For a lot of EU businesses, GDPR isn't a checkbox, it's a genuine constraint on what tools you're willing to put on the website. Orbit doesn't use cookies and doesn't collect the kind of personal data that triggers a consent requirement in the first place, so there's no banner to build, no consent-management platform to configure, and no legal review to schedule.
Orbit avoids the cookie banner because it doesn't collect the personal data that requires consent in the first place — no cookies, no cross-site identifiers, no fingerprinting. That's a stronger privacy position than a tool that just hides its cookie prompt.
Orbit is a hosted service built on the open-source Umami project; it doesn't offer self-hosting, so your data lives on Orbit's infrastructure rather than a server your organization controls.
Not for Orbit's own tracking — since it collects no cookies or personal identifiers, there's nothing for a CMP to manage. You'd only need one if other tools on your site, like ad pixels or chat widgets, require it.
Yes — owner, manager, and view-only roles let you restrict who can edit sites versus who can only view the dashboard, useful for compliance or leadership oversight.