Privacy Policy
Last updated: 2026-08-14
1. Data Controller
The controller of personal data processed via Orbilyn is:
REMIGIUS Tomasz Karkoszka
NIP: PL6462625370
Contact: Contact page
2. What data we process
Depending on how you use the Service, we may process:
- email and account data (login via Supabase Auth),
- data you enter in the platform (file imports, product data, integration settings, comparison results, and account settings),
- technical data (IP-derived hash, browser/device metadata, timestamps),
- analytics and usage data where configured,
- billing-related data (for example the account email linked to payment, and customer/subscription/transaction identifiers at our Merchant of Record) when you use a paid package.
3. Purposes and legal bases (GDPR)
- service operation and security (Art. 6(1)(f) GDPR – legitimate interest),
- handling your requests and providing the B2B platform, including paid packages (Art. 6(1)(b) and (f) GDPR),
- fraud/spam prevention (Art. 6(1)(f) GDPR),
- analytics and product improvement (Art. 6(1)(f) GDPR),
- legal obligations, where applicable (Art. 6(1)(c) GDPR).
4. Recipients and processors
We use trusted processors and infrastructure providers, including: Supabase (database/auth), hosting and CDN providers, email providers, and — for paid packages — Paddle as Merchant of Record (payments, buyer documents, eligible refunds). We may also use analytics providers configured in the Service.
5. Data retention
We keep personal data only as long as necessary for the purposes above, or as required by law. Moderation and security-related records may be kept longer where needed to prevent abuse and protect the Service. Billing data held by Paddle is also subject to Paddle’s policies and retention periods.
6. Cookies and similar technologies
The Service may use cookies/local storage that are necessary for operation, authentication, security, and analytics. You can manage cookies in your browser settings.
7. Your rights
Subject to GDPR, you may request access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interest. You also have the right to lodge a complaint with a competent supervisory authority.
8. International transfers
If data is transferred outside the EEA, we use appropriate safeguards (for example SCCs or equivalent mechanisms required by law).
9. Contact
For privacy-related requests, use the Contact page (subject: Privacy / GDPR).

