Privacy Policy
Effective Date: April 16, 2026 · Last updated: September 30, 2026
Orbit Online LLC ("Orbit," "we," "us," or "our") provides AI-powered receptionist services, AI automation tools, a CRM platform, and website design and hosting services that help businesses communicate with their customers, patients, and website visitors. This Privacy Policy explains how we collect, use, share, and protect personal information when you interact with our services, website, and platform (collectively, the "Service").
1. Information We Collect
1.1 Information You Provide
We collect information that you submit through our website, platform, or services, including:
- Account information: Your name, email address, phone number, and business details when you create an account, request a demo, or subscribe to a plan.
- Booking and inquiry details: When you book a call with us, answer our website questionnaire, or ask us to contact you, we collect your name, email, phone number, practice details you share (such as role, number of locations, practice software, and typical case value), the time you booked, and a record of any consent you give to be contacted (what you agreed to, the wording shown, and when).
- Call and chat content: Audio recordings, transcripts, and chat logs from calls and messages handled by our AI receptionist. Calls and chats handled by the Service are answered and processed by automated AI systems and may be recorded and transcribed; recordings and transcripts are made available to the business on whose behalf the communication was handled. These may contain personal data and Protected Health Information (PHI) related to your practice and patients.
- SMS and email content: Text messages and emails sent through our automation features (follow-up sequences, appointment reminders, review requests). We store message content, recipient information, and delivery status.
- Outbound contact lists: Names, phone numbers, and contact details of leads and customers that our clients provide or direct the Service to contact through AI-assisted outbound calls and texts. We process this information on the client's behalf and store contact outcomes and opt-out status; the client is responsible for having the required consent to contact each individual.
- Scheduling data: Appointment details (e.g., patient or client name, date/time, service type) when our AI books or manages appointments on your behalf.
- CRM data: Lead and contact records, notes, pipeline stages, activity logs, and business information stored in our Lead OS platform. This includes data imported from Google Maps searches and third-party enrichment services.
- Knowledge base content: Business information, FAQs, scheduling rules, and other content you provide to train your AI receptionist.
- Website content and hosting data: If we build and host a website for you, we collect website content, domain configuration details, and any personal data contained within the site (such as contact form submissions).
- Other submissions: Support requests, feedback, and any other data you choose to provide.
1.2 Information Collected Automatically
We automatically collect information about how our services are used, including:
- Device and usage data: IP address, browser type, operating system, and activity logs when you access our website, dashboard, or hosted websites.
- Service logs: Diagnostic logs from our AI receptionist, automation, and web hosting platforms (e.g., call duration, message delivery status, error messages, page load times).
- Cookies and tracking technologies: We use cookies, pixels, and similar technologies on our website for analytics (Google Analytics, a visit summary sent with bookings, and Microsoft Clarity session replay and heatmaps), advertising and ad measurement (Meta Pixel and Conversions API, Google Ads), and functionality (session management, Cal.com scheduling embed). See Section 8 for details.
1.3 Information from Third Parties
We receive information from integration partners and data providers, including:
- Practice management systems: Patient and appointment data from Dentrix Ascend, OpenDental, Denticon, and similar systems when you connect them to our Service.
- Lead enrichment services: Business contact information (names, emails, phone numbers, titles) from third-party data providers when you use our lead search and enrichment features.
- Payment processor: Billing information from Stripe for subscription management.
2. How We Use Your Information
We use personal information to:
- Provide and operate our services. We use call recordings, transcripts, chat logs, SMS/email content, scheduling data, CRM records, and website content to deliver the AI receptionist, automation, CRM, and website hosting functionality.
- Improve our AI. We use anonymized and aggregated interaction data to improve our AI models, call handling, and response quality. We do not use identifiable PHI for model training.
- Communicate with you. We use your contact information to respond to inquiries, send service updates, billing notifications, and provide customer support. You may opt out of marketing emails at any time.
- Process payments. We use billing information to charge subscription fees, process overage charges, and manage your account.
- Comply with legal obligations. We process PHI and other sensitive data in compliance with HIPAA and other applicable privacy laws.
- Analyze and improve. We aggregate and anonymize usage data to understand how the Service is used and to improve quality, reliability, and performance.
- Prevent abuse. We use activity logs to detect and prevent fraud, spam, and violations of our Terms of Service.
We do not sell personal data.
3. How We Contact You: AI Calls, Automated Texts, and Email
If you book a call with us, request a demo or audit, submit a form on our website, or otherwise ask us to get in touch, we may contact you at the phone number and email address you provide. This section applies to Orbit's own communications with prospective and current customers; it is separate from the calls and texts our AI receptionist handles on behalf of our clients (described in Section 1).
3.1 How we may contact you
- Phone calls, including AI calls. Calls may be placed by our AI receptionist, which uses an artificial or AI-generated voice, or by a member of our team. Our AI identifies itself as AI.
- Text messages. Automated and manual text messages (SMS/MMS).
- Email. Automated and manual emails.
3.2 Why we contact you
- Booking and appointments: to confirm, remind you about, reschedule, or follow up on a call or meeting you booked with us, and to ask a few questions that help us prepare for it.
- Information you asked for: to respond to your inquiry or demo request and to show you how our AI receptionist works.
- Marketing: to tell you about Orbit Online's products, services, and offers.
3.3 Your consent and choices
- Consent. We place AI or automated calls and send automated texts based on the consent you give when you contact us, for example by ticking the consent box when you book a call or by submitting a form that asks us to call or text you. Consent is not a condition of buying anything from us. Where you tick a consent box, we keep a record of it, including the wording shown and the date and time.
- Opting out. Reply STOP to any text to stop texts; reply HELP for help. Tell us on any call that you don't want further calls, or email orbit@orbitonline.io, and we will stop. Emails include an unsubscribe link. We honor opt-out requests promptly and keep them on our internal do-not-contact list.
- Frequency and charges. Message frequency varies with your booking and requests. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
3.4 Recordings and AI processing
Our calls with you may be recorded and transcribed, and processed by AI systems to summarize the conversation, capture the answers you give (for example, to prepare for your booked call), and honor any request not to be contacted. We use this information only for the purposes described in this Privacy Policy.
3.5 Your mobile information
We do not sell, rent, or share your mobile phone number, text-messaging opt-in data, or consent with third parties or affiliates for their own marketing or promotional purposes. Text-messaging opt-in data and consent are excluded from every other sharing category in this Privacy Policy. We share your number only with the service providers that deliver our calls and messages on our behalf (see Section 4).
4. How We Share Information
We share information with third parties only as necessary to provide our services or comply with law:
4.1 Service Providers and Sub-processors
- AI and telephony providers. We use third-party services for voice AI, speech-to-text, text-to-speech, and telephony. We maintain Business Associate Agreements (BAAs) with providers that handle PHI.
- Cloud infrastructure. Our platform runs in a HIPAA-compliant cloud environment. Data is encrypted at rest and in transit.
- SMS and email delivery. We use third-party providers (e.g., Twilio for SMS, Resend for email) to deliver messages on your behalf.
- Payment processing. Stripe processes all payments. We do not store your full credit card information.
- Lead enrichment. When you use our lead search features, we query third-party data providers to retrieve publicly available business information.
- Website hosting. Client websites are hosted on managed platforms with appropriate security measures.
4.2 Advertising and Measurement Partners
We use advertising platforms such as Meta (Facebook and Instagram) and Google to show and measure our own ads. Our website uses the Meta Pixel and, where configured, Meta's Conversions API, which send information such as pages viewed, questionnaire completion, and booking events (and, for server-side events, a hashed, one-way encrypted version of your email or phone number) so we can measure which ads lead to bookings. We may also upload hashed contact information to these platforms to avoid showing ads to existing customers and to reach similar businesses (for example, "custom" or "lookalike" audiences). These features are governed by the platforms' business terms for these tools. Text-messaging opt-in data and consent are never shared for these purposes, and we do not sell personal data.
4.3 Practice Management and Other Integrations
When you connect our Service to a practice management system or other third-party tool, we only access and transmit the minimum necessary data to perform the requested tasks. We do not access financial ledger or insurance billing data.
4.4 Legal and Compliance
We may disclose information if required by law, in response to lawful requests by public authorities, or to protect our rights, property, or the safety of our users.
5. Data Security
We implement technical, administrative, and physical safeguards to protect personal data and PHI:
- Encryption: All data is encrypted in transit using TLS and encrypted at rest within our hosting environments.
- Access controls: Access to PHI and sensitive data is restricted to authorized personnel. Multi-factor authentication (MFA) is required for all administrative access.
- Audit logging: We maintain detailed logs of system activity and data access. Logs are reviewed periodically for anomalies.
- Network security: Our environments use firewalls, network security groups, and virtual networks. Only necessary ports are open.
- SOC 2: Our security practices are independently audited.
6. HIPAA Compliance
Orbit is HIPAA-compliant and enters into Business Associate Agreements (BAAs) with covered entities and business associates where required. If your use of the Service involves PHI, you must execute a BAA with Orbit. The BAA is available for electronic signature within the platform dashboard.
We implement the administrative, physical, and technical safeguards required by the HIPAA Security Rule. Our sub-processors that handle PHI are also bound by BAAs.
7. Data Retention
We retain personal data only for as long as necessary to provide the Service and fulfill our contractual and legal obligations:
- Active accounts: Data is retained for the duration of your subscription.
- After cancellation: Call recordings, transcripts, CRM data, and other account data is retained for 30 days after cancellation, then permanently deleted unless a longer retention period is required by law.
- Consent and opt-out records: Kept for as long as needed to show that you consented and to honor any request not to be contacted, even after other data is deleted.
- Aggregated data: We may retain anonymized and aggregated data indefinitely for analytics and service improvement.
You may request deletion of your data at any time by contacting us.
8. Cookies and Tracking Technologies
Our website uses the following cookies and tracking technologies:
- Essential cookies: Required for website functionality, session management, and security.
- Analytics cookies: Google Analytics tracks page views, user behavior, and site performance. This data is aggregated and does not identify individual users.
- Advertising cookies and pixels: The Meta Pixel and Google Ads conversion tracking measure the effectiveness of our advertising campaigns. They record when someone who saw or clicked one of our ads visits our site or completes an action such as finishing our questionnaire or booking a call, and may be used to show our ads to people who visited our site. You can adjust ad preferences in your Meta and Google account settings.
- Visit summary with your booking: On our marketing pages, your browser keeps a short summary of your visit, such as time on the page, how far it was scrolled, which buttons were tapped, how much of a video was played, how long our questionnaire took, and how many times you have visited. It uses a random identifier stored in your browser, not your name, and it does not include anything you type into a form field. The summary is only sent to us if you book a call: it is attached to your booking and saved as a note on your contact record in our CRM so our team can prepare for the conversation, and it is kept with that record until you ask us to delete it. If you do not book, it stays in your browser.
- Session replay and heatmaps (Microsoft Clarity): We partner with Microsoft Clarity and Microsoft Advertising to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay, so we can improve our site and services and market them. Website usage data is captured using first- and third-party cookies and other tracking technologies, and is also used for site optimization and fraud and security purposes. What you type into form fields is masked and not recorded. For more information about how Microsoft collects and uses your data, see the Microsoft Privacy Statement.
- Third-party embeds: Our website may embed third-party services (e.g., Cal.com for scheduling, chat widgets) that set their own cookies subject to their own privacy policies.
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect website functionality.
9. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access or obtain a copy of personal data we hold about you.
- Request correction or deletion of inaccurate information.
- Object to or restrict certain data processing.
- Request data portability (receive your data in a structured, machine-readable format).
- Opt out of marketing communications at any time.
- Request deletion of your account and associated data.
To exercise these rights, please contact us using the details in Section 12.
10. International Data Transfers
Our services are hosted in the United States. If you access the Service from outside the United States, your data may be transferred to and processed in the United States. We ensure appropriate safeguards (such as contractual clauses and encryption) are in place to protect transferred data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on our website, through the dashboard, or by email. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your data rights, please contact:
By using our Service, you acknowledge that you have read and understood this Privacy Policy.