AIT-F-26-0825 · LEGAL
Privacy Policy
Last updated 25 August 2026
Who we are
Arc Institute of Technologies (“Arc”, “we”, “us”) is an intelligence and venture firm based in Toronto, Ontario, Canada. We build and operate business systems for our clients. You can reach us at [email protected].
This policy covers two different groups: people who visit arcait.net or contact us, and the businesses we work with under an engagement. Where the rules differ, we say so.
Information we collect from website visitors
When you submit a form. Our contact form collects your name, company, email address, and whatever you write in the message field. We collect this only because you chose to send it. Form submissions are delivered to us by email through a third-party form service and are received at [email protected].
Analytics. We use Google Analytics to understand which pages are visited and how people arrive at the site. This produces aggregate statistics. We do not use it to identify individuals, and we do not sell or share it with advertisers.
What we do not do. We do not run advertising trackers or advertising pixels on this site, we do not sell personal information to anyone, and we do not buy contact lists.
Information we handle during a client engagement
Operating a client’s systems means we handle data belonging to that client — for example booking or enquiry emails submitted through a client’s website, sales totals from a point-of-sale or delivery platform, and business profile and review data.
Where that data includes a client’s customers (for example a name, phone number or email address on a reservation request), the client is the owner of that information and Arc acts on their behalf. We use it only to operate and report on the systems we were engaged to run.
We work to a principle of least exposure: customer-level detail stays on Arc’s own controlled systems, and the dashboards we publish to clients carry aggregate figures — counts and totals — rather than lists of individuals.
We do not sell client data, we do not use one client’s data to benefit another, and we do not use it to train third-party AI models.
Access credentials
Engagements often require access to a client’s platforms. Where possible we ask to be added as a named user with the minimum role needed, so access can be reviewed and revoked by the client at any time. We prefer scoped, revocable tokens over shared passwords.
Credentials are stored locally on Arc-controlled machines and are excluded from anything we publish or deploy.
How long we keep information
Enquiries from the website are kept while we are in contact and for a reasonable period afterwards for our business records. Client engagement data is kept for the duration of the engagement and a reasonable period afterwards, unless the client asks us to remove it sooner.
You can ask us to delete an enquiry you sent us at any time.
Third parties we rely on
We use a small number of established providers to run this site and our operations: hosting and security (Cloudflare), website analytics (Google Analytics), email (Google), and a form-delivery service that forwards contact submissions to our inbox. Each receives only what it needs to perform its function.
Client engagements may involve that client’s own platforms — their point of sale, delivery marketplace, or business profile — which are governed by those providers’ terms and the client’s account.
Your rights
Under Canadian privacy law (PIPEDA) you may ask what personal information we hold about you, ask us to correct it, ask us to delete it, or withdraw consent to further contact. Email [email protected] and we will respond within 30 days.
If you are a customer of one of our clients and want your information removed, contact that business directly — they control it and we will act on their instruction.
Security, honestly stated
We take reasonable technical measures: encrypted connections, access control on client dashboards, scoped credentials, and a publishing process that checks for exposed secrets before anything ships.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your information, we will tell you and the relevant authorities as required by law.
Changes to this policy
If we change this policy we will update the date at the top of this page. Material changes affecting client engagements will also be communicated directly to the client.
Questions about this page? Email [email protected].