Effective Date: June 1, 2026 · Orbitlex LLC
Orbitlex LLC ("Orbitlex," "we," "our," or "us") respects your privacy and is committed to protecting the information you share with us.
This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit our website, interact with our services, submit information through our forms, communicate with us, or otherwise engage with Orbitlex.
Orbitlex provides compliance-related operational and informational services for U.S. Extended Producer Responsibility (EPR) programs and related packaging compliance matters. Our Services are designed for businesses operating in U.S. markets; we do not actively target or serve consumers or non-U.S. residents.
This Privacy Policy applies to information collected through: our website and related pages; contact and assessment forms; scheduling tools; communications with our team; customer onboarding workflows; operational and compliance-related submissions; and third-party integrations and service providers used in connection with our services.
This Privacy Policy does not constitute legal advice and should not be interpreted as creating any attorney-client relationship.
We collect the following categories of personal information ("PI"). Categories are mapped to the framework used under the California Consumer Privacy Act ("CCPA") and similar U.S. state privacy laws.
A. Identifiers. Name, business name, job title, business email address, business phone number, IP address, account identifiers, and similar.
B. Commercial Information. Records of services requested or purchased, billing information, payment-related metadata (full card details are not collected; payment processing is handled by Stripe, see §9), and related transactional records.
C. Internet or Network Activity Information. Information automatically collected when you access the website, including IP address, browser type and version, device information, operating system, pages viewed, referring URLs, interaction data, session information, approximate geographic location derived from IP, and website performance and diagnostic data. Collected through cookies and similar technologies; see §3.
D. Professional or Employment-Related Information. Job title, business affiliation, and similar professional context information you provide during sign-up, assessment, or engagement.
E. Customer-Provided Operational Information. Information you submit in connection with compliance engagements, including SKU-level information, packaging specifications, material composition data, supplier information, sales geography information, shipment or distribution information, operational records, documents and attachments, and communications and correspondence. This information primarily concerns business operations rather than identified individuals.
F. Inferences. Limited inferences derived from the above categories — for example, segmentation of which Services may be relevant to a customer — used only for legitimate business purposes.
No Sensitive Personal Information. Orbitlex does not seek or knowingly collect "Sensitive Personal Information" as defined under CPRA (including precise geolocation, government identifiers, financial account credentials, racial or ethnic origin, religious or philosophical beliefs, mail or message contents, genetic or biometric data, health information, or sex life or sexual orientation), beyond what may incidentally appear in routine business contact details. Customers should not transmit Sensitive Personal Information to Orbitlex.
Sources of Information. We collect PI directly from you (forms, communications, uploads), automatically (cookies, analytics — see §3), and from third parties (payment processors, analytics providers, scheduling platforms, CRM systems, publicly available sources, and compliance databases).
We may use PI for the following business and commercial purposes: providing and managing the Services; preparing compliance assessments and reports; customer onboarding and account management; communicating with prospective and existing customers; scheduling meetings and consultations; processing transactions and payments; maintaining operational records; improving our website, workflows, and Services; conducting analytics and performance measurement; troubleshooting and security monitoring; complying with legal, tax, accounting, and regulatory obligations; protecting our legal rights and business interests; preventing fraud or misuse of our systems; and sending operational, transactional, and service-related communications.
We may use artificial intelligence and automation tools in support of these purposes; see §10.
We use cookies and similar technologies on our website. Cookies are grouped as follows:
A. Strictly Necessary. Required for the website to operate, including session management, security, and load balancing.
B. Performance / Analytics. Used to measure website performance and aggregate usage patterns. Providers: Google Analytics 4 (Google LLC), Microsoft Clarity (Microsoft Corporation). For attribution, we also store your first-visit source (such as the referring site or search engine, and the page you first landed on) in your browser's local storage, and the Status Check form optionally asks how you heard about Orbitlex. This uses no additional tracker and no third party.
C. Functional. Used to support specific features such as form submission and scheduling. Providers: Web3Forms, Calendly, Brevo (Sendinblue SA).
D. Advertising / Marketing. Orbitlex does not use advertising, marketing, or cross-context behavioral advertising cookies or tags.
You may manage cookies through your browser settings or by clearing site cookies. Most browsers allow you to block, delete, or restrict cookies on a per-site basis.
Global Privacy Control (GPC). Where applicable, we recognize and honor GPC browser signals as a request to opt out of "sale" or "share" of PI for cross-context behavioral advertising under applicable U.S. state privacy laws.
"Sale" and "Share." Orbitlex does not sell PI for monetary or other valuable consideration, and does not share PI for cross-context behavioral advertising as defined under the California Consumer Privacy Act, as amended by the CPRA. We honor Global Privacy Control (GPC) browser signals as a request to opt out of any such sale or sharing.
We may disclose PI in the following circumstances:
A. Service Providers. Vendors, contractors, and service providers that help us operate, under contractual confidentiality / data-processing obligations. Categories include payment processors, scheduling platforms, CRM providers, cloud hosting providers, analytics providers, email and communication providers, automation platforms, AI and document processing providers, and workflow and database providers. See §9 for a representative provider list.
B. Compliance and Legal Requirements. We may disclose PI to comply with applicable law or legal process, to respond to lawful requests by public authorities, to enforce our agreements and policies, or to protect our rights, property, systems, or users.
C. Business Transactions. PI may be disclosed in connection with mergers, acquisitions, financing transactions, asset sales, corporate restructuring, or due diligence processes, subject to appropriate confidentiality protections.
D. With Your Direction. We may share PI when you instruct or authorize us to do so — for example, when we file or correspond with a Producer Responsibility Organization (PRO) or state agency on your behalf under an engagement.
We retain PI for as long as reasonably necessary to fulfill the purposes described in this Policy or as required or permitted by applicable law. Indicative retention criteria by category:
Account and engagement records (Customer contact data, contracts, deliverables): duration of the engagement plus approximately seven (7) years for tax, audit, and dispute-resolution purposes.
Billing and transactional records: approximately seven (7) years (tax / accounting record-keeping).
Customer-provided operational data (packaging, SKU, supplier records): duration of the engagement; archived in deliverables; deletion on documented Customer request, subject to legal/audit retention.
Analytics and website usage data: provider default (e.g., Google Analytics 4 default of fourteen (14) months) unless adjusted.
Marketing-list data: until Customer unsubscribes plus a reasonable suppression-list period.
Communications and correspondence: approximately seven (7) years.
Security and audit logs: approximately two (2) years.
We may retain PI longer where required by law, regulation, or legitimate business purpose (for example, ongoing legal hold). Specific retention periods may be set forth in a separate engagement agreement or service-specific schedule.
We implement commercially reasonable administrative, technical, and organizational measures designed to help protect PI, including:
— Transport-layer encryption (TLS / HTTPS) for data in transit between your browser and our website and service providers.
— Access controls limiting PI access to personnel and contractors with a legitimate need.
— Reliance on Stripe, Inc. for payment processing; Orbitlex does not store full payment card details.
— Use of established cloud and SaaS providers with their own commercially reasonable security postures.
— Reasonable measures to prevent unauthorized access, loss, or alteration of PI.
No method of transmission over the internet or method of electronic storage is completely secure. Accordingly, we cannot guarantee absolute security. You are responsible for using appropriate caution when transmitting sensitive or confidential information electronically.
Security Incident Notification. In the event of a confirmed unauthorized acquisition of PI affecting you, Orbitlex will provide notice consistent with applicable U.S. state breach-notification laws.
Depending on your jurisdiction, you may have certain rights regarding your PI, including rights to: request access to PI we hold about you; request correction of inaccurate PI; request deletion of PI; object to or limit certain processing activities; opt out of certain marketing communications; opt out of "sale" or "share" of PI for cross-context behavioral advertising (see §4 and §8); request portability of certain PI where applicable; and appeal a privacy decision we make.
To exercise applicable privacy rights, contact us at privacy@orbitlex.com. We may need to verify your identity before responding to certain requests. Certain rights may be limited by law, regulatory requirements, security obligations, contractual obligations, or legitimate business purposes. We will respond to verified consumer requests within the timeframes required by applicable law (typically forty-five (45) days under CCPA, with one extension permitted where reasonably necessary).
Residents of certain U.S. states have additional privacy rights under applicable state privacy laws, including (subject to applicability thresholds and exemptions) the laws of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Iowa, New Jersey, Delaware, New Hampshire, Kentucky, Florida, Indiana, Minnesota, Maryland, and other states with similar comprehensive privacy laws as enacted.
Categories of PI Collected and Business Purposes. The categories of PI we collect, and the business or commercial purposes for which we use them, are described in §1 and §2 above. We do not collect, and do not knowingly receive, Sensitive Personal Information beyond what may incidentally appear in routine business contact details (see §1).
Categories Disclosed. We disclose categories A–E (Identifiers, Commercial Information, Internet/Network Activity, Professional Information, Customer-Provided Operational Information) to the categories of service providers described in §4(A) and §9, under contractual confidentiality / data-processing obligations.
No Sale or Share. Orbitlex does not sell PI for monetary or other valuable consideration, and does not share PI for cross-context behavioral advertising as defined under CPRA. We honor Global Privacy Control browser signals where applicable.
Retention. Retention criteria by category are described in §5.
Privacy Rights. Eligible residents may have rights to know, access, correct, delete, port, limit use of Sensitive Personal Information (where applicable), opt out of "sale" or "share," opt out of profiling in furtherance of decisions producing legal or similarly significant effects (where applicable), and appeal denied privacy decisions. To submit a request, contact privacy@orbitlex.com.
Authorized Agents. California residents may designate an authorized agent to submit privacy requests on their behalf. The authorized agent must provide signed written authorization from the consumer; Orbitlex may require the consumer to verify their identity directly or confirm that they provided the agent with written authorization.
Appeals. If we deny your privacy request in whole or in part, you may appeal that decision by replying to our denial response or by emailing privacy@orbitlex.com with the subject line "Privacy Appeal." We will respond to appeals within the timeframes required by applicable law (typically forty-five (45) to sixty (60) days, depending on jurisdiction). If the appeal is denied, you may have the right to contact your state's Attorney General.
Orbitlex may update its practices as state privacy laws evolve.
Our operations may involve third-party service providers, software platforms, integrations, APIs, databases, automation systems, AI technologies, communication providers, analytics providers, and workflow tools. These providers may support functions including payment processing; scheduling and customer communications; form processing; analytics and website performance monitoring; CRM and customer relationship management; workflow automation; document storage and productivity management; cloud infrastructure and hosting; compliance research and operational support; and AI / language model services.
Representative providers currently in use or potentially used include: Stripe (payment processing), Calendly (scheduling), Brevo / Sendinblue (email and marketing automation), Web3Forms (form processing), Google (Google Analytics 4), Microsoft (Clarity), Cloudflare (hosting / CDN), Anthropic and OpenAI (AI / language model services under enterprise / API terms), and similar business service providers. Specific providers in use at any given time may evolve.
Third-party providers operate under their own terms and privacy policies. Orbitlex is not responsible for the independent privacy or security practices of third-party services.
Payment Processing. Payment transactions are processed by Stripe, Inc. Orbitlex does not store or have access to your full payment card details. When you make a purchase, your payment information is transmitted directly to Stripe and handled in accordance with Stripe's Privacy Policy, available at stripe.com/privacy. Stripe may collect information such as your email address, billing information, IP address, and device data as part of the payment process.
AI Providers. Where we use third-party AI / language model providers (such as Anthropic and OpenAI) to support internal operations and Service delivery, we do so under their commercial / enterprise / API terms, which generally provide that customer content submitted via API is not used to train provider models. Customers should nevertheless avoid transmitting Sensitive Personal Information through any Orbitlex channel.
Orbitlex may use artificial intelligence, machine learning, automation systems, and language model technologies to support internal operations and service delivery. These technologies may assist with document analysis, data organization, workflow automation, compliance review support, drafting assistance, operational summarization, and internal productivity and reporting.
You should avoid submitting highly sensitive personal information unless specifically requested and necessary for service delivery. Orbitlex does not use automated systems to make legally binding decisions regarding consumers.
Our website and Services are intended for businesses and professionals. They are not directed to minors. We do not knowingly collect personal information from individuals under 18 years of age. If we become aware that such information has been collected, we will take reasonable steps to delete it.
This Privacy Policy is intended for residents of the United States and businesses operating in U.S. markets. Orbitlex operates primarily in the United States and our Services are designed for U.S. compliance support (see Terms of Service §2, Geographic and Regulatory Scope).
Orbitlex does not target, market to, or actively serve residents of the European Union, the United Kingdom, the European Economic Area, or other jurisdictions whose data-protection laws (such as the EU General Data Protection Regulation, the UK GDPR, and similar regimes) may impose additional obligations. To the extent residents of such jurisdictions access our website or communicate with us, your information will be processed in the United States under U.S. law and this Policy. We do not make any representation as to compliance with the GDPR, UK GDPR, PIPEDA, or other non-U.S. data-protection regimes.
By using our website or Services, you understand that information may be transferred to, processed in, and stored in the United States or other jurisdictions where our service providers operate, and you consent to such transfers subject to applicable law.
You may opt out of receiving marketing or promotional emails by using the unsubscribe link included in such communications or by contacting us directly. Even if you opt out of marketing communications, we may still send operational, transactional, or service-related communications.
Marketing emails sent by Orbitlex include a working unsubscribe mechanism, our legal name, a postal contact address, and other disclosures required by the CAN-SPAM Act (15 U.S.C. §7701 et seq.) and similar applicable U.S. state laws.
We may update this Privacy Policy from time to time. When changes are made, we will revise the "Effective Date" at the top of this page.
For material changes affecting active customers, we will provide reasonable advance notice by email to the address associated with the customer account, allowing customers an opportunity to review the updated Policy before continuing to use the Services.
Continued use of our website or Services following updates constitutes acceptance of the revised Privacy Policy.
If you have questions about this Privacy Policy or our privacy practices, you may contact:
Orbitlex LLC
2800 N 6th Street, Suite 7750
Saint Augustine, FL 32084
USA
General Inquiries: hello@orbitlex.com
Privacy Requests: privacy@orbitlex.com
Legal Notices: legal@orbitlex.com