1. Introduction & Scope
This Privacy Policy describes how Angel Gate Solutions, LLC collects, uses, shares, and protects personal information in connection with Orbix, our AI-powered website builder and business management platform (the "Service"). This Policy applies to:
- All individuals who create an Orbix account or use the Service ("Users");
- Visitors to the angelgatesolutions.com and orbix-related web properties;
- Individuals who contact us for support or information.
This Policy does not govern the privacy practices of websites built and operated by our Users using the Service. Each User is independently responsible for the privacy practices of their own websites. See Section 20 for details.
This Policy is incorporated by reference into our Terms of Service. Capitalized terms not defined herein have the meanings assigned in the Terms of Service.
2. Identity of the Data Controller
Angel Gate Solutions, LLC (Data Controller)
Address: Available on request via legal@angelgatesolutions.com
State of Formation: Florida
Privacy Contact: privacy@angelgatesolutions.com
For users in the European Economic Area ("EEA") and the United Kingdom ("UK"), Angel Gate Solutions, LLC is the Data Controller within the meaning of the General Data Protection Regulation ("GDPR"), Regulation (EU) 2016/679, and the UK GDPR. You may contact us at any time at privacy@angelgatesolutions.com regarding data protection matters.
3. Categories of Personal Information We Collect
The following table describes the categories of personal information we collect, the sources, purposes, and whether we have disclosed it for a business purpose in the preceding 12 months. This table satisfies CCPA § 1798.100 disclosure requirements.
| Category | Examples | Collected? | Business Purpose Disclosed? |
|---|---|---|---|
| Identifiers | Name, email address, IP address, device identifiers, Google account ID (OAuth) | Yes | Yes — to infrastructure providers (Firebase, Cloudflare) |
| Personal Records (Cal. Civ. Code § 1798.80) | Name, email, payment card type and last 4 digits, billing address | Yes | Yes — to Stripe for payment processing |
| Commercial Information | Subscription plan, purchase history, AI credit usage, billing history | Yes | Yes — to Stripe (billing) |
| Referral & Partner Program Data | Your referral code, the code you signed up with, partner earnings and payout ledger, and — if you're a Partner — tax documentation (e.g., W-9/W-8BEN) and 1099 reporting details | If you use referrals / join the Partner Program | Yes — payouts via Stripe; tax filings to tax authorities as required |
| Internet / Network Activity | Pages visited, features used, session duration, browser type, OS, IP address, referrer URL | Yes | No — internal server/event logs only (no third-party analytics by default) |
| Geolocation Data | Approximate location derived from IP address (country/city-level only; no precise GPS) | Yes (coarse) | Yes — to Stripe (fraud prevention) / Cloudflare (security) |
| Professional / Employment Information | Business name, job title (if provided in profile) | If provided | No |
| User-Generated Content | Website content you create, images uploaded, product listings, form responses, customer data you store | Yes | No — stored for your account; sent to our AI providers only when you use AI features (see Section 8) |
| Communications Data | Support tickets, AI support chat messages, emails you send to us | Yes | No — internal support use only |
| Account Credentials | Google sign-in (OAuth) tokens and session identifiers — Orbix does NOT create, see, or store passwords | Yes | No |
| Sensitive Personal Information (CPRA) | See Section 4 below | Limited | No |
* We do not collect: Social Security Numbers, driver's license numbers, state ID numbers, financial account numbers (only tokenized card data via Stripe), precise geolocation, biometric identifiers, genetic data, race or ethnic origin (unless voluntarily provided in user-created content), or protected classification characteristics.
4. Sensitive Personal Information (CPRA)
California Privacy Rights Act (CPRA), Cal. Civ. Code § 1798.121 — Sensitive Personal Information
Under the CPRA, certain categories of personal information are classified as "sensitive" and carry heightened protections.
Angel Gate Solutions collects the following categories of sensitive personal information, and ONLY uses it for the purposes listed — we do not use or disclose sensitive personal information for purposes other than those specified below:
| Sensitive PI Category | Do We Collect? | Purpose | Used Beyond Permitted Purposes? |
|---|---|---|---|
| Account login credentials (Google OAuth tokens / session — no passwords stored) | Yes | Authentication and account security only | No |
| Payment card information | No — Stripe collects/tokenizes directly. We receive only card type and last 4 digits. | N/A | No |
| Precise geolocation | No | N/A | N/A |
| Racial/ethnic origin | No (not intentionally collected; may appear in user-created content) | N/A | No |
| Religious beliefs | No | N/A | N/A |
| Union membership | No | N/A | N/A |
| Genetic data | No | N/A | N/A |
| Biometric identifiers | No | N/A | N/A |
| Health / medical information | No — see HIPAA disclaimer Section 16 | N/A | No |
| Sexual orientation / sex life | No | N/A | N/A |
| Contents of communications (email, mail, text) | Only support communications you send to us | Customer support and dispute resolution | No |
California residents have the right to limit our use of sensitive personal information to uses necessary to perform the Service. To exercise this right, contact privacy@angelgatesolutions.com.
5. How We Collect Information
5.1 Directly From You
We collect information you actively provide when you: create an account; complete your profile; subscribe to a paid plan; contact our support team; submit feedback; complete surveys; or use features of the Service that require data input.
5.2 Automatically
When you use the Service, we automatically collect certain technical and usage information through: (a) web server logs; (b) strictly-necessary and functional browser storage (see Section 11); and (c) our application's own event logging. We do not run third-party analytics or advertising trackers by default; any optional analytics we add in the future will load only with your consent and will respect Global Privacy Control / Do-Not-Track.
5.3 From Third Parties
If you register or sign in using Google OAuth, we receive your name, email address, and profile photo from Google as authorized by you. We may receive fraud signals or verification data from Stripe (our payment processor). We do not purchase third-party marketing lists.
6. Purposes of Collection & Use
| Purpose | Description | Legal Basis (GDPR) |
|---|---|---|
| Service Delivery | Creating and managing your account; hosting your websites; processing payments; delivering all features of the Service | Performance of Contract |
| Payment Processing | Processing subscription fees and refunds through Stripe | Performance of Contract |
| Account Security | Detecting fraud, unauthorized access, and abuse; enforcing Terms of Service | Legitimate Interests |
| Service Improvement | Analyzing usage patterns; A/B testing; developing new features; fixing bugs | Legitimate Interests |
| AI Website Generation | Sending your prompts, uploaded images/PDFs, and the content of any URLs you ask us to read to our AI provider (primarily Google's Gemini API, and a fallback provider such as OpenAI, Anthropic, or xAI where enabled) to generate and edit your website (see Section 8) | Performance of Contract |
| Customer Support | Responding to support tickets and AI-assisted support chat; resolving disputes | Legitimate Interests / Contract |
| Legal Compliance | Complying with applicable laws, regulations, court orders, and legal process | Legal Obligation |
| Marketing & Promotions | Sending marketing emails, product updates, and promotions (with consent) | Consent |
| Business Analytics | Internal reporting, financial auditing, and operational analytics | Legitimate Interests |
| Dispute Resolution | Maintaining records for arbitration, litigation, and regulatory proceedings | Legitimate Interests / Legal Obligation |
6.1 AI Features & Your Content
We do not use the content of your websites or your personal communications to train our own AI models. To generate or edit your site, the prompts, media, and pasted-URL content you provide are sent to our AI provider — primarily Google's Gemini API and, if a fallback model is enabled for availability, a secondary provider (which may include OpenAI, Anthropic, or xAI) — which processes them to return results (see Section 8 and the applicable provider's API data-use terms). You may opt out of optional product analytics at any time in Account → Security & Privacy or by emailing privacy@angelgatesolutions.com.
6.2 Marketing Opt-Out
We send marketing emails only where: (a) you have given explicit consent at signup or subsequently; or (b) you are an existing customer and the email relates to similar products or services (as permitted under applicable law). You may opt out at any time via the unsubscribe link in any marketing email, or through Account Settings > Notifications. Transactional emails (receipts, security alerts, legal notices) are not subject to marketing opt-out.
7. Legal Basis for Processing (GDPR)
GDPR Article 6 — Lawfulness of Processing
Processing of personal data shall be lawful only if and to the extent that at least one of the following applies: (a) the data subject has given consent; (b) processing is necessary for the performance of a contract; (c) processing is necessary for compliance with a legal obligation; or (f) processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party.
For EEA and UK users, the legal bases for our processing activities are as follows:
| Processing Activity | Legal Basis | GDPR Article |
|---|---|---|
| Account creation and management | Performance of Contract | Art. 6(1)(b) |
| Delivering Service features | Performance of Contract | Art. 6(1)(b) |
| Processing payments | Performance of Contract | Art. 6(1)(b) |
| Fraud detection and security | Legitimate Interests | Art. 6(1)(f) |
| Service improvement and analytics | Legitimate Interests | Art. 6(1)(f) |
| Customer support | Performance of Contract / Legitimate Interests | Art. 6(1)(b)/(f) |
| Tax and financial record keeping | Legal Obligation | Art. 6(1)(c) |
| Response to legal process | Legal Obligation | Art. 6(1)(c) |
| Marketing communications | Consent | Art. 6(1)(a) |
| AI website generation (sending your inputs to Google's Gemini and, where enabled, a fallback AI provider) | Performance of Contract | Art. 6(1)(b) |
| Dispute resolution record-keeping | Legitimate Interests / Legal Obligation | Art. 6(1)(c)/(f) |
Where we rely on legitimate interests (Art. 6(1)(f)), we have conducted a balancing test and concluded that our legitimate interests are not overridden by your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time (see Section 14).
9. Do Not Sell or Share My Personal Information
California Consumer Privacy Act (CCPA), Cal. Civ. Code § 1798.120 | California Privacy Rights Act (CPRA) Amendment
California consumers have the right to opt out of the sale or sharing of their personal information. "Sharing" includes disclosing personal information for cross-context behavioral advertising purposes.
9.1 Global Privacy Control (GPC)
We honor Global Privacy Control ("GPC") signals. If your browser or device sends a GPC signal, we treat it as a valid opt-out of sale and sharing of personal information for California residents, consistent with guidance from the California Attorney General. We will not override or ignore GPC signals.
9.2 Opt-Out Rights
Even though we do not sell or share personal information, you have the right to direct us not to do so in the future. To exercise this right or to confirm our current practices, contact privacy@angelgatesolutions.com with the subject line "Do Not Sell or Share Request."
10. Data Retention
We retain personal information for the period reasonably necessary for the purposes set forth in this Policy, and as required to comply with our legal obligations, resolve disputes, and enforce our agreements. The following schedule sets forth our retention practices:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account profile and credentials | Duration of account + 30 days after confirmed deletion | Service delivery |
| User Content (website content, media) | Duration of account + 30 days after deletion request | Service delivery |
| Payment / billing records | 7 years from transaction date | IRS / U.S. tax law requirements |
| Transaction logs | 7 years | Financial compliance |
| Support and communication records | 3 years from resolution | Dispute resolution, legal compliance |
| Security and access logs | 12 months identifiable; then aggregated | Security investigation |
| Usage analytics | 24 months identifiable; then anonymized indefinitely | Service improvement |
| Marketing consent records | Until consent withdrawn + 3 years (compliance) | Legal obligation (CAN-SPAM, GDPR) |
| IP address logs | 12 months | Security and fraud prevention |
| Arbitration / legal hold data | Until final resolution + 3 years | Legal obligation |
Upon expiration of the applicable retention period, we will delete or anonymize your personal information, unless a longer retention period is required by applicable law. To request early deletion of your data, contact privacy@angelgatesolutions.com. We will process deletion requests within 30 days, subject to our legal retention obligations.
12. Data Security
We implement industry-standard technical and organizational measures ("TOMs") to protect personal information against unauthorized access, disclosure, alteration, destruction, and accidental loss:
| Measure | Description |
|---|---|
| Encryption in Transit | TLS for all data transmitted between your browser and our servers |
| Encryption at Rest | Data stored in Firebase / Google Cloud is encrypted at rest (AES-256) by Google by default |
| Authentication | Sign-in is handled by Google OAuth (Firebase Auth). Orbix never creates, sees, or stores account passwords |
| Payment Security | Card data is collected and tokenized exclusively by Stripe (PCI DSS Level 1 Service Provider); we never receive or store raw card numbers |
| Access Controls | Least-privilege access; role-based permissions for collaborators; access to production data limited to authorized personnel |
| Database Security Rules | Strict per-document, per-user Firestore security rules enforced at the database level |
| Secrets Management | API keys and credentials are stored as managed secrets/environment variables, never in client code |
| Multi-Factor Authentication | Supported on Google accounts used to sign in |
| Security Reviews | Ongoing internal security reviews; third-party penetration testing as the platform scales |
| Vendor Security | We use established subprocessors (Google, Stripe, Cloudflare) operating under their own security programs and DPAs |
| Incident Response | We investigate and respond to security incidents; designated contact: security@orbixapp.com |
Despite our security measures, no method of transmission over the Internet or electronic storage system is 100% secure. We cannot guarantee absolute security. You use the Service at your own risk with respect to security. You are responsible for maintaining the security of your account credentials. If you suspect unauthorized access, notify us immediately at security@orbixapp.com.
13. Data Breach Notification
GDPR Article 33 (Controller notification to supervisory authority) | Article 34 (Communication to data subject) | Various U.S. State Data Breach Notification Laws
In the event of a personal data breach, controllers are required to notify the supervisory authority within 72 hours and, where the breach is likely to result in a high risk to individuals, notify affected data subjects without undue delay.
13.1 Our Commitment
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, Angel Gate Solutions will:
- Notify affected Users without undue delay and, where feasible, within 72 hours of becoming aware of the breach, via email to the registered account address;
- Notify relevant supervisory authorities within 72 hours as required by GDPR Article 33 and applicable U.S. state data breach notification laws (including Florida Statute § 501.171, California Civil Code § 1798.82, and similar laws in other states);
- Provide a written notice containing: (a) the nature of the breach; (b) the categories and approximate number of individuals affected; (c) the categories and approximate number of data records affected; (d) the likely consequences of the breach; (e) the measures taken or proposed to address the breach; and (f) protective steps you can take;
- Take immediate containment, remediation, and forensic investigation steps;
- Document the breach internally as required by GDPR Article 33(5); and
- Cooperate with relevant regulatory authorities in their investigation.
13.2 Responsible Disclosure
If you discover a security vulnerability in Orbix, please contact us immediately and confidentially at security@orbixapp.com. We operate a responsible disclosure policy and will acknowledge your report within 48 hours. We ask that you give us a reasonable opportunity to investigate and remediate before public disclosure.
14. Your Privacy Rights
14.1 Rights Available to All Users Globally
Regardless of your location, you have the following rights with respect to your personal information we hold:
- Right of Access: Request a copy of the personal information we hold about you;
- Right to Correction / Rectification: Request correction of inaccurate or incomplete information;
- Right to Deletion / Erasure: Request deletion of your personal information (subject to legal retention obligations);
- Right to Data Portability: Receive your personal information in a structured, machine-readable format (e.g., JSON, CSV);
- Right to Withdraw Consent: Withdraw any consent you have given at any time, without affecting the lawfulness of prior processing;
- Right to Opt Out of Marketing: Unsubscribe from marketing emails at any time via the unsubscribe link in any such email or through Account Settings.
14.2 EEA / United Kingdom Users (GDPR / UK GDPR)
In addition to the rights above, EEA and UK users have:
- Right to Restrict Processing (Art. 18): Request that we restrict processing of your data in certain circumstances;
- Right to Object (Art. 21): Object to processing based on legitimate interests; object to direct marketing at any time;
- Rights Related to Automated Decision-Making (Art. 22): Not to be subject to solely automated decisions that have legal or similarly significant effects, without human review (see Section 15);
- Right to Lodge a Complaint: Lodge a complaint with your national supervisory authority. In the UK: Information Commissioner's Office (ICO) at ico.org.uk. In EU member states: your national Data Protection Authority (find yours at edpb.europa.eu).
14.3 California Residents (CCPA / CPRA)
California residents have the following rights under the California Consumer Privacy Act (CCPA, Cal. Civ. Code § 1798.100 et seq.) and California Privacy Rights Act (CPRA):
| Right | Description | Response Time |
|---|---|---|
| Right to Know (§ 1798.100) | Know the categories and specific pieces of personal information we have collected, used, disclosed, or sold about you over the past 12 months | 45 days (extendable 45 more) |
| Right to Delete (§ 1798.105) | Request deletion of personal information we have collected, subject to exceptions | 45 days (extendable 45 more) |
| Right to Correct (§ 1798.106) | Request correction of inaccurate personal information | 45 days |
| Right to Opt Out of Sale / Sharing (§ 1798.120) | Opt out of sale or sharing of personal information (we do not sell or share — see Section 9) | Honored immediately |
| Right to Limit Sensitive PI Use (§ 1798.121) | Limit use of sensitive personal information to specified purposes | 45 days |
| Right to Non-Discrimination (§ 1798.125) | Not receive discriminatory treatment for exercising CCPA/CPRA rights | N/A — honored continuously |
To submit a CCPA/CPRA verifiable consumer request, contact privacy@angelgatesolutions.com with the subject line "California Privacy Rights Request." We may need to verify your identity before processing your request. We will respond within 45 days of receipt. Authorized agents must provide written proof of authorization.
14.4 Other U.S. State Privacy Rights
The following additional U.S. state privacy laws may apply to residents of those states:
| State | Law | Key Rights |
|---|---|---|
| Virginia | Consumer Data Protection Act (VCDPA), Va. Code § 59.1-575 et seq. | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling, appeal |
| Colorado | Colorado Privacy Act (CPA), C.R.S. § 6-1-1301 et seq. | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling, appeal |
| Connecticut | Data Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq. | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling, appeal |
| Texas | Texas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code § 541 et seq. | Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling |
| Utah | Consumer Privacy Act (UCPA), Utah Code § 13-61-101 et seq. | Access, deletion, portability, opt-out of sale/targeted advertising |
| Oregon | Consumer Privacy Act (OCPA), ORS § 646A.570 et seq. | Access, correction, deletion, portability, opt-out of sale/profiling, appeal |
| Montana | Consumer Data Privacy Act (MTCDPA), MCA § 30-14-3501 et seq. | Access, correction, deletion, portability, opt-out, appeal |
| Iowa | Consumer Data Protection Act (ICDPA) | Access, deletion, portability, opt-out of sale/targeted advertising |
| Indiana | Consumer Data Protection Act (INCDPA) | Access, correction, deletion, portability, opt-out, appeal |
| Tennessee | Information Protection Act (TIPA) | Access, correction, deletion, portability, opt-out, appeal |
| Delaware | Personal Data Privacy Act (DPDPA) | Access, correction, deletion, portability, opt-out, appeal |
If you are a resident of any of the above states, you may exercise your rights by contacting privacy@angelgatesolutions.com. We will respond within the timeframe required by your state's applicable law. You may also have the right to appeal our decision; to do so, include "Privacy Rights Appeal" in the subject line of your email.
14.5 Canada (PIPEDA / Quebec Law 25)
Canadian residents have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5) and, for Quebec residents, Act respecting the protection of personal information in the private sector (Law 25 / Bill 64). These rights include: access to your personal information; correction of inaccurate information; withdrawal of consent; right to know if your information has been disclosed to third parties; and for Quebec residents: right to data portability and right to de-indexation. Contact privacy@angelgatesolutions.com to exercise these rights.
14.6 How to Submit a Privacy Rights Request
Two of the most common rights are available to you directly in the app: go to Account → Security & Privacy to export your data (machine-readable JSON) or to permanently delete your account.
For any other right (or if you can't access your account): email privacy@angelgatesolutions.com with subject line "Privacy Rights Request." Include your full name, the email address associated with your account, your state or country of residence, and a description of the right you wish to exercise. We may need to verify your identity to process your request. We will acknowledge your request within 5 business days. We will not charge a fee for reasonable requests; for manifestly unfounded or excessive requests, we may charge a reasonable fee or decline to act.
15. Automated Decision-Making & Profiling
GDPR Article 22 — Automated Individual Decision-Making, Including Profiling
The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
Angel Gate Solutions does not make solely automated decisions that produce legal effects or similarly significantly affect you. We may use automated tools to: (a) generate risk scores for fraud detection purposes; (b) recommend features or content within the Service based on your usage patterns; and (c) classify support tickets for routing purposes. However, none of these automated processes make final decisions affecting your legal rights or significantly similar effects without human review.
If you believe an automated process has been applied to you in a way that significantly affects your legal rights (e.g., account suspension following automated fraud detection), you have the right to: (a) request human review of that decision; (b) express your point of view; and (c) contest the decision. Contact privacy@angelgatesolutions.com to exercise these rights.
16. Health Data & HIPAA Disclaimer
If your intended use case requires HIPAA compliance, please contact legal@angelgatesolutions.com to discuss potential HIPAA Business Associate Agreement arrangements before proceeding.
17. Government Access & Law Enforcement
Electronic Communications Privacy Act (ECPA), 18 U.S.C. § 2510 et seq. | Stored Communications Act (SCA), 18 U.S.C. § 2701 et seq.
The Stored Communications Act governs when and under what circumstances government entities may require disclosure of electronic communications stored by service providers.
17.1 Legal Process Requirements
We do not disclose personal information to government or law enforcement agencies except pursuant to: (a) a valid court order; (b) a valid subpoena; (c) a valid legal demand issued under applicable law; or (d) other valid legal process. We carefully review all government requests for user data and require legally sufficient process before complying.
17.2 Notice to Users
Where permitted by law and operationally feasible, we will attempt to notify you before disclosing your information to a government authority by emailing the address associated with your account. We may be prohibited by law from notifying you in certain circumstances (e.g., under a non-disclosure order or National Security Letter).
17.3 Transparency
We reserve the right to publish transparency reports disclosing aggregate statistics regarding government requests for user data, to the extent permitted by applicable law.
17.4 USA PATRIOT Act
Under the USA PATRIOT Act and similar national security legislation, Angel Gate Solutions may be required to provide government agencies with access to stored electronic communications and associated records. If applicable, we will comply with legally valid national security requests while challenging overbroad requests to the extent legally permissible.
18. Children's Privacy (COPPA)
Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq. | 16 C.F.R. Part 312
COPPA imposes requirements on operators of commercial websites and online services directed to children under 13 years of age (or who have actual knowledge that they are collecting personal information from children under 13).
Orbix is intended for and directed exclusively to individuals 18 years of age or older. We do not knowingly collect, solicit, use, or maintain personal information from children under 13 years of age, nor from individuals under 18. Our Service is not directed to children.
If we discover that we have inadvertently collected personal information from a child under 13 (in violation of COPPA) or under 18 (in violation of our Terms of Service), we will: (a) immediately delete such information; (b) terminate the associated account; and (c) take reasonable steps to prevent re-registration.
If you are a parent or guardian and believe that your child has provided personal information to Orbix, please contact us immediately at privacy@angelgatesolutions.com with the subject "COPPA Request." We will promptly investigate and, if confirmed, delete the data. You may review, request deletion of, or refuse further collection of your child's personal information by contacting us.
19. International Data Transfers
19.1 Cross-Border Transfers
Angel Gate Solutions, LLC is headquartered and operates primarily in the United States. If you access Orbix from the European Economic Area ("EEA"), the United Kingdom ("UK"), Canada, or any other jurisdiction with data transfer restrictions, your personal information will be transferred to and processed in the United States, which may have different data protection laws and may not be deemed to provide an "adequate" level of protection by your jurisdiction's standards.
19.2 Transfer Safeguards for EEA/UK
For transfers of personal data from the EEA or UK to the United States, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs): We incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914) for EEA-to-U.S. transfers with our sub-processors;
- UK International Data Transfer Agreements (IDTAs): For UK-to-U.S. transfers, we use the UK IDTA approved by the UK Secretary of State;
- Supplementary Measures: Where required by post-Schrems II guidance, we implement supplementary technical and organizational measures (e.g., encryption, pseudonymization).
19.3 Sub-Processor Transfers
Our sub-processors (including Google LLC and Stripe, Inc.) maintain their own internationally recognized transfer mechanisms, including participation in applicable data transfer frameworks and implementation of SCCs. You may request a list of our sub-processors and their transfer mechanisms by contacting privacy@angelgatesolutions.com.
20. Your Website Visitors (You as Data Controller)
When you use Orbix to build and operate a website, you collect personal data from your website visitors (e.g., contact form submissions, email signups, order information, live chat conversations, member account sign-ups, and membership or subscription status). In this context:
- You are the Data Controller for your website visitors' personal data. Angel Gate Solutions acts as a data processor on your behalf.
- Your responsibilities include: establishing a lawful basis for collecting visitor data; providing your visitors with a privacy policy that accurately describes your data practices; obtaining required consents; complying with applicable privacy laws (including CCPA, GDPR, CAN-SPAM, TCPA, and others) with respect to your visitors; and responding to your visitors' privacy rights requests.
- Angel Gate Solutions is not responsible for your compliance with privacy laws governing your website visitors' data, and shall not be liable to you, your website visitors, or any third party for your failure to comply.
- We strongly recommend that you consult with a qualified attorney regarding your privacy obligations before launching a website that collects personal data.
Our processing of visitor data on your behalf is governed by a data processing arrangement incorporated into our Terms of Service. To request a separate Data Processing Agreement (DPA) for GDPR compliance, contact legal@angelgatesolutions.com.
21. Third-Party Links & Services
The Service may contain links to third-party websites, applications, or services not operated by Angel Gate Solutions. This Privacy Policy does not apply to those third-party properties, and we have no control over and are not responsible for their content, privacy practices, or data handling. We encourage you to review the privacy policies of any third-party properties before interacting with them or sharing personal information.
Our inclusion of a link to or integration with a third-party service does not constitute an endorsement of that service's privacy practices or any other aspect of its operations.
22. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or the Service. When we make material changes, we will:
- Provide at least 14 days' advance notice by email to the address associated with your account;
- Post a prominent notice within the Orbix dashboard for a period of 30 days;
- Update the "Effective Date" at the top of this Policy; and
- For material changes that alter how we use previously collected data, obtain your consent where required by applicable law.
Non-material changes (formatting corrections, clarifications, addition of new rights that benefit users) may be made by updating the Policy and the Effective Date without separate advance notice. Your continued use of Orbix after the effective date of any updated Policy constitutes your acceptance of the changes. If you do not agree to the updated Policy, you must stop using the Service and close your account before the effective date.
23. Contact & Data Protection Officer
If you have any questions, concerns, complaints, or requests regarding this Privacy Policy or our data practices, please contact us:
Angel Gate Solutions, LLC — Privacy Team
Address: Available on request via legal@angelgatesolutions.com
Privacy email: privacy@angelgatesolutions.com
Security: security@orbixapp.com
Legal: legal@angelgatesolutions.com
23.1 EEA / UK Data Subjects
If you are located in the EEA or UK and are not satisfied with our response to your privacy request or complaint, you have the right to lodge a complaint with your local supervisory authority:
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- European Union: Your national Data Protection Authority (directory at edpb.europa.eu)
23.2 Response Timeframes
We will acknowledge privacy requests within 5 business days and provide a substantive response within: 30 days for general requests; 45 days for CCPA/CPRA verifiable consumer requests (extendable by 45 days with notice); 30 days for GDPR requests (extendable by 2 months for complex requests, with notice); and within the period required by other applicable state privacy laws.
© 2026 Angel Gate Solutions, LLC. All rights reserved.
Read our Terms of Service →