Legal

AI Assistant Data Terms

Version 2026-08-31

You accept these terms when you connect an AI assistant to a store. They sit alongside the AI Features Addendum and the Data Processing Addendum.

Before you connect

Orbit lets you connect an AI assistant to a store so it can read what you allow and make the changes you allow. That is a real handover of access, so we show you these terms on the approval screen and record which version you agreed to and when. You can see that record next to the connection in your dashboard at any time.

This page is the same text, published so you can read it before you start. The approval screen is where you accept it.

1. What the assistant can see and do

The assistant works with the permissions you tick on this screen. It can read whatever those permissions cover, and it can make the changes they allow. Nothing is hidden from it inside a permission you grant.

The company that runs your assistant processes everything the assistant reads. That includes order details and customer details if you grant those permissions. Only grant what you need.

2. Marketplace orders from Amazon, eBay and other channels

If you sync orders from Amazon, eBay or another sales channel, those orders sit alongside your own in Orbit. The assistant will see them too.

Amazon and eBay set their own rules for that data, and those rules are stricter than the rules for your own store data. You must not use an AI assistant to export, copy, keep or build reports and dashboards from marketplace order data or marketplace buyer data, unless that marketplace allows it.

Buyer names, addresses, phone numbers and email addresses from those channels may only be used to fulfil the orders they came with. You confirm you will keep to each marketplace policy you sell under.

If you are not sure whether something is allowed, do not grant the order permissions.

3. Your duties under GDPR and UK GDPR

You are the data controller for your store customer data. Orbit is your processor. The assistant provider you pick here becomes a further processor, and by approving this connection you are authorising them.

You need a lawful basis for this, and your own privacy notice needs to reflect it. That is your call to make, not ours.

Send the assistant only the personal data it needs for the job in hand. Do not paste customer records into a chat when a summary would do.

You can revoke this connection at any time from your dashboard. Revoking stops all future access straight away. It cannot pull back anything the assistant has already received.

4. Keeping and training

Ask your assistant provider two things before you connect. Do they keep your prompts and the data in them, and for how long? Do they use that data to train their models?

Orbit cannot see or control what your provider does with data once it leaves us. Their terms decide that, not ours. If their answers do not suit your customers, do not connect them.

5. Keeping the connection safe

The token this connection creates is a credential, like a password. Anyone holding it can act with the permissions you granted.

If you share the assistant with other people, or you think the token has leaked, revoke the connection in your dashboard and connect again. Revoking takes effect on the next request the assistant makes.

Changes to these terms

Each version of these terms has a date, and every connection records the version it was approved under. We do not change a version you already agreed to. If we change what you are agreeing to, the version changes with it, and the next connection you approve shows you the new text.

Connections you approved under an earlier version keep running. Your dashboard shows which version each one accepted.

Contact

Questions about a connection: support@orbitcommerce.net

Data protection: support@orbitcommerce.net