Privacy Policy
Version 2.0 · Last updated 22 September 2026
The short version
- Your organisation stays in charge of the operational data it puts into Orin. We process it on your instructions, under a data processing agreement.
- Everything runs on Microsoft Azure in the EU. A handful of named providers process specific data outside it, under Standard Contractual Clauses.
- We do not sell your data, we do not advertise, and nothing you correct in the AI reader is shared with another customer.
- Analytics on this website load only if you accept them, and you can change that choice at any time.
- You can export or delete your data yourself, and ask us for a copy of what we hold.
The full text below is what governs. This box is a summary, not a substitute.
1. Who this policy is for
This policy covers everyone whose personal data reaches us. That is broader than the people who log in:
- Visitors to orin.software, including anyone who books a demo or writes to us through the contact page.
- Users of the Orin platform: planners, administrators and key users at a customer organisation.
- Drivers using the Orin driver app.
- People named inside a customer's operational data: contacts at a shipper, a consignee at a delivery address, a subcontractor's driver.
Section 2 matters most to that last group, because for their data we are not the one making the decisions.
2. Who is responsible for what
GDPR distinguishes the party that decides why and how data is processed (the controller) from the party that processes it on their instructions (the processor). Orin is both, for different data, and it is worth being precise about which is which.
We are the controller for:
- website visitors, demo bookings and contact requests;
- the administrator and billing contacts of a customer account;
- our own security, diagnostics and accounting records.
We are the processor for:
- everything a customer organisation puts into the platform to run its transport: shipments, addresses, consignee contacts, drivers, proof of delivery, rates and invoices.
For that second set, the customer organisation is the controller. We act on their instructions under our Data Processing Agreement, and we do not decide what is collected or why. If you are a consignee, a driver at a subcontractor or a contact at a shipper and you want your data corrected or removed, the company that arranged your transport is the right place to ask. Write to us and we will point you at them and help them answer.
Orin Technologies BV, registered in the Netherlands.
Privacy contact: legal@orin.software
We have not appointed a statutory Data Protection Officer; we are not required to. The address above reaches the people who can answer.
3. What we collect
Only what a feature needs. Where something is optional or belongs to one feature, it says so.
A. Account and contact
- Name and work e-mail address.
- Mobile phone number (required for drivers, who sign in with it; optional for everyone else).
- VAT or tax identification number (only for accounts we invoice).
B. Billing
- Billing address and payment records.
- Card details are handled by Stripe and never reach our servers.
C. Operational data (your customer organisation is the controller)
- Pickup and delivery addresses, time windows and instructions.
- Description of the goods.
- Contact name and phone number at a stop.
- Trip and shipment history, statuses and events.
- Proof of delivery: photographs and a signature, with the time and place they were captured.
D. Technical
- Device type, operating system and app version.
- IP address.
- Error and crash reports, and diagnostic logs.
E. Website and demo requests
- The name, work e-mail, company and preferred time you enter when booking a demo.
- Website statistics, but only if you accept analytics cookies. See section 12.
4. The driver app on a phone
The driver app is a web app that runs in the phone's browser; there is also a native iOS app. Both ask for the following, and the phone will not grant any of it without the driver agreeing.
- Camera. For proof of delivery photographs and for documenting an incident (damage, refused delivery, address not found). Photos are stored against the delivery they belong to.
- Location. Read once, at the moment the driver marks an arrival or departure, so the stop carries where it actually happened. It is not read continuously and the app does not track a driver between stops. Declining it does not stop the driver working: the stop is recorded without a position.
- Push notifications. For a newly assigned trip, changes to it, and messages from support. Can be switched off in the phone's settings.
- Local storage. To hold the trip and any captured evidence while there is no signal, so the driver keeps working offline and the queue syncs on reconnect.
5. Why we process it, and on what basis
| Purpose | Legal basis |
|---|---|
| Running the platform and the driver app for the organisation that contracted us | Performance of a contract |
| Billing, collecting payment and keeping accounting records | Contract, and a legal obligation for the records |
| Answering a demo request, a contact form or a support question | Steps taken at your request before a contract |
| Keeping the Service secure, preventing abuse and diagnosing faults | Legitimate interest |
| Understanding which features are used, so we know what to improve | Legitimate interest in the platform; your consent on this website |
| Sending optional product updates you asked for | Consent, withdrawable at any time |
We do not sell, rent or share personal data for advertising, and we do not profile you for it.
6. Who else sees it
A. The people you send a tracking link to
When you share a tracking link, its recipient sees what the link's visibility level allows, which you choose. You can revoke a link at any time.
B. Providers who process data for us
| Provider | What for | Processed in |
|---|---|---|
| Microsoft Azure (West Europe) | Hosting, database, file storage | EU |
| Postmark (ActiveCampaign) | Transactional e-mail and inbound order e-mail | United States |
| Anthropic (Claude) | Reading order e-mails and transport documents | United States |
| Voyage AI | Text embeddings that improve reading accuracy | United States |
| Stripe | Subscription billing | United States |
| Google Maps Platform | Address lookup, geocoding, map display | United States |
| Google Analytics 4 | Website statistics, only after you accept | United States |
| PostHog | Product analytics inside the platform | EU |
| Crisp | Live chat support in the platform and the driver app | EU |
| Apple APNs and Firebase Cloud Messaging | Push notifications to phones | United States |
| Twilio | SMS, where your account uses it | United States |
| Google Fonts | The two typefaces this website is set in | United States |
| YouTube | Two product videos, loaded only when you press play | United States |
Each is bound by a data processing agreement and may use the data only to provide that service to us. The authoritative list, with the data categories per provider, is the sub-processor list, and we give customers 30 days' notice before adding to it.
C. When the law requires it
We may disclose data where a law, a court or a regulator requires it, or to protect the rights and safety of Orin, our customers or third parties.
7. Reading documents with AI
To turn order e-mails, transport documents, carrier invoices and signed proofs of delivery into structured records, we send their content to AI providers acting as our processors: Anthropic (Claude) for the reading itself, Postmark for inbound e-mail, and Voyage AI for the text representations that improve accuracy. None of them uses the content to train their models.
By default a person reviews and confirms every reading before it becomes a shipment in your operation. Automatic confirmation of high-confidence readings is a separate setting that ships switched off. Where a customer organisation switches it on, they choose the confidence threshold, records created that way carry a banner marking them for review, and a supplier invoice is never posted automatically regardless of the setting. Whether it is on is the customer organisation's decision, not ours.
Corrections made while reviewing are stored as examples for that customer's own account and used to improve that account's future readings. A pooled bank shared across customers exists as a separate opt-in and is switched off unless a customer deliberately enables it.
8. Data outside the EU
The platform itself, including its database and its file storage, runs on Microsoft Azure in the European Union. Product analytics (PostHog) and live chat (Crisp) are also processed in the EU.
Specific features send specific data to providers that process it in the United States: AI reading, inbound e-mail, payments, address lookup, push notifications, SMS and website statistics. For those transfers we rely on the European Commission's Standard Contractual Clauses, incorporated into each provider's processing agreement, and on the provider's certification under the EU-US Data Privacy Framework where it holds one. We send each provider only what its feature requires.
This is why we describe the platform as EU-hosted rather than claiming nothing ever leaves the EU. The sub-processor list says which is which, per provider.
9. How long we keep it
| Data | Kept for | Counted from |
|---|---|---|
| Account and contact details | For as long as the account is active | Account creation |
| Shipment and trip records | 5 years | Completion of the shipment |
| Proof of delivery: photos and signatures | 2 years, or longer where your contract requires it | Capture |
| Invoices and financial records | 7 years | End of the financial year (Dutch statutory period) |
| Application and diagnostic logs | Up to 90 days | Creation of the log entry |
| A deleted account | Removed within 90 days, except where a statutory retention period applies to specific records | The deletion request |
A customer organisation can set shorter periods for its own operational data, and what happens to that data when the contract ends is governed by the Data Processing Agreement. Deleting your own account is described on Delete my account.
10. Your rights
Under GDPR you can ask for access to your data, correction of it, erasure, restriction of processing, a portable copy, and you can object to processing based on legitimate interest or withdraw a consent you gave. You can also complain to a supervisory authority: in the Netherlands that is the Autoriteit Persoonsgegevens, and elsewhere in the EU your own national authority.
Where to send the request depends on section 2. If it concerns your own account, your website visit or a demo booking, write to legal@orin.software and we answer within one month. If it concerns operational data that a transport company put into Orin, that company is the controller and decides; send it to them, or to us and we will route it and assist them.
Account holders can also export or delete their own data from inside the platform without asking anyone.
11. Security
These are the measures actually in place:
- Encryption in transit (TLS) and at rest, on Azure managed storage and database.
- The production database is reachable only over a private network endpoint inside our own virtual network, not from the public internet.
- Passwords and driver PINs are stored hashed, never in readable form.
- Strict separation between customer accounts, enforced in the data layer rather than by application code remembering to filter.
- Role-based access, with access to a department's data limited to the people who need it.
- Secrets held in Azure Key Vault rather than in configuration files.
- Automated, encrypted backups.
- Application and infrastructure logging with alerting on failures.
Sign-in to the platform is with an e-mail address and password, or through your own identity provider using Microsoft Entra ID single sign-on on Enterprise accounts, in which case your organisation's own multi-factor policy applies. Drivers sign in with a phone number or company code plus a PIN.
We do not currently hold an ISO 27001 certificate or a SOC 2 report. If your procurement process needs one, tell us and we will say so plainly rather than point you at a page that implies otherwise.
No system is perfectly secure. If a breach occurs that is likely to present a risk, we notify the affected customer organisations without undue delay and the supervisory authority as the law requires.
12. Cookies and analytics
- Necessary. Sign-in, session and security. These are required for the Service to work and are not optional.
- Local storage. Preferences such as your language and your cookie choice, held on your own device.
- Website statistics on orin.software. Google Analytics 4, loaded only after you press Accept in the cookie banner. Press Reject and it is never loaded at all.
- Product analytics inside the platform. PostHog, hosted in the EU, used to see which features are used and where people get stuck. Not used for advertising.
Two more third parties touch this website specifically. Google Fonts serves the two typefaces the site is set in, which means your browser requests them from Google on every page and Google sees your IP address; it is not used to identify or track you. YouTube hosts the two product videos, and nothing is requested from it until you press play: until then you are looking at an image we serve ourselves. Pressing play loads the player from youtube-nocookie.com, and from that moment Google's own terms apply to the playback.
We do not use advertising cookies and we do not track you across other websites. You can change your choice at any time: .
13. Children
Orin is a business tool. It is not directed at children and we do not knowingly collect their data. Accounts are created by a customer organisation for its own staff, and it is that organisation's responsibility to issue them only to people it employs or engages. If you believe a child's data has reached us, write to legal@orin.software and we will remove it.
14. Advertising
There is none. No advertisements in the platform or the driver app, no third-party ad networks, and no advertising identifiers.
15. Changes to this policy
This policy carries a version number and a date, both at the top. When we change something material we update both, notify customer account administrators by e-mail, and show a notice in the platform. Where a change depends on consent, we ask for it again rather than assume it.
16. Contact
Privacy questions, requests and complaints: legal@orin.software.
Related documents: the Data Processing Agreement, the sub-processor list, and Delete my account.