PRIVACY AND DATA USE · 2026-09-23.1
Know what your information is used for.
Who operates Orbit?
Orbit, and the MEX Orbit application shown on Google and Meta permission screens, are operated by MEX MEDYA TİCARET LİMİTED ŞİRKETİ. Our registered address: CEVİZLİ MAH. ZUHAL CAD. A BLOK NO: 46 İÇ KAPI NO: 50 MALTEPE / İSTANBUL.
For data use, access or deletion requests, you can reach us at info@mexmedya.com.
What information do we collect in a demo request?
Your name, business or brand name, email address, optional phone number and your stage in the e-commerce journey are saved in Orbit’s management system with your demo request. After the record is created, the same details, the request number and the notice acknowledgement are sent to the FormSubmit service and delivered by email to info@mexmedya.com. According to its own documentation, FormSubmit may keep submission records for 30 days. Our team uses this information to assess your request, schedule a demo call and share a scope that fits your needs.
Submitting the form does not start a paid subscription and does not sign you up for an advertising newsletter. The Starter price shown is TRY 3,999.00 + VAT per month or TRY 35,988.00 + VAT annually upfront; the contract and service scope are assessed separately.
When card payment is enabled, orders, payment status and refund records will be processed to provide the service, verify collection, answer support requests and meet legal record-keeping obligations. Card numbers and security codes are not collected in the Orbit marketing form; the planned flow is explained on the payment security page.
When you connect your Google account
The connection is optional. You approve access to the accounts and services you select on the Google permission screen. You do not need to give Orbit your Google password. Account and resource identifiers, the access scope, and the access/refresh credentials needed to maintain the connection are processed.
Depending on the connection you permit: Google Analytics visitor and site performance reports; Google Ads account and ad performance; Merchant Center account, product and product issue information; Tag Manager container/workspace information; and Search Console site and search performance data are read. This information is used to verify the connection of the relevant store and to show its reports.
Google Ads and Merchant permission screens may also show editing permission because of the scopes Google offers. Orbit’s current reporting connections do not start campaigns, change ad budgets or publish products. If site ownership and sitemap setup are chosen, the additional permission required is requested separately for that action.
When you connect your Meta account
The Meta connection is optional and is started with your own authorized Facebook account. You choose only the purpose: reading reports or managing ads. You do not need to give Orbit your Meta password. The permission scope, access token, and the ID, name and currency of the ad account you select are processed; when ad management is selected, the IDs and names of the Facebook Pages you are authorized for are also processed.
Ad account and Page information is used to choose the right customer resources and verify access; ad performance data is used to show your store’s reports. In ad management, the text, image URL, target URL, country and budget you prepare are sent to Meta. Creating, publishing, pausing and budget changes for ads are done with separate preview and approval steps. Granting the connection does not by itself start ad spend. Card details are not taken into Orbit; ad payment is made directly on Meta.
Meta connection details are kept in a protected vault on the server within the access limits of the relevant store. Other customers cannot access this connection. Data received from Meta is not sold and is not used to train general-purpose AI models. The availability of the integration depends on Meta permissions, app review and account eligibility.
Access, retention and sharing
Only the authorized Orbit team sees demo requests. Google connections are opened to the authorized administrators of the relevant store; an employee who only has theme-editing permission cannot see connection secrets. This information is not opened to other customers’ stores.
Connection credentials are kept in a protected vault on the server. Service providers such as Google Cloud, used to run the application infrastructure, process data to the extent the service requires. Google user data is not sold, not shared for ad targeting and not used to train general-purpose AI models.
Orbit’s use of information received from Google APIs and its transfer to other applications are limited by the Google API Services User Data Policy, including its Limited Use requirements.
Removing the connection and deletion
For Meta, you can use the path Account connections → Meta Ads → Remove connection in the Orbit panel. You can also remove the app permission on the Meta side by selecting MEX Orbit under Business integrations in your Facebook settings. Removing the authorization does not automatically stop ads already created on Meta; check ongoing ads in Meta Ads Manager.
For the Meta connection, ad drafts and report records kept in Orbit, send your deletion request to info@mexmedya.com with the subject “Meta data deletion request”. State your store name, the email address you use in the panel and the relevant ad account ID; do not send a password, access token or card details. The request is processed after you are verified as an authorized person; when it is completed, or if there is a record that must legally be kept, you are told the result and the reason.
You can remove Google access from the connections section of your Google account. This stops new Google data from being received; it does not by itself delete records kept earlier.
Connection details are used for as long as the connection continues, and demo requests while your request is being assessed. You can write to us to withdraw your request or to ask for stored connection and request records to be deleted. Requests are processed by the team after the authorized person of the relevant account is verified. You are informed when the process is complete or when a specific record must be kept because of a statutory retention obligation.
Repeated and unwanted submissions
To prevent a second record when the same form is submitted again and to limit request volume, a technical transaction ID and an audit record are kept. When the form is submitted, your contact details are not passed to third-party advertising or analytics tags; they are sent only to the FormSubmit service for the email notification described above.
The rules on using the Orbit service are explained on the Terms of Use and Service page.
Back to the request