This Privacy Policy explains how Urbigjump UK Ltd ("Urbigjump", "OrbiSignage", "we", "us", "our") collects, uses, discloses, and protects information in connection with the OrbiSignage website (orbisignage.com), the OrbiSignage content-management system and dashboard (app.orbisignage.com), our screen/player applications (including the OrbiSignage web player and Android TV player app), and our device ordering service (together, the "Service"). Please read it alongside our Terms of Service.
For the account, billing, and device data described below, Urbigjump UK Ltd is the controller under the UK GDPR and the Data Protection Act 2018. For the media and other content you or your team upload to the Service to display on your own screens (which may itself contain personal data, e.g. photos of staff or customers), you are the controller and we act only as your processor, acting on your instructions to store, host, and display that content. If you need a data processing agreement covering that relationship, contact us at the address above.
What we collect depends on how you use the Service.
| Category | Examples | Source |
|---|---|---|
| Account & workspace | Name, work email, password (stored as a salted hash), company name, workspace/company ID, role, two-factor authentication (TOTP) setup | You, at signup and in Settings |
| Billing | Billing contact name/email, billing address, VAT number, plan, subscription status, invoice and credit-note history | You; Stripe (see Section 4) |
| Payment details | Card brand and last 4 digits, Stripe customer/subscription/payment IDs | Stripe — we never receive or store your full card number |
| Device & screen | Screen name, pairing codes, device make/model/serial number, OS and app version, screen resolution, storage capacity, online/offline status, uptime and downtime history | The player app running on your screen/device |
| Playback & usage | What content played, on which screen, and when (proof-of-play), playlist and schedule configuration, alerts (e.g. a screen going offline) | The player app and CMS |
| Device orders | Recipient name, delivery address, phone number, order contents, order status | You, when ordering signage hardware |
| Content you upload | Images, video, documents, and other media you upload or import for display on your screens | You, or a linked Google Drive / Microsoft OneDrive / Dropbox account you choose to import from |
| Marketing leads | Name, work email, company name, estimated number of screens | Sign-up and contact forms on our website |
| Support | Correspondence and attachments you send to our support mailboxes; knowledge-base usage | You |
| Security & audit logs | Login history, IP address, admin and account actions, timestamps | Automatically, to secure the Service |
We do not use third-party advertising networks or behavioural-tracking pixels on the website or in the CMS, and the Service does not request access to your device's camera, microphone, or precise location.
Subscription and device-hardware payments are processed by Stripe, Inc. Card and other payment-method details are entered directly into Stripe's hosted checkout or payment element and are sent straight to Stripe — they do not pass through or get stored on our servers. We receive back only the information needed to manage your subscription (such as your Stripe customer ID, subscription status, card brand/last 4 digits, and invoice records). Stripe acts as an independent controller of the payment data it processes; see Stripe's Privacy Policy.
The player app running on a paired screen periodically reports technical status (make, model, serial number, OS/app version, storage, and online/offline state) and a log of what content played and when. This data is used to keep your screens in sync, alert you if a screen goes offline, and give you playback/proof-of-play reports. It is tied to the screen/device and to the company workspace it is paired with, not to an individual member of the public who happens to view the screen.
The CMS lets you optionally import media from your own Google Drive, Microsoft OneDrive, or Dropbox account using that provider's own file picker and authorisation flow. You choose exactly which files to import; we do not gain broader access to your Drive/OneDrive/Dropbox account, and we never see or store your provider password. Once you select files, a copy is transferred into your OrbiSignage media library for use on your screens, and from that point it is handled like any other content you upload (Section 2).
We use a single first-party cookie that is strictly necessary to sign you in and keep you signed in to the CMS. When you sign up or log in on the marketing site, we hand your session over to the CMS using a short-lived, single-use token (passed in the sign-in link, not stored as a cookie); the CMS then sets the session cookie on its own domain. We do not currently use analytics, advertising, or third-party tracking cookies, and there is no non-essential cookie for which we would need your consent. If that changes, we will update this Policy and request your consent where the law requires it.
We do not sell or rent personal data. We share information with the following categories of service providers, each acting under contract and only to the extent needed to provide the Service:
We may also disclose information where required by law, regulation, or a valid legal process, to protect the rights, property, or safety of Urbigjump, our customers, or others, or in connection with a merger, acquisition, or sale of assets (subject to equivalent protections for your data).
Our infrastructure providers operate globally, so information may be processed outside the United Kingdom, including in the United States. Where that happens, we rely on appropriate safeguards recognised under UK data protection law, such as the UK International Data Transfer Addendum or Standard Contractual Clauses, or the provider's own certifications.
We use transport encryption (TLS) for connections between your devices, the CMS, and our servers; store passwords as salted hashes; support optional two-factor authentication (TOTP); route all card payments directly to Stripe rather than handling them ourselves; and maintain audit logs and access controls over our infrastructure. No method of transmission or storage is completely secure, and you are responsible for keeping your own account credentials, screen pairing codes, and connected-device access secure.
Under the UK GDPR, you have the right to access, rectify, erase, and restrict the processing of your personal data, to object to certain processing, to data portability, and to withdraw consent where processing is based on consent. To exercise these rights over data we hold as controller (Section 1), contact us using the details below. If your request concerns content uploaded to a screen by an OrbiSignage customer (for example, you appear in a photo displayed on someone else's screen), please contact that customer directly, as they are the controller of that content; we will assist them as needed. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
The Service is intended for business use and is not directed to children. You must be at least 18 years old, and legally able to bind your organisation, to create an account. We do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notice on the website or in the CMS. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
Questions, requests, or complaints about privacy: