Privacy policy
Last updated 1 October 2026
What personal data OrbAPI collects, why, how long we keep it and the rights you have under the General Data Protection Regulation (GDPR).
Who is responsible
The data controller is To be completed before launch, To be completed before launch. For any privacy question or to exercise your rights, write to privacy@orbapi.dev.
Data we collect
| Data | When | Purpose | Legal basis | Kept for |
|---|---|---|---|---|
| Cookie choice | When you answer the cookie banner | Remember your consent decision | Legal obligation | 6 months |
| Server logs (IP address, user agent, URL, time) | Every request | Security, abuse prevention, debugging | Legitimate interest | 30 days |
| Audience measurement | Only if you accept it | Understand which pages are used | Consent | 13 months |
| Email address and message | When you write to us | Answer you, manage access requests | Pre-contractual steps, legitimate interest | 3 years after last contact |
| Sign-in data (email address or wallet address, session identifiers) | When you sign in | Authenticate you and keep you signed in | Contract | Life of the account |
| Account data (email, API key identifiers, usage and billing records) | When you use the gateway | Provide the service, bill, prevent fraud | Contract, legal obligation | Life of the account, then 10 years for accounting records |
| Provider API keys connected by sellers | When a seller lists capacity | Execute buyer requests within the seller's cap | Contract | Until the listing is revoked, then deleted |
We do not sell personal data, we do not use it for advertising and we make no decision about you by automated means alone that has a legal effect.
Request content
Requests sent through the gateway (search queries, URLs to scrape, RPC calls) are forwarded to the provider that serves them. We keep request metadata (time, market, provider, units, price) for billing. We do not keep request or response bodies beyond the time needed to deliver them, unless you turn on request logging for your own key.
Blockchain data
Wallet addresses and transactions on Robinhood Chain are public and permanent. We cannot edit or erase them. If you connect a wallet to an account, we treat the link between the two as personal data.
Who receives data
- Our hosting provider: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, United States.
- Privy (United States), our sign-in and wallet provider, which processes your email address, wallet address and session when you sign in.
- The API provider that serves a given gateway request, for that request only.
- Payment and accounting processors, for billing.
- Authorities, when the law requires it.
Some recipients are outside the European Economic Area. Those transfers rely on an adequacy decision or on the European Commission's standard contractual clauses. Ask us for a copy.
Your rights
You can ask to access, correct, erase or export your data, to restrict or object to its processing, and to withdraw consent at any time without affecting what was done before. Write to privacy@orbapi.dev. We answer within one month.
If you think we have mishandled your data, you can complain to the data protection authority of the country where you live or work.
Cookies
See the cookie policy. You can change your choice at any time from the footer.
Changes
We will post any change here and update the date at the top. Material changes are announced by email to account holders.