Orbit is the revenue and relationship system that VG Tech Consulting ("we"), a
Singapore-based consultancy, uses to run its business. Our team and invited client
workspaces use it, and AI agents acting for other businesses can reach us through it.
This policy covers the Orbit web app at orbit.vgtc.io, the Orbit MCP
connector used from AI assistants such as Claude, agent-to-agent conversations, and
the Orbit Capture browser extension. We handle personal data in line with Singapore's
Personal Data Protection Act 2012 (PDPA).
01Whose data this is
Each Orbit workspace belongs to the organization it was set up for. Records in a workspace (companies, people, conversations, notes, reminders) are entered, captured, or imported by that workspace's users. We process them only to provide Orbit to that organization. Workspaces are isolated from each other.
02What we collect
- Account data: your name, email address, a hashed password, and the workspace you belong to.
- Workspace content: the records you and your teammates create, capture, import, or sync from connected mailboxes.
- Connector and API data: OAuth client registrations, hashed access and refresh tokens, hashed API keys, and an audit log of which user or agent made each change.
- Agent conversations: messages that external agents send us, the identity and organization they state, and timestamps.
- Operational data: server logs (IP address, request path, timestamps, errors) and usage counts for rate limiting.
Orbit uses one session cookie to keep you signed in. It uses no advertising or third-party analytics cookies.
03The Orbit MCP connector
When you connect Orbit to an AI assistant, you sign in to Orbit and approve access to one
named workspace. The assistant receives an access token (scope orbit:full) that acts as you in
that workspace. It can read, create, update, and delete records there, and every change is recorded under your name.
What Orbit returns is then processed by the assistant's provider under that provider's own terms and privacy policy. We see the tool calls the assistant makes to Orbit, not your conversation with it.
You can revoke access at any time by disconnecting the connector. Access tokens expire after an hour, and each refresh token works only once.
04Agent-to-agent conversations
Orbit lets AI agents acting for other businesses find the services VG Tech Consulting publishes and start a conversation with us. When an agent does, we keep what it sends and the identity it presents, and use them to reply, assess fit, and follow up, as we would with an email enquiry.
Please do not have an agent send us sensitive personal data. If an agent contacted us for you and you want that record removed, email alex@vgtc.io.
05The Orbit Capture extension
- When you click the extension icon, it reads the active tab to pre-fill name, title, company, emails, phone, and links. It does not read other tabs.
- On LinkedIn profile and company pages and on WhatsApp Web, it also reads the open tab in the background and asks your Orbit server whether that person or organization is already recorded, so it can show a toolbar badge. Nothing is saved until you click save.
- On WhatsApp Web, the messages visible in the open chat are sent to Orbit only if you tick the option to log them.
- Captured data goes over HTTPS only to your configured Orbit server (default
https://orbit.vgtc.io). - Your session token and settings are kept in
chrome.storage.localand cleared when you sign out. Uninstalling the extension removes them. - Permissions:
activeTabandscriptingto read the current tab on request,storagefor settings, and host access to your Orbit server,linkedin.comandweb.whatsapp.comfor the badge. Any other host is requested only if you point the extension at a self-hosted Orbit server.
06Service providers
These providers help us run Orbit. Optional features send data only when a workspace turns them on. Some providers process data outside Singapore. Where they do, we require protection comparable to the PDPA.
| Provider | Purpose | When |
|---|---|---|
| DigitalOcean | Hosting and database | Always |
| OpenAI | Research agents, answers to questions asked of Orbit, and search embeddings | When AI features are used |
| Apollo, People Data Labs, Prospeo, Dropcontact | Contact and company enrichment | When a workspace runs enrichment |
| Zoho Mail or another IMAP provider | Mailbox sync | When a workspace connects a mailbox |
| Meta (WhatsApp Business) | Message ingest | When a workspace connects WhatsApp |
We do not sell personal data or share it for advertising.
07Security
All traffic uses HTTPS. Passwords, API keys, and OAuth codes and tokens are stored as hashes. Stored mailbox credentials are encrypted with AES-256-GCM. OAuth uses PKCE (S256) with single-use authorization codes.
08Retention and deletion
Workspace content is kept until a workspace user deletes it or the workspace is closed. When a workspace is closed, we delete its data within 90 days, including from backups. Server logs are kept for 90 days.
To delete your account or workspace, or to get a copy of your data, email alex@vgtc.io.
If your details are in someone else's Orbit workspace, that organization controls the record, so contact them first. If you cannot reach them, email us and we will pass your request on.
09Your rights
Under the PDPA you can ask to access or correct your personal data, and withdraw consent to its use. Depending on where you live, you may also have rights to deletion, portability, or to object to processing. Email alex@vgtc.io. We reply within 30 days.
10Changes
We post changes on this page and update the date at the top. We email workspace admins before a material change takes effect.
11Contact
VG Tech Consulting, Singapore. Data protection contact: alex@vgtc.io.
