1. Scope and consent position
Orbis Sign does not use advertising pixels, audience analytics, session replay or optional marketing trackers. Authenticated-session storage is strictly necessary. Preference and interface-customisation storage is used when an account user requests or uses those features. The site therefore does not ask for consent to optional tracking. Infrastructure providers may use strictly necessary security or routing storage; optional tracking would not be introduced without updating this notice and implementing any consent controls required by law.
3. Local storage
| Key | Classification and contents | Expiry |
|---|---|---|
orbis_branding_v1 | Functional cache containing workspace/company display name, logo URL, colours, portal name and support email returned by the branding API. | No automatic expiry; overwritten on refresh and removable through browser controls. |
orbis_ui_prefs | Functional preference containing the selected sidebar or horizontal navigation style. | No automatic expiry. |
orbis_settings | Functional application preferences: organisation name, default delivery method, reminder/deadline defaults, default OTP choice and reply-to email. | No automatic expiry; the in-app reset removes it. |
4. Other browser and third-party storage
Orbis Sign does not use sessionStorage, IndexedDB, a CSRF cookie, remember-me cookie or client-side authentication token. CSRF defence for cookie-authenticated changes uses same-origin Origin/Referer checks rather than a stored token. The Inter font is self-hosted.
If an authenticated user is directed to Stripe's hosted service, Stripe may use cookies or similar technology on its own domain under its own notices; those are not cookies set on the Orbis Sign site. Brevo email and VoodooSMS API calls occur server-side, not through browser tracking scripts. Brevo delivery webhooks can record email delivery, opens and clicks as workflow evidence; this is server-side message telemetry, not website cookie analytics.
Strictly necessary storage added by a hosting or security provider may also be present where needed to route or protect the service.
5. Your controls
You can inspect, block and delete cookies and local storage through browser settings. Blocking orbis.sid prevents authenticated use. Deleting functional values resets preferences and branding cache but does not delete server-held account or document data.
Read the ICO's current guidance on storage and access technologies. Questions can be sent through the contact form or to .

