orbitreach · EU
Privacy
orbitreach is operated from the EU. This notice explains how we handle information across our website, workspaces, lead tools, campaigns and connected mailboxes.
Who we are
orbitreach provides a collaborative workspace for lead research, campaign preparation, email sending and response tracking. Questions or privacy requests can be sent to support@orbitreach.io.
Information we collect
Account and workspace information includes your name, email address, profile details supplied by your sign-in provider, authentication sessions, workspace memberships and invitations. Website and waitlist information may include your email address, the page used to sign up and the signup time.
Product information includes lead contact and professional details that you import or create, public website research, lead tables, templates, campaign settings, schedules, activity, delivery outcomes, reply and bounce states, and sourcing automation logs.
When you connect a mailbox, we store its address, provider, connection settings, access choice and synchronization status. IMAP and application-specific passwords, together with Google, Microsoft and Zoho OAuth access and refresh tokens where applicable, are encrypted before storage. We do not sell personal information.
Google and Gmail data
The standard Google Mail connection uses a Google-generated App Password with Gmail’s IMAP and SMTP services. You must not provide your normal Google Account password. Existing mailboxes previously connected through Google OAuth may continue to use gmail.readonly and gmail.send until they are disconnected.
For normal synchronization we process message identifiers, sender and recipient addresses, subject headers, dates and labels. We request raw message content only when a message appears to be a delivery report and it must be parsed to determine the affected recipient and delivery outcome. Outgoing message content is passed to Gmail for delivery but is not retained as an email body by orbitreach.
Google user data is not sold, used for advertising, used to build advertising profiles, or used to train general-purpose AI models. We do not permit people to read Google user data except when you give specific consent, when access is necessary for security or support, or when required by law.
orbitreach’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Microsoft and Zoho mailbox data
Microsoft connections use delegated Microsoft Graph permissions to identify the connected account, send messages and inspect recent mailbox messages for replies. Zoho connections use the narrow Zoho Mail account, message-create and message-read scopes. Access and refresh tokens are encrypted before storage and are never shown to workspace members.
For both providers, orbitreach processes recent message identifiers, sender and recipient addresses, subjects and dates to match campaign activity and replies. Outgoing content is sent to the selected provider for delivery and is not retained by orbitreach as an email body.
How we use information
We process information to provide and secure the service, authenticate users, operate shared workspaces, research and organize leads, send requested campaigns, synchronize delivery and response states, troubleshoot errors, prevent abuse, communicate service information and meet legal obligations. Depending on the context, our legal bases include performing our agreement with you, your consent, our legitimate interests in operating and protecting the service, and compliance with law.
Workspace and mailbox access
Workspace members can access the workspace’s shared leads, templates, campaigns and operational records according to their role. A mailbox marked Personal can be selected for sending only by the member who connected it. A mailbox marked Workspace can be selected by other workspace members. Other members do not receive the mailbox password or OAuth tokens. Making a mailbox Personal pauses an active campaign that was using it until its owner reviews and restarts the campaign.
Service providers and transfers
We share information only as needed with providers that operate the product, such as hosting and database infrastructure, authentication and transactional-email providers, Google or another connected email provider, and research or automation infrastructure. We may also disclose information when required by law, to protect users and the service, or as part of a business transaction subject to appropriate safeguards.
Some providers may process information outside your country or the European Economic Area. Where required, we use appropriate contractual and technical safeguards for those transfers.
Retention, removal and security
We retain account and workspace information while it is needed to provide the service and for a reasonable period afterward where required for security, dispute resolution or legal compliance. Retention may differ for backups and operational records.
Removing a mailbox deletes its stored credentials or OAuth tokens and its mailbox synchronization records. Related campaign and delivery records may be retained without the mailbox connection so the workspace keeps an accurate activity history. For Gmail, orbitreach also attempts to revoke the stored Google token. You can separately revoke access at any time from your Google Account permissions.
We use access controls, encryption in transit, encrypted mailbox credentials and tokens, restricted production access, backups and monitoring. No system can be guaranteed completely secure, so please contact us promptly if you believe your account or data has been compromised.
Your choices and rights
You can disconnect mailboxes and change Personal or Workspace access under Email settings. You may ask to access, correct, export or delete your personal information, object to or restrict certain processing, or withdraw consent by emailing support@orbitreach.io. You may also have the right to complain to your local data-protection authority.
Cookies and authentication
We use essential cookies and similar storage for sign-in, OAuth security, workspace selection and session protection. These are required for the service to operate. We do not use connected-mailbox data for cross-site advertising.
Children and updates
orbitreach is intended for business users and is not directed to children. We may update this notice as the product or legal requirements change. Material changes will be communicated when appropriate, and the effective date below identifies the current version.
Effective 31 July 2026 · EU