Arco Privacy Policy

Last Updated: September 26, 2026

At Arco ("we", "our", or "us"), we take your privacy seriously. This policy explains how we collect, use, and protect your personal data when you use the Arco platform to organize or register for archery events.

1. Our Role: Controller vs. Processor

Under UK GDPR, the responsibilities for data are split depending on how you use Arco:

  • For Club Organisers: Arco is the Data Controller of your account information (e.g., your login email, billing details).
  • For Archers: The archery club hosting the event is the Data Controller of your registration data. Arco acts strictly as a Data Processor, storing and processing this data solely on behalf of the club to facilitate the event.

2. The Data We Collect

From Club Organisers:

  • Name and email address.
  • Club details and billing information (processed securely via our payment partner).

From Archers (Collected on behalf of the Host Club):

  • Name and contact email.
  • Archery governing body details (e.g., Archery GB number).
  • Date of Birth / Age bracket (strictly required for accurate tournament categorization).
  • Emergency contact information.

Automatically Collected Data: When you interact with Arco, we automatically collect basic technical information to keep the platform secure and functional. This includes your IP address, browser type, device information, and essential login cookies.

3. How We Process Your Data

We use this information to:

  • Facilitate tournament registrations, target allocations, and waitlists.
  • Send transactional emails (e.g., registration receipts, event updates).
  • Process payments securely.

Our Lawful Basis (For Organisers): We process your account data based on the performance of a contract (providing the Arco platform to you) and our legitimate interests (improving our software and maintaining security).

4. Our Trusted Sub-Processors

We never sell your data. To operate the Arco platform, we share essential data with the following secure, GDPR-compliant service providers:

  • Vercel & Supabase: For secure cloud hosting and database storage.
  • Stripe: For payment processing. (Arco never touches or stores complete credit card numbers).
  • Loops & Postmark: For delivering transactional receipts and club communications.
  • International Transfers: Some of our sub-processors are based outside the UK and European Economic Area (EEA), primarily in the United States. When your data is transferred internationally, we ensure it is protected by approved legal safeguards, such as the UK International Data Transfer Agreement (IDTA) or the EU-US Data Privacy Framework.

5. Data Retention & Your Rights

We retain archer registration data only as long as necessary for the club to manage the event, or until the club instructs us to delete it. Under UK GDPR, you have the right to access, correct, or request the deletion of your personal data.

  • Archers: Please contact the host club directly to exercise these rights regarding event data.
  • Organisers: Contact us at support@app.arco-events.com to manage your workspace data.

Right to Complain: If you have concerns about how we handle your personal data, we hope you will reach out to us first so we can fix it. However, you always have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.