Effective Date: July 31, 2026
Orca ("we," "our," or "us") provides a cross-platform in-app purchase infrastructure SDK and related services (the "Service"). We value the privacy of the developers who use our Service ("Customers") and the end-users of their applications ("End Users").
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use the Orca SDK.
When you register for a Orca account, we act as a Data Controller and collect:
When a Customer integrates the Orca SDK into their application, we act as a Data Processor. We collect data necessary to validate receipts and manage entitlements:
Important: We do not collect or store End Users' raw credit card numbers or banking credentials. These are handled exclusively by the underlying platform providers (Apple, Google, Stripe, GoCardless, etc.).
When a Customer connects AI agents or LLM assistants to Orca's built-in Model Context Protocol (MCP) Server:
We use the collected data for the following purposes based on the associated legal bases (GDPR Art. 6):
We use cookies and similar tracking technologies (like web beacons and tags) to track the activity on our Service and hold certain information.
We do not sell personal data. We share data only with trusted third-party service providers ("Sub-Processors") strictly necessary to maintain our edge infrastructure, process payments, and deliver our services:
We may also disclose information if required by law, such as to comply with a valid court order, subpoena, or regulatory audit.
Orca operates a globally distributed edge gateway architecture. Data collected may be processed in the United States, Europe, or other global edge nodes. We comply with GDPR requirements for cross-border data transfers by utilizing the EU-U.S. Data Privacy Framework (DPF), the UK Extension, and Standard Contractual Clauses (SCCs) to ensure data remains protected to European Union standards regardless of processing location.
You can access, update, export, or delete your account information directly from the Orca Dashboard. If you request full organization deletion, all associated project data is permanently purged within 30 days.
Since Orca acts as a Data Processor for End User entitlement data, End Users exercising rights under GDPR (Art. 17 Right to Erasure) or CCPA should contact the app developer (our Customer) directly. Orca provides dedicated REST API endpoints (/v1/customers/{id}/purge) enabling developers to programmatically trigger complete End User data erasure across all global gateways within 24 hours.
Orca does not engage in automated individual decision-making, credit scoring, or profiling that produces legal or significant effects for End Users.
We do not "sell" or "share" personal information for cross-context behavioral advertising as defined by the California Consumer Privacy Act. You have the right to request disclosure of data practices and non-discriminatory service access.
Our Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us so that we can take necessary actions.
We implement industry-standard security measures, including encryption in transit (TLS 1.3) and encryption at rest (AES-256), to protect your data. However, no method of transmission over the Internet is 100% secure.
We retain transaction data for as long as the Customer's account is active to ensure continued access to entitlements (e.g., restoring a "Lifetime" purchase made 3 years ago). If a Customer deletes their account, we delete all associated End User data within 30 days.
If you have questions about this Privacy Policy, please contact our Data Protection Officer at:
Email: privacy@maxint.com
Address: 1875 Mission St Ste 103 # 180, San Francisco, CA 94103