ARC does not sell or rent submitted personal information.
1. Information ARC collects
- Contact and business details: name, email, business name, phone, public contact details, industry, location, website, and service information.
- Project brief: goals, services, customers, offers, design choices, five-page content priorities, lead-routing preferences, proof details, launch information, and feedback.
- Submitted assets: logos, photos, brand materials, links, reviews, and files you choose to provide.
- Transaction records: Stripe session identifiers, payment status, amount, currency, timestamps, and customer contact details returned by Stripe. ARC does not receive full payment-card numbers.
- Handoff records: opaque Netlify site, deploy, session, and destination-account identifiers; claim status and verification timestamps; and delivery evidence. ARC does not intentionally place names, email addresses, form answers, or other customer details inside claim credentials.
- Request attribution: landing path, referrer host, and allowlisted UTM parameters are attached to a completed preview request.
- First-party analytics: when the separately controlled receiver is enabled, ARC’s Netlify Function and Blobs store record event type, page path, CTA label or form step, server time, and random event and browser-session identifiers. The analytics record does not store names, business names, emails, phone numbers, addresses, form answers, IP addresses, user agents, referrers, or UTM values. The current site does not use analytics or advertising cookies.
- Communications: email messages, approvals, revision requests, and support history.
2. How ARC uses information
- Review a request and create, validate, deliver, revise, and support a website preview or paid site.
- When providing a Netlify production handoff, create a temporary claimable site, issue and verify the claim invitation, confirm the destination account and deployed files, and provide launch support.
- Route form submissions and project notifications to the appropriate workflow and email recipient.
- Verify payment and prevent duplicate delivery, fraud, abuse, and security incidents.
- Measure aggregate page views, CTA clicks, form starts, form-step reach, and completed requests. For completed requests, ARC also measures which campaign or link produced the request.
- Comply with legal, tax, accounting, platform, and dispute obligations.
- Improve ARC’s templates, validation, and operations using minimized or de-identified information where practical.
ARC does not use a client’s confidential brief to create public advertising claims about that client without permission.
3. Service providers
ARC uses providers that process information only as needed to operate the service. These may include Netlify for site hosting, first-party Function and private Blobs intake, and ownership claim and transfer; Zapier for workflow automation; OpenAI for generating and checking draft website content; GitHub for versioned website files and preview hosting; Resend for automated customer transactional email; Gmail and Apollo.io, when the separately controlled outreach program is enabled, for outbound sales outreach rather than customer transactional messages; and Stripe for payment processing.
Those providers handle information under their own terms and privacy policies. ARC may also disclose information when required by law, to protect rights or security, or in connection with a business transfer. ARC does not sell or rent submitted personal information.
4. Preview visibility
ARC preview URLs are unlisted and configured with noindex controls, but they are not password-protected. Anyone who receives or discovers the URL may be able to open it.
ARC excludes the requester’s private email address from public preview HTML. Only content intended for the draft website should be published. Do not submit passwords, government identifiers, financial account details, health information, private customer lists, or other sensitive data.
5. Retention
ARC generally retains preview requests, project records, and related communications for up to 24 months after the last project interaction, unless a shorter period is requested or a longer period is needed for payment, tax, dispute, fraud-prevention, backup, or legal obligations. Payment and accounting records may be retained for the legally required period.
ARC’s retention target for first-party analytics events is 90 days. The deletion control is currently disabled pending operator approval, so ARC does not claim automatic 90-day deletion until that control is activated and verified. Unsubmitted form answers saved in this browser are not restored after seven days and are cleared the next time you open ARC after they expire, when ARC confirms a successful submission, or when you clear this site’s browser data. ARC cannot delete browser storage while the site is closed. On a verified request, ARC will delete or de-identify information it controls when reasonably possible. Copies held in backups or by service providers may take additional time to expire.
6. Security
ARC uses access controls, HTTPS, workflow validation, noindex preview metadata, restricted payment handling, and data minimization. No internet service can guarantee perfect security, and unlisted links should not be treated as secret storage.
Treat a Netlify claim invitation like a password. Anyone who obtains an unused invitation may be able to claim the site. Report a lost, forwarded, exposed, or unexpected invitation immediately so ARC can pause the handoff.
7. Your choices and rights
You may ask to access, correct, or delete personal information, withdraw an optional request, or object to a use through the support form. ARC may need to verify the requester’s identity and may retain information where law or legitimate dispute and security needs require it.
Depending on where you live, additional privacy rights may apply. ARC will respond to valid requests as required by applicable law.
8. Children
ARC is a business service not directed to children under 13. A person under 18 may not purchase alone; a parent, legal guardian, or authorized adult must review and accept the agreement and complete payment.
9. Changes and contact
ARC may update this policy by posting a revised effective date. Material changes apply prospectively.