Our primary standard is UK GDPR. Protections for other jurisdictions are layered on top. Arc Social Ltd is the data controller.
1. Data we collect and why
- Account data (phone, name, username, date of birth, photo, bio, location, email, device fingerprint, IP, declaration): legal basis is contract performance and legal obligation.
- Content data (posts, photos, videos, messages, listings): contract performance.
- Transaction data (records stored by Arc; card details are processed by Stripe only): contract performance and legal obligation.
- Communications data (messages stored, not read except for safety or legal reasons): contract performance.
- Usage data (pages, features, searches, device info, IP-derived location): legitimate interests.
- Location data (IP-derived approximate location, never precise GPS without consent): legitimate interests and consent.
- Special category data (dating and matrimonial profiles may contain sexual orientation, religion or ethnicity): explicit consent, visible only to the relevant section, never used for advertising.
- Age-assurance data (the result of an age-estimation or identity-verification check from our verification partners, and, where an account is removed for being under 18, a one-way hash of the identity document used): legal basis is legal obligation and legitimate interests in keeping under-18s off an adults-only platform. We do not retain the underlying facial image or document number; those are processed by our verification partner.
2. Data sharing
We share data only with service providers who help us run Arc: Stripe (payments and identity verification), Yoti (age estimation), Twilio (SMS), Resend (email), Supabase (hosting) and Vercel (deployment); and with law enforcement under valid legal process only. Your data is never sold. Ever.
3. International transfers
Data may be processed outside the UK by our service providers (Stripe US, Twilio US, Resend US). These transfers are protected by Standard Contractual Clauses and UK adequacy decisions.
4. Retention
Active account data is retained while your account is active. Deleted account data is purged within 30 days, except financial records (kept 7 years per HMRC requirements) and data under legal hold.
5. Your rights under UK GDPR
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. We respond within 30 days. Contact privacy@thearcsocial.com.
6. Rights in other jurisdictions
- EU GDPR: the same rights as UK GDPR for EU residents.
- CCPA (California): right to know, right to delete, right to opt out of sale (Arc does not sell data), and right to non-discrimination. Contact privacy@thearcsocial.com.
- Australia Privacy Act 1988: access and correction rights; complaints via privacy@thearcsocial.com then the Australian Information Commissioner if unresolved.
- India DPDPA 2023: access, correction, erasure and grievance redressal. Point of contact for Indian users: privacy@thearcsocial.com. Response within 30 days.
- Pakistan PECA 2016: complaint process via privacy@thearcsocial.com. Arc cooperates with the Pakistan FIA when presented with valid legal process.
7. Children
Arc is for adults aged 18 and over; we do not permit under-18 accounts. We operate age-assurance measures and may verify age using an age-estimation check or an identity document handled by our verification partners. Where we remove an account for being under 18, we retain only a one-way hash of the identity document to prevent immediate re-registration, and that record lifts on the person's eighteenth birthday.
8. Complaints
UK users can complain to the ICO at ico.org.uk. EU users can complain to their national supervisory authority. Australian users can complain to the OAIC. Indian users can complain to the Data Protection Board of India when operational.
9. Contact
privacy@thearcsocial.com
Arc Social Ltd, registered in England and Wales. Company Number: [COMPANY NUMBER]. Registered address: [ARC REGISTERED ADDRESS]. ICO registration: [ICO REGISTRATION NUMBER].