Legal

Privacy Policy

Effective 13 September 2026 · Version 1.0

This policy explains what Orbitra collects, why, where it is stored, who it is shared with, how long it is kept and how it is deleted. It covers your account information and the marketplace information — including buyer details from Amazon — that Orbitra accesses only because you authorised it.

On this page

1. Who we are

Orbitra (“Orbitra”, “we”, “us”) is a multichannel commerce platform operated by NexByte Innovations, a company registered in Dubai, United Arab Emirates. NexByte Innovations is the contracting entity and the party responsible for the data described here.

Operating entity
NexByte Innovations, Dubai, United Arab Emirates
General / privacy / security
admin@orbitracommerce.com

For your account, billing and support data we are the controller. For the catalog, order and buyer data we access from your connected platforms and marketplaces we are a processor acting on your instructions: it is your data, we handle it to run the service you asked for, and we do not use it for our own purposes.

2. What we collect

CategoryWhat it includesWhere it comes from
Account and billingName, business name, email, country, password (salted hash only), card type and last four digitsYou. Full card details go to our payment processor, never to us
Catalog and listingsTitles, descriptions, images, variants, identifiers, prices, stock, listing attributesThe source platform you connect, such as Shopify
OrdersOrder identifiers, items, quantities, status, fulfilment channelThe marketplaces you connect
Buyer personal informationBuyer name, delivery address, phone, and any marketplace-issued masked emailMarketplace order APIs, per order, at the point of shipping
Technical and usageIP address, browser and device, features used, and the result of every API call made for youAutomatically, as you use the service
Support messagesWhat you write to us and what we agreedYou

We do not collect special-category data — health, biometric, racial or ethnic origin, religious or political belief, trade union membership or sexual orientation — and ask that you do not send it. We do not buy data from brokers and do not track you across other sites for advertising.

3. How we use it

We use the above only to import your catalog, build and publish listings, keep prices and stock aligned, retrieve and help you fulfil orders, produce shipping documents, run the optional AI features you switch on, bill you, support you, secure the platform, and tell you about material changes. Product marketing email is separate, optional and unsubscribable in one click.

What we never do

  • Sell, rent or trade your data or your buyers’ personal information to anyone.
  • Use buyer personal information for marketing, advertising, retargeting or profiling.
  • Use your catalog, order or buyer data to train machine-learning models that serve other customers.
  • Aggregate or benchmark one merchant’s data to produce insights for another, or for our own research.
  • Contact your buyers, for any reason.
  • Use marketplace information for any purpose other than the seller-authorised service it was retrieved for.

4. Marketplace and Amazon information

This section applies in addition to everything above, and governs where it is stricter.

4.1 You authorise it, and can withdraw it

Orbitra reaches a marketplace account only after you complete that marketplace’s own consent flow — for Amazon, the OAuth authorisation inside Seller Central. We never ask for your marketplace password. You can revoke access at any time from your seller account or by asking us, and revocation stops all further access immediately.

4.2 Amazon Information

“Amazon Information” means any data we retrieve from Amazon’s Selling Partner API for your seller account — listing, pricing, inventory and order data, and personally identifiable buyer information. We treat it as confidential and handle it in line with Amazon’s Acceptable Use Policy and Data Protection Policy.

4.3 Buyer data is fetched per order, for fulfilment only

We hold no standing copy of buyer data. Buyer name, delivery address and phone are retrieved through a Restricted Data Token scoped to a single order, at the moment that order is being despatched, and used solely to purchase postage, produce the label and packing documentation, and hand delivery details to the carrier. Nothing else.

4.4 Retention, segregation and notification

Buyer personal information is deleted within 30 days of shipment, unless a tax authority or marketplace rule requires a specific record to be kept longer — in which case only that record is kept, for only as long as required. Each merchant account is stored separately and is not reachable from another account. Buyer data is encrypted at the field level on top of full-disk encryption, and every access is logged against a named user or service. If we confirm unauthorised access to Amazon Information we notify Amazon at security@amazon.com within 24 hours of detection, and notify you and any regulator as the law requires.

4.5 Other marketplaces

The same handling applies to eBay and, as they ship, Etsy and Walmart. Where a marketplace imposes stricter requirements than this policy, we apply the stricter requirement.

5. Who we share it with

Only the providers needed to run Orbitra, each given the minimum it needs and each bound by a written contract with confidentiality and security obligations at least as strict as ours. We do not sell data and do not share it with advertisers or data brokers. We give advance notice before adding a provider; the current list is available from admin@orbitracommerce.com.

CategoryWhat they receive
Cloud hosting and databasesAll service data, encrypted at rest and in transit
Marketplaces and source platformsOnly what is needed to publish, sync and fulfil
Shipping carriersBuyer name, address and phone for the order being shipped
Payment processingYour billing name, email and card token — never buyer data
Transactional emailYour name and email for service notifications
Monitoring and supportTechnical logs scrubbed of personal data; your support messages

We also disclose where legally required, and will tell you unless prohibited. In a merger or sale of assets your data may transfer to the acquirer, on notice to you, bound by this policy or one no less protective.

6. Where it is stored, and transfers

Primary infrastructure runs in a single cloud region, with encrypted backups replicated to a separate region in a different country. Our team accesses production from the United Arab Emirates and, where a team member is based elsewhere, from their own location under the same controls. Where personal data protected by the EU or UK GDPR leaves that jurisdiction we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, alongside the technical measures on our Trust & Security page. Where UAE PDPL applies, transfers go to jurisdictions with adequate protection or under safeguards the law permits.

7. How long we keep it

DataRetention
Buyer personal informationDeleted within 30 days of shipment
Catalog, listing and order recordsDeleted within 30 days of account closure
Account and billing recordsWhile the account is open; invoices as long as UAE tax law requires
Operational logs90 days
Security audit events12 months
Support messages24 months from last contact

Deletion covers live systems and backups within the backup rotation window. Where a backup cannot be selectively edited, data is removed as that backup expires on its normal schedule and stays encrypted and access-controlled until it does. You can export everything first, and can ask us to delete sooner.

8. How we protect it

Data in transit is protected with TLS 1.2 or above; data at rest is encrypted with AES-256, and buyer personal information is additionally encrypted at the application layer. Databases run on private networks with no public route, access is limited by role on a need-to-know basis with multi-factor authentication on every account, and every access to personal information is logged. Our full posture — network protection, key management, backups and recovery objectives, logging, incident response, vulnerability management and secure development — is documented on our Trust & Security page.

9. Your rights

Wherever you are, you can ask us to give you a copy of your personal data, export your catalog and order data, correct anything inaccurate, delete your data (subject to records we must legally keep), restrict or object to processing, or withdraw a consent you gave. Email admin@orbitracommerce.com from your account address and we will respond within 30 days. We may need to verify your identity first.

These rights arise under the EU and UK GDPR, under the CCPA as amended by the CPRA if you are in California, and under UAE Federal Decree-Law No. 45 of 2021. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no “Do Not Sell or Share” action to take. Where we process buyer data as your processor, requests from your buyers should come to you as controller — tell us and we will help you answer in time. You can complain to the UAE Data Office, or to your own supervisory authority, though we would rather you gave us the chance to fix it first.

10. Cookies

We use as few as we can. Strictly necessary cookies keep you signed in and protect against cross-site request forgery, and the service will not work without them. Preference cookies remember interface choices. First-party analytics cookies tell us which features are used. We run no advertising or cross-site tracking cookies. Where consent is required we ask before setting anything beyond strictly necessary, declining is one click, and you can clear or block cookies in your browser at any time.

11. AI features

The optional AI features — pricing intelligence, inventory forecasting, SKU revenue ranking, channel recommendation and the listing optimiser — are advisory. They surface a suggestion; nothing changes a price, listing or order until you approve it, so there is no automated decision-making with a legal effect on you or a buyer. They run on your own catalog and order history inside your own account, and we do not use your data to train models serving other merchants. Where the listing optimiser uses a third-party model it receives only the product content needed to write the listing — never buyer personal information — under a contract prohibiting training on it. You can switch every AI feature off.

12. Changes, and how to contact us

If we change this policy we update the version and date above, and for any change that materially affects how we handle your data we email you at least 30 days before it takes effect. Earlier versions are available on request. For anything here, or to exercise a right, email admin@orbitracommerce.com; for a suspected security issue, admin@orbitracommerce.com, acknowledged within one business day.

See also: Terms of Service

Back to Sign In