Terms of Service
The agreement between you and ShellOrbit for use of ShellOrbit, including acceptable use, billing, uptime, and liability.
These terms govern your use of ShellOrbit, a hosted service that receives inbound webhooks, stores them, and delivers them to destinations you configure. In this document, “we”, “us”, and “ShellOrbit” mean the operator of the service, and “you” means the person or organisation using it. If you use the service on behalf of a company, you confirm you have authority to accept these terms for that company.
By creating an account or sending traffic to an ingest endpoint, you accept these terms. If you do not accept them, do not use the service.
1. What the service does
ShellOrbit provides:
- HTTP ingest endpoints that accept webhook requests from third party providers or your own systems.
- Durable storage of each received request, including method, headers, query string, and raw body, for the retention window on your plan.
- Delivery of received events to one or more destination URLs you configure, with retry and backoff on failure.
- A dashboard and API for inspecting events, delivery attempts, and responses, and for replaying events inside the retention window.
- Notifications about delivery failures and account state.
The service is a relay and a record. It does not interpret your payloads for you, guarantee that your destination behaves correctly, or replace your own error handling.
2. Accounts and authentication
Authentication is handled by WorkOS. Creating an account means an identity record is created with WorkOS on our behalf, and session credentials are issued through it. You are responsible for the security of your login method, for any credential you connect through a single sign on provider, and for every action taken through your account.
You must give accurate account information and keep the contact address current. Delivery failure notices, security notices, and billing notices go to that address, and a stale address is not a defence against a notice we sent.
You must be at least the age of legal majority in your jurisdiction and legally able to enter a contract. The service is not offered to children.
3. Endpoint secrets and signing keys
Ingest endpoint identifiers, signing secrets, and API keys are credentials. Treat them as such. Anyone who holds an ingest URL can post events to it, and anyone who holds an API key can read your stored payloads and manage your endpoints. Rotate any credential you believe is exposed, from the dashboard or the API, and tell us at security@shellorbit.com if you think our systems are involved.
4. Your responsibilities
You are responsible for:
- The destination URLs you configure, including that they are yours or that you have permission to send traffic to them.
- The content of the payloads that pass through the service, and for having a lawful basis to store and forward that content.
- Whatever your own handler does with a delivered event, including duplicate handling. Delivery is at least once, not exactly once, so your handler must tolerate a repeated event.
- Complying with the terms of the providers whose webhooks you route through us.
5. Acceptable use
You may not use the service for any malicious purpose, meaning any use intended to attack, deceive, defraud, or damage us, another customer, or a third party. That includes, without limiting the general rule:
- Send traffic to a destination that has not consented to receive it, including using retries or fan out as a way of generating load against a third party. Using the service as a load generator, amplifier, or proxy for denial of service is prohibited.
- Route content that is unlawful in the jurisdiction where it is stored or received, including material that infringes intellectual property, child sexual abuse material, or content that is unlawful to transmit.
- Distribute malware, ransomware, or phishing content, stage or coordinate an attack on a third party system, or use a delivered event to deliver an exploit payload to a destination.
- Impersonate a person, provider, or organisation, or forge a webhook’s origin or signature in order to deceive a destination about where a request came from.
- Circumvent plan limits, including by creating multiple accounts to obtain additional free volume, or by sharing one account’s endpoints across unrelated products in order to avoid usage charges.
- Probe, scan, or test the vulnerability of the service without written permission, or interfere with another customer’s endpoints, data, or delivery.
- Resell the service as if it were your own infrastructure, unless we have agreed that in writing.
- Store payment card data, government identity numbers, or health records in payloads where doing so puts either of us under a compliance regime we have not agreed to. If your payloads carry data of that kind, the data processing addendum applies and you must tell us before you begin.
We may set technical protections, including per endpoint rate limits and maximum payload sizes, and publish them in the documentation. Traffic that threatens the stability of the platform may be throttled without notice, and we will tell you when we do.
Malicious use of the service, including anything in this section, is grounds for immediate suspension or termination of the account under section 15, without the notice period that applies to an ordinary breach and without refund of fees already paid, at our discretion and in addition to any other remedy available to us in law.
6. Plan limits, overage, and volume
Each plan includes a monthly event volume and a retention window. Volume is measured by events received, not by delivery attempts, so a retried event counts once.
On paid plans, events received above the included volume are billed at the per thousand rate published for your plan. Going over the included volume does not by itself interrupt the service.
Every paid account also has a monthly safety limit, set well above the included volume, which exists to stop a misconfigured or looping provider running up a bill nobody intended. Reaching it pauses acceptance rather than continuing to charge: new events are refused at the edge with a 429 status, which providers treat as a signal to retry later, so events wait at the provider rather than being lost. You can raise the limit in billing settings, and delivery resumes as soon as you do. We will tell you before you reach it.
On the free plan, once you pass the included volume we continue accepting events and hold them for up to 48 hours while we notify you. If the account is still over its limit at the end of that window, delivery slows and, if it remains over for a sustained period, new events may be rejected at the edge with a 429 status so the provider retries on its own schedule. We will always tell you before that happens.
We do not delete stored events as a consequence of exceeding a plan limit. Events leave storage when they age out of your retention window, when you delete them, or when the account is closed as described in section 15.
7. Billing through Paddle
Payments are processed by Paddle as merchant of record. Paddle is the seller of record for your purchase, handles the payment instrument, and collects sales tax, VAT, or GST where it applies. We never see or store your full card details.
- Your payment relationship for the transaction is with Paddle, and Paddle’s buyer terms apply to it alongside these terms.
- Subscriptions renew automatically for the period you selected until cancelled. Cancel from the dashboard before the period ends to stop the next renewal.
- Usage charges for volume above your included events are calculated from our metering records and billed through Paddle in arrears.
- Prices are stated in United States dollars and exclude tax unless the checkout says otherwise. Paddle may present a local currency at checkout.
- If a payment fails, we retry it through Paddle’s dunning process and notify you. If it keeps failing, the account moves to the free plan limits, and eventually to suspension under section 15. Events already stored stay inside the retention window that applied when they were received, unless the account is closed.
- Annual plans are paid up front for the year. The refund policy governs what happens to money already paid.
We may change prices. For an existing subscription we will give at least 30 days notice by email before a price change takes effect, and you may cancel before it does.
8. Free plan and beta features
The free plan exists so you can run a real project without paying. It carries no uptime commitment and we may change its limits with notice.
Features labelled beta, preview, or experimental are provided as they are. They may change or be withdrawn, and they carry no uptime or support commitment. Do not put a beta feature on a path where a failure would hurt you.
9. Uptime, support, and maintenance
The Business plan carries a 99.9 percent monthly availability commitment on the ingest endpoint, measured as the proportion of well formed requests that receive a 2xx acknowledgement. Availability excludes:
- Scheduled maintenance announced at least 48 hours in advance on the status page.
- Failures caused by your configuration, your destination, or your provider.
- Traffic throttled under section 5 or rejected under section 6.
- Events outside our control, as described in section 19.
If we miss that commitment in a month, tell us within 30 days and we will credit the affected month in proportion to the shortfall, up to one month of the plan fee. Service credit is the only remedy for missed availability, and credit is applied to future invoices rather than paid out.
Lower plans run on the same infrastructure with no contractual availability target. Support response targets by plan are published on the pricing page and are targets, not guarantees.
10. Security
We take the measures set out in the data processing addendum, including encryption in transit, encryption at rest, least privilege access to production systems, and audit logging of administrative access. No system is immune to compromise, and nothing in this section is a warranty against it.
Report a suspected vulnerability to security@shellorbit.com. Do not test against other customers’ endpoints, do not exfiltrate data belonging to anyone else, and give us reasonable time to fix an issue before publishing it. We will not pursue a researcher who follows those conditions in good faith.
11. Your data and our use of it
You keep all rights in the events, payloads, and configuration you send us. We do not sell your data, do not use payload content to train models, and do not share payload content with third parties except the subprocessors listed in the subprocessors page, and then only to run the service.
We use aggregate operational metrics, such as counts, sizes, status codes, and latency, to run and improve the service and to bill usage. Those metrics describe traffic shape, not payload content.
You grant us the limited licence needed to store, transmit, transform where you configure it, and display your content back to you for the purpose of providing the service. That licence ends when the content is deleted.
12. Third party services
The service runs on Amazon Web Services. Transactional email goes through Zoho Corporation’s ZeptoMail. Authentication uses WorkOS. Payments use Paddle. These providers are subprocessors, listed with their purpose on the subprocessors page. We are responsible for their performance as part of the service, and we are not responsible for services you connect to on your own account, including the providers whose webhooks you route and the destinations you deliver to.
13. Intellectual property
The service, including the dashboard, the API, the documentation, and the ShellOrbit name and mark, belongs to us. These terms grant you a right to use the service, not a right to our software or brand. You may say you use ShellOrbit. You may not present the service as your own product, or use our name or mark in a way that suggests endorsement.
Feedback you send us may be used without obligation to you, and sending feedback does not transfer any rights in your own product.
14. Confidentiality
Each side may learn non public information about the other. Neither side will disclose the other’s non public information except to people who need it to perform this agreement and who are bound to keep it confidential, or where disclosure is legally required. Your payload content is treated as confidential regardless of whether it is marked as such.
15. Suspension, termination, and what happens to your data
You may cancel at any time from the dashboard. Cancellation takes effect at the end of the current paid period, and the refund policy applies to money already paid.
We may suspend or limit the account, with notice where practical:
- For non payment that survives the dunning process.
- For a breach of section 5 that is serious or that we asked you to fix and you did not.
- Where continuing would expose us or another customer to legal risk or platform instability.
We may terminate for a material breach that is not fixed within 14 days of written notice, or immediately and without notice for unlawful use or for a malicious use described in section 5. If we discontinue the service entirely, we will give at least 90 days notice and provide export access during that period.
After the account closes, stored events and configuration are retained for 30 days so you can export them, then deleted from live systems. Backups age out within a further 35 days. Billing records are kept for as long as tax and accounting rules require.
16. Disclaimers
The service is provided as it is and as it becomes available. To the extent the law allows, we exclude implied warranties of merchantability, fitness for a particular purpose, and non infringement.
We do not warrant that delivery will be instant, that every attempt will succeed, that the service will be uninterrupted, or that stored data can never be lost. Delivery is at least once. You must design your handler for retries, duplicates, and out of order arrival.
17. Limitation of liability
To the extent the law allows:
- Neither side is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, lost revenue, lost business, or lost goodwill, even if warned that they were possible.
- Our total liability arising out of or related to these terms is limited to the greater of the fees you paid us in the 12 months before the event giving rise to the claim, or 50 United States dollars.
- Where a service credit is available under section 9, it is the exclusive remedy for the unavailability it covers.
Nothing here limits liability that cannot be limited by law, including liability for death or personal injury caused by negligence, or for fraud.
These limits reflect the price of the service. The free plan and the lower paid plans are priced on the basis that this allocation of risk applies.
18. Indemnity
You will defend and indemnify us against third party claims arising from your content, your use of the service in breach of section 5, or your infringement of a third party’s rights. We will tell you promptly about such a claim, let you control the defence of it, and cooperate at your expense.
19. Events outside our control
Neither side is liable for a failure to perform caused by an event beyond its reasonable control, including a failure of an upstream provider, a network outage, a state action, or a natural event. This does not excuse an obligation to pay for service already provided.
20. Changes to the service and to these terms
We improve and change the service continuously. We will not remove a material feature from a paid plan without at least 30 days notice by email.
We may update these terms. For a material change we will give at least 30 days notice by email and publish the effective date at the top of this page. Continuing to use the service after the effective date means you accept the change. If you do not accept it, cancel before that date.
21. General
- These terms, together with the privacy policy, the data processing addendum where it applies, the refund policy, and the plan you selected, are the whole agreement between us about the service.
- If a provision is unenforceable, the rest stays in force.
- Not enforcing a right on one occasion does not waive it.
- You may not assign this agreement without our consent. We may assign it as part of a merger, acquisition, or sale of assets, with notice to you.
- Notices to you go to the account email address. Notices to us go to legal@shellorbit.com.
- Nothing here creates a partnership, agency, or employment relationship.
22. Governing law and disputes
This agreement is governed by the law of the jurisdiction in which the operator is established, and the courts of that jurisdiction have exclusive jurisdiction over disputes, except that either side may seek injunctive relief where its intellectual property or confidential information is at stake. Where you contract with Paddle for payment, Paddle’s own terms govern that payment relationship.
Before filing a claim, contact legal@shellorbit.com and give us 30 days to resolve it. Most disputes about billing or delivery come down to a record we can both read.
23. Contact
- General and account questions: support@shellorbit.com
- Billing: billing@shellorbit.com
- Privacy and data rights: privacy@shellorbit.com
- Security reports: security@shellorbit.com
- Legal notices: legal@shellorbit.com