Privacy policy
Effective 25 November 2024
1. Who we are
Orbator Ventures Private Limited (referred to as "Orbator", "we", "us", "our") is a company incorporated in India with its registered office at 11/56D, Valparamba, Panakkad, Malappuram, Kerala 676519, India. CIN: U58200KL2024PTC090723. GSTIN: 32AAECO5528N1Z7.
2. Scope
This policy describes how we collect, use and protect personal data when you visit https://orbator.in, when you contact us through our website, when you engage us for a paid software engineering or research engagement, and when you pay for one of our productised services or retainers using a card, UPI handle, net banking, SWIFT wire or other instrument.
3. Personal data we collect
3.1 Submitted by you
- Identifying information you provide on our contact and pricing enquiry forms: name, work email, company, role, project description.
- Any documents or briefs you choose to attach during an engagement discussion (project specifications, screenshots, sample data).
- Billing identity required for invoicing: company legal name, registered address, GSTIN or equivalent tax identifier, and the billing contact's email.
3.2 Payment data
We do not store full card numbers, card expiry dates, CVV, UPI PINs or net-banking credentials on our systems at any point. Payments are processed by our PCI-DSS compliant payment partners — Razorpay Software Private Limited for INR and Stripe Payments Europe Limited for international cards — who handle card data on our behalf within the scope of their own privacy policies.
Where you opt to save a card for future or recurring payments ("card-on-file" or non-3DS subsequent transactions for subscription billing), only a tokenised reference issued by the payment partner is retained against your client record. We use that token only to initiate transactions you have authorised; we cannot read or transmit the underlying card details.
We do retain transaction metadata (amount, currency, status, last-4 digits where supplied by the partner, partner reference ID) for audit, tax, and accounting purposes as required by Indian law.
3.3 Automatically collected
- IP address, user agent, device, locale and timestamps of requests reaching our infrastructure.
- Application logs related to the operation of services we deliver to you (engagements only — never on the public marketing site).
We use this only for security, abuse prevention and basic operational monitoring. We do not deploy advertising or cross-site tracking cookies on https://orbator.in.
4. How we use personal data
- To respond to your inquiry and discuss potential engagements.
- To deliver services we have contracted with you, including authentication into systems we build for you.
- To bill you and issue tax-compliant invoices (Indian GST or equivalent), including auto-billing for retainer subscriptions.
- To send operational communications about a project we are delivering for you.
- To meet our legal, accounting and audit obligations under Indian law (including the Companies Act 2013, the Income-tax Act 1961, and the GST Act 2017).
- To detect, investigate and respond to fraud, abuse, chargebacks and security incidents.
We do not sell personal data. We do not use it for advertising or profiling, and we do not share it with data brokers.
5. Lawful basis (Digital Personal Data Protection Act, 2023)
We process personal data on the basis of:
- Your consent for inquiry-form submissions and any optional newsletter sign-ups;
- The performance of a contract for active engagements (delivery, billing, payment processing);
- Our legitimate interest in operating a lawful business (security, audit, accounting, fraud prevention).
6. Third-party processors
The following processors handle limited personal data strictly to deliver functionality of our website and services:
- Vercel Inc. — site hosting and edge delivery (request logs).
- Resend Inc. — transactional email delivery (your email address, message content).
- Razorpay Software Private Limited — INR payments, card-on-file tokenisation, subscription billing.
- Stripe Payments Europe Limited — international card payments.
- Amazon Web Services, Inc., Microsoft Azure, Cloudflare — cloud and edge infrastructure used in engagements as contracted for your project.
Each of the above operates under its own privacy notice, is bound to confidentiality, and is selected for its security and compliance posture (SOC 2 / ISO 27001 / PCI-DSS as applicable). We require any sub-processor to handle your data only for the purpose we have contracted with them.
7. Cross-border transfers
Some of our processors are located outside India (United States, European Union, etc.). Where personal data is transferred outside India for the purpose of delivering our services, we rely on the provisions of the Digital Personal Data Protection Act, 2023 and on standard contractual safeguards with the processor.
8. Retention
- Inquiry-form submissions: retained for 24 months unless you ask earlier deletion.
- Active engagement records: retained for the duration of the engagement plus seven (7) years for tax and audit compliance.
- Invoice and payment metadata: retained for eight (8) years as required by the GST Act 2017 and the Companies Act 2013.
- Saved-card tokens (when you opt to save one): retained until you remove the token or your subscription ends.
- Server access logs: retained for 90 days unless required longer by an active security investigation.
9. Security
Personal data is stored on infrastructure operated by reputable cloud providers in regions selected for the engagement at hand. We apply encryption in transit (TLS 1.2+), at rest (provider-managed AES-256), role-based access controls, multi-factor authentication on administrative accounts, and audit logging on systems that hold customer data.
10. Your rights
- Access — request a copy of personal data we hold about you.
- Correction — ask us to correct anything that is inaccurate or incomplete.
- Erasure — ask us to delete personal data we no longer need.
- Withdraw consent — at any time, with no impact on processing carried out before withdrawal.
- Grievance — escalate to our Grievance Officer (below) and, if unresolved, to the Data Protection Board of India.
Email hello@orbator.in to exercise any of these rights. We respond within thirty (30) days as required by the Act.
11. Cookies and similar technologies
See our cookie policy. The marketing site does not set advertising or analytics cookies by default.
12. Children
Our services are intended for businesses and adults. We do not knowingly collect personal data from children under the age of eighteen. If you believe we have done so inadvertently, contact us and we will delete it.
13. Grievance Officer
In accordance with the Information Technology Act, 2000 (and applicable rules), and the Digital Personal Data Protection Act, 2023:
Email: hello@orbator.in
Phone: +91 90742 20130
Address: Orbator Ventures Private Limited, 11/56D, Valparamba, Panakkad, Malappuram, Kerala 676519, India
Office hours: Mon–Fri, 09:30–18:30 IST.
14. Changes to this policy
We will update this page if our practices change. Substantive changes affecting how we handle your personal data are flagged at the top of this page for at least thirty (30) days before they take effect.
This document is a placeholder drafted alongside the website launch and may be revised. The authoritative version is the one currently published on this URL.
