Scope and responsibility
Orbit Studios operates this website and is responsible for the personal information it processes for storefront presentation, customer support, reviews, security, and administration. For privacy questions or requests, email support@orbitstudios.net or open a private ticket in the Orbit Discord server. You do not need to have bought a resource to make a privacy request.
Tebex is the Merchant of Record and legal seller for purchases made through this store. Tebex operates checkout and handles payment, tax, fraud, transaction, and fulfilment information under its own privacy notice. Orbit does not receive your full payment-card details.
When you continue to checkout, the cart loads Tebex.js and passes the current Tebex checkout request token to Tebex’s payment interface. That sensitive token can also authorize the associated Tebex basket. Orbit supplies it only after a checkout request validates the current basket and checkout URL on its server, not from browser input. The payment interface opens over the cart, with a full-page Tebex link available if needed. Tebex receives the information needed to operate that checkout under its own privacy and cookie policies. Orbit does not cache the private cart, persist the token in browser storage, send it to analytics or application logs, or use browser payment events as proof of purchase.
This notice covers this Orbit storefront and its administration tools. Services you open separately, including Tebex Checkout, Cfx.re, Discord, YouTube, and the Orbit documentation website, also apply their own privacy terms.
Information we handle
- Storefront and security data: ordinary request information such as IP address, device and browser details, requested pages, timestamps, response status, and security events may be processed by our hosting provider and server logs. To limit abusive requests, Orbit also keeps short-lived request counters in private PostgreSQL. These counters use a keyed cryptographic identifier derived from the trusted request IP address, a fixed operation group, a count, and window and expiry times. The counter records do not contain the raw IP address, customer identity, request body, or full URL, and are not used for advertising or customer profiling.
- Checkout reliability: Orbit counts server-observed cart, coupon, gift-card, creator-code, Cfx.re sign-in return and checkout-preparation outcomes by UTC hour in private PostgreSQL. The counters contain only fixed action, outcome and reason categories and their totals. They contain no customer or basket identifiers, IP addresses, redemption codes, payment amounts, URLs or individual event history. Authorized administrators can inspect a 30-day reporting window; daily cleanup removes expired counters, normally within about 31 days. These counts help find service errors and are not a record of completed purchases.
- Public-site measurement: Vercel Web Analytics records cookie-free, privacy-minimized page-view information such as the public route, referrer, approximate country, device type, operating system, and browser. It derives a rotating daily visitor identifier from request information, including the IP address and user agent, rather than using an analytics cookie. Vercel Speed Insights records privacy-minimized Web Vitals and related browser, device, network, route, and country information. Orbit strips query strings and fragments and excludes cart, account, dashboard, authentication, API, draft-preview, and development-tool routes. It does not send customer, basket, checkout, or administrator identifiers as analytics fields.
- Tebex catalogue, basket, gifting, and Cfx.re connection data: when browsing without a confirmed Cfx.re-connected basket, your browser requests public product prices directly from the fixed Tebex Headless API. Tebex receives ordinary browser and network information, including your IP address, to determine customer-location pricing, currency, and tax. This read sends no cookies, authorization header, referrer, or stored location and retains only prices in page memory. If you already have an active Cfx.re-connected basket, Orbit instead sends its server-only identifier and the validated request address through the authenticated package listing to preserve basket-specific pricing. Browsing does not create a basket or a currency-tracking cookie. If contextual pricing is unavailable, Orbit uses the location-neutral live Tebex base price, identifies it as tax-exclusive, and Tebex finalizes applicable tax at checkout. The site also keeps a Tebex basket identifier in a secure first-party cookie and receives the basket state needed to display your cart. When the storefront creates a Tebex basket, it sends Tebex the validated IPv4 address used for that request because the Tebex Headless API requires it. After Tebex confirms a Cfx.re connection, the browser may receive a bounded display username. Orbit’s server may request matching public Cfx.re forum profile JSON from a fixed Cfx.re origin to resolve a custom avatar or verify a gift-recipient username. Cfx.re receives that username in the URL plus ordinary server request information. Orbit keeps the bounded canonical username, public numeric forum ID, and any validated custom-avatar URL in server memory for at most 15 minutes; it does not persist the profile in its database and does not proxy or store the image. When you explicitly buy an eligible package as a gift, Orbit sends the verified recipient ID to Tebex as target_username_id. The same cart receives the bounded gift-recipient display username so you can verify the recipient; the stable numeric recipient ID and all other Tebex gift-recipient fields remain server-only. After strict avatar validation, the browser loads the image directly from Cfx.re without credentials or a referrer, so Cfx.re also receives ordinary browser and network request information for that image. The avatar never authorizes customer actions, Orbit never receives your Cfx.re password, and the local initial remains when the lookup fails or returns a generated/default avatar.
- Optional Discord connection: when you select Connect Discord, Orbit sends you to Discord’s authorization page with the identity-only scope. Discord returns your user ID and display name after your approval. Orbit immediately requests revocation of the temporary access token and discards it; no Discord refresh token is requested or stored. An authenticated, encrypted and HttpOnly cookie binds the OAuth state, PKCE verifier, Tebex basket, and exact Cfx.re username ID. Orbit Sentinel confirms that the Discord user is a member of the configured server and can retain the Cfx.re username ID-to-Discord ID association until you unlink it. The storefront keeps only a short-lived encrypted association state and revalidates a linked identity before Discord-delivered cart additions.
- My resources: when a linked customer opens this list, Orbit Sentinel checks that customer’s current resource roles in the Orbit Discord server. Sentinel sends Orbit an encrypted, request-bound list of matching resource groups. The website displays the associated resource names and documentation links to that same customer. It does not receive payment history or display Discord role IDs, and this check does not grant or remove access. A separate encrypted, HttpOnly cookie holds the request identity and temporary decryption key for up to four minutes; the resource result remains only in the open menu and is not saved in browser storage. The Discord /myresources command performs its role check within Discord without needing this website lookup.
- Discord package delivery: for a Tebex package whose only supported required variable is discord_id, Orbit passes the currently verified Discord ID to Tebex as variable_data.discord_id when the package is added. Tebex captures that value for its Discord Action delivery. An encrypted first-party delivery cookie binds the verified ID to the current basket and exact package rows. Before checkout, Orbit refreshes those package capabilities and revalidates the association through Sentinel; checkout stops if the binding is missing, stale, or changed. Removing an Orbit storefront association does not erase an earlier Tebex transaction, a staff-created transaction association, or another non-storefront transaction association. Tebex does not publish a Headless API that lets this website inspect or mutate an account link created through the official Tebex Discord bot.
- Purchase support data: when required to verify access or support a purchase, authorized administrators may use a Tebex transaction reference and a Discord user identifier to link or unlink a customer in Orbit Sentinel. The sensitive command input is hidden from dashboard reads and redacted after the command reaches a terminal state.
- Coupon and gift-card delivery: an administrator may issue a Tebex code and ask Orbit Sentinel to send it privately to a supplied Discord ID or an existing Cfx.re-to-Discord association. Both recipient fields are optional. Sentinel checks the public Cfx.re identity and Discord server membership when supplied. Entering a Cfx.re username restricts a coupon to that account; a gift card remains transferable credit. When both identifiers are entered, the final issuance confirmation includes recording a customer-confirmed association before a first purchase, provided it does not conflict with an existing link; that association can be removed through the storefront unlink flow. This does not authenticate the customer with Cfx.re or change an account link in Tebex. Tebex receives the code settings, any username restriction and internal note. Discord receives the private delivery message. The delivery recipient is fixed when the code is issued and is not silently changed later.
- Reviews: Orbit may select feedback submitted in its Discord feedback channel for public display. Published fields can include a display name, profile image URL, rating from zero to five, review text, date, product, and verified-purchase status. When a valid external avatar is published, the visitor browser requests it directly from an approved Discord CDN host with credentials and the referrer omitted; Discord still receives ordinary network and browser request information. Orbit keeps the originating Discord message reference in private server source for editorial traceability; that internal field is not sent to visitors. Feedback is labelled as a verified purchase only when Orbit has separate Tebex evidence.
- Team images: the About page can load a small public team-member avatar directly from avatars.githubusercontent.com. The image request omits credentials and the referrer, but GitHub still receives ordinary network and browser request information. Orbit does not call an authenticated GitHub API or store avatar binaries or GitHub customer profiles. A local initial is shown if the image is unavailable.
- Support and Discord data: if you open a Discord ticket or contact us by email, the relevant service and Orbit support staff process the account details and message content you choose to provide. Sentinel keeps ticket assignment, priority, waiting state and private handover notes to coordinate support. The existing closure message may offer an optional, one-use resolution check for seven days. Your answer and optional comment are private to staff, are not product reviews and do not reopen the ticket. Private notes and resolution comments become unavailable 90 days after closure and are removed by daily maintenance; downtime and protected backups can delay physical removal. Minimal delivery and response state remains to prevent duplicate messages and submissions. Closed DMs do not affect ticket closure or trigger repeated messages. This website does not receive those private notes, resolution comments or ticket transcripts.
- Administration data: approved store administrators use Supabase authentication and mandatory authenticator-app verification. We process their account identifier, email, display name, role, status, session and assurance information, temporary authenticator setup identifiers, content changes, and security audit records. After successful password-backed setup, Orbit retains the administrator account identifier, exact approved authenticator factor UUID, and approval time in a private registry and atomically authorizes the exact live session. The factor UUID is the only factor-specific value retained. Passwords, authenticator secrets, QR payloads, and six-digit verification codes are not written to Orbit PostgreSQL or application logs. Later challenges expose and accept only Orbit-approved factors that Supabase still reports as verified authenticator-app factors.
- Operational bot data: the private dashboard can display aggregate Discord member, customer, staff, ticket, review, command, role-sync, and host-health metrics reported by Orbit Sentinel. Sentinel also sends sales totals grouped by currency, payment status, and time period. The website keeps only the latest aggregate for each reporting range. Individual financial records remain with Sentinel on the bot VPS, and Tebex remains the commerce authority. Storefront telemetry does not retain Discord message bodies, ticket transcripts, payment-card data, or customer email addresses.
How we use information
- Provide the catalogue, basket, account connection, purchase access, documentation, and support you request.
- Verify purchases, manage customer roles, prevent fraud and abuse, and protect Orbit resources and services.
- Publish approved reviews and maintain accurate product, compatibility, and support information.
- Operate, diagnose, secure, and improve the storefront, dashboard, and Orbit Sentinel integration.
- Understand aggregate public-page use and measure loading, responsiveness, and visual stability so we can improve storefront performance.
- Meet legal obligations and establish, exercise, or defend legal claims.
Depending on the activity and applicable law, we rely on performing a contract or taking steps you request, our legitimate interests in operating and securing the store and supporting customers, compliance with legal obligations, or your consent. YouTube showcase content is not loaded until you choose to play it.
Providers and disclosures
We disclose information only where needed to operate the service, follow your request, protect our services, or comply with law. Our principal technology providers and external destinations are Tebex for commerce and the identity connection you choose, the public Cfx.re forum for the optional connected-customer profile image, Vercel for hosting and image delivery, Supabase for PostgreSQL and administrator authentication, Discord for community support and customer roles, GitHub for public team-member images, Google for click-to-load YouTube video, and the provider hosting Orbit Sentinel on a separate VPS.
Messages sent to support@orbitstudios.net are also processed by the service that operates that email inbox. Requests to the separate Orbit documentation website are processed by its hosting provider.
These providers may process information in countries outside your own. Their contractual safeguards, subprocessors, and transfer mechanisms apply to their processing. We do not sell personal information and do not share it for cross-context behavioural advertising.
Tebex Privacy Policy
This policy applies to checkout, payment, tax, fraud, fulfilment, and other data processed by Tebex as Merchant of Record.
Read the Tebex Privacy Policy (opens in a new tab)Vercel Privacy Notice
Vercel provides the hosting, edge delivery, server execution, image optimisation, cookie-free Web Analytics, and cookie-free Speed Insights used by this website.
Read the Vercel Privacy Notice (opens in a new tab)Cfx.re and Rockstar Games Privacy Policy
This policy applies when Orbit’s server requests public Cfx.re forum profile JSON, when the browser loads a validated custom avatar directly from Cfx.re, and when you use Cfx.re services.
Read the Rockstar Games Privacy Policy (opens in a new tab)Vercel Web Analytics privacy information
Vercel describes its page-view measurement as anonymous and cookie-free; Orbit uses the more conservative privacy-minimized wording in this notice.
Read the Web Analytics privacy information (opens in a new tab)Vercel Speed Insights privacy information
Vercel describes its Web Vitals measurement as anonymous and cookie-free; Orbit uses the more conservative privacy-minimized wording in this notice.
Read the Speed Insights privacy information (opens in a new tab)Supabase Privacy Policy
Supabase provides the PostgreSQL database and administrator authentication used by Orbit.
Read the Supabase Privacy Policy (opens in a new tab)Discord Privacy Policy
Discord processes account, community, support ticket, and customer-role activity carried out through Discord.
Read the Discord Privacy Policy (opens in a new tab)Google Privacy Policy
Google processes information when you choose to activate a YouTube showcase video.
Read the Google Privacy Policy (opens in a new tab)Continuing a purchase after sign-in
If you select Add to cart or Buy now before connecting Cfx.re, a signed, HttpOnly first-party cookie keeps the product reference, quantity, selected action and optional gift-recipient username for up to 15 minutes. It is bound to the current Tebex basket and cleared when the purchase resumes; invalid or expired selections are not accepted. It contains no price, password or payment-card details and is not used for advertising. Orbit rechecks the product and delivery requirements with Tebex after sign-in.
Retention
For coupon and gift-card issuance, Sentinel retains recipient delivery details for at most 30 days of active access; daily maintenance redacts expired details, with physical deletion delayed during downtime or by protected backup retention. Minimal issuance identifiers, one-way request digests, provider references and outcome records remain to prevent duplicate financial issuance. Equivalent minimal mutation records prevent repeated gift-card credit changes. They do not contain plaintext codes, internal notes or Discord message bodies. Codes remain managed by Tebex. Authorized administrators can request private code lists and details, delete coupons, void gift cards or add gift-card credit. These management actions do not send messages or alter customer associations. Code lists, balances, notes and username restrictions are returned in encrypted, short-lived receipts. The webstore command history contains safe metadata and encrypted receipts, not plaintext codes; only the requesting administrator can retrieve the receipt through the dashboard.
We keep information only for as long as needed for the purpose described, to maintain security and accountability, and to meet legal requirements. The exact period depends on the record and any active dispute or legal hold.
- Necessary browser cookies expire on the schedules stated above or when you clear them. Signing out of the local Cfx.re basket connection removes the basket cookie from this site.
- The temporary administrator authenticator-enrollment cookie expires within five minutes and is cleared after successful setup or when validation detects invalid state. The private approved-factor registry retains the administrator account identifier, exact approved factor UUID, and approval time, but no password, authenticator secret, QR payload, or six-digit code. A registered factor is eligible for a later challenge only while Supabase still reports it as a verified authenticator-app factor. Authorization for the exact administrator session that completed verification expires after at most 24 hours by default. Administrators who explicitly select Keep me signed in on this device after password-backed verification can authorize that session for up to 14 days. The deadline does not extend with activity or token refresh. Recovery, invitation and magic-link sessions retain the 24-hour limit. Signing out, revoking access or clearing browser cookies can end access earlier. This option does not create a separate device-tracking cookie or bypass authenticator verification.
- Raw Discord bot metric samples are retained for 14 days, hourly rollups for 180 days, daily rollups for up to 10 years, and scheduled-run history for 90 days.
- Abuse-prevention counters have counting windows of at most ten minutes. Expired rows are removed by the daily database cleanup, normally within about 24 hours and ten minutes of the last counted request. Denied requests do not extend the expiry. Cleanup interruptions and protected backup copies can delay physical removal. An expired counter is reset before requests are counted in a new window.
- Discord control-command metadata is retained for up to 180 days. Exact transaction, Cfx.re, and Discord identifiers in command inputs are hidden from dashboard reads and redacted after terminal processing; a one-way correlation may remain in security audit records for accountability. A storefront lookup result stores only an RSA-OAEP ciphertext that the matching short-lived browser cookie can decrypt, never a plaintext Discord ID or display name. Orbit Sentinel may retain the durable Cfx.re username ID-to-Discord ID association until a valid unlink removes that storefront- or staff-created identity association. Past Tebex transaction records and non-storefront associations are not erased by that action.
- Published reviews and their private source references remain available until they are unpublished, removed, no longer required, or a valid deletion request applies. When handling a removal, we also check retained source history, deployed copies, and backups for information covered by the request, and explain any applicable retention exception or delayed removal. Unpublishing a review does not by itself erase every retained copy.
- Administrator, revision, audit, security, webhook, reporting, support, and provider log records follow the period required for their operational, legal, fraud-prevention, and accountability purpose.
Your privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, or portability of your information, object to certain processing, or withdraw consent. You may also complain to the data-protection authority responsible for your location.
Email support@orbitstudios.net or open a private Discord ticket in the “Other” category and say what you want us to check, correct, provide, or remove. “Privacy request” is a helpful subject, not a required format. Include only the account, review, purchase reference, or interaction needed to locate the information. Do not send passwords, login links, payment-card details, or identity documents unless we arrange a necessary, secure verification step. If you cannot use Discord, use email; a purchase, customer role, or Discord membership is not required for an email request.
We may ask for proportionate verification before disclosing or changing information. We respond under the rules applicable to your request; where the GDPR applies, this normally means within one month. If a permitted extension is needed because of the complexity or number of requests, we explain it within that month. We handle information for which Orbit is responsible and coordinate with our service providers where needed. For information independently controlled by Tebex, Discord, Google, or another provider, we can explain the appropriate contact route; contacting Orbit does not require you to contact every provider first.
Contact Orbit privately
In our Discord server, open an “Other” ticket so the request is shared with support staff rather than posted in a public channel. Email remains available if you cannot open a ticket.
Open Orbit Discord (opens in a new tab)European data-protection rights
The European Data Protection Board provides an overview of GDPR rights and links to European supervisory authorities.
Review EDPB data-subject rights (opens in a new tab)Security and changes
We use access controls, server-side secrets, secure cookies, signed agent requests, row-level database controls, bounded validation, redaction, and audit records to protect the service. No online service can guarantee absolute security.
We may update this notice when the storefront, providers, or legal requirements change. The current version and date will be published on this page. Material changes will be communicated through the storefront when appropriate.