Privacy Policy
Version 2026-10-03. Valid from 3 October 2026.
1. Controller
Orbita Media GmbH
Ericusspitze 4
20457 Hamburg
Germany
Register court: Hamburg Local Court (Amtsgericht Hamburg), commercial register no. HRB 161613
Managing directors: Noah Malik, Stefan Schott
E-mail: datenschutz@orbita-media.de
[DATA PROTECTION OFFICER: to be filled in, or the sentence "We are not required to appoint a data protection officer under Sec. 38 BDSG" if that is the case after the takeover.]
2. What this policy covers
This policy describes how we process personal data when you use the publishing platform Shelf Publisher at shelfpublisher.com (formerly portal.orbita-media.de). It applies to visitors of the public pages, to registered authors, to affiliates, and to people who contact us.
Data of readers who buy a book in a shop is not processed by us through this Platform; that relationship is with the respective retailer.
3. Legal bases
We rely on the following legal bases of the General Data Protection Regulation (GDPR):
- Art. 6(1)(b) GDPR: performance of a contract, or steps taken before entering into a contract. This covers the account, the order, the review and publication of a title, the statements and the payouts.
- Art. 6(1)(c) GDPR: compliance with a legal obligation. This covers in particular the retention of accounting records under Sec. 147 of the German Fiscal Code and Sec. 257 of the German Commercial Code, and tax reporting.
- Art. 6(1)(f) GDPR: our legitimate interests, namely the security and stability of the Platform, the prevention and investigation of fraud and abuse, and the assertion of legal claims.
- Art. 6(1)(a) GDPR: your consent, for optional cookies, for the affiliate tracking cookie, and for e-mails that are not needed to perform the contract. You can withdraw your consent at any time with effect for the future.
Where we act on the basis of your consent for the storage of information on your device, we also rely on Sec. 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG); for what is strictly necessary we rely on Sec. 25(2) no. 2 TDDDG.
4. What we process, and why
4.1 Visiting the website
Every request is logged by our server with the IP address, the date and time, the page requested, the referrer, the browser and the operating system. Purpose: delivering the page, security, and finding faults. Legal basis: Art. 6(1)(f) GDPR. These logs are deleted after 7 days.
Before the login and registration forms we use Cloudflare Turnstile to tell humans from bots. Turnstile receives the IP address and technical information about the browser. Legal basis: Art. 6(1)(f) GDPR, our interest in keeping automated attacks away from the login.
4.2 Account and login
We process: name, e-mail address, password in hashed form or the identifier of your login provider, postal address, country, telephone number, tax number or VAT identification number, bank details, profile picture if you upload one, and the date of registration.
Registration and login are handled for us by [AUTHENTICATION PROVIDER: Clerk, Inc.]. Logging in with a Google account is possible; in that case Google tells us your name, your e-mail address and your profile picture. We store a session identifier in an encrypted cookie and in our Redis cache; a one-time password sent by e-mail is stored for 10 minutes.
Purpose: giving you access to the Platform and being able to identify you. Legal basis: Art. 6(1)(b) GDPR. Bank and tax data: Art. 6(1)(b) and (c) GDPR.
4.3 Orders and payments
We process the order data, the package chosen, the price, coupons used, the country used to determine value added tax, and the status of the payment.
Card and account data are entered on the pages of our payment service provider and are not stored by us. We receive from the provider only the fact of payment, the amount, the payment method, the last four digits of a card where applicable, and an identifier for the transaction.
Purpose: performing the contract, preventing fraud, accounting. Legal basis: Art. 6(1)(b) and (c) GDPR, and Art. 6(1)(f) GDPR for fraud prevention.
4.4 Invoices and credit notes
Invoices for your purchases and credit notes for your earnings are created in our accounting system and stored. They contain your name, your address, your tax identifiers, the items and the amounts. Purpose and legal basis: performing the contract and complying with the retention duties under Sec. 147 of the German Fiscal Code, Art. 6(1)(b) and (c) GDPR.
4.5 Manuscripts, covers and other uploads
The files you upload are stored in our object storage and in our database together with the metadata of the title. Files can contain personal data, for example your name as the author, an author photograph, a biography, and the names of persons mentioned in the book. Purpose: performing the contract. Legal basis: Art. 6(1)(b) GDPR.
4.6 Automated pre-check of manuscripts
Before a person reviews your manuscript, an automated check runs. It looks at technical printability and at indications of content that we are not allowed to publish. For part of that check we transmit text from the manuscript to an external provider of a large language model (at present none: the automated pre-check is switched off, and no manuscript leaves our servers for it).
- The provider processes the text only for the purpose of returning the result to us. Where the provider offers it, we have switched off the use of the data for training.
- The transmission may involve a transfer to a third country; see clause 6.
- The result of the automated check is not a decision about you within the meaning of Art. 22 GDPR. It is a recommendation. Every acceptance and every rejection is decided by a person at Orbita, who can overrule the machine. You can ask for the reasons for a rejection and can contest it.
Legal basis: Art. 6(1)(b) GDPR, because the check is part of the service we owe, and Art. 6(1)(f) GDPR as regards our interest in not publishing unlawful content.
4.7 Publication and distribution
For a title that we publish, the metadata (title, author name as given by you, blurb, cover, ISBN, price, categories) is passed to the bibliographic directories and to the distribution channels, and from there to retailers. The author name is published. If you publish under a pseudonym, we still need your real name for the contract, for accounting and for the ISBN registration, but we do not publish it.
Legal basis: Art. 6(1)(b) GDPR. This transfer is the point of the contract and cannot be undone once a title is in circulation: catalogues, libraries and shops keep bibliographic records permanently.
4.8 Sales reports, earnings and payouts
We import the sales reports of the distribution channels, allocate the sales to titles and accounts, calculate the earnings and record them in your wallet. For a payout we process your bank details and the amount. Legal basis: Art. 6(1)(b) and (c) GDPR.
Part of this processing currently runs through a spreadsheet and a file storage of Google Drive and Google Sheets that we use as a working area for the reports.
4.9 Support and tickets
Messages you send through the ticket system or by e-mail are stored with your name, your e-mail address, the content and the attachments. Purpose: answering your request and documenting what was agreed. Legal basis: Art. 6(1)(b) GDPR for requests about the contract, Art. 6(1)(f) GDPR for other requests.
4.10 E-mails we send
We send e-mails that are needed to perform the contract: one-time passwords, order confirmations, status changes of a title, statements, reminders about expiring slots, and answers to tickets. Legal basis: Art. 6(1)(b) GDPR. You cannot unsubscribe from these while the contract runs.
Advertising e-mails are only sent with your consent, Art. 6(1)(a) GDPR and Sec. 7(2) no. 2 of the German Act against Unfair Competition. Every advertising e-mail contains an unsubscribe link.
4.11 Affiliate programme
If you take part in the affiliate programme, we process your referral code, the clicks on your link, the accounts attributed to you, the amounts on which commission is calculated and the commission itself. Legal basis: Art. 6(1)(b) GDPR.
If you were referred by an affiliate, we store which affiliate you were referred by. That affiliate sees only your first name, the initial of your last name, the month of your registration and the amounts on which its commission is calculated. The affiliate does not see your address, your e-mail address, your titles or your earnings. Legal basis: Art. 6(1)(f) GDPR, our interest and the affiliate's interest in being able to check the commission, balanced against your interest by reducing the data to the minimum described.
The tracking cookie of the affiliate programme is only set with your consent, Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG. Its lifetime is 90 days.
4.12 Fraud prevention and enforcement of the terms
To detect multiple accounts, self-referrals and manipulated attributions, we compare master data, payment identifiers and technical attribution data within our own systems. Legal basis: Art. 6(1)(f) GDPR. No decision that produces legal effects is taken automatically here either; a person decides.
5. Cookies
We use the following categories:
| Category | Purpose | Basis | Lifetime |
|---|---|---|---|
| Strictly necessary | session, login, CSRF protection, cookie banner choice, bot protection | Sec. 25(2) no. 2 TDDDG, Art. 6(1)(f) GDPR | session up to 30 days |
| Affiliate tracking | attributing a registration to a referrer | consent, Sec. 25(1) TDDDG, Art. 6(1)(a) GDPR | 90 days |
| [Further categories, if any: analytics, marketing] | consent |
You choose in the cookie banner. You can change or withdraw your choice at any time at https://shelfpublisher.com/legal/cookie-policy. Details are in the Cookie Policy.
6. Recipients and processors
We use the following service providers. Those marked as processors act on our instructions under a contract pursuant to Art. 28 GDPR.
| Service provider | What for | Role | Location |
|---|---|---|---|
| [HOSTING PROVIDER: Hetzner Online GmbH] | servers, database, backups | processor | Germany |
| [CDN AND SECURITY: Cloudflare] | delivery, bot protection, object storage | processor | EU and USA |
| [AUTHENTICATION PROVIDER: Clerk] | registration, login, session | processor | USA |
| Google Ireland Ltd / Google LLC | login with a Google account, spreadsheet and file storage for the sales reports | processor for the storage, controller for the login on its side | Ireland and USA |
| [PAYMENT PROVIDER: Stripe Payments Europe Ltd] | payment processing | own controller for payment data | Ireland and USA |
| [ACCOUNTING: sevdesk GmbH] | invoices and credit notes | processor | Germany |
| [E-MAIL DELIVERY: Amazon Web Services EMEA SARL] | sending transactional e-mail | processor | EU |
| none at present | automated pre-check of manuscripts | processor | Germany |
| Distribution channels: Ingram, BoD, Amazon and the further channels listed on the Platform | publication and sale of the title | own controllers | EU and USA |
| Bibliographic directories | registration of the title | own controllers | EU |
| Tax advisers, auditors, lawyers | where the law requires it or a claim has to be pursued | own controllers or processors | Germany |
We do not sell personal data and do not pass it on for the advertising of third parties.
7. Transfers to third countries
Some of the providers named above process data in the United States. A transfer takes place on one of the following bases:
- an adequacy decision of the European Commission of 10 July 2023 for the EU-US Data Privacy Framework, where the provider is certified under it (Art. 45 GDPR), or
- the standard contractual clauses of the European Commission of 4 June 2021 together with additional measures, in particular encryption in transit and at rest (Art. 46(2)(c) GDPR).
You may ask us for a copy of the guarantees at datenschutz@orbita-media.de.
For the AI provider used in the pre-check under clause 4.6 the basis is [TO BE COMPLETED once the provider is chosen]. If no adequacy decision applies, we use standard contractual clauses.
8. How long we keep data
| Data | Period |
|---|---|
| Account and master data | for the duration of the account, then 3 years to the end of the year, following the limitation period of Sec. 195, 199 BGB |
| Invoices, credit notes, payment records and everything else relevant to accounting | 10 years, Sec. 147(3) of the German Fiscal Code, Sec. 257(4) of the German Commercial Code |
| Contract documents and consent records | for the duration of the contract and a further 3 years, so that we can prove consent under Art. 7(1) GDPR |
| Manuscripts and covers | while the title is published and a further 12 months |
| Metadata of a published title | permanently in the bibliographic record, which cannot be undone |
| Ticket messages | 3 years from the end of the year in which the ticket was closed |
| Server logs | 7 days |
| Affiliate attribution data | for the duration of the participation and a further 3 years |
Where a retention duty applies, we restrict the processing of the data instead of deleting it, until the period has expired.
9. Your rights
You have the right to:
- access the data we hold about you (Art. 15 GDPR);
- have inaccurate data corrected (Art. 16 GDPR);
- have data deleted (Art. 17 GDPR), unless we have to keep it;
- have processing restricted (Art. 18 GDPR);
- receive your data in a machine-readable format and have it transmitted (Art. 20 GDPR);
- withdraw a consent at any time with effect for the future (Art. 7(3) GDPR).
Right to object (Art. 21 GDPR). Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We then stop processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. Where data is processed for direct marketing, you may object at any time without giving reasons.
Requests go to datenschutz@orbita-media.de. We answer within one month.
Complaint. You may complain to a supervisory authority, in particular in the member state of your residence or workplace. The authority responsible for us is the Hamburgische Beauftragte fuer Datenschutz und Informationsfreiheit, Ludwig-Erhard-Strasse 22, 20459 Hamburg, Germany.
10. Do you have to give us data?
You have to give us the data we need to conclude and perform the contract: identification data, contact data, and, for a payout, bank and tax data. Without it we cannot open an account, publish a title, or pay out earnings. Everything else is voluntary.
11. Automated decision-making and profiling
We do not take decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing within the meaning of Art. 22(1) GDPR. The automated pre-check under clause 4.6 and the fraud checks under clause 4.12 prepare a decision; the decision itself is always taken by a person.
12. Changes to this policy
We update this policy when the processing changes, when we add or replace a service provider, or when the law requires it. The current version is always available at https://shelfpublisher.com/legal/privacy-policy. If a change is material, we will ask you for your consent again through the Platform.