Privacy Policy

Last updated: March 2026 · Subject to revision

1. What We Collect

When you use fair-arc, we collect:

  • Account data: Email address, name, and password (hashed, never stored in plaintext).
  • Entry data: Name, email, and shipping address provided at the time of entry. These are used for prize fulfillment only.
  • Payment data: Processed by Stripe. fair-arc does not store card numbers or CVVs.
  • Usage data: Pages visited, actions taken, and approximate IP address for rate limiting and fraud prevention.

2. How We Use Your Data

  • To operate the Platform and process your entries and payments.
  • To ship prizes to winners.
  • To send transactional emails (entry confirmation, countdown notifications, results).
  • To prevent fraud and abuse.
  • To improve the Platform based on usage patterns.

We do not sell your personal data. We do not use your data for advertising.

3. Public Information

Arc entry lists are publicly visible — showing your first name and last initial alongside your assigned slot number. This is an intentional transparency feature: anyone can verify that the entry list is accurate. Full names and contact details are never publicly displayed.

4. Data Sharing

We share data only with:

  • Stripe — payment processing.
  • Supabase — database and authentication hosting.
  • Resend / email provider — transactional email delivery.
  • Vercel — application hosting.
  • Law enforcement when required by law.

5. Data Retention

Account data is retained while your account is active. Entry data for completed Arcs is retained indefinitely as part of the provably fair audit trail. You may request deletion of your account and associated data at any time by contacting us — note that Arc result records (slot numbers, entry IDs, winners) may be retained for transparency and audit purposes even after account deletion.

6. Security

We use industry-standard encryption for data at rest and in transit. RNG seeds are encrypted before storage. Passwords are hashed using bcrypt. We conduct regular security reviews. However, no system is perfectly secure — if you discover a vulnerability, please disclose it responsibly to security@fair-arc.com.

7. Cookies

We use strictly necessary cookies for session management (authentication). We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

8. Your Rights

Depending on your jurisdiction, you may have rights including:

  • Access to the data we hold about you.
  • Correction of inaccurate data.
  • Deletion of your account and personal data.
  • Objection to processing in certain circumstances.

To exercise these rights, email privacy@fair-arc.com.

9. Children

fair-arc is not directed at users under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us immediately.

⚠️ This Privacy Policy is a working draft and has not been reviewed by legal counsel. It will be finalized before public launch.

Questions? Contact us at privacy@fair-arc.com