Privacy Policy

Effective Date: July 31, 2026

1. Introduction

Orca ("we," "our," or "us") provides a cross-platform in-app purchase infrastructure SDK and related services (the "Service"). We value the privacy of the developers who use our Service ("Customers") and the end-users of their applications ("End Users").

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use the Orca SDK.

2. Information We Collect

2.1 Information from Developers (Customers)

When you register for a Orca account, we act as a Data Controller and collect:

  • Identity Data: Name, email address, GitHub username, or organization name.
  • Billing Data: Credit card details (processed securely via Stripe) and billing address for SaaS fees.
  • Technical Data: API keys, organization settings, and IP addresses used to access the dashboard.

2.2 Information from End Users

When a Customer integrates the Orca SDK into their application, we act as a Data Processor. We collect data necessary to validate receipts and manage entitlements:

  • Transaction Data: Purchase receipts, transaction IDs, product IDs, and purchase timestamps from app stores (Apple App Store, Google Play, Stripe, GoCardless, Microsoft Store, etc.).
  • Device Data: Generalized device model, operating system version, and platform (e.g., "iOS 17.0", "Windows 11", "Linux 6.8") to ensure SDK compatibility.
  • App User IDs: The unique identifier generated by the Customer to link a specific user to an entitlement.
  • Usage Data: Anonymized interactions with paywalls (if A/B testing is enabled).

Important: We do not collect or store End Users' raw credit card numbers or banking credentials. These are handled exclusively by the underlying platform providers (Apple, Google, Stripe, GoCardless, etc.).

2.3 AI & Model Context Protocol (MCP) Server Integration

When a Customer connects AI agents or LLM assistants to Orca's built-in Model Context Protocol (MCP) Server:

  • Scope of MCP Operations: AI agents operate strictly under Customer-managed API tokens to perform entitlement checks, query subscription validity, or automate customer support workflows.
  • No AI Model Training: Transaction and entitlement data processed through Orca's MCP Server is never sold, shared, or used to train third-party machine learning or artificial intelligence models.

3. How We Use Your Information

We use the collected data for the following purposes based on the associated legal bases (GDPR Art. 6):

  • Service Provision (Contractual Necessity): To validate purchase receipts, calculate taxes, sync entitlements across devices, serve remote configuration, and process MCP server queries.
  • Analytics (Legitimate Interest): To provide Customers with dashboards showing Monthly Recurring Revenue (MRR), churn, and retention cohorts.
  • Infrastructure Monitoring (Legitimate Interest): To detect fraud, debug SDK errors, and ensure the uptime of our API.
  • Communication (Consent/Legitimate Interest): To send Customers technical notices, updates, and security alerts.

4. Cookies and Tracking Technologies

We use cookies and similar tracking technologies (like web beacons and tags) to track the activity on our Service and hold certain information.

  • Essential Cookies: Necessary for the dashboard to function (e.g., session management).
  • Analytics Cookies: We use tools like PostHog to understand how developers navigate our documentation and dashboard. You can opt-out of these via your browser settings.

5. Data Sharing and Sub-Processors

We do not sell personal data. We share data only with trusted third-party service providers ("Sub-Processors") strictly necessary to maintain our edge infrastructure, process payments, and deliver our services:

  • Hosting & Edge Network: Cloudflare (Pages & Edge Workers), Amazon Web Services (AWS)
  • Database & Data Storage: PostgreSQL (Data Storage)
  • Payment Processors: Stripe (Web & SaaS Billing), GoCardless (European Direct Debit)
  • Communications: UseSend (Transactional Emails & Newsletter Subscriptions)
  • Analytics & Diagnostics: PostHog (Anonymized Dashboard & Documentation Analytics)

We may also disclose information if required by law, such as to comply with a valid court order, subpoena, or regulatory audit.

6. International Data Transfers

Orca operates a globally distributed edge gateway architecture. Data collected may be processed in the United States, Europe, or other global edge nodes. We comply with GDPR requirements for cross-border data transfers by utilizing the EU-U.S. Data Privacy Framework (DPF), the UK Extension, and Standard Contractual Clauses (SCCs) to ensure data remains protected to European Union standards regardless of processing location.

7. Your Data Rights & Erasure API

For Developers (Customers)

You can access, update, export, or delete your account information directly from the Orca Dashboard. If you request full organization deletion, all associated project data is permanently purged within 30 days.

For End Users & Automated Erasure API

Since Orca acts as a Data Processor for End User entitlement data, End Users exercising rights under GDPR (Art. 17 Right to Erasure) or CCPA should contact the app developer (our Customer) directly. Orca provides dedicated REST API endpoints (/v1/customers/{id}/purge) enabling developers to programmatically trigger complete End User data erasure across all global gateways within 24 hours.

No Automated Profiling (GDPR Art. 22)

Orca does not engage in automated individual decision-making, credit scoring, or profiling that produces legal or significant effects for End Users.

California Residents (CCPA/CPRA)

We do not "sell" or "share" personal information for cross-context behavioral advertising as defined by the California Consumer Privacy Act. You have the right to request disclosure of data practices and non-discriminatory service access.

8. Children's Privacy

Our Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us so that we can take necessary actions.

9. Security

We implement industry-standard security measures, including encryption in transit (TLS 1.3) and encryption at rest (AES-256), to protect your data. However, no method of transmission over the Internet is 100% secure.

10. Data Retention

We retain transaction data for as long as the Customer's account is active to ensure continued access to entitlements (e.g., restoring a "Lifetime" purchase made 3 years ago). If a Customer deletes their account, we delete all associated End User data within 30 days.

11. Contact Us

If you have questions about this Privacy Policy, please contact our Data Protection Officer at:

Email: privacy@maxint.com
Address: 1875 Mission St Ste 103 # 180, San Francisco, CA 94103