Last updated 6 August 2026
Privacy Policy
How Codigo Vision Inc. collects, uses, stores and protects your data — including data we access on your behalf from systems you connect, such as QuickBooks Online.
This policy explains what we collect, why we collect it, who we share it with, and the choices you have. It applies to the OrbitLoop web application, our APIs and command-line tools, and this website.
1. Who we are
OrbitLoop is a registered trade name of Codigo Vision Inc. OrbitLoop is a platform for planning, tracking, delivering and billing recurring client work. For the personal data our customers put into OrbitLoop, we act as a processor — our customer decides why and how that data is used. For account, billing and website data we act as a controller.
Questions, requests or complaints: privacy@orbitloop.com.
2. What we collect
Account data
Name, email address, password (stored only as a salted one-way hash), profile photo, organisation name, role and permissions, and the preferences you set.
Customer content
The working data you and your team enter or upload: clients, projects, tasks, comments, sprints, time entries, expenses, invoices, bills, payments, files and attachments. You own this content. We process it to run the service for you.
Connected-system data
If you connect an external system, we access data from it on your behalf and only with the scope you authorise. See section 5.
Technical and usage data
IP address, browser and device type, pages and features used, timestamps, and application and error logs. We use this to keep the service secure, diagnose faults and understand which features are used.
Billing data
Subscription plan, billing contact and invoice history. We do not receive or store full payment card numbers — card details are entered directly with our payment processor.
3. How we use data
- To provide, operate and maintain OrbitLoop and its features.
- To authenticate you and enforce permissions.
- To sync data with the external systems you have connected, at your instruction.
- To send service messages — invoices, notifications, security and account notices.
- To provide support, and to investigate and fix faults.
- To protect the service against abuse, fraud and security threats.
- To meet legal, tax and accounting obligations.
We do not sell personal data, and we do not share it for advertising. We do not use your customer content or connected-system data to train machine-learning models.
4. Legal bases
Where the UK/EU GDPR applies, we rely on: contract (to provide the service you signed up for), legitimate interests (security, fault diagnosis, service improvement, balanced against your rights), legal obligation (tax and accounting records), and consent where we ask for it — which you may withdraw at any time.
5. QuickBooks Online and other connected systems
OrbitLoop can connect to QuickBooks Online. The connection is made by you, through Intuit's OAuth 2.0 authorisation screen, and can be withdrawn by you at any time.
What we access
Only the QuickBooks accounting scope, and only the records the feature needs: customers, vendors, invoices, bills, payments, employees and time activities. We do not request payroll scopes, and we do not access bank feeds or credentials for your financial institutions.
Why we access it
Solely to provide the functionality you enabled: pushing OrbitLoop invoices, payments and contractor bills into QuickBooks, mirroring payments recorded in QuickBooks back onto the matching OrbitLoop records, and keeping customer and vendor names aligned between the two systems.
What we will not do
- We do not give any third party access to your QuickBooks data, whether by API or any other means.
- We do not export, save or store QuickBooks data for any purpose other than the functional use of OrbitLoop described above.
- We do not sell QuickBooks data, and we do not use it for advertising.
How the connection is secured
Your OAuth access and refresh tokens are encrypted at rest using AES-based authenticated encryption, with the encryption keys held separately from the database. Tokens are never shown in the application interface, never written to logs, and never shared. All traffic to Intuit runs over TLS.
Disconnecting
You can disconnect QuickBooks at any time from the integration settings in OrbitLoop, or from the Apps area of your QuickBooks company. On disconnect we revoke the tokens and stop all syncing. Records already created in OrbitLoop stay in OrbitLoop, and records already created in QuickBooks stay in QuickBooks — disconnecting stops future syncing, it does not delete history. To have the retained data deleted, contact us (see section 10).
6. Artificial intelligence features
OrbitLoop includes an assistant that can answer questions about your workspace and carry out actions you ask for. When you use it, the relevant portion of your workspace data — which may include invoice records that are also synced with QuickBooks — is sent to our AI sub-processor to generate a response.
That data is sent only to produce your answer, and it is not used to train models. The assistant sends nothing on its own: no scheduled or background job transmits your workspace data. It moves only when a person asks it something.
Connecting your own AI tools
OrbitLoop also publishes an MCP server, which lets you connect your own AI client — Claude Desktop, Cursor or similar — to your workspace using a token you generate. If you do that, that client reads tasks, projects, time entries, sprints and tags directly.
This is a connection you make, to a vendor you choose, and your agreement with that vendor governs what they do with the data. We are not a party to it and we cannot control it. You can revoke the token at any time from your OrbitLoop settings.
7. Sub-processors
We use a small number of vendors to run the service. Each is bound by contract to protect your data:
- Amazon Web Services — hosting, database, file storage and outbound email (United States).
- Anthropic — the AI assistant described in section 6 (United States).
- Stripe — subscription billing and card processing (United States).
- Intuit — where you have connected QuickBooks Online (United States).
- Google — analytics for the public marketing pages only, as described in section 12 (United States).
We will give notice before adding a sub-processor that materially changes how your data is handled.
8. International transfers
Our infrastructure is hosted in the United States. If you are in the UK, EU or elsewhere, your data is transferred to the United States under appropriate safeguards, including standard contractual clauses where required.
9. Security
- All traffic is encrypted in transit with TLS; HTTPS is enforced across the service.
- Integration credentials and API tokens are encrypted at rest with AES-based encryption.
- Passwords are stored only as salted one-way hashes, never in plain text.
- Access to production systems is restricted, authenticated and logged.
- Session cookies are marked
SecureandHttpOnly. - We do not log user credentials or the contents of connected accounting records.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any regulator as required by law, without undue delay.
10. Retention and deletion
We keep customer content for as long as your account is active. After termination we keep it for at least 30 days so you can still retrieve it, and we delete it on request — except where we must keep records longer for legal, tax or accounting reasons.
You can request deletion at any time by writing to privacy@orbitloop.com. We action deletion requests within 30 days.
Encrypted backups are kept on a short rolling cycle for disaster recovery. Deleted data disappears from backups as that cycle turns rather than at the moment of deletion.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to receive a portable copy, and to withdraw consent. California residents have the right to know what is collected and to opt out of “sale” or “sharing” — neither of which we do.
Write to privacy@orbitloop.com. We respond within 30 days. We will not discriminate against you for exercising a right. If you are unsatisfied, you may complain to your local data protection authority.
If your data was entered into OrbitLoop by an organisation using the service, we will refer your request to them, as they control that data.
12. Cookies and analytics
Inside the OrbitLoop application we use only cookies that are strictly necessary to sign you in and keep your session secure. We set no advertising or cross-site tracking cookies anywhere, and we do not sell or share your data for advertising.
These public marketing pages — the ones you are reading now, not the signed-in application — use Google Analytics to understand which pages and which buttons are useful. It sets a couple of cookies in your browser and records the pages you visit, the links and buttons you click and their labels, roughly where you arrived from, general details about your device and browser, and whether you went on to submit the contact form. It answers questions like “does anyone click the pricing button” — not to build a profile of you, and never to identify you personally. We do not record anything you type, and the contact form’s contents are not sent to Google. Google processes this information as a service provider; their handling of it is covered by Google’s own privacy policy.
You can block cookies in your browser, though the application will not function without the essential ones.
13. Children
OrbitLoop is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
14. Changes to this policy
We may update this policy as the service changes. The “last updated” date at the top always reflects the current version. For material changes affecting your rights we will give notice by email or in the application before they take effect.
15. Contact
Codigo Vision Inc. — privacy@orbitloop.com. You can also reach us through our contact page.
See also our Terms of Service.