← Back to orbisignage.com OrbiSignage
OrbiSignage
by Urbigjump UK Ltd

Privacy Policy

OrbiSignage · Published by Urbigjump UK Ltd
Effective date: 25 July 2026 · Last updated: 25 July 2026

This Privacy Policy explains how Urbigjump UK Ltd ("Urbigjump", "OrbiSignage", "we", "us", "our") collects, uses, discloses, and protects information in connection with the OrbiSignage website (orbisignage.com), the OrbiSignage content-management system and dashboard (app.orbisignage.com), our screen/player applications (including the OrbiSignage web player and Android TV player app), and our device ordering service (together, the "Service"). Please read it alongside our Terms of Service.

The short version. OrbiSignage is a business tool: you (or your organisation) create an account, upload media, connect screens, and we host and deliver that content and give you reporting on it. We collect account, billing, device, and content information needed to run the Service, we use Stripe to process payments (we never see or store your full card number), and we do not use advertising or third-party tracking cookies. We act as a data controller for account, billing and device data, and as a data processor for the content you upload to display on your screens.

1. Who we are

For the account, billing, and device data described below, Urbigjump UK Ltd is the controller under the UK GDPR and the Data Protection Act 2018. For the media and other content you or your team upload to the Service to display on your own screens (which may itself contain personal data, e.g. photos of staff or customers), you are the controller and we act only as your processor, acting on your instructions to store, host, and display that content. If you need a data processing agreement covering that relationship, contact us at the address above.

2. Information we collect

What we collect depends on how you use the Service.

CategoryExamplesSource
Account & workspaceName, work email, password (stored as a salted hash), company name, workspace/company ID, role, two-factor authentication (TOTP) setupYou, at signup and in Settings
BillingBilling contact name/email, billing address, VAT number, plan, subscription status, invoice and credit-note historyYou; Stripe (see Section 4)
Payment detailsCard brand and last 4 digits, Stripe customer/subscription/payment IDsStripe — we never receive or store your full card number
Device & screenScreen name, pairing codes, device make/model/serial number, OS and app version, screen resolution, storage capacity, online/offline status, uptime and downtime historyThe player app running on your screen/device
Playback & usageWhat content played, on which screen, and when (proof-of-play), playlist and schedule configuration, alerts (e.g. a screen going offline)The player app and CMS
Device ordersRecipient name, delivery address, phone number, order contents, order statusYou, when ordering signage hardware
Content you uploadImages, video, documents, and other media you upload or import for display on your screensYou, or a linked Google Drive / Microsoft OneDrive / Dropbox account you choose to import from
Marketing leadsName, work email, company name, estimated number of screensSign-up and contact forms on our website
SupportCorrespondence and attachments you send to our support mailboxes; knowledge-base usageYou
Security & audit logsLogin history, IP address, admin and account actions, timestampsAutomatically, to secure the Service

We do not use third-party advertising networks or behavioural-tracking pixels on the website or in the CMS, and the Service does not request access to your device's camera, microphone, or precise location.

3. How we use information

4. Payments (Stripe)

Subscription and device-hardware payments are processed by Stripe, Inc. Card and other payment-method details are entered directly into Stripe's hosted checkout or payment element and are sent straight to Stripe — they do not pass through or get stored on our servers. We receive back only the information needed to manage your subscription (such as your Stripe customer ID, subscription status, card brand/last 4 digits, and invoice records). Stripe acts as an independent controller of the payment data it processes; see Stripe's Privacy Policy.

5. Device telemetry and proof-of-play

The player app running on a paired screen periodically reports technical status (make, model, serial number, OS/app version, storage, and online/offline state) and a log of what content played and when. This data is used to keep your screens in sync, alert you if a screen goes offline, and give you playback/proof-of-play reports. It is tied to the screen/device and to the company workspace it is paired with, not to an individual member of the public who happens to view the screen.

6. Importing content from Google Drive, OneDrive, or Dropbox

The CMS lets you optionally import media from your own Google Drive, Microsoft OneDrive, or Dropbox account using that provider's own file picker and authorisation flow. You choose exactly which files to import; we do not gain broader access to your Drive/OneDrive/Dropbox account, and we never see or store your provider password. Once you select files, a copy is transferred into your OrbiSignage media library for use on your screens, and from that point it is handled like any other content you upload (Section 2).

Where this feature uses Google APIs, OrbiSignage's use and transfer of information received from those APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: data is used solely to import the files you select into your media library, is not sold, and is not used for advertising.

7. Cookies

We use a single first-party cookie that is strictly necessary to sign you in and keep you signed in to the CMS. When you sign up or log in on the marketing site, we hand your session over to the CMS using a short-lived, single-use token (passed in the sign-in link, not stored as a cookie); the CMS then sets the session cookie on its own domain. We do not currently use analytics, advertising, or third-party tracking cookies, and there is no non-essential cookie for which we would need your consent. If that changes, we will update this Policy and request your consent where the law requires it.

8. Sharing and sub-processors

We do not sell or rent personal data. We share information with the following categories of service providers, each acting under contract and only to the extent needed to provide the Service:

We may also disclose information where required by law, regulation, or a valid legal process, to protect the rights, property, or safety of Urbigjump, our customers, or others, or in connection with a merger, acquisition, or sale of assets (subject to equivalent protections for your data).

9. International transfers

Our infrastructure providers operate globally, so information may be processed outside the United Kingdom, including in the United States. Where that happens, we rely on appropriate safeguards recognised under UK data protection law, such as the UK International Data Transfer Addendum or Standard Contractual Clauses, or the provider's own certifications.

10. Retention

11. Security

We use transport encryption (TLS) for connections between your devices, the CMS, and our servers; store passwords as salted hashes; support optional two-factor authentication (TOTP); route all card payments directly to Stripe rather than handling them ourselves; and maintain audit logs and access controls over our infrastructure. No method of transmission or storage is completely secure, and you are responsible for keeping your own account credentials, screen pairing codes, and connected-device access secure.

12. Your rights

Under the UK GDPR, you have the right to access, rectify, erase, and restrict the processing of your personal data, to object to certain processing, to data portability, and to withdraw consent where processing is based on consent. To exercise these rights over data we hold as controller (Section 1), contact us using the details below. If your request concerns content uploaded to a screen by an OrbiSignage customer (for example, you appear in a photo displayed on someone else's screen), please contact that customer directly, as they are the controller of that content; we will assist them as needed. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

13. Children

The Service is intended for business use and is not directed to children. You must be at least 18 years old, and legally able to bind your organisation, to create an account. We do not knowingly collect personal data from children.

14. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notice on the website or in the CMS. Your continued use of the Service after an update constitutes acceptance of the revised Policy.

15. Contact us

Questions, requests, or complaints about privacy: