Privacy Notice
Last updated: June 2026
1. Who we are
Orbita OS is operated by Antonio Huerta Flores ("we", "us"). We act as the data controller for personal data processed through the Service. Contact: soporte@orbitaos.com.
2. Data we collect
- Account data: name, email, login credentials.
- Business data: restaurant name, menu, reservations, orders, inventory, and other operational data you submit.
- Customer data of your guests: names, contact details and reservation history, which you process as data controller.
- Support communications: messages you send to support.
- Usage and device data: IP address, browser, OS, telemetry, and product analytics.
3. How we use it
- Provide the Service (contract performance).
- Security, fraud prevention, abuse detection (legitimate interests).
- Product improvement and analytics (legitimate interests).
- Customer support (contract performance / legitimate interests).
- Marketing (consent, where required).
- Legal compliance (legal obligation).
4. Who we share data with
- Service providers / subprocessors: hosting (Cloudflare, Supabase), email delivery (Resend), AI model providers (Google, OpenAI) — strictly to provide the Service.
- Merchant of Record: Paddle.com — for sale of subscriptions, subscription management, payments, tax compliance and invoicing.
- Professional advisers: legal, accounting, where necessary.
- Authorities: where required by law.
5. International transfers
Some of our subprocessors are located outside the EEA/UK/Switzerland. Where this occurs we rely on appropriate safeguards (Standard Contractual Clauses or adequacy decisions).
6. Retention
We retain personal data only as long as needed to provide the Service, comply with legal obligations, and resolve disputes. Account data is deleted within 90 days of account closure, subject to legal retention periods.
7. Your rights
Under applicable law (GDPR / Swiss FADP) you have the right to: access, rectify, erase, restrict, port, object, and withdraw consent. You also have the right to lodge a complaint with a supervisory authority. We respond within one month.
8. Security
We implement appropriate technical and organisational measures including encryption in transit, encryption at rest, access controls, audit logging, and row-level security across tenants.
9. Cookies
We use essential cookies for authentication and session management. We may use limited analytics cookies to understand product usage. You can manage cookie preferences in your browser.
10. Contact
For privacy questions, contact soporte@orbitaos.com.