On this page
1. Who we are
Orbitra (“Orbitra”, “we”, “us”) is a multichannel commerce platform operated by NexByte Innovations, a company registered in Dubai, United Arab Emirates. NexByte Innovations is the contracting entity and the party responsible for the data described here.
- Operating entity
- NexByte Innovations, Dubai, United Arab Emirates
- General / privacy / security
- admin@orbitracommerce.com
For your account, billing and support data we are the controller. For the catalog, order and buyer data we access from your connected platforms and marketplaces we are a processor acting on your instructions: it is your data, we handle it to run the service you asked for, and we do not use it for our own purposes.
2. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account and billing | Name, business name, email, country, password (salted hash only), card type and last four digits | You. Full card details go to our payment processor, never to us |
| Catalog and listings | Titles, descriptions, images, variants, identifiers, prices, stock, listing attributes | The source platform you connect, such as Shopify |
| Orders | Order identifiers, items, quantities, status, fulfilment channel | The marketplaces you connect |
| Buyer personal information | Buyer name, delivery address, phone, and any marketplace-issued masked email | Marketplace order APIs, per order, at the point of shipping |
| Technical and usage | IP address, browser and device, features used, and the result of every API call made for you | Automatically, as you use the service |
| Support messages | What you write to us and what we agreed | You |
We do not collect special-category data — health, biometric, racial or ethnic origin, religious or political belief, trade union membership or sexual orientation — and ask that you do not send it. We do not buy data from brokers and do not track you across other sites for advertising.
3. How we use it
We use the above only to import your catalog, build and publish listings, keep prices and stock aligned, retrieve and help you fulfil orders, produce shipping documents, run the optional AI features you switch on, bill you, support you, secure the platform, and tell you about material changes. Product marketing email is separate, optional and unsubscribable in one click.
What we never do
- Sell, rent or trade your data or your buyers’ personal information to anyone.
- Use buyer personal information for marketing, advertising, retargeting or profiling.
- Use your catalog, order or buyer data to train machine-learning models that serve other customers.
- Aggregate or benchmark one merchant’s data to produce insights for another, or for our own research.
- Contact your buyers, for any reason.
- Use marketplace information for any purpose other than the seller-authorised service it was retrieved for.
4. Marketplace and Amazon information
This section applies in addition to everything above, and governs where it is stricter.
4.1 You authorise it, and can withdraw it
Orbitra reaches a marketplace account only after you complete that marketplace’s own consent flow — for Amazon, the OAuth authorisation inside Seller Central. We never ask for your marketplace password. You can revoke access at any time from your seller account or by asking us, and revocation stops all further access immediately.
4.2 Amazon Information
“Amazon Information” means any data we retrieve from Amazon’s Selling Partner API for your seller account — listing, pricing, inventory and order data, and personally identifiable buyer information. We treat it as confidential and handle it in line with Amazon’s Acceptable Use Policy and Data Protection Policy.
4.3 Buyer data is fetched per order, for fulfilment only
We hold no standing copy of buyer data. Buyer name, delivery address and phone are retrieved through a Restricted Data Token scoped to a single order, at the moment that order is being despatched, and used solely to purchase postage, produce the label and packing documentation, and hand delivery details to the carrier. Nothing else.
4.4 Retention, segregation and notification
Buyer personal information is deleted within 30 days of shipment, unless a tax authority or marketplace rule requires a specific record to be kept longer — in which case only that record is kept, for only as long as required. Each merchant account is stored separately and is not reachable from another account. Buyer data is encrypted at the field level on top of full-disk encryption, and every access is logged against a named user or service. If we confirm unauthorised access to Amazon Information we notify Amazon at security@amazon.com within 24 hours of detection, and notify you and any regulator as the law requires.
4.5 Other marketplaces
The same handling applies to eBay and, as they ship, Etsy and Walmart. Where a marketplace imposes stricter requirements than this policy, we apply the stricter requirement.
6. Where it is stored, and transfers
Primary infrastructure runs in a single cloud region, with encrypted backups replicated to a separate region in a different country. Our team accesses production from the United Arab Emirates and, where a team member is based elsewhere, from their own location under the same controls. Where personal data protected by the EU or UK GDPR leaves that jurisdiction we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, alongside the technical measures on our Trust & Security page. Where UAE PDPL applies, transfers go to jurisdictions with adequate protection or under safeguards the law permits.
7. How long we keep it
| Data | Retention |
|---|---|
| Buyer personal information | Deleted within 30 days of shipment |
| Catalog, listing and order records | Deleted within 30 days of account closure |
| Account and billing records | While the account is open; invoices as long as UAE tax law requires |
| Operational logs | 90 days |
| Security audit events | 12 months |
| Support messages | 24 months from last contact |
Deletion covers live systems and backups within the backup rotation window. Where a backup cannot be selectively edited, data is removed as that backup expires on its normal schedule and stays encrypted and access-controlled until it does. You can export everything first, and can ask us to delete sooner.
8. How we protect it
Data in transit is protected with TLS 1.2 or above; data at rest is encrypted with AES-256, and buyer personal information is additionally encrypted at the application layer. Databases run on private networks with no public route, access is limited by role on a need-to-know basis with multi-factor authentication on every account, and every access to personal information is logged. Our full posture — network protection, key management, backups and recovery objectives, logging, incident response, vulnerability management and secure development — is documented on our Trust & Security page.
9. Your rights
Wherever you are, you can ask us to give you a copy of your personal data, export your catalog and order data, correct anything inaccurate, delete your data (subject to records we must legally keep), restrict or object to processing, or withdraw a consent you gave. Email admin@orbitracommerce.com from your account address and we will respond within 30 days. We may need to verify your identity first.
These rights arise under the EU and UK GDPR, under the CCPA as amended by the CPRA if you are in California, and under UAE Federal Decree-Law No. 45 of 2021. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no “Do Not Sell or Share” action to take. Where we process buyer data as your processor, requests from your buyers should come to you as controller — tell us and we will help you answer in time. You can complain to the UAE Data Office, or to your own supervisory authority, though we would rather you gave us the chance to fix it first.
11. AI features
The optional AI features — pricing intelligence, inventory forecasting, SKU revenue ranking, channel recommendation and the listing optimiser — are advisory. They surface a suggestion; nothing changes a price, listing or order until you approve it, so there is no automated decision-making with a legal effect on you or a buyer. They run on your own catalog and order history inside your own account, and we do not use your data to train models serving other merchants. Where the listing optimiser uses a third-party model it receives only the product content needed to write the listing — never buyer personal information — under a contract prohibiting training on it. You can switch every AI feature off.
12. Changes, and how to contact us
If we change this policy we update the version and date above, and for any change that materially affects how we handle your data we email you at least 30 days before it takes effect. Earlier versions are available on request. For anything here, or to exercise a right, email admin@orbitracommerce.com; for a suspected security issue, admin@orbitracommerce.com, acknowledged within one business day.
See also: Terms of Service
Back to Sign In