Legal

Trust & Data Center

Last updated: August 5, 2026

This page is maintained by Orbit Advisory & Technology to answer the questions landlords, agents and tenants ask most often about how Orbit Property Portal handles data. It describes the controls that are enabled in the product today. It is not an independent audit, certification, or a guarantee — where you need contractual assurances, ask us for a written agreement.

1. Who holds your data

Orbit Property Portal is operated by Orbit Advisory & Technology. Your organization is the owner of every record you create — properties, units, tenants, leases, rent history, receipts, maintenance tickets, utility bills and uploaded documents.

We act as a processor of that data on your instructions. We do not sell it, rent it, or use it to build products for anyone else.

2. Where it is stored

Application data lives in a managed PostgreSQL database, and uploaded files live in managed object storage, both provisioned through our cloud hosting provider.

Data is encrypted in transit using HTTPS/TLS, and encrypted at rest by the hosting provider.

If your organization has a specific data-residency requirement — for example, records that must remain in a particular jurisdiction — contact us before onboarding so we can confirm what is possible for your account.

3. Who can see it

Every table is protected by row-level security scoped to your organization. Members of one organization cannot read another organization's records, even through the API.

Inside your organization, access is role-based: owner, admin, manager, property manager, finance and staff each see the surfaces relevant to their role.

Tenants who accept a portal invitation see only their own lease, rent history, receipts, utility shares and maintenance tickets.

Contractors invited to the job board see only the maintenance jobs assigned to them, through a single-purpose link — never your rent or tenant financial data.

A small number of authorised Orbit staff can access production systems for support and incident response. Administrative actions taken by platform staff are written to an audit log.

4. Sign-in and account security

Sign-in uses email and password, with sessions managed by our authentication provider. Passwords are never stored in plain text.

Self-service password reset is available from the sign-in page — you do not need to contact support to regain access.

Organization owners can add and remove members at any time from Settings, which immediately revokes access.

5. Subprocessors and integrations

Cloud hosting, database and file storage: our managed infrastructure provider.

Email delivery: our transactional email provider, used to send rent reminders, late notices, receipts and portal invitations from our own verified sending domain.

AI features: payment-screenshot parsing and rent risk scoring send only the minimum data needed for that single request to our AI provider. These requests are not used to train third-party models.

Calendar availability for booking a demo is read from Google Calendar for the Orbit team's own calendar only — it does not touch your portfolio data.

6. Email, notifications and opt-out

We send operational email only: rent reminders, late notices, receipts, portal invitations and account notices. Automated rent reminders and late notices are off until you switch them on in Settings, and you control the timing.

Every recipient can unsubscribe from non-essential email using the link in the footer of the message.

7. Retention, export and deletion

Your records are retained for as long as your organization is active.

You can export data at any time. Reports and Compliance produce CSV and print-ready exports; receipts and tax packs can be exported per year.

Deleting a record removes it from the app. Closing your organization removes your records within 30 days, except where we are required by law to retain them. Backups age out on their own retention cycle.

Non-payment never triggers deletion or transfer of your data. See the Terms of Service for the full commitment.

8. Reporting a security issue

If you believe you have found a vulnerability or a data-exposure issue, email alphalabtechnology1@gmail.com with the details and steps to reproduce. Please give us a reasonable window to investigate before disclosing publicly.

For privacy requests — access, correction, export or deletion — use the same address and tell us which organization you are writing about.

9. What we do not claim

Orbit is not currently certified against SOC 2, ISO 27001, PCI DSS or HIPAA, and we do not claim compliance with those frameworks.

Nothing on this page is legal, tax or accounting advice. Compliance and tax-pack features help you keep records and produce statements; confirm your obligations with your own accountant, attorney or revenue authority.

Questions about this document? Email alphalabtechnology1@gmail.com.