Skip to content

Privacy Policy

How Orbav collects, uses, stores and deletes personal data. Last updated 14 August 2026.

Document status — drafted from the site's actual mechanics, not a template. External counsel review is pending before final sign-off. Anything not yet settled is stated as unsettled where it appears, rather than invented. Questions about anything on this page: hello@orbav.com.

Who we are

Orbav is a trading name of Ahsan Saleem, a sole proprietorship registered in Pakistan, based in Lahore, Pakistan. For anything in this policy, write to us through the contact page or at hello@orbav.com.

What we collect, and why

This site collects personal data in exactly two places: the written contact form and the AI Readiness Audit. The calendar booking, when enabled, is operated by the booking vendor under its own privacy policy, and we name it here when it goes live.

Contact form — your words
Your name, work email, company (optional) and message, as you type them. Purpose: replying to you. Lawful basis: steps you ask for before any contract, and our legitimate interest in answering business enquiries.
Contact form — anti-abuse records
The form stores your browser’s user-agent string and a one-way fingerprint (a SHA-256 hash of the form’s render timestamp and your email) — never your password, never anything you didn’t type. The fingerprint exists solely so a double submission can’t create a duplicate. Your IP address is checked in memory to rate-limit the form and is not written to our database by our code. Lawful basis: legitimate interest in keeping the form usable.
AI Readiness Audit — your answers and your report
Your work email, your twelve answers, the scores and ranked opportunities they produce, and the page or campaign you arrived from (the ?from= parameter) when there is one. Purpose: generating and emailing your report, and sending the five follow-up emails the audit page tells you about before you submit — they stop when you reply STOP. Lawful basis: your request for the report, and our legitimate interest in answering business enquiries. The same anti-abuse records as the contact form apply.
Theme preference
If you switch light/dark mode, that choice is stored in your own browser’s local storage. It is never transmitted to us — we cannot see it.
Hosting and delivery logs
When the site is deployed, the hosting platform (Vercel) processes standard request logs (IP, user-agent, pages) to serve and protect the site. The hosting platform is selected but the account is not yet enabled; this line is confirmed at go-live.

What we don't collect — and won't

  • No analytics, advertising or tracking scripts run on this site. No cookies are set for analytics, advertising or marketing, and nothing follows you to other sites.
  • We do not sell personal data, and we do not share it for third-party marketing.
  • The contact form does not subscribe you to anything — that promise is printed on the form itself. The audit form tells you exactly what it sends (your report, then five emails over two weeks) before you submit, and they stop the moment you reply STOP.
  • If privacy-respecting analytics is ever enabled, it will load only after an on-site consent choice, and this page will be updated first.

Where your data lives

Contact messages are stored in a single database table (Supabase) with row-level security enabled and no anonymous access; writes happen only through a server-held key. Until that database is provisioned, the form refuses to accept a message rather than store it anywhere else — an honest failure, never a silent drop. Audit submissions (answers, scores and report) live in their own table in the same database, under the same rules and the same honest-failure behaviour.

Retention. Contact messages are kept for 24 months after our last contact with you, then deleted. Audit records are kept for 24 months after submission, then deleted. Where first-party analytics is enabled, those records are kept at most 24 months and then purged. Ask for deletion sooner and it happens sooner.

Sub-processors

No vendor stores this site's visitor data today, so the honest list is empty — and an out-of-date list is worse than none, so it starts empty on purpose. (The database and mailbox named on this page are the intended providers; each is added to the list below the day it is actually provisioned.) The maintained list lives on the Trust page; every vendor is added there, with purpose and region, before it processes any data.

International transfers

We are based in Pakistan and work for clients in the UK, Australia, the US and Canada, so your message may be processed outside your jurisdiction, including in countries without an adequacy decision. Where an engagement needs more — residency requirements, a data processing agreement, or your own paper — say so before we start; that is normal for us, not an exception.

Your rights

If the UK GDPR or EU GDPR applies to you, you can ask to access, correct, delete, restrict or object to our processing of your personal data, and ask for a portable copy. Write to us through the contact page and we respond within the statutory one month — almost always faster. You can also complain to the ICO (UK) or your local supervisory authority; we'd rather fix the problem first, if you give us the chance.

Cookies

This site sets no cookies. Two kinds of browser storage may exist on your device, both readable in your own browser: your theme preference (local storage, set by the theme switch) and — only if analytics is ever enabled and you accept it — your consent choice itself. Nothing else.

Changes

The date at the top is the version. Material changes are posted on this page — and because the policy is written from the code, it changes only when the code does.

Accessibility statement

This site is built to WCAG 2.2 Level AA as a hard acceptance criterion, verified by automated and manual audit. If you find something that isn't accessible, tell us and we'll fix it.