Privacy Policy.
Last updated: 5 August 2026
This Privacy Policy explains how Vextria Atlas Group Limited, a company registered in England and Wales, operating as Orderly (“Orderly,” “we,” “us,” “our”), collects, uses, and shares personal data when you visit our websites (including orderly-hub.com and intelligence.orderlycore.com), create an account, or use the Orderly platform, APIs, and related services (the “Service”).
A note on whose data we hold. Orderly is a business-to-business platform. We process two different kinds of personal data, and your rights depend on which one applies to you:
- Account Data — information about our customers and their authorized users (the merchants, 3PLs, and businesses that sign up for Orderly). For this data, Orderly is the controller, and this Privacy Policy applies in full.
- Customer Content — order and shipment data our customers sync through the Service, which may include their end customers’ names, addresses, emails, and phone numbers. For this data, Orderly is a processor acting on the instructions of the business you bought from. If you are an end customer of one of our customers, please direct privacy requests to that business; we will assist them in responding as described in our Data Processing Addendum.
1. Who We Are and How to Contact Us
Vextria Atlas Group Limited 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Email: privacy@vextria.tech
Our UK contact for data protection matters is Byron Stokes (privacy@vextria.tech).
2. Personal Data We Collect
Data you provide to us:
- Account and profile information: name, business email address, phone number, company name, job title, password (hashed)
- Billing information: billing contact details, VAT/tax identifiers, and payment method details (collected and stored by our payment processor, Stripe — we do not store full card numbers)
- Communications: support requests, emails, and feedback you send us
Data we collect automatically:
- Usage data: log data, IP address, browser and device information, pages viewed, features used, API request metadata, and timestamps
- Cookies and similar technologies: see Section 9
Data from third parties:
- Information from platforms you connect via Bridges (e.g., your e-commerce or carrier accounts), as configured by you
- Fraud-prevention and payment signals from Stripe
Customer Content (as processor):
- Order, shipment, inventory, and customer records synced from our customers’ connected platforms, processed solely on their instructions
3. How We Use Personal Data and Our Legal Bases
Where UK or EU GDPR applies, we rely on the following legal bases for Account Data:
| Purpose | Legal basis |
|---|---|
| Providing, operating, and securing the Service; account administration | Performance of a contract |
| Billing, payment processing (via Stripe), and usage metering (via Metronome) | Performance of a contract; legal obligation |
| Service communications (transactional emails, security notices, changes to terms) | Performance of a contract; legitimate interests |
| Improving and developing the Service, analytics, troubleshooting | Legitimate interests (running and improving a commercial service) |
| Network Data processing for Orderly Intelligence (see Section 4) | Legitimate interests, to the extent data protection law applies at all |
| Marketing communications | Consent, or legitimate interests for existing customers (soft opt-in), with opt-out in every message |
| Fraud prevention, enforcing our terms, establishing or defending legal claims | Legitimate interests; legal obligation |
| Compliance with law, tax, and accounting requirements | Legal obligation |
We process Customer Content only on our customers’ documented instructions under our Data Processing Addendum, not for our own purposes — with the sole exception of Network Data, described next.
4. Network Data and Orderly Intelligence
To improve prediction accuracy across our network, we derive a limited, de-identified dataset (“Network Data”) from shipments processed through the Service. Network Data includes operational attributes such as origin and destination postal/ZIP code, city, state or region, carrier, service level, package weight and dimensions, tracking scan events and timestamps, and delivery outcomes.
Personal identifiers — names, email addresses, phone numbers, street addresses, and order contents — are never ingested into the Orderly Intelligence system. Our ingestion APIs discard these fields at the point of collection, whether the data comes from Orderly Hub or directly from carriers. We consider Network Data effectively anonymized, we commit not to attempt to re-identify any individual from it, and we require the same of anyone who receives aggregated insights derived from it. Network Data processing applies to all shipments processed through the Service and cannot be opted out of; it is a condition of use described in our Terms of Service.
5. How We Share Personal Data
We do not sell personal data. We share personal data with:
- Service providers (sub-processors): cloud hosting, payment processing (Stripe), usage metering and billing (Metronome), AI model providers for the AI Agent, email delivery, and monitoring providers, each bound by contractual data protection obligations. Our current sub-processor list is available in Annex III of our Data Processing Addendum.
- Carriers: when you purchase shipping services, we transmit the shipment data needed for delivery (including recipient name and address) to the selected carrier (e.g., UPS, FedEx, USPS, DHL, Royal Mail). Carriers process this data as independent controllers under their own privacy policies.
- Platforms you connect: data flows to and from the third-party platforms you link via Bridges, as configured by you.
- Professional advisers and authorities: where required by law, legal process, or to protect our rights, users, or the public.
- Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality and this Policy.
6. International Transfers
We are based in the United Kingdom and use service providers in the United States and elsewhere. Where personal data protected by UK or EU GDPR is transferred to a country without an adequacy decision, we use appropriate safeguards: the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and/or the EU–US Data Privacy Framework (including its UK Extension) where the recipient is certified. You may request a copy of the relevant safeguards by contacting privacy@vextria.tech.
7. Retention
We keep Account Data for as long as your account is active and for up to 6 years afterwards where needed for tax, accounting, legal claims, or fraud prevention, then delete or anonymize it. Customer Content is retained for the duration of the customer’s agreement and deleted within the export/deletion window described in our Terms and DPA, subject to backup rotation of up to 90 days. Network Data, being non-identifiable, may be retained indefinitely.
8. Security
We use appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, multi-tenant isolation, role-based access controls with MFA, audit logging, and an incident response process. No system is perfectly secure; if we become aware of a personal data breach, we will notify affected parties and regulators as required by law.
9. Cookies
We use only cookies and similar technologies that are strictly necessary to operate the Service (authentication, session management, security). We do not currently set analytics or advertising cookies. You can manage or clear cookies through your browser settings; blocking essential cookies may prevent parts of the Service from working.
10. Your Rights — UK and EU (GDPR)
If you are in the UK or EEA, you have the right to: access your personal data; rectify inaccurate data; erasure; restriction of processing; data portability; object to processing based on legitimate interests (including direct marketing, where the right to object is absolute); and withdraw consent at any time where processing is based on consent, without affecting prior processing.
To exercise these rights, contact privacy@vextria.tech. We will respond within one month (extendable by two further months for complex requests). We may need to verify your identity. If we act as processor for the data in question, we will refer your request to the relevant business.
You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner’s Office (ico.org.uk); in the EEA, your local data protection authority. We would appreciate the chance to address your concerns first.
We do not use Account Data for automated decision-making producing legal or similarly significant effects.
11. Your Rights — United States
If you are a resident of California or another US state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, and Texas), you may have the right to: know/access the personal information we hold about you; correct it; delete it; obtain a portable copy; and opt out of “sales,” “sharing” for cross-context behavioral advertising, and certain profiling. We do not sell personal information or share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes requiring a right to limit under the CCPA.
The categories of personal information we collect, the purposes, and the categories of recipients are described in Sections 2, 3, and 5. To exercise your rights, email privacy@vextria.tech; we will verify your request and respond within the timeframe required by applicable law (generally 45 days). You may use an authorized agent as permitted by law. We will not discriminate against you for exercising your rights.
If you are an end customer of a business that uses Orderly, we process your information as that business’s service provider; please direct requests to that business.
12. Children
The Service is intended for business use and not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a revised “Last updated” date and, for material changes, notify account holders by email or through the Service.
14. Contact
Questions or requests: privacy@vextria.tech Vextria Atlas Group Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom