Orbit

Privacy Policy

Last updated: 2026-05-21

This is preliminary copy pending review by counsel before launch. We expect to refine the wording without changing the substance.

What we collect

When you sign up, Orbit stores the account fields you provide through Clerk (our authentication provider): name, email address, and the verification status of that email. We also store the profile information you choose to fill in inside Orbit: headline, bio, links, photo, interests, and any founder or investor preferences you indicate.

When you take actions inside Orbit (joining a network, opening a profile, RSVPing to an event, sending a plan-a-call request) we record an activity event so the platform can surface what your network is doing. These events include the participant id, the action, a timestamp, and a small JSON payload describing the action.

Network membership rows record which networks you belong to and your role within each (member, organizer, network admin). If your network has a verified email domain (e.g. @northeastern.edu) we record the domain match that led to your auto-acceptance.

Why we collect it

To deliver the platform: match you with other members, display your profile, send the transactional emails the product relies on (call request notifications, event reminders, invitations), and route you to the right network.

To improve the product: aggregated analytics tell us which screens get used, which features get ignored, and where users hit friction. We never sell personal data and we do not use it for cross-site advertising.

Where it lives

Orbit runs on Vercel and Neon. Both are configured to host our data in the European Union. Files you upload (raise documents, profile photos, network logos) live on Vercel Blob.

Who we share with

We rely on a small set of vendors who each receive only the data they need to do their job:

  • Clerk: authentication, password hashing, email verification.
  • Mailgun: sending the transactional emails described above. Mailgun sees the recipient address and the email body.
  • PostHog: product analytics and (where configured) session replay.
  • Sentry: error and performance monitoring. Sentry receives stack traces and the metadata we attach to an error (your participant id, the action that failed).
  • Cloudflare: DNS, certificate management, and (optionally) edge caching of public pages.

We don't sell personal data to anyone. If a vendor in this list changes we'll update this page.

Your rights

You can request a copy of the data Orbit holds about you, request that we delete your account and the data associated with it, or request that we correct anything you can't edit yourself in the app. Email privacy@orbit-app.com and we'll respond within thirty days.

Deletion is irreversible. We remove your participant row, your profile, your activity events, and the per-network membership rows. Some audit log records may be retained for compliance reasons (e.g. records of role changes), with personal identifiers redacted where the law allows.

Cookies and similar

Orbit uses a small number of cookies: the authentication cookie Clerk sets to keep you signed in, a CSRF cookie used by Next.js for server actions, and a PostHog cookie that anonymises your session. We do not use third-party advertising cookies.

Contact

Questions about this policy or about how we handle your data can go to privacy@orbit-app.com.