Skip to content

Privacy policy

What personal data Orbit holds about visitors and customers, why, who receives it, how long it is kept, and how to use your rights.

Last updated 4 October 2026

Draft. The company details on this page, and some of its terms, are placeholders until launch. It is not in force yet.

In short

  • We hold what the service needs: your name and email address, your team, your apps, your billing records, the IP address you sign in from and details of the GitHub account you connect.
  • The website sets no cookies and uses no analytics, and we send no marketing email and sell no personal data.
  • Runtime logs are whatever your app prints: we do not filter them, and they are kept for about a week.
  • A small number of authorized staff can see customer accounts, and every sign-in of theirs to an account is recorded.
  • The personal data inside the apps you host is your responsibility, and we only process it for you.
  • To close your account or to get a copy of your data, write to privacy@arrangic.com.

The full text below is what counts.

On this page

This policy says what personal data we hold, why we hold it, who receives it and how long we keep it. “We”, “us” and “our” mean Example Hosting, Inc., the company that runs Orbit. “You” means the person who visits our website or uses the service.

Who is responsible

The company responsible for the personal data described here is Example Hosting, Inc., 123 Example Street, Suite 100, Wilmington, DE 19801, United States. Data protection law calls this the controller. For anything about privacy, write to privacy@arrangic.com.

What this policy covers

This policy covers the website at https://arrangic.com, the dashboard at https://app.arrangic.com and the service itself: building and running your apps.

It does not cover the apps that our customers host. A customer decides what personal data an app collects, and is responsible for it. We only process that data for the customer, under the data processing addendum. If you use an app that is hosted on Orbit and have a question about your data, ask whoever runs that app.

The data we hold

When you visit the website

The website sets no cookies, uses no analytics and loads nothing from other companies. As with any website, the servers that deliver the pages see your IP address and the page you asked for. The cookie policy describes two small values that your browser keeps until you close the tab.

When you have an account

What What it is exactly Where it comes from
Account Your name and your email address: an account needs both. We store no passwords and no profile pictures. You
Sign-in codes For each six-digit code we email you: a hash of the code, the email address and the IP address that asked for it. You and your browser
Sessions While you are signed in: the IP address and the user agent of your browser, which is the text your browser sends to say which browser and operating system it is. The cookies that keep you signed in are in the cookie policy. Your browser
GitHub connection The id of the installation, the name and id of the GitHub account, and the names of the repositories you chose. For the trial: your GitHub id, your username and the date your GitHub account was created. GitHub, once you connect it
Team and invitations The name of the team, its members and their roles. For an open invitation: the invited email address and who sent it. You and the people in your team
Apps Settings, environment variables, custom domains (hostname and status), deployments with their build logs, and built images. For each deployment: the commit id, the commit message and the name of the commit’s author. You, GitHub and the builds of your app
Usage For each app and each hour: the seconds it ran and the bytes it sent, by region. The service
Billing The plan, usage statements, invoices and payment records. Of the card only the brand, the last four digits and the expiry date. You, our payment provider and the service
Activity trail Who did what in the team, and when: the member, their name, the app and the action. No IP address. An entry keeps the name after the member has left. What members do in the dashboard
Notifications Notices in the dashboard: a failed deployment, a crash, a domain problem, usage, a member who joined. The service

If you write to us by email, we receive your address and what you wrote.

We do not store request logs for your apps, or the IP addresses of the people who visit them.

What we read from GitHub

The connection is a GitHub App that you install on the repositories you choose. From them we read the list of repositories, the names of the files in the root folder, the files package.json and .nvmrc, and of the newest commit of the branch its id, the first line of its message and the name of its author. For a build, the repository is downloaded through a short-lived link.

GitHub tells us when you push. From such a notice we keep only the commit details in the table.

Logs

Runtime logs are whatever your app prints. We do not filter them: if your app prints a name, an email address or a secret, it is in the log, and every member of your team can read it. We do not store runtime logs in our database. The infrastructure provider that runs your app keeps them for about a week, and they are read from there when a member of your team opens the log.

Where a log or a variable holds personal data of the people who use your app, we process it for you under the data processing addendum.

Build logs hold the output of a build and of your deploy commands. We store them with the deployment, up to 1 MB each, and delete them 90 days after the deployment ended.

What our staff can see

A small number of authorized staff can see customers’ accounts, teams, apps, repository names, deployments, usage statements, payments (the card’s brand and last four digits) and the activity trail.

To give support, or to look into a fault or abuse, they can sign in to a customer’s account through a link that works for two minutes. They then see what the customer sees. Creating such a link and using it are recorded, with the staff member and their IP address.

What we do not do

  • We show no advertising and give no personal data to advertisers.
  • We do not sell personal data.
  • We do not track you across other websites.
  • We use no analytics, no error tracking service, no session recording and no tag manager, on the website or in the dashboard.
  • We send no marketing email and have no newsletter. If we ever start one, you get it only if you ask.

The emails we send belong to the service: sign-in codes, codes that confirm a new email address, team invitations, billing notices, and notices that the agreement with you calls for, such as a change to our terms and policies. Other notifications about your apps and your team appear in the dashboard only.

Why we use your data

Each use has its ground in data protection law:

  • To provide the service: your account, your team, your apps and the emails that belong to the service. The ground is our contract with you, the terms of service.
  • To keep the service secure and to stop abuse: the IP addresses kept with sign-in codes and sessions, the IP address the servers of the website see, the limit on requests for codes, the activity trail, the record of staff sign-ins, and the check that a trial is given once for each person and each GitHub account and that the GitHub account is old enough for a trial. The ground is our legitimate interest in a service that is safe and is not misused.
  • To run the service for people who are not our customer themselves: an invited email address, the author of a commit, a member of a team that an organization owns. The ground is our legitimate interest, and that of the team, in a service that works.
  • To bill you, and to keep the records that tax and accounting law require. The grounds are the contract and our legal duty.
  • To answer you when you write to us. The ground is the contract where your question is about the service, and otherwise our legitimate interest in answering.

Nothing we do today rests on your consent. If we ever ask for it, you can withdraw it at any time.

Some things are decided without a person: whether a trial is given, and the pausing of apps when a trial ends or a payment stays unpaid. We do no profiling.

Who receives it

Some companies process data for us so that the service can run. Each gets only what it needs:

  • The cloud provider that hosts the dashboard and its database holds all account data.
  • The infrastructure providers that build and run your apps receive your source code during a build, the built images, the environment variables, the hostnames, the runtime logs and the traffic of your apps.
  • Our payment provider receives the name and email address of the team’s owner, the plan and the payment details.
  • Our email delivery provider receives the address of the recipient and the message.
  • Our DNS provider receives the addresses of apps, and no personal data.
  • The provider that delivers this website sees your IP address and the page you asked for, as any web server does.
  • The provider of our mailboxes holds the messages you send us.

The list of these companies is available on request at privacy@arrangic.com.

Payments are handled by our payment provider. Card details go to the provider and never reach our servers. Where the provider acts as the seller of record, it charges you, adds the taxes that apply and issues the invoice, and its terms for buyers apply to the payment.

Personal data also reaches:

  • GitHub, when you connect it. GitHub knows that you installed our GitHub App, and on which repositories. Two pages of the dashboard show GitHub profile pictures, which your browser loads from GitHub, so GitHub sees your IP address when you open those pages.
  • The people in your team. Every member can read the runtime logs. The owner and the admins can see the values of environment variables, the activity trail and the team’s billing.
  • The customer who runs an app, when you send us a complaint or a request about that app.
  • Professional advisers, such as accountants and lawyers, where their work for us requires it.
  • Authorities, when the law compels us or when we report a crime, as “Requests from authorities” below describes.
  • A buyer, if the business is sold or merged.

Nobody else receives it.

Where your data is

Account data, which is everything in the dashboard’s database, is stored in the United States. That includes the records of your apps: settings, environment variables and build logs. An app runs in the region you chose for it, out of several regions on several continents. Requests to an app enter the network of the infrastructure provider near the visitor and are carried to that region. The runtime logs are kept by that provider.

When data leaves the country you live in, we rely on the safeguards the law provides, such as standard contractual clauses. Write to privacy@arrangic.com for a copy of them.

How long we keep it

  • Account and team data: while the account exists. After you ask us to close it, or after a team is deleted, we delete it within 30 days. The exception is your name in the activity trail of a team you were in, which stays while that team exists.
  • Invoices and payment records: 7 years.
  • A deleted app: stopped and removed from the servers at once. Its records (settings, environment variables, deployments and build logs) are deleted within 30 days.
  • Build logs: 90 days after the deployment ended.
  • Built images: the newest ten of an app, and those in use. Older ones are removed.
  • Runtime logs: about a week.
  • Sign-in codes: a code works for 10 minutes. It is deleted when it is used or when a new one replaces it. A code that is never used stays until the next one is asked for.
  • Sessions: until 120 minutes pass without activity. A remembered sign-in lasts up to 400 days, or until you sign out.
  • Invitations: 3 days, then deleted.
  • Activity trail and notifications: while the team exists.
  • The record of staff sign-ins: while the account exists.
  • Messages you send us: while the matter is open, and after that for as long as we need them to show what was said.

What the law requires us to keep, we keep for as long as it requires.

Your rights

Depending on where you live, data protection law lets you:

  • see the personal data we hold about you,
  • have it corrected,
  • have it deleted,
  • receive a copy of it,
  • object to a use that rests on our legitimate interest,
  • have its use restricted,
  • withdraw a consent you gave,
  • complain to the data protection authority where you live.

If you live in California, you have the right to know what personal data we hold about you, to have it corrected and to have it deleted. We do not sell personal data, and we do not share it for advertising.

In the dashboard, the owner or an admin of a team can delete an app, and the owner can delete a team once its apps are deleted, apart from the personal team every account starts with. There is no button for closing an account, and none for a copy of your data. For those, and for any other right, write to privacy@arrangic.com from the email address of your account. If you have no account, write to the same address and we ask for what we need to find your data. We answer within 30 days. We do not treat you worse for using a right.

Security

You sign in with a code sent by email, so there are no passwords, and we store each code only as a hash. Environment variables are encrypted at rest. Each replica of an app runs in its own virtual machine. No system is perfectly secure, and we hold no security certification. The security page says more.

Children

Orbit is for people aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has given us personal data, write to privacy@arrangic.com and we delete it.

Requests from authorities

We hand personal data to an authority only when a valid legal order requires it, or when we report a crime, as the acceptable use policy describes. We hand over no more than the order or the report requires. When an order names a customer, we tell that customer first, unless the law forbids it.

Changes to this policy

When we change this policy, we post the new version on this page and change the date at the top. For a change that matters, we tell account holders by email.

Contact

Questions about this policy or about your data go to privacy@arrangic.com. Our postal address is Example Hosting, Inc., 123 Example Street, Suite 100, Wilmington, DE 19801, United States. The contact page lists the other ways to reach us.