Orbital Payload

Privacy Policy

Last updated: August 3, 2026

Overview

This Privacy Policy explains how Orbital Payload ("Orbital Payload," "we," "us," or "our") collects, uses, shares, and protects information when you visit orbitalpayload.com, play Orbital Payload, create or claim a pilot account, submit content, or use related services.

Orbital Payload is a browser-based spaceport docking game in active development. The service uses account, gameplay, storage, and analytics data so that pilots can sign in, keep progress, participate in shared zones, use in-game systems, and help us improve the product.

Information We Collect

Account and profile information

Pilot handle, display name, optional email address, account role and state, profile claim status, home/current zone, and records showing when you accepted the Terms and this Policy.

Authentication and security information

Passwords are stored in hashed form and never in plain text. We also keep session records (such as hashed session tokens and session expiration and revocation state), hashed IP addresses used for rate limiting and abuse prevention, user agent strings, sign-in attempts, and security and audit logs.

Social login information

If you use Google or Discord login, we receive and store basic account information from that provider, such as the provider name and account identifier, email and verification status when provided, display name, avatar URL, and the scopes you approve, along with sign-in timestamps. We do not store provider access tokens as account credentials.

Gameplay and service records

We store gameplay state needed to run Orbital Payload, including zone membership, ship presence, pose snapshots, damage state, cargo jobs and transfers, docking run metrics, leaderboard records, training licenses, wallet balances, credit ledger entries, fuel state and fuel events, purchases, inventory, loadouts, keyboard control profiles, customization settings, and player HAIL contact metadata.

Player HAIL communications

For short-range player HAIL, we retain directed contact and block metadata: the two internal user ids, public OPC license identity used for display, whether a link was ever accepted, first/recent hail and link timestamps, direction, outcome, interaction counters, block timestamp, and row-update time. We also retain your private HAIL reception preference and its update time; reception defaults on until you turn it off. MANUAL transmission bodies and QUICK phrase/context ids are relayed transiently to the two pilots. They are not stored in D1, Durable Object storage or WebSocket attachments, analytics, application logs, local storage, or session storage, and they are not delivered offline or replayed after reconnect. A participating page may hold up to four recent rows in memory for no more than 30 seconds while the link is active; link end, ZONE change, disconnect, or reload clears that transcript state.

Content you submit

This includes feedback, feedback votes, billboard pixel art and placement metadata, cockpit panel customization settings, and cockpit panel images you upload. Uploaded cockpit panel images are stored in Cloudflare R2 along with basic file metadata such as file type, size, and dimensions.

Usage, diagnostics, and device context

We collect events such as page opens, app loads, zone joins, gameplay milestones, purchase and fuel events, failures, and exceptions. These events may include technical context such as the page or route, build version, approximate device and browser characteristics, and identifiers we use to correlate events and diagnose issues. We avoid sending raw IP addresses, passwords, OAuth tokens, session cookies, and obvious secrets to analytics.

Browser storage

We use cookies for authenticated sessions and OAuth state. We use local storage for preferences and local recovery state such as control mode, keyboard/gamepad bindings, audio settings, cockpit customization drafts, bobble charm loadout, cargo job state, and training license claim data. PostHog may also use browser storage for analytics identifiers.

How We Use Information

  • Authenticate pilots, maintain sessions, and protect accounts.
  • Operate multiplayer zones, WebSocket presence, ship state, cargo systems, fuel systems, leaderboards, market purchases, wallets, and inventory.
  • Relay short-range player HAIL transmissions, enforce communication limits and blocks, and maintain OPC license contact metadata.
  • Save account preferences, cockpit customization, uploaded assets, and gameplay progress.
  • Display public or shared game surfaces, including leaderboards, feedback, active pilot presence, cargo activity, and billboard art.
  • Debug crashes, measure performance, understand product health, prevent fraud or abuse, and improve controls and onboarding.
  • Comply with legal obligations, enforce the Terms, and respond to safety, security, or support requests.

Cookies And Local Storage

Authentication cookies are set with security attributes (such as HttpOnly and SameSite protections, and the Secure attribute in production) and are time-limited, expiring after a set period unless you log out or the session is revoked sooner.

OAuth state cookies are temporary and are used to protect Google and Discord login flows. Local storage is used for game preferences, control bindings, audio settings, local training license recovery data, cockpit customization drafts, and similar client-side settings. Clearing browser storage may remove local-only recovery data or preferences.

Analytics And Diagnostics

We use PostHog to understand product health, diagnose failures, and improve Orbital Payload. Our browser telemetry configuration disables session replay and autocapture. We send explicit product events, page views, app-load events, exception reports, and selected server events.

We identify analytics users by internal Orbital Payload user ids when available. We do not intentionally send profile email addresses, passwords, raw IP addresses, OAuth tokens, session cookies, or full request and response bodies to analytics. Feedback text may be mirrored to PostHog for triage when enabled, but we automatically redact content that looks like emails, tokens, secrets, or other sensitive strings before sending. Please do not include sensitive personal information in feedback or billboard art.

How We Share Information

Cloudflare

Orbital Payload runs on Cloudflare Workers and uses Cloudflare D1, Durable Objects, R2, and related Cloudflare services for hosting, database, live zone state, object storage, security, and network delivery.

PostHog

We use PostHog for product analytics, diagnostics, server and browser event capture, exception reporting, event correlation, and feedback triage. Session replay and autocapture are disabled in our browser configuration, and we send explicit product events instead. Feedback text may be mirrored to PostHog when enabled, after automated redaction of content that looks like emails, tokens, or other secrets.

Google and Discord

If you choose Google or Discord login, we redirect you to that provider and receive account information allowed by the scopes you approve. Those providers process your data under their own terms and privacy policies.

Public and shared game surfaces

Your handle, display name, public OPC license code and phonetic identity, leaderboard results, feedback, votes, live pilot presence, ship position, cargo activity, and billboard art may be visible to other players or site visitors depending on the feature. A HAIL transmission is relayed only to the other pilot's active account connections, not to the whole ZONE.

Legal, safety, and business transfers

We may disclose information when reasonably necessary to comply with law, protect rights and safety, investigate abuse, enforce the Terms, or transfer the service as part of a merger, financing, acquisition, reorganization, or sale of assets.

We do not sell personal information, and we do not use personal information for cross-context behavioral advertising.

Retention

We keep information for as long as reasonably necessary to provide Orbital Payload, maintain account and gameplay history, operate leaderboards and shared worlds, preserve transaction and audit records, prevent abuse, resolve disputes, comply with law, and improve the service.

Some records, such as expired OAuth login attempts, are designed to be short-lived. Other records, such as account, wallet, ledger, leaderboard, cargo, fuel, HAIL contact/block metadata, feedback, audit, and uploaded asset records, may be kept for longer because they preserve service integrity. If you request deletion, we will evaluate the request and delete or de-identify information where reasonably possible, subject to legal, security, anti-abuse, accounting, and operational needs.

Your Choices And Rights

  • You can update your display name and email in the product where profile controls are available.
  • You can log out to revoke the active browser session cookie.
  • You can clear local browser storage to remove local preferences, local training license recovery data, and local analytics identifiers from that browser.
  • You can block or unblock an OPC license contact from HAIL controls. Blocking ends a current link and prevents later HAIL delivery in either direction until you unblock that contact.
  • You can turn Do Not Disturb (DND) on or off for HAIL. DND defaults off; turning it on ends live HAIL state and makes your pilot unavailable for HAIL until you turn DND off.
  • You can use browser privacy controls, content blockers, or storage restrictions to limit analytics cookies and browser storage.
  • You can request access, correction, export, deletion, or analytics opt-out assistance through the contact channel below. We may need to retain some records for security, legal, anti-abuse, accounting, leaderboard integrity, or service continuity reasons.

Security

We use administrative, technical, and organizational measures intended to protect the service and the information we hold. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

Children

Orbital Payload is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information, contact us so we can review and respond.

International Processing

Orbital Payload and its providers may process information in the United States and other countries where we or our providers operate. Those countries may have data protection laws different from the laws where you live.

Changes

We may update this Privacy Policy as Orbital Payload changes. The updated policy will be posted on this page with a new last-updated date. Continued use of the service after an update means the updated policy applies to later use.

Contact

For privacy questions or requests, contact Orbital Payload at support@orbitalpayload.com.