Privacy Policy
1. What we collect
- Account data. Your name, email address, hashed password, account tier, and your chosen timezone.
- Workflow definitions. The step configurations you build: step types, their parameters, any credentials you enter (encrypted at rest), schedules, and triggers.
- Data you upload. Files you put into Data Storage and the rows they contain. These are yours; we store them so your workflows can read them.
- Execution history. Records of workflow runs: which steps executed, how long they took, step output snapshots, error messages, and the small HTML reports we render for each run.
- Usage telemetry. Counts of API calls per minute/hour/day, used to enforce rate limits and show you your own usage chart. No third-party analytics and no tracking cookies.
- Billing metadata. If you subscribe, Stripe customer and subscription identifiers, plus the subscription's current status and period. Your card number never touches Orkidata servers. Stripe handles payment data directly.
- Transactional logs. Standard infrastructure logs (IP address, request path, timestamp, response status) retained for security and debugging.
2. What we don't collect
- No third-party analytics (no Google Analytics, no Mixpanel, no Facebook pixel).
- No marketing cookies. Only a session cookie used to keep you logged in.
- No content of your data files beyond what is necessary to execute the workflow you configured.
3. How we use it
- Operating and securing the service (authenticating you, running your workflows, billing).
- Communicating with you about your account (confirmation emails, password resets, subscription notices, security alerts).
- Enforcing rate limits and detecting abuse.
- Complying with legal obligations when required by valid process.
We do not use your data to train machine-learning models and we do not sell it to any party.
4. Where it lives
All customer data is stored in Amazon Web Services us-east-1 (N. Virginia, USA), in MongoDB Atlas (account metadata, workflow definitions, execution history) and Amazon S3 (Data Storage files). Payment data is held by Stripe in the United States. Email sending is performed by Resend in the United States. DNS and CDN edge are operated by Cloudflare globally.
5. Sub-processors
Orkidata relies on the following sub-processors to operate the service. Each is listed with the category of data it receives. This list is authoritative as of the effective date above; material additions will be announced at least 30 days in advance by email.
| Sub-processor | Purpose | Data received | Region |
|---|---|---|---|
| Amazon Web Services | Cloud compute, object storage, content delivery, API gateway, and secrets management | All customer data, workflow definitions, execution history, transactional logs | us-east-1 (USA) |
| MongoDB Atlas | Primary database for account metadata, workflow definitions, execution history, rate-limit counters | Account data, workflow definitions, execution history, billing metadata | AWS us-east-1 (USA) |
| Stripe | Payment processing, subscription state, Customer Portal | Name, email, billing address, card details (held by Stripe, not by us), subscription status | USA |
| Resend | Transactional email (confirmation, password reset, billing notices), recipient-verification emails, workflow send_email steps (Orkidata mode), reminders consent invitations, and Gmail re-authentication notices | Email address, name, email content | USA |
| Cloudflare | Authoritative DNS and edge DNS/CDN for orkidata.com | Request metadata (IP, URL, headers) transiting the edge | Global anycast |
| Sentry | Error tracking, performance monitoring, and system stability | IP addresses, user IDs, and application error payloads (personally identifying fields are included for debugging; request bodies and credential headers are stripped before sending) | USA |
6. Google user data (Sign-In, Drive, Gmail)
If you connect a Google account, Orkidata accesses Google user data only through the narrow OAuth scopes you grant, and only to do what you configured:
- Google Sign-In. We receive your Google account email and a stable account identifier to authenticate you. Nothing else is read from your Google account at sign-in.
- Google Drive (
drive.file). We can read and write only the specific files and folders you explicitly pick through the Google picker — never your whole Drive. File contents are read to execute the workflow steps you configured and are not retained beyond what those steps produce. - Gmail sending (
gmail.send). We send email from your Gmail address only when a workflow step you configured runs (the Reminders step and the Send Email step's "via Gmail" mode). We do not read, index, or store your mailbox; this scope cannot access received mail. - OAuth tokens. Refresh tokens are encrypted at rest and used solely to perform the actions above on your behalf. Disconnecting Google in your profile invalidates them; you can also revoke access at any time from your Google Account permissions page.
Orkidata's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used strictly to execute the workflows you explicitly configured. It is never sold or rented, never shared for advertising purposes, and never used to train machine-learning or artificial-intelligence models.
7. Your recipients' data (controller and processor roles)
Some features process personal data about people who are not Orkidata users — the recipients you email. This includes email addresses and names entered in workflow steps, information recipients submit through the Reminders public intake form or QR code (such as names and appointment dates), the consent ledger (opt-ins, opt-outs, and unsubscribes), and the attestation audit logs referenced in the Terms of Service.
- For this recipient data, you (the Orkidata user) act as the Data Controller: you decide who is contacted, why, and on what consent basis.
- Orkidata acts strictly as a Data Processor, handling recipient data only under your direction to execute the workflows you configured, and never for our own purposes.
- One exception is processed on our own behalf: opt-out and suppression records are retained and enforced platform-wide so that a recipient's unsubscribe is always honored, even across workflow changes or deletions.
- Recipients who want their data corrected or deleted should contact the sender (the Orkidata user who emailed them); we support those requests through the controller. Recipients can opt out directly at any time via the unsubscribe link in every email.
8. International transfers
Primary processing happens in the United States. If you access Orkidata from outside the US, your data will be transferred to and processed in the US under the sub-processors listed above. Where required, transfers are covered by the sub-processor's own Standard Contractual Clauses or equivalent legal mechanisms.
9. Retention
- Account and workflow data: retained for as long as your account is active.
- Execution history: retained for the life of the account unless you delete specific runs or clear history.
- Infrastructure logs: retained for up to 90 days for security and debugging.
- Billing records: retained for the period required by applicable tax and accounting law (typically 7 years).
10. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. To exercise any of these, or to ask a question about this policy, email privacy@orkidata.com. We will respond within 30 days.
You can request deletion of your account at any time by emailing the address above. Deletion removes your account metadata, workflow definitions, execution history, and uploaded files. Backups older than 30 days may retain a copy until they are overwritten on the normal rotation schedule.
11. Cookies
Orkidata uses one cookie: a secure, HTTP-only session cookie that keeps you logged in. The browser also stores a small sessionStorage hint so in-tab navigation feels instant, this is cleared when you log out and is never shared with any third party.
12. Security
Passwords are stored using strong, industry-standard one-way hashing. Credentials you enter for database or API connectors are encrypted at rest with industry-standard authenticated encryption, and all traffic is encrypted in transit using TLS 1.2 or higher. Infrastructure secrets are held in a managed secrets store with least-privilege access, applied across all services. Security is a moving target; no system is perfectly safe, and you should follow good operational hygiene in what you upload.
13. Children
Orkidata is not intended for and is not directed at children under 18. If you believe a child has created an account, please email privacy@orkidata.com and we will delete it.
14. Changes to this policy
Material changes will be announced by email to the address on file and reflected here with an updated version number. Continued use of the service after the effective date of an update constitutes acceptance.
15. Contact
Privacy questions: privacy@orkidata.com.
General: hello@orkidata.com.