BUILD YOUR ORBITTwo phases · Transparent risk · 80% trader reward split
Beta privacy notice

Privacy Notice

The personal data the Orbit Beta currently processes when you use the website, test checkout or connect a demo exchange account.

1. Beta status and contact

Orbit is a private development project and its future operating company and European registration jurisdiction have not yet been finalized. During Beta, privacy or deletion requests can be sent to [email protected]. Final company/controller details will be published before a public production launch. Payment providers and exchanges may act as separate controllers under their own notices.

2. Data processed

  • Account: name, email, profile image, authentication-provider identifiers, password hash where used, role, verification status and country-of-residence code.
  • Security: sessions, verification attempts/timestamps, request rate-limit keys and operational logs.
  • Order/consent: evaluation configuration, simulated size, price/currency, country/jurisdiction status, provider invoice/payment identifiers, status and versioned acceptance timestamps.
  • Crypto accounting: received asset/amount/network, timestamp, transaction hash where provided, preserved rate/EUR-value snapshot, raw signed provider payload, refund fields and linked Performance Reward records.
  • Simulation: exchange, masked key hint, encrypted read-only demo credentials, positions, executions, fees, funding, equity, snapshots, trading days, adjustments, alerts and breaches.
  • Optional analytics after consent: normalized page route/title, referral and campaign parameters, approximate geography, device/browser characteristics, and non-sensitive product-funnel events. Query strings and dynamic user or challenge identifiers are removed from analytics page locations. Names, emails, verification codes, destination wallets and exchange secrets are not intentionally sent to GA4.
  • Support, complaint, rights-request and reward-review correspondence.
  • Browser preferences listed in the Cookie Policy. Orbit does not store card numbers, wallet private keys or seed phrases.

3. Purposes and legal bases

  • Contract: authenticate users, process an Evaluation Fee, deliver the evaluation, track rules, show history and handle support/rewards.
  • Legal obligation: preserve accounting, tax, consumer, complaint and lawful-authority records where applicable.
  • Legitimate interests: service security, deterministic rule enforcement, fraud prevention, reconciliation and reliability, balanced against user rights.
  • Consent: measure audiences, acquisition sources and the product funnel through optional Google Analytics. Consent can be refused or withdrawn without affecting necessary service access.

4. Service providers

Data may be sent to Fly.io (application/database infrastructure), Google (OAuth and consent-based GA4), Resend (transactional email), NOWPayments (crypto checkout), Stripe (administrator test checkout and optional subscription), and the user-selected Binance or Bybit demo API. Google Analytics may process data on infrastructure outside the EEA under its applicable transfer safeguards. Advisers and authorities receive only necessary data. Processor-role, transfer and data-location records are maintained proportionately and will be expanded as the service scales.

5. Retention and security

Account and simulation data is retained while needed to deliver the service and resolve disputes. Payment, consent, crypto valuation, refund and reward records are retained for applicable accounting, tax, consumer and claims periods. Verification codes expire after 10 minutes. Demo API secrets use AES-256-GCM encryption and only masked hints return to the browser. No security measure is absolute.

6. Rights

Request access, correction, deletion, restriction, portability or objection at [email protected]. Withdrawal of consent does not affect earlier lawful processing. Orbit verifies identity and aims to respond within one month. The final production notice will identify the operating company, its lead supervisory authority and the complaint route applicable to its European jurisdiction.

7. Automated rules and human review

Orbit automatically applies objective risk rules and may lock an evaluation when a threshold is reached. The interface records the reason. A user may dispute a breach and request human administrator review through support. A deeper GDPR Article 22 and DPIA assessment is scheduled for post-beta review unless the processing or impact materially changes.

8. Children and changes

Orbit is for persons aged 18 or older. Material policy changes receive a new version and, where legally required, a notice or renewed acceptance.