, Messaging | Contract Performance |
| Lead Engine Data | Prospects, Enrichment | Contract + Legitimate Interest |
| Gmail Data | Cold Emailer | Consent |
| Content Data | LinkedIn, Blog, Email | Contract Performance |
| Billing Data | Credits, Subscriptions | Contract + Legal Obligation |
Questions About Your Jurisdiction?
If you are located in a jurisdiction not specifically addressed above and have questions about your privacy rights, please contact us at support@orbitaim.io. We will work with you to understand and address your concerns in accordance with applicable local laws.
By using Orbit, you acknowledge that you have read and understood this privacy policy and agree to its terms.