Orbit — Reward system for autism families
  • How it Works
  • Features
  • Pricing
Log in Start free
How it Works Features Pricing
Log in Start free
Legal

Privacy Policy

Effective date: May 2, 2026  ·  Last updated: May 2, 2026  ·  Version 2026-05-02

1. Introduction

Orbit Family ("Orbit," "we," "us," or "our") operates orbitfamily.app — a reward and routine management system for families of children with autism spectrum disorder (ASD/TEA). This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data and your children's data.

We built Orbit for families who need a trustworthy, privacy-respecting tool. That means: we collect only what we need, we never sell your data, and we give you full control over your household's information.

2. Information We Collect

Caregiver account information

When you sign in using Google OAuth, we receive your name, email address, and Google profile picture URL. We use this to identify your account and send you service-related messages.

Child profile information

You create child profiles under your caregiver account. A child profile contains:

  • A first name or nickname (a label you provide — not a legal name requirement)
  • A numeric PIN, stored as a one-way cryptographic hash (never in readable form)
  • An avatar emoji you select
  • Timezone preference

We do not collect a child's full legal name, date of birth, email address, phone number, photo, location, school, or any other personally identifying information.

Activity data

We store tasks, task completions, rewards, and point balance entries associated with your household. This is the core function of the service.

Billing information

Payment processing for Orbit Pro is handled entirely by Stripe. We never see or store your credit card number. We store only your Stripe customer ID and your current subscription plan status.

Usage and technical information

Our servers log standard technical data: IP addresses, browser type, referring URLs, and pages visited. We use this to maintain service reliability and diagnose errors. We do not use third-party advertising trackers or behavioral analytics tools.

3. How We Use Your Information

  • To provide the service: Authenticate your account, display your household's tasks and rewards, calculate point balances.
  • To communicate with you: Send transactional emails (account activity, subscription updates). We do not send marketing emails without your consent.
  • To improve Orbit: Analyze aggregate, anonymized usage patterns to understand how the product is being used and where it can be better.
  • To maintain security: Detect and respond to fraud, abuse, or unauthorized access.

4. Children's Privacy & COPPA

Children's Online Privacy Protection Act (COPPA)

Orbit is designed as a caregiver-facing tool. Caregiver accounts are held by adults. Children interact only with a supervised child dashboard that operates under a parent's account — they do not create accounts, sign in to Orbit, provide an email address, or communicate through Orbit.

We do not knowingly collect personal information directly from children under 13. The limited data we store about a child profile (a nickname or first name, a hashed PIN, an avatar emoji, and timezone) is provided by and controlled entirely by the adult caregiver.

Parental representation and consent. By creating a child profile, you represent and warrant that you are the parent or legal guardian of that child, that you have the authority to provide consent on the child's behalf, and that you provide verifiable parental consent under COPPA (15 U.S.C. § 6501 et seq.) for Orbit's collection and processing of the limited child profile data described above. Orbit relies on this representation and does not independently verify guardianship, custody, or parental rights.

Parental rights under COPPA. As the caregiver account holder, you may at any time:

  • Review all data associated with your child's profile
  • Edit or correct your child's profile information
  • Delete a child profile from your household settings
  • Refuse further collection or use of your child's information by deleting the child profile or your account
  • Request complete deletion of all household data by emailing hello@orbitfamily.app

If you believe a child profile has been created in Orbit without the consent of the child's parent or legal guardian, please contact hello@orbitfamily.app immediately and we will investigate and, where appropriate, delete the profile.

5. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. We share data only with the following service providers who help us operate Orbit:

  • Google (OAuth): Used for caregiver authentication. Governed by Google's Privacy Policy.
  • Stripe: Payment processing for Orbit Pro. Governed by Stripe's Privacy Policy.
  • Google Cloud Platform (GCP): Our servers and database run on GCP infrastructure in the United States. Governed by Google Cloud's Data Processing Addendum.

We may disclose information if required by law, court order, or to protect the rights and safety of our users.

6. Data Retention

Active accounts: Your data is retained for as long as your account is active.

Account deletion: When you request deletion of your account, we permanently delete all associated caregiver data, child profiles, tasks, rewards, and point entries within 30 days. Stripe may retain billing records independently per their own retention policy.

Server logs: Standard server logs are retained for up to 90 days for security and debugging purposes, then purged.

Our right to delete. We may delete your data, in whole or in part, at any time after account termination, after prolonged inactivity (24 months or more without a successful login), or where we believe deletion is appropriate for operational, legal, safety, or risk-management reasons. Deletion is generally irreversible. You are responsible for exporting or backing up any data you wish to retain before deletion. We are not liable for any loss arising from deletion under this section.

7. Security

We take reasonable, commercially appropriate measures to protect your information:

  • All data is transmitted over TLS/HTTPS encryption.
  • Database data is encrypted at rest on Google Cloud Platform.
  • Child PINs are stored as one-way cryptographic hashes — we cannot read them, and neither can anyone else.
  • Caregiver passwords are not stored by Orbit; sign-in is delegated to Google OAuth.
  • Access to production data is restricted to authorized personnel on a need-to-know basis.

No system is 100% secure. While we work in good faith to protect your data, you acknowledge and accept that you provide your data to Orbit at your own risk and that we cannot and do not guarantee against unauthorized access, disclosure, alteration, or loss. To the maximum extent permitted by applicable law, we disclaim liability for any unauthorized access to or use of your data that occurs despite our reasonable security measures.

In the event of a data breach affecting your information, we will notify affected users and applicable regulators where and to the extent required by applicable law (such as state breach-notification statutes, GDPR, or Ley 172-13). If you believe your account has been compromised, contact us immediately at hello@orbitfamily.app.

8. Your Privacy Rights

United States — California (CCPA)

California residents have the right to know what personal information we collect, request deletion of their data, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact hello@orbitfamily.app.

Dominican Republic — Ley No. 172-13

Residents of the Dominican Republic have rights under Ley No. 172-13 de Protección de Datos de Carácter Personal, including the right to access, rectify, cancel, and object to the processing of their personal data (derechos ARCO). To exercise these rights, please contact us at hello@orbitfamily.app. We will respond within 30 days.

Mexico — LFPDPPP

Mexican residents have rights under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), including ARCO rights (Acceso, Rectificación, Cancelación y Oposición) and the right to revoke consent. To exercise these rights, contact hello@orbitfamily.app.

All other users

Regardless of where you live, you may contact us at any time to access, correct, or delete your data. We will honor all reasonable requests within 30 days.

9. Cookies & Tracking

Orbit uses only essential session cookies required to keep you logged in and maintain your preferences (such as language selection). We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies that profile your behavior.

10. International Data Transfers

Our servers are located in the United States (Google Cloud Platform). If you access Orbit from outside the United States — including from the Dominican Republic, Mexico, or other countries — your data is transferred to and processed in the United States. By using Orbit, you consent to this transfer.

We rely on the terms of our service provider agreements (including Google Cloud's data processing addendum) to ensure appropriate safeguards are in place for international transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email at least 30 days before the new policy takes effect. Continued use of Orbit after the effective date constitutes your acceptance of the updated policy.

The current version of this policy is always available at orbitfamily.app/privacy/.

12. Your Acknowledgment

By creating an Orbit account, completing onboarding, or otherwise using Orbit, you acknowledge that you have read, understood, and agree to this Privacy Policy and to the Terms of Service, and that together they form a binding legal agreement between you and Orbit Family. If you do not agree, do not create an account or use Orbit.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

  • Email: hello@orbitfamily.app
  • Website: orbitfamily.app

We aim to respond to all privacy-related inquiries within 5 business days.

Orbit Logo
Rewards for Little Stars

A reward and routine system built specifically for autism families.

Product

How it works Features Pricing Sign up free

For Families

Free plan Orbit Pro Privacy & safety

Support

Contact us Give feedback Terms of service Privacy policy
© 2025 Orbit Family · All rights reserved Made with ❤️ for autism families