Who we are
Orbit is a restaurant data tool made and run by The Modev Shop, LLC (“we”, “us”). This policy covers the Orbit web app at orbit.modevshop.com, the Orbit browser extension, and these Orbit web pages.
Orbit is used by restaurants (“restaurants” or “you”) and their staff. A restaurant decides which services to connect and what its guests' information is used for. For guest information, we act on the restaurant's behalf.
What we collect
Your account
When you sign in with Google we receive your name, email address, profile photo and whether Google has verified your email. We use these to create your Orbit account and to link it to the restaurants you belong to. Teams that use a shared team password have a sign-in session stored in the browser; we don't store the password in readable form.
Data from services a restaurant connects
Orbit only receives data from a service after someone at the restaurant connects it. The Connections page lists each one in detail.
| Service | What Orbit receives |
|---|---|
| Toast POS | Orders and items, menu names and prices, discounts and voids with reasons, payment type, servers, clocked hours, sections and tables. |
| Toast Tables | Reservations and waitlist entries, including the guest's name, email and phone number when the guest provided them, party size, date and status. |
| Scheduling (through Toast) | Scheduled shifts: employee, job, start and end. |
| QuickBooks Online | Company name, chart of accounts and profit-and-loss reports. |
| Google Analytics 4 | The list of GA4 properties the signed-in Google account can see, and daily totals for the chosen property (see Data from Google). |
| Google Ads | Daily ad cost, clicks and impressions by campaign, as reported through Google Analytics. |
| NOAA | Public daily weather data. No account involved. |
Orbit also stores the sign-in tokens these services issue, so it can keep syncing. They are encrypted; see Storage and security.
Guest information
Reservations and orders can include guests' names, email addresses, phone numbers, visit dates, party sizes and what they ordered. Orbit uses this to show a restaurant its own guests: who is new, who comes back, and who hasn't been in for a while. Orbit never contacts guests. Having a guest's contact details isn't permission to market to them, and Orbit doesn't treat it as such. If you are a guest, see Your choices.
The browser extension
The extension stores a device token that links it to one restaurant, and it fetches that restaurant's connection status from Orbit. It can only talk to Orbit's own server. It doesn't read the pages you visit, your browsing history, or the sign-ins you use for Toast, QuickBooks, Google or Meta. Removing the device in Orbit or uninstalling the extension ends the link.
Technical information
Our hosting providers keep standard server logs, such as IP address, time of request and the page or API called, to run and secure the service. These Orbit web pages don't use analytics, advertising cookies or tracking pixels. The Orbit app uses your browser's storage only to keep you signed in and remember simple settings.
How we use it
- To run Orbit: sync connected services, compute the restaurant's insights, and show them to the restaurant's team.
- To tell you when a connection needs attention.
- To keep Orbit secure, fix problems, and check that its numbers are correct.
- To build new insights for restaurants. Our team uses AI tools, including Anthropic's Claude, to review restaurant data and test new analyses. Research notes we keep leave out guests' names and contact details. Data received from Google APIs is not used for this.
- To respond to you and to meet legal obligations.
We don't sell personal information, use it for advertising, or share one restaurant's data with another restaurant.
Data from Google
Orbit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access. With Google sign-in: your name, email address and profile photo. When a restaurant connects Google Analytics, Orbit requests read-only access (the analytics.readonly scope) and receives the names and IDs of the GA4 properties the Google account can see, plus daily totals for the property the restaurant chooses: visits, new visitors and key events by channel and campaign, and Google Ads cost, clicks and impressions by campaign when Ads is linked to that property. These are totals; Orbit doesn't receive data about individual website visitors.
How we use it. Only to show that restaurant its own website and advertising results in Orbit, next to its other data, and to keep that connection working.
Who sees it. The restaurant's Orbit team. We don't sell it, use it for advertising, share it with other restaurants, or use it to develop, improve or train AI or machine-learning models. People at The Modev Shop, LLC don't read it except when the restaurant asks us to for support, when needed for security, or when the law requires it.
How it's protected. The Google access token is encrypted before it's stored. Report data is stored in Orbit's database, which only Orbit's server code can reach.
Keeping and deleting it. Disconnecting Google Analytics in Orbit revokes Orbit's access with Google and deletes the stored token straight away. You can also remove Orbit's access at myaccount.google.com/permissions. Daily totals already synced stay with the restaurant's data until the restaurant asks us to delete them or closes its account; we then delete them within 30 days.
Who we share it with
We share information only as needed to run Orbit:
- Service providers that host or run Orbit for us: Convex (database and server), Render (these web pages), Google (sign-in), and Anthropic (AI tools our team uses, as described above). They may only use the information to provide their service to us.
- Meta, only if a restaurant turns on booking events. Orbit then sends each new online reservation to Meta as an event, with the guest's email and phone number hashed before they leave Orbit. The restaurant is responsible for having the right to do this.
- The services a restaurant connects, when Orbit calls them to fetch that restaurant's data.
- When the law requires it, or to protect the rights, property or safety of our users, guests or us.
- In a sale or merger of Orbit, under a commitment that this policy continues to apply.
Storage and security
Orbit's data is stored in the United States. Connections use HTTPS. Sign-in tokens for connected services are encrypted with AES-256-GCM before they're stored, and disconnecting a service deletes its token. Orbit's pages and data are behind sign-in, and each restaurant's data is kept separate. No system is perfectly secure; if we learn of a breach that affects your information, we'll tell you and the affected restaurant as the law requires.
Keeping and deleting data
We keep a restaurant's data while it uses Orbit so that comparisons with past weeks and years work. When a restaurant closes its account or asks us to, we delete its data, including guest information and data from connected services, within 30 days, except records we must keep by law. Any backups are removed on their normal schedule after that. Server logs are kept by our hosting providers for a limited time for security.
Your choices
- Restaurants can switch any connection off, disconnect it, and ask us to export or delete their data.
- Team members can ask us for a copy of their account information, or to correct or delete it.
- Guests of a restaurant that uses Orbit can ask that restaurant, or us, to see, correct or delete their information. We'll work with the restaurant to respond.
Depending on where you live, you may have further rights under laws such as the California Consumer Privacy Act. Email us and we'll respond within 30 days. We won't treat you differently for asking.
Children
Orbit is a business tool and isn't meant for anyone under 16. We don't knowingly collect information from children.
Changes to this policy
If we change this policy, we'll update the date at the top. If a change affects how we use information we already have, we'll tell restaurants in Orbit or by email before it takes effect.
Contact
The Modev Shop, LLC
info@modevshop.com