Data handling

Export, retention and deletion

The customer owns their data. This page explains what Orbit stores, how to get all of it out, and how to have it deleted. For infrastructure and access control, see security.

What Orbit stores

  • CRM records — contacts, companies, deals and pipeline stages, tasks and follow-ups, notes and activity history, tags.
  • Documents — proposals, contracts and signatures, invoices, and any files uploaded to a record.
  • Communications — email campaigns and templates, chatbot conversations, meeting summaries and transcripts you sync in.
  • Programmes — events and registrations, quests and submissions, goals and OKRs, Orbit Sync sessions and their transcripts.
  • Configuration — workspace settings, branding, team membership, API key hashes, webhook endpoints and delivery logs.
  • Account data — user email, name, sign-in timestamps and in-app usage events.

Exporting your data

Full workspace export. Any workspace member can generate a complete machine-readable export from Settings → Data. It downloads as a single JSON file covering the record types listed above, with row counts included. API key hashes and webhook secrets are deliberately excluded.

CSV. Contacts can be exported to CSV directly from the Contacts tab for spreadsheet use.

API. Data can also be pulled programmatically — see the API documentation.

Exports are generated on demand, scoped to the requesting user's workspace, and are not rate-limited for normal use.

Retention

Customer data is retained for as long as the workspace is active. Deleting a record in the app removes it from the workspace immediately; it may persist in encrypted database backups until those backups age out, typically within 30 days.

Webhook delivery logs and in-app activity events are retained for operational and analytics purposes and are removed with the workspace.

Deleting a workspace or account

A workspace member can request deletion from Settings → Data → Delete workspace. The request is recorded with the requester and timestamp, and can be cancelled by the workspace while it is still pending.

We action deletion requests within 30 days. Deletion removes workspace records, uploaded files, API keys and webhook configuration. Residual copies in encrypted backups age out within a further 30 days. Records we are legally required to keep — for example invoices and payment records held for tax purposes — are retained for the statutory period.

To delete an individual user account rather than a whole workspace, or to request deletion on behalf of a data subject, email will.blakey@me.com. We recommend taking an export first, because deletion is irreversible.

Data subject requests

If you are a customer using Orbit to hold personal data about your contacts, you are the data controller and Orbit is the processor. We will assist with access, correction, portability and erasure requests from your data subjects; contact us and we will respond within 30 days. We are happy to sign a data processing agreement.