Legal

Privacy Policy

Existing policy terms last updated May 30, 2026. Orbit addendum updated September 2, 2026.

Overview

This Privacy Policy explains how Geo Commerce Private Limited ("Geo Commerce", "we", "us", or "our") collects, uses, and shares personal data when you use our services, including our web applications and client platforms. We act as the data controller for the personal data described below.

1. Data We Collect

  • Account data — name, email address, login credentials, organization and role.
  • Workspace content — tasks, quotes, invoices, comments, files, and other content you upload.
  • Support data — messages and attachments you send us.
  • Usage & device data — log data, IP address, browser type, device identifiers, and telemetry about how the Service is used.

Payment data (card details, billing address) is collected and processed directly by our payment processor and is not stored by us.

2. How We Use Personal Data

  • To create and operate your account and provide the Service (contract performance);
  • To prevent fraud, abuse, and maintain security (legitimate interests);
  • To improve and develop the Service (legitimate interests);
  • To provide customer support (contract performance / legitimate interests);
  • To send service-related communications, and, with your consent, marketing communications;
  • To comply with legal obligations.

3. Sharing

We share personal data with the following categories of recipients:

  • Service providers / subprocessors — hosting, database, analytics, email delivery, and support tooling providers acting on our instructions.
  • Payment processor — for payment authorization, fraud prevention, tax compliance, and invoicing.
  • Professional advisers — legal, accounting, and audit professionals.
  • Authorities — where required by law, court order, or to protect our rights or the safety of others.

4. International Transfers

Personal data may be processed in countries outside your country of residence, including India and the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

5. Retention

We retain personal data for as long as your account is active and as needed to provide the Service. After account closure, we delete or anonymize data within a reasonable period, except where we are required to retain it for legal, tax, or accounting purposes.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate data;
  • Request erasure or restriction of processing;
  • Object to processing or withdraw consent where processing is based on consent;
  • Receive your data in a portable format;
  • Lodge a complaint with your local data protection authority.

To exercise these rights, contact us at privacy@geocommerce.co. We will respond within one month.

7. Security

We use appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, and audit logging. No system is fully secure, and we cannot guarantee absolute security.

8. Cookies

We use strictly necessary cookies to keep you signed in and to operate the Service. We may also use limited analytics cookies to understand product usage. You can manage cookies through your browser settings.

9. Changes

We may update this Policy from time to time. Material changes will be notified through the Service or by email.

10. Contact

Geo Commerce Private Limited — privacy@geocommerce.co.

Orbit addendum

11. Additional Privacy Terms for Orbit

Orbit is a multi-channel commerce, analytics and management application operated by Geo Commerce Private Limited. When you install, connect, authorize or use Orbit, the following additional privacy terms apply alongside the policy above. Orbit may support connections to commerce platforms, marketplaces, analytics services, search platforms and advertising platforms, and access is limited to the data, resources and permissions you authorize and that the relevant platform makes available.

Connected platforms and platform requirements

Data obtained from a connected platform is also handled subject to the applicable platform agreements, developer policies, API terms, authorization scope and approved use cases. Where a platform imposes stricter requirements concerning access, use, combination, disclosure, retention or deletion of its data, those platform-specific requirements apply to that data in addition to this Policy.

Shopify data

Orbit may access and process data made available through Shopify APIs and webhooks according to the permissions granted to the application. This may include store information, products, variants, inventory, orders, customers where authorized, fulfilment and operational metadata, analytics-related information, and synchronization or webhook records. Orbit uses this information to provide multi-store analytics, reporting, catalogue and inventory visibility, issue detection, operational management and related product functionality.

Google Analytics 4 and Google Search Console

If you choose to connect a Google account, Orbit may request read-only access to Google Analytics 4 and Google Search Console. Depending on the resources you select, Orbit may retrieve property and site information, sessions, users, engagement, traffic-source data, landing-page data, device and geographic data, Search Console clicks, impressions, queries, pages, countries, devices, average position and related reporting information.

Orbit uses Google user data only to provide and improve user-facing analytics, reporting, comparison and management functionality inside Orbit. Google user data is not sold, rented, or used for advertising, and is not transferred to third parties except service providers acting on our instructions where necessary to operate Orbit, or where required by law.

Google Ads

If you choose to connect a Google Ads account, Orbit may access advertising data for the customer accounts and resources you authorize. Depending on the available permissions and reporting resources, this may include account and customer identifiers, campaigns, ad groups, advertisements, keywords or search-term information where available, budgets and bidding-related information, impressions, clicks, cost, conversions, conversion value and related advertising performance metrics.

Orbit uses Google Ads data to provide authorized advertising reporting, analytics, historical comparisons, connection monitoring and related Orbit functionality. Orbit does not create or modify Google Ads campaigns, bids, budgets or advertisements unless such functionality is separately enabled and authorized. Google Ads data is not sold or rented.

Meta Ads

If you choose to connect a Meta advertising account, Orbit may request read-only access through the Meta Marketing API according to the permissions and advertising resources you authorize. Orbit may retrieve Meta ad account identifiers and account information, campaigns, ad sets, advertisements, impressions, clicks, spend, reach, CTR, CPC, CPM, conversion actions, and Meta-attributed conversion or purchase values.

Orbit uses Meta advertising data only to provide advertising performance reporting, analytics, historical comparisons, multi-store reporting and related Orbit functionality. Orbit does not create, modify or manage advertisements unless additional permissions and functionality are separately authorized. Meta advertising data is not sold or rented.

Amazon Selling Partner data

If you choose to connect an Amazon seller account, Orbit may access data made available through the Amazon Selling Partner API (SP-API) according to the permissions granted to Orbit and any applicable Amazon approvals. Depending on the authorized resources, this may include seller and account identifiers, marketplaces, product catalogue and listing information, pricing, inventory, orders, fulfilment information, operational reports, financial or settlement-related information where authorized, and related seller-account data. Personal or protected data is accessed only where specifically authorized, approved where required, and necessary to provide the requested functionality.

Orbit uses authorized Amazon Selling Partner data to provide store and marketplace synchronization, catalogue and inventory visibility, sales and operational reporting, issue detection and related Orbit functionality. Amazon Selling Partner data is not sold or rented and is handled subject to applicable Amazon requirements and permitted uses.

Amazon Advertising

If you choose to connect an Amazon Advertising account, Orbit may request authorized access through Amazon authentication and Advertising API services. Depending on the permissions, advertiser resources and advertising products you authorize, Orbit may access advertiser and account identifiers, advertising profiles, marketplace and currency information, campaigns, ad groups, advertised products, keywords, targeting information, search-term information where available, impressions, clicks, advertising spend, attributed orders, attributed sales and related advertising performance or reporting information.

Orbit uses Amazon Advertising data only to provide the Amazon Advertising functionality you authorize, including account synchronization, advertising analytics, performance reporting, historical comparisons, connection monitoring and related operational features. Amazon Advertising data is not sold, rented, syndicated or made available to unauthorized third parties, and it is handled subject to applicable Amazon agreements, policies and approved uses.

OAuth credentials, authorization tokens and API credentials

Access tokens, refresh tokens where applicable, authorization credentials and similar API credentials for supported integrations are treated as confidential credentials. They are stored using appropriate security controls and are used only by server-side systems to retrieve or process data that you have authorized Orbit to access. Orbit does not expose these credentials in the client-facing application and does not request or store your third-party account passwords.

Data synchronization and derived analytics

Orbit may periodically synchronize authorized data from supported integrations and store normalized or derived analytics so that dashboards, historical comparisons and operational features can function efficiently. Where permitted by the applicable platform terms and authorization, Orbit may use connected data to provide cross-store, cross-channel or comparative reporting. Recent analytics data supplied by third-party platforms may be provisional and may be re-synchronized as those platforms finalize or revise their reporting.

Platform-specific restrictions take precedence over general Orbit functionality. In particular, Amazon data is processed only for permitted and approved purposes under applicable Amazon requirements. Where those requirements restrict combining, sharing, retaining or otherwise using Amazon data with other data sources, Orbit applies those restrictions and may keep the relevant data logically segregated from other connected-platform datasets.

Disconnecting, revoking access and deletion

You may disconnect supported integrations from Orbit where that control is available, uninstall Orbit from Shopify, revoke Google access through your Google Account permissions, revoke Meta access through your Meta account or business settings, or revoke Amazon authorization through the applicable Amazon account or advertising authorization controls. Revocation stops future access using the revoked authorization.

Previously synchronized data may be retained for a reasonable period for account continuity, security, backup, legal or operational purposes and will then be deleted or anonymized in accordance with our retention practices, unless a platform-specific requirement or applicable law requires a different retention period. For Amazon data, when authorization is revoked, an integration is terminated, or the data is no longer required for a permitted use, applicable data will be deleted or anonymized in accordance with Amazon requirements and applicable law.

You may request deletion of Meta-derived data, Amazon-derived data or other integration data associated with your Orbit account by contacting privacy@geocommerce.co. We will delete or anonymize applicable data in accordance with this Policy and our legal, security, platform and compliance obligations.

Security and vulnerability reporting

If you believe you have identified a security vulnerability, unauthorized data exposure or privacy incident affecting Orbit, a Geocommerce service or data obtained through a connected platform, please report it to privacy@geocommerce.co. Where possible, include a description of the issue, the affected service or integration, steps to reproduce it and supporting information that can help us investigate safely.

We will review reported issues, investigate as appropriate, take reasonable corrective action, and notify affected platform providers, users or authorities where required by applicable law, contractual obligations or platform requirements.

Google API Services User Data Policy

Orbit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.