Privacy Policy
Last updated: August 2026
At Orbit, protecting your information is a non-negotiable core value. This document provides transparency into our data collection, use, and storage processes, in compliance with the California Consumer Privacy Act (CCPA), other applicable US privacy laws, and the policies of integrated platforms (Meta Platform Terms and Developer Policies).
By using the platform, the user expressly agrees to the practices described herein.
1. Data Processing Roles
Orbit is maintained by CAMPOS ENGENHARIA GYN LTDA, a limited liability company incorporated in Brazil under corporate taxpayer registry (CNPJ) No. 52.791.820/0001-42, hereinafter referred to as the DATA CONTROLLER regarding the registration data of its users, operating under the principles of legitimate purpose, adequacy, necessity, free access, transparency, and security.
Privacy Contact: support.orbit@expertbr.com
2. What Orbit Does
Orbit is a Software as a Service (SaaS) platform that centralizes and automates Instagram Direct and WhatsApp conversations. By connecting your accounts, you authorize Orbit to receive, display, store, and reply to messages on your behalf through Meta's official APIs.
3. Data Collected
3.1. From the Platform User (Our Client)
- Registration: name, email, password (irreversibly stored by Firebase Authentication), and organization name.
- Connected Accounts: public identifiers of the accounts (ID, @username, display name, profile picture, business phone number).
- Access Tokens: credentials provided by Meta, stored encrypted (AES-256-GCM) and never exposed to the interface or third parties.
- Settings: AI assistant preferences, automation flows, language, and theme.
- Logs: IP addresses, access times, and system events, for security and auditing purposes.
3.2. From End Contacts (Who Chats with Our Client)
When receiving a message, Orbit processes the following data from the person who initiated the contact:
- Conversation identifier provided by Meta (IGSID or WhatsApp number);
- Public name and profile picture, when made available by the source platform;
- Content of the messages exchanged (text, images, videos, documents, and audio);
- Public comments on posts, when the client enables this feature;
- Voice message transcripts, when the feature is enabled;
- Client notes about the contact: tags and custom fields that the client themselves creates and fills in within the platform's CRM. The content of these fields is defined entirely by the client, who is responsible for it as the Data Controller (see item 4).
- Media files: images, videos, audio, and documents received or sent in the conversation are stored in Firebase Storage for as long as the conversation exists, so the history remains viewable (Meta's original URLs expire within minutes).
3-A. Waitlist
When you sign up to be notified of a feature launch, we collect your email, preferred language, IP address (abuse prevention), and the source of the sign-up. Legal basis: consent (LGPD Art. 7, I). Use: sending a single launch notice in the registered language. Removal can be requested at any time via the support email.
4. Client's Role: Data Controller and Data Processor
This is the most critical point of this policy. Regarding the data of end contacts(item 3.2), the Orbit user is the Data Controller — they are the ones who decide to connect their accounts, how to provide customer service, and what to do with the information. Orbit acts as the Data Processor, processing the data exclusively under the client's direction and to provide the contracted service.
It is the client's responsibility, as the Data Controller, to:
- Have a legal basis for processing the data of their contacts;
- Inform their contacts about the use of automated customer service;
- Respect requests for deletion, correction, or objection made by their contacts;
- Not use the platform for spam, unsolicited messages, or illegal purposes.
4-A. Bulk Sending (Broadcast)
The platform allows the client to send a message template previously approved by Meta to several contacts at once, over WhatsApp. In this feature:
- Recipients are selected exclusively by the client, from contacts who have already started a conversation with them. Orbit does not provide, sell, or suggest contact lists.
- When the send is created, Orbit copies each recipient's name, phone number, and custom fields into the broadcast record, so the delivered message matches what was reviewed — this copy is deleted along with the broadcast record.
- Each message is charged by Meta directly to the client, according to the platform's current rate table. Orbit does not intermediate, pass through, or invoice these amounts.
- It is the client's responsibility, as Data Controller, to have a legal basis for contacting each recipient and to honor opt-out requests. Using this feature for unsolicited messages violates these terms and Meta's policies.
5. Purposes and Legal Bases
| Purpose | Legal Basis |
|---|---|
| Create and maintain the account; provide the service | Performance of a Contract |
| Display, store, and reply to messages | Performance of a Contract / Legitimate Interest of the Controller |
| Transcribe audio for reading and customer service | Performance of a Contract |
| Bulk sending of approved templates, at the client's request | Performance of a Contract / Controller's responsibility |
| Security, logs, fraud and abuse prevention | Legitimate Interest |
| Comply with legal and regulatory obligations | Legal Obligation |
| Aggregated and anonymized metrics | Anonymized Data |
6. Use of Data Obtained from Meta
In accordance with the Meta Platform Terms, we expressly declare that data obtained from the Instagram and WhatsApp APIs is used solely and exclusively to operate Orbit's features on behalf of the client who connected the account. We do not:
- Sell, rent, or trade this data;
- Use this data for advertising, targeting, or enriching databases;
- Transfer this data to data brokers;
- Use message content to train our own or third-party AI models.
7. Sharing and International Transfer
Orbit never sells its database. Sharing only occurs with essential operation providers:
- Google Cloud / Firebase — database, authentication, and media storage.
- Meta Platforms — Instagram and WhatsApp Cloud API (message source and destination).
- Groq Inc. — natural language processing for the assistant and audio transcription.
- Stripe, Inc. — subscription payment processing. Card data is collected and stored directly by Stripe (PCI-DSS certified); Orbit neither accesses nor stores card numbers, receiving only the transaction status and subscription identifiers.
- Hostinger — application hosting.
- Client's own n8n (BYON mode): when the client chooses to use their own automation engine, Orbit forwards the conversation text to the address they configured. In this case, the responsibility for subsequent processing lies entirely with the client.
Due to the global nature of these providers, by using the platform you agree to the international data transfer, including to servers in the United States, observing the contractual clauses and compliance standards adopted by these companies. Orbit's primary database is hosted in the southamerica-east1 (São Paulo) region.
8. Artificial Intelligence and Automated Decisions
- Conversations may be answered by an AI assistant configured by the client, processed by Groq.
- Responses are based exclusively on the information the client provides (catalog, rules, objective).
- No decisions with significant legal or financial effects are made entirely automatically.
- Human agents can take over the conversation at any time ("Takeover" function).
- It is possible to request human review by contacting the support email.
9. Automated Service Opt-out
Anyone receiving automated messages from Orbit can reply "STOP" or "SAIR" at any time to interrupt the automated service in that conversation. To resume, simply reply "VOLTAR" or "RESUME". The notice about this possibility is displayed periodically in conversations.
10. Retention and Deletion
| Data | Retention Period |
|---|---|
| Conversations, messages, and media | While the account is active, or until deletion is requested |
| Access tokens (encrypted) | Until the channel is disconnected or revoked by Meta |
| User registration | While the account exists |
| Security logs | Up to 6 months |
| Records required by law | For the applicable legal period |
| Waitlist data | Until the launch notice is sent or removal is requested, whichever comes first (max. 24 months) |
| Broadcast records | While the account is active, or until deletion is requested |
| Technical channel-link record (item 10.1) | 5 years from the asset's last connection |
Upon disconnecting a channel, the token is immediately deleted. When deleting an account, associated data is irreversibly deleted within 7 business days, except for the record described in item 10.1.
10.1. Technical Channel-Link Record (Anti-Fraud)
When an Instagram account, a Facebook Page, or a WhatsApp number is connected to the platform, we permanently record that asset's public identifier and the connection date. This record contains no messages, contacts, name, email, or content of any kind, and remains stored even after the client's account is deleted.
Purpose: to prevent the same asset from being repeatedly reconnected under new accounts to circumvent free-plan limits, and to prevent the same account from being connected to two different workspaces at once. Legal basis: legitimate interest in fraud prevention, with minimal impact on the data subject, since it is a technical identifier already public on the source platform itself.
Retention period: the record is kept for 5 years from the last connection of that asset, and automatically deleted thereafter.
10.2. Deletion of Conversations and Contacts by the Client
At any time, directly in the platform, the client may delete a conversation (along with its full message history) or delete a contact. Deleting a contact removes, in cascade, their conversations, messages, tags, and custom fields. The action is immediate and irreversible.
11. Your Rights
You may request confirmation of processing, access, correction, anonymization, portability, deletion, information about data sharing, and revocation of consent. Just write to support.orbit@expertbr.com — we will respond within 15 days.
To delete your data, you can also use the Data Deletion page.
12. Security
- Encryption in transit (TLS) for all communications;
- Access tokens encrypted at rest with AES-256-GCM;
- Strict tenant isolation (Firestore Security Rules) — no client can access another's data;
- Session authentication with httpOnly cookies;
- Audit logs of access and administrative actions.
No system is infallible. In the event of a relevant security incident, we will notify the data subjects and competent authorities within the legal timeframes.
13. Cookies
We use strictly necessary cookies only, which are exempt from prior consent:
| Cookie | Purpose |
|---|---|
| Authenticated session (httpOnly) | Keep the login active securely |
| Language | Remember the chosen language |
| Theme | Remember the light/dark mode preference |
| View mode | Internal use by platform administration |
We do not use advertising cookies, third-party analytics, tracking pixels, or any profiling technology. Since all cookies are essential, we do not display a consent banner — rejecting these cookies in your browser makes login impossible. Should we adopt non-essential tools, this policy will be updated and consent will be requested in advance.
14. Children's Data
Orbit is intended exclusively for individuals over 18, given the professional nature of the platform. We do not intentionally collect data from children or adolescents. If we identify accidental collection of data from a minor under 13, we will proceed with immediate deletion.
15. Updates
This policy may be adjusted as technology and legislation evolve. Substantial changes will be communicated on the platform. We recommend reviewing it periodically.
16. Jurisdiction
This policy is governed by the laws of the Federative Republic of Brazil, where Orbit is established, with exclusive jurisdiction in the courts of Goiânia, State of Goiás — without prejudice to mandatory data protection rights applicable in your country of residence.
© 2026 Orbit. All rights reserved.