Your data, handled with care

Privacy Policy.

OrbitOps Pro ("OrbitOps Pro," "we," "us"), operated by OrbitOps Pro, LLC, provides field-service-management software to service businesses ("Operators"). This policy explains what personal information we handle, how, and why. It covers both our marketing site (orbitopspro.com) and our application (app.orbitopspro.com).

Two kinds of data, two roles

OrbitOps Pro handles personal information in two distinct roles, and it's important to understand the difference:

  • Data about Operators (we are the controller). When you sign up for and use OrbitOps Pro as a service business, we collect and control certain information about you and your business directly.
  • Data about an Operator's customers (we are the processor). When an Operator uses OrbitOps Pro to manage their own customers, that customer information belongs to the Operator. We process it on the Operator's behalf and under their instructions — we do not own it, sell it, or use it for our own purposes. If you are a customer of a business that uses OrbitOps Pro and you have questions about your data, contact that business directly; they are the controller of that information.

Information we collect

From Operators (account and business data): business name, business email and phone, business address, your name, username, role, and login credentials, your business logo, tax settings, your payment-processor connection details (see Payments below), and — if you choose to connect QuickBooks Online — your QuickBooks connection details and accounting preferences (see QuickBooks Online Integration below).

From Operators, about their customers (processed on the Operator's behalf): customer or household names, service addresses, contact name/phone/email, service locations and their geolocation coordinates, on-site equipment records, service history and job notes, and invoice and payment records. OrbitOps Pro does not decide what customer data an Operator enters; the Operator does.

From our marketing site: if you submit an interest or contact form, we collect the email address, name, and any details you provide.

Automatically: our hosting provider logs standard technical request data (such as IP address and timestamps) for security and reliability. Our product analytics (see below) record how Operators use the application.

We do not collect Social Security numbers, health data, or biometric data, and we do not store payment card numbers (see Payments).

Payments

Payment card processing is handled entirely by Stripe. When a payment is made, card details are entered on Stripe's own hosted checkout — OrbitOps Pro never receives, sees, or stores card numbers or security codes. Our systems store only non-sensitive references such as payment amounts, status, method, and Stripe transaction identifiers. Operators connect their own Stripe accounts to receive funds directly; Stripe handles Operator identity and payout verification through its own onboarding. Stripe's handling of this data is governed by Stripe's privacy policy.

QuickBooks Online Integration

An Operator may connect their own QuickBooks Online company to OrbitOps Pro so that summary accounting entries can be posted into their books. The integration is optional, is initiated by the Operator, and works as described below.

What we access. The connection uses Intuit's OAuth 2.0 authorization with a single scope — com.intuit.quickbooks.accounting, the Accounting API. We do not request or use the QuickBooks Payments API or the QuickBooks Payroll API. Within that scope:

  • We read the chart of accounts only — account id, name, type, and classification — so the Operator can map which accounts OrbitOps Pro posts to.
  • We write summary journal entries. Journal entries are the only records OrbitOps Pro creates in QuickBooks.
  • We do not read or import QuickBooks customers, invoices, transactions, or any other financial records. Apart from reading the chart of accounts, data flows in one direction only: from OrbitOps Pro into QuickBooks.

What we store. For a connected company we store only:

  • The OAuth access token, refresh token, and QuickBooks company (realm) id — each encrypted at rest with AES-256-GCM, with the encryption key held as a platform secret separate from the database.
  • The Operator's account mapping — which of their accounts revenue, sales tax, receivables, and cash post to.
  • A record of the journal entries we posted: the period, the QuickBooks entry id, and the amounts.

We store no customer financial data retrieved from QuickBooks.

How it is used. This information is used solely to post monthly summary journal entries that the Operator triggers manually — nothing is automated or scheduled. Tokens are used only server-side and are never sent to the browser. Each connected company's data is isolated from every other company's.

What we never do with QuickBooks data. We do not sell it, share it, or make it available to any third party. We do not use it for marketing or advertising, and we do not send it to our product analytics provider. It is not used for any purpose other than the accounting-posting function described above. The stored connection record lives in our own hosted database, encrypted at rest, and is not disclosed to anyone else.

Disconnecting. An Operator can disconnect QuickBooks at any time from Settings in the application. Disconnecting deletes the stored connection outright — access token, refresh token, realm id, and account mapping are all removed. Journal entries already posted remain in the Operator's QuickBooks company, because that data belongs to the Operator.

Questions about this integration can be sent to chris@orbitopspro.com.

Service providers we share data with

We use a small set of trusted providers to operate OrbitOps Pro. Each processes data only as needed to provide their service:

  • Supabase — our database and authentication provider; stores account and application data.
  • Stripe — payment processing (see Payments).
  • Resend — delivery of transactional emails (invoices, estimates, statements, and similar), which may include attached documents containing customer names, addresses, and line items.
  • PostHog — product analytics, configured to identify only Operators and their organizations. It is deliberately configured so that an Operator's customer personal information is not sent to it.
  • Cloudflare — hosting and request logging.
  • Google Maps Platform — where enabled, customer service addresses are sent to Google's geocoding and routing services to validate addresses and optimize technician routes.

None of these providers receive data from an Operator's connected QuickBooks Online company, and none of them are given access to it.

We do not sell personal information, we do not share it with third parties for their own marketing, and we do not share it with anyone beyond the providers listed above, except where required by law.

Analytics and tracking

Our marketing site uses no analytics, advertising, or tracking cookies. Our application uses PostHog for product analytics, configured privacy-first: no automatic capture of page content, no session recording, and an enforced filter that prevents Operator customer personal information from being sent to analytics. We measure how Operators use features, not who their customers are. No QuickBooks Online data is sent to analytics. We do not use any of the data described in this policy for advertising, and we do not run advertising on our site or in our application.

How we protect data

Access to the application requires authentication. Each Operator organization's data is logically separated, and our application enforces that separation on every request so that one Operator cannot access another Operator's data. Sessions use secure, HTTP-only cookies. We work to protect information but no method of transmission or storage is completely secure.

Data retention and your choices

We retain Operator account data for as long as an account is active. Operators can remove or archive customer records within the application. QuickBooks Online connection data is retained only while the connection is active and is deleted when an Operator disconnects, as described under QuickBooks Online Integration above. To request deletion of your Operator account data, or if you are an Operator with questions about customer-data handling, contact us at chris@orbitopspro.com — we handle deletion requests as an operational process. If you are an Operator's customer, direct data requests to the business that serves you, as they control that data.

Children

OrbitOps Pro is a business tool not directed to children and is not intended for anyone under 18.

Scope

OrbitOps Pro currently serves businesses in the United States. This policy is written accordingly; if we expand internationally, we will update it to address additional obligations.

Changes and contact

We may update this policy; material changes will be reflected in the "last updated" date. Questions about this policy, or about privacy and data handling generally: chris@orbitopspro.com.