Last Updated: January 3, 2026
Introduction
OrbitalPing ("we", "our", or "us") operates the ISS Tracker web application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.
Information We Collect
Personal Information
When you use our email notification service, we collect:
- Email Address: Required to send ISS pass notifications (requires verification)
- Location Data: Latitude, longitude, and elevation to calculate ISS passes for your area
- Location Name: Optional location identifier you provide (city, region, etc.)
- Notification Preferences: Your choices for ISS and Starlink notifications
- IP Address: Automatically collected for security and abuse prevention
Automatically Collected Information
- Browser Information: Browser type, version, and device information
- Usage Data: Pages visited and API endpoint usage
- Cookies: Email cookie for returning user experience (HttpOnly, 1 year expiration)
- Log Data: Access times, API requests, and error logs for troubleshooting
How We Use Your Information
We use the collected information to:
- Calculate and provide ISS pass predictions for your location
- Send email notifications about upcoming ISS and Starlink train passes
- Verify email addresses before activating notifications (one-time verification required)
- Manage your notification preferences and unsubscribe requests
- Display Global Spotlight cities (top 3 upcoming ISS passes worldwide)
- Maintain and improve service functionality and accuracy
- Ensure security, prevent abuse, and enforce rate limits
- Respond to support requests and communications
Data Storage and Security
Storage
- User data is stored in secure, encrypted databases
- All data is encrypted in transit and at rest
- Session data is stored using secure cookies
- Temporary data is cached to improve performance
Security Measures
- Industry-standard TLS encryption for all connections (HTTPS enforced)
- HttpOnly cookies to prevent JavaScript access
- Content Security Policy (CSP) headers to prevent XSS attacks
- Rate limiting on all API endpoints (3-60 requests/minute depending on endpoint)
- Email verification required before sending notifications
- Protection against common web attacks (XSS, CSRF, SQL injection)
- Regular security updates and monitoring
Data Retention
- User email and location data is retained while you use the service
- Unverified emails are not used for notifications
- Users can unsubscribe at any time (unsubscribe link in every email)
- Inactive accounts may be purged after 365 days of inactivity
- Log data is retained for 90 days for troubleshooting
- Cached ISS and weather data expires automatically (1-24 hours depending on data type)
Third-Party Services
External APIs
We use the following external services:
- CelesTrak: For ISS orbital element (TLE) data (public domain)
- Open-Meteo: For weather and cloud cover information (free API)
- SpaceX API: For Starlink launch data (public API)
- AWS SES: For sending email notifications
Data Sharing
We do not sell, trade, or rent your personal information to third parties. We may share data only:
- With your explicit consent
- To comply with legal obligations or court orders
- To protect our rights, safety, and prevent fraud
- With AWS SES for email delivery (subject to strict confidentiality)
We never share your data with advertisers or marketing companies.
Cookies and Tracking
Essential Cookies
- Session Cookie: Maintains your login state and preferences
- Preference Cookie: Stores your settings for convenience
Analytics Cookies
We may use cookies to:
- Track anonymous usage statistics
- Improve service performance
- Understand user behavior patterns
Advertising Cookies (Google AdSense)
We use Google AdSense to display advertisements on our website. Google AdSense uses cookies and similar technologies to:
- Show personalized ads based on your interests
- Measure ad performance and effectiveness
- Prevent the same ads from showing repeatedly
- Detect and prevent fraud and abuse
Google's Advertising Cookies:
- Google uses cookies to serve ads based on your prior visits to our website or other websites
- Google's use of advertising cookies enables it and its partners to serve ads based on your visits to our site and/or other sites on the Internet
- You may opt out of personalized advertising by visiting Google Ads Settings
- You can also opt out of third-party vendor use of cookies by visiting aboutads.info
Data Shared with Google:
When ads are displayed, the following information may be shared with Google:
- Your IP address (anonymized)
- Browser type and language
- Device information (type, screen size, operating system)
- Pages viewed and time spent on our site
- Referring website or source that brought you to our site
Google uses this information in accordance with their Privacy Policy.
Managing Cookies
You can control cookies through your browser settings. Disabling cookies may limit functionality and prevent personalized ads from displaying properly. Most browsers allow you to:
- View and delete cookies
- Block third-party cookies
- Block cookies from specific sites
- Block all cookies
- Delete all cookies when you close your browser
Your Rights
Access and Control
You have the right to:
- Access: Request a copy of your stored data
- Correction: Update or correct your information
- Deletion: Request deletion of your account and data
- Portability: Request your data in a portable format
- Opt-Out: Unsubscribe from email notifications at any time
Exercising Your Rights
To exercise these rights, contact us or use the account management features in the application.
Children's Privacy
Our service is not intended for users under 13 years of age. We do not knowingly collect information from children under 13. If we discover we have collected such information, we will delete it immediately.
Location Data
Collection and Use
- Location data is used exclusively for calculating ISS pass times
- You can provide location data manually or through browser geolocation
- Location data is never shared with third parties for marketing purposes
- You can update or delete your location data at any time
Geolocation Services
If you use browser geolocation:
- Your browser controls access permissions
- We do not track your location continuously
- Location is only used when you request pass calculations
Email Communications
Verification Email
When you first sign up:
- We send a one-time verification email with a unique verification link
- You must click the link to activate notifications
- Verification links do not expire but can only be used once
Notification Emails
After verification:
- We send emails only about ISS and Starlink train passes over your location
- Frequency: only when excellent viewing opportunities occur (typically a few per month)
- Each email includes upcoming passes for the next 24-48 hours
- We may send critical service announcements (rare)
- We never send marketing or promotional emails
Global Spotlight Notifications
If your city is featured in the Global Spotlight (top 3 worldwide passes):
- You receive a special notification highlighting the exceptional viewing opportunity
- These are sent in addition to regular notifications
- Limited to prevent spam (minimum 6 hours between emails)
Unsubscribe
You can unsubscribe at any time by:
- Clicking the unsubscribe link in any email (unique token per user)
- Your data remains in the database but notifications stop immediately
- Re-subscribing requires email verification again
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in compliance with this Privacy Policy.
Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date
- Sending an email notification (for material changes)
Your continued use after changes constitutes acceptance of the updated policy.
California Privacy Rights
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt-out of the sale of personal information
- Right to deletion of personal information
- Right to non-discrimination for exercising CCPA rights
We do not sell personal information.
GDPR Compliance (EU Users)
For users in the European Union:
- Legal Basis: We process data based on consent and legitimate interests
- Data Protection Officer: Contact information provided below
- Right to Lodge Complaint: You can file complaints with your local supervisory authority
- Data Portability: Request your data in machine-readable format
- Automated Decision-Making: We do not use automated decision-making or profiling
Contact Information
For privacy-related questions, concerns, or requests:
Email: privacy@orbitalping.com
Website: https://orbitalping.com/contact
Response Time: We aim to respond within 48 hours
Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify affected users within 72 hours of discovery
- Provide details about the breach and affected data
- Explain steps taken to address the breach
- Offer guidance on protecting your information
Software Information
This is a proprietary web application. Our security practices and infrastructure are regularly audited to ensure your data protection.
Legal Disclaimer
This privacy policy constitutes a legal agreement between you and OrbitalPing. By using our service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
This Privacy Policy is effective as of November 29, 2025, and governs the collection and use of information by OrbitalPing ISS Tracker.