Legal
Privacy notice
Last updated: September 24, 2026
Version: 2026-09-24
This notice explains how Orquestr collects, uses, shares, and protects personal data when you visit the site, create an account, communicate with us, or use the API, point-of-sale connectors, and related services (the “Services”).
Orquestr offers the Services and determines these purposes. Privacy requests go to legal@orquestr.com.
1. When this notice applies
This notice applies when Orquestr decides why and how personal data is processed: account administration, billing, product analytics, communications, security, and support.
The customer also submits business records and other information for the Services to process on the customer's behalf (“Customer Content”). For personal data inside that content, the customer generally decides the purposes and acts as controller, and Orquestr acts as processor. That processing is governed by the customer's agreement and the data processing agreement. If you are an end user of an Orquestr customer, direct a request about that content to the customer first.
This notice does not govern independent products of a point of sale, an ERP, a payment processor, or a model provider, even when they connect with Orquestr.
2. Information we collect
Information you provide
- Account and profile: name, email, organization, role, authentication data, preferences, and settings.
- Billing: plan, subscription, invoices, history, balances, usage, tax details, and limited payment-method data. Full card details are generally collected and stored by the payment processor, not by Orquestr.
- Communications: support requests, feedback, emails, and other messages with us.
- Customer Content: sales, inventory, prices, customers, suppliers, catalogs, files, configurations, webhooks, and metadata you choose to process through the Services.
- Connections: identifiers, credentials, tokens, permissions, and metadata needed to connect a point of sale or another system.
Information collected automatically
- IP address, device type, browser, operating system, language, approximate location, and identifiers.
- Pages and features viewed, clicks, navigation, timestamps, and referrers.
- API calls, webhook activity, usage volume, errors, performance data, logs, and security events.
- Use of the subscription and of the features you buy.
Information from third parties
We may receive information from account and authentication providers; from the point-of-sale systems, payment processors, and other systems you connect; from customers or users who invite or administer you; from analytics and security providers; and from public sources where the law allows.
3. How we use information
Primary purposes, needed to provide the service:
- provide, configure, maintain, and secure the Services;
- create and administer accounts, organizations, permissions, and connectors;
- charge subscriptions, credits, usage, overages, and taxes;
- transmit the point-of-sale operations you request, executed in your cloud;
- provide support and communicate about service, billing, security, and policies;
- prevent fraud and abuse, enforce the Terms, and investigate incidents; and
- comply with law and respond to valid legal requests.
Secondary purposes:
- understand product use, diagnose failures, and develop features;
- send commercial information about Orquestr, where the law allows; and
- carry out a corporate transaction, such as a financing, reorganization, or sale.
If you do not want your information used for marketing messages, you can ask at legal@orquestr.com or use the unsubscribe link in the message. We may still send transactional, billing, security, and service communications. We may aggregate or de-identify information for analytics and security, and we do not attempt to re-identify what we keep de-identified.
4. Automated features
If you use an automated or model feature, we process the inputs, context, files, outputs, and metadata needed to provide it. Depending on the feature, that information may be sent to a provider named on the subprocessor list.
Orquestr does not use Customer Content to train general-purpose models, its own or a provider's, except under a written agreement. Where commercially available, providers are engaged under arrangements that restrict them from using that data to train their general models. The customer should not submit restricted data to an automated feature without written approval.
5. Legal bases
Where a law such as the GDPR requires a legal basis, we process personal data on one or more of these:
- Contract: to provide the Services and the pre-contract steps you request.
- Legitimate interests: to secure, operate, and improve the Services, communicate, prevent abuse, and run the business, where that interest is not overridden by the person's rights.
- Consent: where we ask for it, for example for certain cookies or optional messages. Consent can be withdrawn.
- Legal obligation: to keep records and respond to lawful requests.
- Protection of rights: to establish, exercise, or defend claims and protect people, systems, and property.
When we process Customer Content as a processor, the customer identifies the lawful basis and gives us instructions. If the person is in Mexico, access, rectification, cancellation, and objection rights are exercised as the rights section describes. This notice does not place the contract under Mexican law: the contract's governing law is that of the State of Delaware, under the Terms.
6. How we disclose information
We may disclose personal data to:
- affiliates, when they exist, that support engineering, operations, or support;
- processors for hosting, databases, storage, monitoring, analytics, email, billing, models, and security, listed on Subprocessors when they process Customer Content;
- third-party platforms you connect, such as a point of sale, which may act as independent controllers for part of the processing;
- your organization and users with permissions on the account;
- professional advisers bound by a duty of confidence;
- authorities and affected parties, when reasonably necessary to comply with law, process, or a valid request, or to protect rights, safety, and systems;
- participants in a financing, merger, acquisition, or sale, with appropriate safeguards; and
- others, at your direction or with your consent.
We do not sell personal data for money. We do not rent it or transfer it to outsiders without a basis this notice describes. If a U.S. state law treats a particular advertising cookie as a “sale,” “sharing,” or targeted advertising, you may opt out at legal@orquestr.com. This site does not describe an active advertising network today.
7. Cookies and similar technologies
We and our providers may use cookies, local storage, and similar technologies to keep you signed in, remember language, secure the site, and understand use. Some are necessary. The browser can block others, and blocking necessary ones can affect features. The language switcher stores the preference in a cookie named NEXT_LOCALE. This site uses Google Analytics, from Google LLC, to measure visits. That measurement does not include the customer's point-of-sale or ERP content.
8. International transfers
Orquestr may use providers in the United States and other countries. Personal data may be processed outside the country where it was collected.
Where the law requires it, we use recognized mechanisms, such as adequacy decisions, the European Commission's standard contractual clauses, and the United Kingdom addendum. The data processing agreement adds terms for Customer Content.
9. Retention
We keep information for as long as reasonably necessary for the purposes in this notice, including to provide the service, comply with law, resolve disputes, secure systems, and enforce the contract. The period depends on the type of information.
- Account, project, connector, and content data may remain while the account or project is active.
- Operational logs, webhook events, and telemetry may be kept for shorter periods, from days to months.
- Billing, tax, fraud, security, audit, and legal records may be kept longer.
- Information in backups is deleted on the normal backup rotation.
- When an account or project is deleted, we generally delete or de-identify Customer Content from active systems within a commercially reasonable period, typically 30 to 90 days, subject to technical limits, backup cycles, legal duties, security, and a different customer instruction.
10. Security
We use technical and organizational measures designed to protect information: access controls, authentication safeguards, encryption to the extent the infrastructure supports it, monitoring, change management, incident response, and vendor review. No system is completely secure, and we cannot guarantee absolute security.
Point-of-sale operations run in the customer's cloud. You protect your credentials and systems, configure the Services, limit permissions, and tell us promptly if you suspect a compromise. The infrastructure list is waiting on confirmed providers: we do not claim a data center here that is not published on Subprocessors.
11. Your rights
Depending on where you live, you may:
- access your personal data or ask for a copy;
- correct inaccurate data;
- delete data;
- object to certain processing or ask that it be restricted;
- withdraw consent;
- receive data in a portable format;
- opt out of targeted advertising, sale, or sharing as applicable law defines those terms; and
- appeal a decision on a privacy request.
If the person is in Mexico, those rights include access, rectification, cancellation, and objection. The request goes to legal@orquestr.com and states the full name, a way to reply, the data the request covers, and documents that prove identity or authority to represent.
We may verify identity and authority before acting. An authorized agent may submit a request where the law allows. If the information is in Customer Content controlled by an Orquestr customer, contact that customer first. We will assist the customer as the data processing agreement requires.
People in the EEA, the United Kingdom, or Switzerland may complain to their data-protection authority. We prefer that you write to us first. We do not discriminate for exercising a privacy right.
12. Children
Accounts are not intended for anyone under 18. We do not knowingly collect personal data from children under 18 to register an account. If we learn that a child under 18 created an account, we will take steps to close it and delete the associated personal data, subject to law. Write to legal@orquestr.com if you believe this happened. Customer Content is processed on the customer's behalf under the data processing agreement.
13. Business customers and end users
Anyone who uses Orquestr to provide products to their own customers must give those people the privacy notice that applies, obtain required permissions, and configure the Services consistently with that notice. If we receive a request from an end user, we may direct it to the relevant customer.
14. Changes
We may update this notice as the Services or our practices change. If a change is material, we will give reasonable notice through the Services, by email, or by another appropriate method. The update date shows the revision.
15. Contact
Orquestr. Email: legal@orquestr.com.
