O
Orbix by Angel Gate Solutions

Privacy Policy

Effective Date: July 13, 2026 · Terms of Service →

Angel Gate Solutions, LLC ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy governs our collection, use, disclosure, and protection of personal information in connection with the Orbix platform. By using Orbix, you agree to the data practices described herein. If you do not agree, do not use the Service.

1. Introduction & Scope

This Privacy Policy describes how Angel Gate Solutions, LLC collects, uses, shares, and protects personal information in connection with Orbix, our AI-powered website builder and business management platform (the "Service"). This Policy applies to:

  • All individuals who create an Orbix account or use the Service ("Users");
  • Visitors to the angelgatesolutions.com and orbix-related web properties;
  • Individuals who contact us for support or information.

This Policy does not govern the privacy practices of websites built and operated by our Users using the Service. Each User is independently responsible for the privacy practices of their own websites. See Section 20 for details.

This Policy is incorporated by reference into our Terms of Service. Capitalized terms not defined herein have the meanings assigned in the Terms of Service.

2. Identity of the Data Controller

Angel Gate Solutions, LLC (Data Controller)

Address: Available on request via legal@angelgatesolutions.com

State of Formation: Florida

Privacy Contact: privacy@angelgatesolutions.com

For users in the European Economic Area ("EEA") and the United Kingdom ("UK"), Angel Gate Solutions, LLC is the Data Controller within the meaning of the General Data Protection Regulation ("GDPR"), Regulation (EU) 2016/679, and the UK GDPR. You may contact us at any time at privacy@angelgatesolutions.com regarding data protection matters.

3. Categories of Personal Information We Collect

The following table describes the categories of personal information we collect, the sources, purposes, and whether we have disclosed it for a business purpose in the preceding 12 months. This table satisfies CCPA § 1798.100 disclosure requirements.

CategoryExamplesCollected?Business Purpose Disclosed?
IdentifiersName, email address, IP address, device identifiers, Google account ID (OAuth)YesYes — to infrastructure providers (Firebase, Cloudflare)
Personal Records (Cal. Civ. Code § 1798.80)Name, email, payment card type and last 4 digits, billing addressYesYes — to Stripe for payment processing
Commercial InformationSubscription plan, purchase history, AI credit usage, billing historyYesYes — to Stripe (billing)
Referral & Partner Program DataYour referral code, the code you signed up with, partner earnings and payout ledger, and — if you're a Partner — tax documentation (e.g., W-9/W-8BEN) and 1099 reporting detailsIf you use referrals / join the Partner ProgramYes — payouts via Stripe; tax filings to tax authorities as required
Internet / Network ActivityPages visited, features used, session duration, browser type, OS, IP address, referrer URLYesNo — internal server/event logs only (no third-party analytics by default)
Geolocation DataApproximate location derived from IP address (country/city-level only; no precise GPS)Yes (coarse)Yes — to Stripe (fraud prevention) / Cloudflare (security)
Professional / Employment InformationBusiness name, job title (if provided in profile)If providedNo
User-Generated ContentWebsite content you create, images uploaded, product listings, form responses, customer data you storeYesNo — stored for your account; sent to our AI providers only when you use AI features (see Section 8)
Communications DataSupport tickets, AI support chat messages, emails you send to usYesNo — internal support use only
Account CredentialsGoogle sign-in (OAuth) tokens and session identifiers — Orbix does NOT create, see, or store passwordsYesNo
Sensitive Personal Information (CPRA)See Section 4 belowLimitedNo

* We do not collect: Social Security Numbers, driver's license numbers, state ID numbers, financial account numbers (only tokenized card data via Stripe), precise geolocation, biometric identifiers, genetic data, race or ethnic origin (unless voluntarily provided in user-created content), or protected classification characteristics.

4. Sensitive Personal Information (CPRA)

California Privacy Rights Act (CPRA), Cal. Civ. Code § 1798.121 — Sensitive Personal Information

Under the CPRA, certain categories of personal information are classified as "sensitive" and carry heightened protections.

Angel Gate Solutions collects the following categories of sensitive personal information, and ONLY uses it for the purposes listed — we do not use or disclose sensitive personal information for purposes other than those specified below:

Sensitive PI CategoryDo We Collect?PurposeUsed Beyond Permitted Purposes?
Account login credentials (Google OAuth tokens / session — no passwords stored)YesAuthentication and account security onlyNo
Payment card informationNo — Stripe collects/tokenizes directly. We receive only card type and last 4 digits.N/ANo
Precise geolocationNoN/AN/A
Racial/ethnic originNo (not intentionally collected; may appear in user-created content)N/ANo
Religious beliefsNoN/AN/A
Union membershipNoN/AN/A
Genetic dataNoN/AN/A
Biometric identifiersNoN/AN/A
Health / medical informationNo — see HIPAA disclaimer Section 16N/ANo
Sexual orientation / sex lifeNoN/AN/A
Contents of communications (email, mail, text)Only support communications you send to usCustomer support and dispute resolutionNo

California residents have the right to limit our use of sensitive personal information to uses necessary to perform the Service. To exercise this right, contact privacy@angelgatesolutions.com.

5. How We Collect Information

5.1 Directly From You

We collect information you actively provide when you: create an account; complete your profile; subscribe to a paid plan; contact our support team; submit feedback; complete surveys; or use features of the Service that require data input.

5.2 Automatically

When you use the Service, we automatically collect certain technical and usage information through: (a) web server logs; (b) strictly-necessary and functional browser storage (see Section 11); and (c) our application's own event logging. We do not run third-party analytics or advertising trackers by default; any optional analytics we add in the future will load only with your consent and will respect Global Privacy Control / Do-Not-Track.

5.3 From Third Parties

If you register or sign in using Google OAuth, we receive your name, email address, and profile photo from Google as authorized by you. We may receive fraud signals or verification data from Stripe (our payment processor). We do not purchase third-party marketing lists.

6. Purposes of Collection & Use

PurposeDescriptionLegal Basis (GDPR)
Service DeliveryCreating and managing your account; hosting your websites; processing payments; delivering all features of the ServicePerformance of Contract
Payment ProcessingProcessing subscription fees and refunds through StripePerformance of Contract
Account SecurityDetecting fraud, unauthorized access, and abuse; enforcing Terms of ServiceLegitimate Interests
Service ImprovementAnalyzing usage patterns; A/B testing; developing new features; fixing bugsLegitimate Interests
AI Website GenerationSending your prompts, uploaded images/PDFs, and the content of any URLs you ask us to read to our AI provider (primarily Google's Gemini API, and a fallback provider such as OpenAI, Anthropic, or xAI where enabled) to generate and edit your website (see Section 8)Performance of Contract
Customer SupportResponding to support tickets and AI-assisted support chat; resolving disputesLegitimate Interests / Contract
Legal ComplianceComplying with applicable laws, regulations, court orders, and legal processLegal Obligation
Marketing & PromotionsSending marketing emails, product updates, and promotions (with consent)Consent
Business AnalyticsInternal reporting, financial auditing, and operational analyticsLegitimate Interests
Dispute ResolutionMaintaining records for arbitration, litigation, and regulatory proceedingsLegitimate Interests / Legal Obligation

6.1 AI Features & Your Content

We do not use the content of your websites or your personal communications to train our own AI models. To generate or edit your site, the prompts, media, and pasted-URL content you provide are sent to our AI provider — primarily Google's Gemini API and, if a fallback model is enabled for availability, a secondary provider (which may include OpenAI, Anthropic, or xAI) — which processes them to return results (see Section 8 and the applicable provider's API data-use terms). You may opt out of optional product analytics at any time in Account → Security & Privacy or by emailing privacy@angelgatesolutions.com.

6.2 Marketing Opt-Out

We send marketing emails only where: (a) you have given explicit consent at signup or subsequently; or (b) you are an existing customer and the email relates to similar products or services (as permitted under applicable law). You may opt out at any time via the unsubscribe link in any marketing email, or through Account Settings > Notifications. Transactional emails (receipts, security alerts, legal notices) are not subject to marketing opt-out.

8. Sharing, Disclosing & Selling Your Information

WE DO NOT SELL YOUR PERSONAL INFORMATION TO THIRD PARTIES. WE HAVE NOT SOLD PERSONAL INFORMATION IN THE PAST 12 MONTHS AND WE WILL NEVER SELL IT.

8.1 Service Providers (Subprocessors)

We engage the following third-party vendors to process personal data on our behalf, under their respective data processing terms (e.g., the Google Cloud DPA and Stripe DPA), which restrict use of the data to providing their services to us:

ProviderRoleData SharedLocationSafeguards
Google LLC (Firebase / Google Cloud)Authentication (Google sign-in), database, file storage, hosting, serverless functionsAccount data, User Content, usage logsUSA, globalGoogle Cloud DPA, SCCs
Stripe, Inc.Payment processing, subscriptions, payouts (Stripe Connect), and fraud preventionBilling details (card data tokenized by Stripe directly), payout detailsUSAPCI DSS Level 1, Stripe DPA
Google LLC (Gemini / Generative AI, via Firebase AI Logic)Primary AI provider for website, content, and image generationYour prompts, uploaded images/PDFs, and the content of URLs you ask us to read for contextUSAGoogle APIs Terms & data-use policies
Fallback AI providers (may include OpenAI, Anthropic, and xAI), where enabledSecondary AI generation used only if the primary provider is unavailable or a given model is enabled for reliabilityThe same prompt and any attached media as aboveUSAProvider API terms & data-use policies
Cloudflare, Inc.CDN, security/DDoS protection, and subdomain routing for published sitesVisitor IP addresses and request metadataUSA / globalCloudflare DPA, SCCs
Brevo (Sendinblue, Sibo Technology)Sending transactional email (sign-in codes, receipts, alerts, invites)Recipient email address and message contentUSA / EUProvider DPA, SCCs
Unsplash Inc.Royalty-free stock imagery for AI-generated and template sitesSearch keywords derived from your business/industry (no account PII); visitor browsers load images directly from UnsplashUSAUnsplash API Terms
Google LLC (Google Ads API)Placing managed advertising campaigns only if you purchase the optional managed-ads add-onAd copy, keywords, and destination URL from your ad orderUSAGoogle Ads API Terms

8.2 Legal Requirements

We may disclose personal information to law enforcement, courts, government agencies, or other third parties when: (a) required by applicable law, regulation, valid subpoena, court order, or legal process; (b) we believe disclosure is necessary to protect our rights or property; (c) we believe disclosure is necessary to protect the safety of any person; or (d) disclosure is required in connection with a government investigation. Where legally permitted, we will notify you before disclosing your information in response to such requests. See also Section 17 (Government Access).

8.3 Business Transfers

In connection with any merger, acquisition, asset sale, reorganization, or bankruptcy proceeding involving Angel Gate Solutions, personal information may be transferred to the acquiring or surviving entity. We will provide you with at least 30 days' advance notice by email before your personal information becomes subject to a materially different privacy policy, and will give you the opportunity to delete your account before the transfer takes effect.

8.4 Aggregated / De-Identified Data

We may share aggregated or de-identified information (such as statistical usage data, industry trend reports, or benchmark data) with third parties for research, marketing, analytics, or other commercial purposes. De-identified data does not contain information that can reasonably be used to identify you.

8.5 With Your Explicit Consent

We may share your information for purposes not described above with your prior, informed, and explicit consent.

8.6 Referral & Partner Program

If you refer others or join the Orbix Partner Program, we process referral and payout data as follows: (a) we attribute new signups to a referral code using cookies/browser storage and our server records; (b) we calculate commissions on referred accounts' subscription payments after covering taxes, payment-processing fees, and platform costs, and record them in your earnings ledger; (c) we process payouts through Stripe (see our subprocessor table above); and (d) where required, we collect tax documentation (e.g., IRS Form W-9 or W-8BEN) and report payments to tax authorities (e.g., IRS Form 1099). Partners receive only anonymized, aggregated performance data about the accounts they refer (such as amounts paid, plan, and their share) — never the personal information or identity of a referred account or its customers. Your participation is governed by the Partner Program terms in our Terms of Service (Section 5.11).

9. Do Not Sell or Share My Personal Information

California Consumer Privacy Act (CCPA), Cal. Civ. Code § 1798.120 | California Privacy Rights Act (CPRA) Amendment

California consumers have the right to opt out of the sale or sharing of their personal information. "Sharing" includes disclosing personal information for cross-context behavioral advertising purposes.

ANGEL GATE SOLUTIONS DOES NOT SELL OR SHARE PERSONAL INFORMATION AS THOSE TERMS ARE DEFINED UNDER CCPA/CPRA. WE DO NOT SELL PERSONAL INFORMATION FOR MONEY. WE DO NOT SHARE PERSONAL INFORMATION WITH THIRD PARTIES FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING PURPOSES.

9.1 Global Privacy Control (GPC)

We honor Global Privacy Control ("GPC") signals. If your browser or device sends a GPC signal, we treat it as a valid opt-out of sale and sharing of personal information for California residents, consistent with guidance from the California Attorney General. We will not override or ignore GPC signals.

9.2 Opt-Out Rights

Even though we do not sell or share personal information, you have the right to direct us not to do so in the future. To exercise this right or to confirm our current practices, contact privacy@angelgatesolutions.com with the subject line "Do Not Sell or Share Request."

10. Data Retention

We retain personal information for the period reasonably necessary for the purposes set forth in this Policy, and as required to comply with our legal obligations, resolve disputes, and enforce our agreements. The following schedule sets forth our retention practices:

Data CategoryRetention PeriodBasis
Account profile and credentialsDuration of account + 30 days after confirmed deletionService delivery
User Content (website content, media)Duration of account + 30 days after deletion requestService delivery
Payment / billing records7 years from transaction dateIRS / U.S. tax law requirements
Transaction logs7 yearsFinancial compliance
Support and communication records3 years from resolutionDispute resolution, legal compliance
Security and access logs12 months identifiable; then aggregatedSecurity investigation
Usage analytics24 months identifiable; then anonymized indefinitelyService improvement
Marketing consent recordsUntil consent withdrawn + 3 years (compliance)Legal obligation (CAN-SPAM, GDPR)
IP address logs12 monthsSecurity and fraud prevention
Arbitration / legal hold dataUntil final resolution + 3 yearsLegal obligation

Upon expiration of the applicable retention period, we will delete or anonymize your personal information, unless a longer retention period is required by applicable law. To request early deletion of your data, contact privacy@angelgatesolutions.com. We will process deletion requests within 30 days, subject to our legal retention obligations.

11. Cookies & Tracking Technologies

11.1 Types of Cookies We Use

CategoryExamplesPurposeCan You Opt Out?
Strictly NecessarySign-in/session (Firebase Auth), security tokensAuthentication, session management, and security. The Service CANNOT function without these.No
Functional / PreferenceTheme preference, sidebar state, shopping cart, referral code (browser storage)Remember your settings and enable core features.Yes (may impair some features)
Performance / AnalyticsNone active by defaultIf we ever enable optional analytics, it loads only with your consent and is disabled when you decline or send a GPC/Do-Not-Track signal.Yes — consent banner / Account → Security & Privacy
Marketing / AdvertisingNoneWe do not use advertising, retargeting, or cross-site tracking cookies.N/A

11.2 Third-Party Cookies

Some cookies may be set by third-party services embedded in our platform (for example, Stripe on payment/checkout pages). These cookies are governed by those third parties' own cookie and privacy policies, which we encourage you to review independently.

11.3 Cookie Consent (EEA/UK)

We present a cookie/storage consent banner before enabling any non-essential storage, and we default to declining it when your browser sends a Global Privacy Control or Do-Not-Track signal. You can change your choice at any time in Account → Security & Privacy. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

11.4 Do Not Track & Global Privacy Control

We respect browser "Do Not Track" (DNT) signals where technically feasible — when a DNT signal is detected, we will not place performance or marketing cookies. We also honor Global Privacy Control (GPC) signals from browsers that support it (see Section 9.1).

11.5 How to Control Cookies

You can configure your browser to reject, block, or delete cookies at any time. Most browsers allow you to: view what cookies have been set; refuse all or certain cookies; delete cookies when you close the browser. Disabling strictly necessary cookies will prevent you from logging in and using the Service. Browser cookie controls are available in your browser's Settings or Preferences menu.

12. Data Security

We implement industry-standard technical and organizational measures ("TOMs") to protect personal information against unauthorized access, disclosure, alteration, destruction, and accidental loss:

MeasureDescription
Encryption in TransitTLS for all data transmitted between your browser and our servers
Encryption at RestData stored in Firebase / Google Cloud is encrypted at rest (AES-256) by Google by default
AuthenticationSign-in is handled by Google OAuth (Firebase Auth). Orbix never creates, sees, or stores account passwords
Payment SecurityCard data is collected and tokenized exclusively by Stripe (PCI DSS Level 1 Service Provider); we never receive or store raw card numbers
Access ControlsLeast-privilege access; role-based permissions for collaborators; access to production data limited to authorized personnel
Database Security RulesStrict per-document, per-user Firestore security rules enforced at the database level
Secrets ManagementAPI keys and credentials are stored as managed secrets/environment variables, never in client code
Multi-Factor AuthenticationSupported on Google accounts used to sign in
Security ReviewsOngoing internal security reviews; third-party penetration testing as the platform scales
Vendor SecurityWe use established subprocessors (Google, Stripe, Cloudflare) operating under their own security programs and DPAs
Incident ResponseWe investigate and respond to security incidents; designated contact: security@orbixapp.com

Despite our security measures, no method of transmission over the Internet or electronic storage system is 100% secure. We cannot guarantee absolute security. You use the Service at your own risk with respect to security. You are responsible for maintaining the security of your account credentials. If you suspect unauthorized access, notify us immediately at security@orbixapp.com.

13. Data Breach Notification

GDPR Article 33 (Controller notification to supervisory authority) | Article 34 (Communication to data subject) | Various U.S. State Data Breach Notification Laws

In the event of a personal data breach, controllers are required to notify the supervisory authority within 72 hours and, where the breach is likely to result in a high risk to individuals, notify affected data subjects without undue delay.

13.1 Our Commitment

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, Angel Gate Solutions will:

  • Notify affected Users without undue delay and, where feasible, within 72 hours of becoming aware of the breach, via email to the registered account address;
  • Notify relevant supervisory authorities within 72 hours as required by GDPR Article 33 and applicable U.S. state data breach notification laws (including Florida Statute § 501.171, California Civil Code § 1798.82, and similar laws in other states);
  • Provide a written notice containing: (a) the nature of the breach; (b) the categories and approximate number of individuals affected; (c) the categories and approximate number of data records affected; (d) the likely consequences of the breach; (e) the measures taken or proposed to address the breach; and (f) protective steps you can take;
  • Take immediate containment, remediation, and forensic investigation steps;
  • Document the breach internally as required by GDPR Article 33(5); and
  • Cooperate with relevant regulatory authorities in their investigation.

13.2 Responsible Disclosure

If you discover a security vulnerability in Orbix, please contact us immediately and confidentially at security@orbixapp.com. We operate a responsible disclosure policy and will acknowledge your report within 48 hours. We ask that you give us a reasonable opportunity to investigate and remediate before public disclosure.

14. Your Privacy Rights

14.1 Rights Available to All Users Globally

Regardless of your location, you have the following rights with respect to your personal information we hold:

  • Right of Access: Request a copy of the personal information we hold about you;
  • Right to Correction / Rectification: Request correction of inaccurate or incomplete information;
  • Right to Deletion / Erasure: Request deletion of your personal information (subject to legal retention obligations);
  • Right to Data Portability: Receive your personal information in a structured, machine-readable format (e.g., JSON, CSV);
  • Right to Withdraw Consent: Withdraw any consent you have given at any time, without affecting the lawfulness of prior processing;
  • Right to Opt Out of Marketing: Unsubscribe from marketing emails at any time via the unsubscribe link in any such email or through Account Settings.

14.2 EEA / United Kingdom Users (GDPR / UK GDPR)

In addition to the rights above, EEA and UK users have:

  • Right to Restrict Processing (Art. 18): Request that we restrict processing of your data in certain circumstances;
  • Right to Object (Art. 21): Object to processing based on legitimate interests; object to direct marketing at any time;
  • Rights Related to Automated Decision-Making (Art. 22): Not to be subject to solely automated decisions that have legal or similarly significant effects, without human review (see Section 15);
  • Right to Lodge a Complaint: Lodge a complaint with your national supervisory authority. In the UK: Information Commissioner's Office (ICO) at ico.org.uk. In EU member states: your national Data Protection Authority (find yours at edpb.europa.eu).

14.3 California Residents (CCPA / CPRA)

California residents have the following rights under the California Consumer Privacy Act (CCPA, Cal. Civ. Code § 1798.100 et seq.) and California Privacy Rights Act (CPRA):

RightDescriptionResponse Time
Right to Know (§ 1798.100)Know the categories and specific pieces of personal information we have collected, used, disclosed, or sold about you over the past 12 months45 days (extendable 45 more)
Right to Delete (§ 1798.105)Request deletion of personal information we have collected, subject to exceptions45 days (extendable 45 more)
Right to Correct (§ 1798.106)Request correction of inaccurate personal information45 days
Right to Opt Out of Sale / Sharing (§ 1798.120)Opt out of sale or sharing of personal information (we do not sell or share — see Section 9)Honored immediately
Right to Limit Sensitive PI Use (§ 1798.121)Limit use of sensitive personal information to specified purposes45 days
Right to Non-Discrimination (§ 1798.125)Not receive discriminatory treatment for exercising CCPA/CPRA rightsN/A — honored continuously

To submit a CCPA/CPRA verifiable consumer request, contact privacy@angelgatesolutions.com with the subject line "California Privacy Rights Request." We may need to verify your identity before processing your request. We will respond within 45 days of receipt. Authorized agents must provide written proof of authorization.

14.4 Other U.S. State Privacy Rights

The following additional U.S. state privacy laws may apply to residents of those states:

StateLawKey Rights
VirginiaConsumer Data Protection Act (VCDPA), Va. Code § 59.1-575 et seq.Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling, appeal
ColoradoColorado Privacy Act (CPA), C.R.S. § 6-1-1301 et seq.Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling, appeal
ConnecticutData Privacy Act (CTDPA), Conn. Gen. Stat. § 42-515 et seq.Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling, appeal
TexasTexas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code § 541 et seq.Access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling
UtahConsumer Privacy Act (UCPA), Utah Code § 13-61-101 et seq.Access, deletion, portability, opt-out of sale/targeted advertising
OregonConsumer Privacy Act (OCPA), ORS § 646A.570 et seq.Access, correction, deletion, portability, opt-out of sale/profiling, appeal
MontanaConsumer Data Privacy Act (MTCDPA), MCA § 30-14-3501 et seq.Access, correction, deletion, portability, opt-out, appeal
IowaConsumer Data Protection Act (ICDPA)Access, deletion, portability, opt-out of sale/targeted advertising
IndianaConsumer Data Protection Act (INCDPA)Access, correction, deletion, portability, opt-out, appeal
TennesseeInformation Protection Act (TIPA)Access, correction, deletion, portability, opt-out, appeal
DelawarePersonal Data Privacy Act (DPDPA)Access, correction, deletion, portability, opt-out, appeal

If you are a resident of any of the above states, you may exercise your rights by contacting privacy@angelgatesolutions.com. We will respond within the timeframe required by your state's applicable law. You may also have the right to appeal our decision; to do so, include "Privacy Rights Appeal" in the subject line of your email.

14.5 Canada (PIPEDA / Quebec Law 25)

Canadian residents have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5) and, for Quebec residents, Act respecting the protection of personal information in the private sector (Law 25 / Bill 64). These rights include: access to your personal information; correction of inaccurate information; withdrawal of consent; right to know if your information has been disclosed to third parties; and for Quebec residents: right to data portability and right to de-indexation. Contact privacy@angelgatesolutions.com to exercise these rights.

14.6 How to Submit a Privacy Rights Request

Two of the most common rights are available to you directly in the app: go to Account → Security & Privacy to export your data (machine-readable JSON) or to permanently delete your account.

For any other right (or if you can't access your account): email privacy@angelgatesolutions.com with subject line "Privacy Rights Request." Include your full name, the email address associated with your account, your state or country of residence, and a description of the right you wish to exercise. We may need to verify your identity to process your request. We will acknowledge your request within 5 business days. We will not charge a fee for reasonable requests; for manifestly unfounded or excessive requests, we may charge a reasonable fee or decline to act.

15. Automated Decision-Making & Profiling

GDPR Article 22 — Automated Individual Decision-Making, Including Profiling

The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

Angel Gate Solutions does not make solely automated decisions that produce legal effects or similarly significantly affect you. We may use automated tools to: (a) generate risk scores for fraud detection purposes; (b) recommend features or content within the Service based on your usage patterns; and (c) classify support tickets for routing purposes. However, none of these automated processes make final decisions affecting your legal rights or significantly similar effects without human review.

If you believe an automated process has been applied to you in a way that significantly affects your legal rights (e.g., account suspension following automated fraud detection), you have the right to: (a) request human review of that decision; (b) express your point of view; and (c) contest the decision. Contact privacy@angelgatesolutions.com to exercise these rights.

16. Health Data & HIPAA Disclaimer

ANGEL GATE SOLUTIONS IS NOT A "COVERED ENTITY" OR "BUSINESS ASSOCIATE" WITHIN THE MEANING OF THE HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996 ("HIPAA"), 45 C.F.R. PARTS 160 AND 164. THE SERVICE IS NOT DESIGNED TO COMPLY WITH HIPAA AND IS NOT HIPAA COMPLIANT. YOU MUST NOT USE THE SERVICE TO COLLECT, STORE, PROCESS, OR TRANSMIT "PROTECTED HEALTH INFORMATION" ("PHI") AS DEFINED UNDER HIPAA, 45 C.F.R. § 160.103, INCLUDING ANY INDIVIDUALLY IDENTIFIABLE HEALTH INFORMATION. USE OF THE SERVICE FOR PHI WITHOUT AN EXECUTED BUSINESS ASSOCIATE AGREEMENT (BAA) WITH ANGEL GATE SOLUTIONS IS STRICTLY PROHIBITED AND MAY SUBJECT YOU TO SIGNIFICANT LEGAL LIABILITY UNDER HIPAA AND HITECH ACT REQUIREMENTS.

If your intended use case requires HIPAA compliance, please contact legal@angelgatesolutions.com to discuss potential HIPAA Business Associate Agreement arrangements before proceeding.

17. Government Access & Law Enforcement

Electronic Communications Privacy Act (ECPA), 18 U.S.C. § 2510 et seq. | Stored Communications Act (SCA), 18 U.S.C. § 2701 et seq.

The Stored Communications Act governs when and under what circumstances government entities may require disclosure of electronic communications stored by service providers.

17.1 Legal Process Requirements

We do not disclose personal information to government or law enforcement agencies except pursuant to: (a) a valid court order; (b) a valid subpoena; (c) a valid legal demand issued under applicable law; or (d) other valid legal process. We carefully review all government requests for user data and require legally sufficient process before complying.

17.2 Notice to Users

Where permitted by law and operationally feasible, we will attempt to notify you before disclosing your information to a government authority by emailing the address associated with your account. We may be prohibited by law from notifying you in certain circumstances (e.g., under a non-disclosure order or National Security Letter).

17.3 Transparency

We reserve the right to publish transparency reports disclosing aggregate statistics regarding government requests for user data, to the extent permitted by applicable law.

17.4 USA PATRIOT Act

Under the USA PATRIOT Act and similar national security legislation, Angel Gate Solutions may be required to provide government agencies with access to stored electronic communications and associated records. If applicable, we will comply with legally valid national security requests while challenging overbroad requests to the extent legally permissible.

18. Children's Privacy (COPPA)

Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq. | 16 C.F.R. Part 312

COPPA imposes requirements on operators of commercial websites and online services directed to children under 13 years of age (or who have actual knowledge that they are collecting personal information from children under 13).

Orbix is intended for and directed exclusively to individuals 18 years of age or older. We do not knowingly collect, solicit, use, or maintain personal information from children under 13 years of age, nor from individuals under 18. Our Service is not directed to children.

If we discover that we have inadvertently collected personal information from a child under 13 (in violation of COPPA) or under 18 (in violation of our Terms of Service), we will: (a) immediately delete such information; (b) terminate the associated account; and (c) take reasonable steps to prevent re-registration.

If you are a parent or guardian and believe that your child has provided personal information to Orbix, please contact us immediately at privacy@angelgatesolutions.com with the subject "COPPA Request." We will promptly investigate and, if confirmed, delete the data. You may review, request deletion of, or refuse further collection of your child's personal information by contacting us.

19. International Data Transfers

19.1 Cross-Border Transfers

Angel Gate Solutions, LLC is headquartered and operates primarily in the United States. If you access Orbix from the European Economic Area ("EEA"), the United Kingdom ("UK"), Canada, or any other jurisdiction with data transfer restrictions, your personal information will be transferred to and processed in the United States, which may have different data protection laws and may not be deemed to provide an "adequate" level of protection by your jurisdiction's standards.

19.2 Transfer Safeguards for EEA/UK

For transfers of personal data from the EEA or UK to the United States, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs): We incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914) for EEA-to-U.S. transfers with our sub-processors;
  • UK International Data Transfer Agreements (IDTAs): For UK-to-U.S. transfers, we use the UK IDTA approved by the UK Secretary of State;
  • Supplementary Measures: Where required by post-Schrems II guidance, we implement supplementary technical and organizational measures (e.g., encryption, pseudonymization).

19.3 Sub-Processor Transfers

Our sub-processors (including Google LLC and Stripe, Inc.) maintain their own internationally recognized transfer mechanisms, including participation in applicable data transfer frameworks and implementation of SCCs. You may request a list of our sub-processors and their transfer mechanisms by contacting privacy@angelgatesolutions.com.

20. Your Website Visitors (You as Data Controller)

This section addresses your responsibilities regarding the personal data of visitors to websites you build and publish using Orbix.

When you use Orbix to build and operate a website, you collect personal data from your website visitors (e.g., contact form submissions, email signups, order information, live chat conversations, member account sign-ups, and membership or subscription status). In this context:

  • You are the Data Controller for your website visitors' personal data. Angel Gate Solutions acts as a data processor on your behalf.
  • Your responsibilities include: establishing a lawful basis for collecting visitor data; providing your visitors with a privacy policy that accurately describes your data practices; obtaining required consents; complying with applicable privacy laws (including CCPA, GDPR, CAN-SPAM, TCPA, and others) with respect to your visitors; and responding to your visitors' privacy rights requests.
  • Angel Gate Solutions is not responsible for your compliance with privacy laws governing your website visitors' data, and shall not be liable to you, your website visitors, or any third party for your failure to comply.
  • We strongly recommend that you consult with a qualified attorney regarding your privacy obligations before launching a website that collects personal data.

Our processing of visitor data on your behalf is governed by a data processing arrangement incorporated into our Terms of Service. To request a separate Data Processing Agreement (DPA) for GDPR compliance, contact legal@angelgatesolutions.com.

21. Third-Party Links & Services

The Service may contain links to third-party websites, applications, or services not operated by Angel Gate Solutions. This Privacy Policy does not apply to those third-party properties, and we have no control over and are not responsible for their content, privacy practices, or data handling. We encourage you to review the privacy policies of any third-party properties before interacting with them or sharing personal information.

Our inclusion of a link to or integration with a third-party service does not constitute an endorsement of that service's privacy practices or any other aspect of its operations.

22. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or the Service. When we make material changes, we will:

  • Provide at least 14 days' advance notice by email to the address associated with your account;
  • Post a prominent notice within the Orbix dashboard for a period of 30 days;
  • Update the "Effective Date" at the top of this Policy; and
  • For material changes that alter how we use previously collected data, obtain your consent where required by applicable law.

Non-material changes (formatting corrections, clarifications, addition of new rights that benefit users) may be made by updating the Policy and the Effective Date without separate advance notice. Your continued use of Orbix after the effective date of any updated Policy constitutes your acceptance of the changes. If you do not agree to the updated Policy, you must stop using the Service and close your account before the effective date.

23. Contact & Data Protection Officer

If you have any questions, concerns, complaints, or requests regarding this Privacy Policy or our data practices, please contact us:

Angel Gate Solutions, LLC — Privacy Team

Address: Available on request via legal@angelgatesolutions.com

Privacy email: privacy@angelgatesolutions.com

Security: security@orbixapp.com

Legal: legal@angelgatesolutions.com

23.1 EEA / UK Data Subjects

If you are located in the EEA or UK and are not satisfied with our response to your privacy request or complaint, you have the right to lodge a complaint with your local supervisory authority:

  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
  • European Union: Your national Data Protection Authority (directory at edpb.europa.eu)

23.2 Response Timeframes

We will acknowledge privacy requests within 5 business days and provide a substantive response within: 30 days for general requests; 45 days for CCPA/CPRA verifiable consumer requests (extendable by 45 days with notice); 30 days for GDPR requests (extendable by 2 months for complex requests, with notice); and within the period required by other applicable state privacy laws.

© 2026 Angel Gate Solutions, LLC. All rights reserved.

Read our Terms of Service →