Privacy Policy
Last updated: August 31, 2026
1. Introduction
This Privacy Policy explains how Arco Labs LLC (“Arco Labs,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you visit arcops, use our workspace, or use our tracker, API, CLI, MCP server, events, webhooks, and related Services. It describes our practices as a service provider to workspace customers and as the controller of account and service information.
2. Scope and roles
A workspace customer decides what product, visitor, customer, inbox, billing, and Search Console data to connect. For that workspace data, Arco Labs generally processes information on the customer's instructions to provide the Services. The customer is responsible for its notices, consents, lawful basis, and requests from people whose data it sends to Arcops. For account, security, billing, and direct support information, Arco Labs determines the purposes and means of processing.
3. Information you provide
- Account and identity: name, email address, profile details, login and session records, and connected Google sign-in information.
- Workspace configuration: organization membership, site names and domains, allowed origins, lifecycle definitions, experiments, releases, and settings.
- Integration credentials: Stripe API and webhook secrets, Search Console OAuth tokens, email or Cloudflare connection details, and other credentials you choose to connect. Sensitive credentials are encrypted at rest.
- Workspace data: product events, pageviews, sessions, identities, accounts, attribution fields, revenue records, inbox messages, attachments, event deliveries, agent actions, approvals, signals, and audit records that a workspace sends or generates.
- Communications and billing: support requests, feedback, subscription or plan metadata, invoices, and payment-provider identifiers. Payment providers process full payment card details.
4. Information collected automatically
We collect technical and usage information when you use the Services, such as IP address and approximate location derived from edge headers, browser and device information, pages and features used, referring URL, timestamps, request and error logs, and performance information. Our tracking script collects the event fields configured by a workspace, including pageviews, custom events, UTM values, session identifiers, and trusted product user or account identifiers. The tracker does not turn an untrusted browser identity into a Stripe identity.
5. Cookies and similar technologies
The Arcops website and workspace use cookies and similar browser storage for the categories described below. The Arcops tracking script is a first-party script that runs on a workspace's site; it keeps a short-lived session identifier in browser session storage and does not require a third-party advertising cookie.
| Category | What we use it for | Duration | Examples |
|---|---|---|---|
| Strictly necessary | Signing in, protecting accounts, CSRF and security checks, and processing invitations. The Services cannot function without these. | Session, or up to 30 days where you choose to stay signed in | Better Auth session and CSRF cookies, sign-in state |
| First-party analytics | Understanding how the website, workspace, and public interfaces are used so we can operate, maintain, and improve them. | Session | Our own product pageview pipeline and session identifiers |
We do not currently set advertising cookies or cross-site tracking cookies on our own site, and the tracking script does not use them. Your browser controls can block or delete cookies and site storage; disabling essential mechanisms may prevent sign-in or parts of the workspace from working.
6. Connected accounts and data sources
If a workspace connects Google Search Console, Stripe, Cloudflare, an email channel, or another provider, we process the data made available through the selected scopes. Search Console queries and dimensions are cached for product reporting. Stripe customers, subscriptions, invoices, charges, refunds, disputes, and webhook events support revenue reporting and reconciliation. Provider permissions can be revoked from the provider or workspace settings. Each provider's own privacy policy also applies.
7. How we use information
- Provide, secure, troubleshoot, and improve the Services and their public interfaces.
- Join the acquisition, product, lifecycle, revenue, and customer facts a workspace asks us to process.
- Authenticate users and API keys, enforce organization and site boundaries, rate-limit requests, and record audit events.
- Run requested synchronization, reconciliation, delivery, and maintenance jobs.
- Respond to support, send service notices, process billing, and communicate changes.
- Detect fraud, abuse, security incidents, and violations of our Terms.
- Generate aggregated or de-identified operational insights, such as reliability and feature usage, without exposing a workspace's raw content.
Arcops does not contain an in-product language model. We do not use a workspace's raw content to train our own foundation model. An external coding agent may read or act on data only through the interfaces and credentials a workspace authorizes.
8. How we share information
We may disclose information:
- to infrastructure, hosting, database, email, authentication, monitoring, and payment providers that process it under our instructions;
- to a connected provider when a workspace requests a sync, publish, delivery, or other integration action;
- to workspace members and agents authorized by that workspace, subject to its roles, scopes, and approvals;
- when required by law, legal process, or a valid safety or security request; or
- in connection with a merger, financing, reorganization, or sale, subject to appropriate confidentiality protections.
We do not sell personal information or share workspace event data for cross-context behavioral advertising. We do not disclose a workspace's raw inbox, billing, or analytics content to another workspace.
9. Legal bases
Where privacy law requires a legal basis, we process account and service information to perform a contract, pursue legitimate interests such as security and reliability, comply with law, or with consent where we request it. For workspace data, the relevant workspace customer determines its own legal bases and notices, and Arco Labs acts on that customer's instructions.
10. European privacy rights
If you are in the European Economic Area, the United Kingdom, or Switzerland, you may have the right to:
- access the personal information we hold about you and receive a copy;
- correct inaccurate or incomplete personal information;
- request deletion of personal information where permitted by law;
- restrict or object to processing, including where we rely on legitimate interests;
- receive your personal information in a structured, machine-readable format (data portability); and
- withdraw consent at any time where processing is based on consent.
You may also lodge a complaint with your local data protection supervisory authority. For personal information that a workspace controls, we will coordinate with that workspace customer so it can respond to the request.
11. U.S. state privacy rights
Residents of California and other states with comprehensive privacy laws (such as Colorado, Connecticut, Utah, and Virginia) may have rights to know, access, correct, delete, and opt out of certain processing, and to not be discriminated against for exercising those rights.
We do not sell personal information, and we do not share workspace event data for cross-context behavioral advertising. We have no actual knowledge that we sell or share the personal information of anyone under 16. If you are a California resident, the categories of personal information we may collect are described in sections 3, 4, 5, and 6, and the categories of recipients are described in section 8.
12. Data subject requests
To exercise a privacy right, send your request to [email protected]. We may verify your identity and may need to coordinate with the workspace customer that controls the data before we can respond. We aim to respond within the period required by law and will let you know if we need more time or more information. If you are unhappy with our response, you may ask us to reconsider.
13. Retention and deletion
We retain information only as long as needed for the purposes in this Policy, a workspace's use of the Services, security and accounting, legal obligations, or dispute resolution. Current retention behavior includes:
- Better Auth profile, session, and connected-account records remain while a login account is active; deleting them runs through the request channel in section 12.
- Workspace sites, analytics, inbox, integrations, agent history, audit, and transaction facts generally remain while the workspace is active; there is no general scheduled purge of active analytics.
- Search Console cache records are pruned after up to 365 days.
- Raw Stripe webhook payloads and raw outbound event payloads are nulled after 30 days; the limited idempotency, delivery, audit, and transaction facts needed for integrity may remain.
- Terminal event-delivery attempts may be removed after 90 days.
A personal account and a workspace are different owners. Deleting an individual login removes that person's identity and access; it does not silently delete the organization's sites or operational history. A workspace owner may contact us about workspace-level deletion, subject to verification, legal holds, backups, and the retention facts above.
14. Security
We use HTTPS in transit, managed PostgreSQL infrastructure, access controls, rate limits, audit logging, and AES-256-GCM encryption at rest for sensitive integration credentials. No security measure is perfect, and you are responsible for protecting credentials, devices, API keys, and the systems that send data to Arcops. If you believe there is a security issue, contact us promptly and do not include unnecessary secrets or personal information.
15. International processing
Arco Labs and our service providers may process information in the United States and other countries where they operate. Those places may have different data-protection rules. Where a customer's transfers require a safeguard, we agree on the applicable terms with that customer.
16. Children
The Services are not directed to children under 13, or a higher age where local law requires. We do not knowingly collect a child's personal information. Contact us if you believe a child has sent us information so we can review and remove it where appropriate.
17. Third-party links and services
The Services may link to or interoperate with third-party websites, platforms, and software. Their privacy practices, terms, and security are outside our control. Review those policies before connecting an account or sending data.
18. Changes
We may update this Policy as the Services, law, or data practices change. We will post the revised version and update the date above. If a change is material, we will provide additional notice when reasonable.
19. Contact
Privacy questions and rights requests can be sent to [email protected]. You may also write to Arco Labs LLC, 30 N Gould St Ste R, Sheridan, WY 82801, USA.
