Privacy Policy
Last updated: June 2026
ArcMirror is operated by Revenue Arc ("we", "us"). This policy explains what information we handle when you use the ArcMirror website and application, and how we protect it. ArcMirror is a business tool used by advertising agencies and brands ("customers").
Information we handle
- Account information — the name, work email, and company you provide to create an account or join the waitlist.
- Customer seed data — files a customer uploads containing their own customers' email addresses and related fields (e.g., purchase date, order value). Emails are hashed (SHA-256) on ingest; we use them only to build the customer's audiences.
- Generated audiences — the hashed-email lists ArcMirror produces (target and suppression) for the customer.
- Usage data — basic logs needed to operate and secure the service.
How we use it
- To provide the service: score a customer's seed list and generate their audiences.
- To deliver audiences to the destinations the customer chooses (e.g., their own ad-platform accounts), on the customer's behalf.
- To communicate with you about access, updates, and support.
- To secure, maintain, and improve the service.
What we do not do
- We do not sell personal information.
- We do not use a customer's uploaded data to benefit any other customer.
- We do not receive unhashed identifiers from data partners; identifiers are hashed.
Sharing
We share data only as needed to run the service: with infrastructure providers that host the application and database (under contract), and with the destinations a customer explicitly connects to activate their audiences. We may disclose information if required by law.
Data location & retention
Data is stored in the United States. We retain account data for the life of the account and uploaded seed data only as long as needed to provide the service; customers may request deletion of their programs and associated files at any time.
Security
Emails are hashed, access is authenticated by per-account tokens, and traffic is encrypted in transit (HTTPS). No method of transmission or storage is perfectly secure, but we work to protect your information using reasonable safeguards.
Your rights
Depending on your location (including under CCPA/CPRA and GDPR), you may have rights to access, correct, or delete personal information, and to opt out of certain processing. To exercise these rights, contact us at the address below. Customers are responsible for having a lawful basis and any required consent for the data they upload.
Contact
Questions about this policy: andrew@revenuearc.com.
This policy is provided for transparency and does not constitute legal advice.