BUILD YOUR ORBITChallenges from €45 · Configure before you register
GDPR notice

Privacy Notice

How Orbit collects, uses, protects, and shares personal data when you use the website, create an account, purchase a challenge, or connect a demo exchange account.

Version 2026-08-10Governing framework: Estonia / European Union

1. Controller and scope

The operator identified on this page is the data controller for Orbit account and evaluation data. Stripe acts as an independent controller for parts of payment processing; Google and the connected exchanges process data under their own notices where you interact directly with them.

2. Data we process

  • Identity and account data: name, email, profile image, authentication provider identifiers, role, and verification status.
  • Security data: password hash, session identifiers, verification attempts, timestamps, IP-derived rate-limit keys, and security logs.
  • Purchase data: challenge configuration, currency, amount, Stripe customer/session/payment references, legal acceptance timestamps, and order status. Orbit does not store full card details.
  • Evaluation data: exchange, masked API-key hint, encrypted demo API credentials, positions, executions, fees, funding, balances, risk events, snapshots, and rule breaches.
  • Preference data: challenge configuration and cookie-notice preference stored in your browser.
  • Support and rights-request correspondence when you contact Orbit.

3. Purposes and legal bases

  • Contract: create and secure accounts, process challenge orders, deliver evaluation tracking, display history, and provide support.
  • Legal obligation: accounting, tax, consumer-protection records, sanctions compliance where applicable, and responding to lawful requests.
  • Legitimate interests: fraud prevention, service security, debugging, enforcing fair-use rules, and improving reliability, balanced against user rights.
  • Consent: only for optional activities that genuinely require consent. Orbit currently has no advertising or behavioural analytics cookies.

4. Recipients and transfers

Data may be processed by Fly.io infrastructure and PostgreSQL hosting, Stripe payments, Google OAuth/Gmail delivery, and Binance or Bybit demo APIs selected by the user. Professional advisers and authorities receive data only where necessary. Some providers may process data outside the EEA; before live launch Orbit must document the relevant adequacy decision, Standard Contractual Clauses, or other lawful transfer safeguard.

5. Retention and security

Account and evaluation data are retained while the account is active and then deleted or anonymised when no longer necessary, except transaction, tax, dispute, fraud, or legal records that must be retained longer. Exact production retention periods will be finalised before live launch. Demo API secrets are protected with AES-256-GCM encryption; only masked hints are returned to the browser. No security measure is absolute.

6. Your rights

Subject to GDPR conditions, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent without affecting earlier lawful processing and complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Orbit will verify identity and normally respond within one month.

7. Automated decisions and children

Orbit automatically calculates challenge limits and can lock a challenge when deterministic rules are breached. The dashboard shows the triggering reason and preserves an audit trail; production support must provide a human review channel. Orbit is intended only for persons aged 18 or older and does not knowingly target children.

8. Changes

Material changes will receive a new version date and, where required, an in-product notice or renewed acceptance. Contact the operator shown on this page for privacy requests.