Privacy policy
Last updated 30 August 2026
Who we are
Arcify (“we”, “us”) provides an all-in-one business suite for UK small businesses at arcify.co.uk. This policy explains what personal data we collect, why, and the rights you have over it under UK data protection law (the UK GDPR and the Data Protection Act 2018).
Arcify plays two distinct roles. For the data that runs your Arcify account — your name, sign-in details, billing records and how you use the service — we are the controller. For the data your business stores inside Arcify about its own customers, staff and suppliers, you are the controller and we act as your processor: we store and process it only on your instructions, and requests about that data should go to the business that holds it.
What we collect
- Account data — your name, email address, and the sign-in credentials and security settings (such as multi-factor authentication) for your login.
- Business data you store — the customers, bookings, invoices, staff records and other content your business puts into the suite. We process this as your processor, as described above.
- Billing data — your plan, seat count and payment history. Card payments are handled by Stripe, our payment provider; full card numbers never reach or touch our systems.
- Operational data — security and audit logs (such as sign-in events and changes to records), kept to protect accounts and to give your business the audit trail the product promises.
- Correspondence — messages you send us for support or sales, and your preferences for hearing from us.
Our public website works without any advertising or analytics trackers, and we do not buy data about you from anyone.
Why we process it
- To provide the service (contract) — operating your account, storing your business data, and taking payment for your subscription.
- To keep the service safe (legitimate interests) — authentication, fraud and abuse prevention, security logging, and service diagnostics.
- To meet legal obligations — accounting and tax records we are required to keep.
- To tell you about Arcify (consent) — marketing messages, only where you have opted in, and you can withdraw that consent at any time.
Where your data lives and who touches it
Your data is hosted in the United Kingdom. We use a small number of service providers to run Arcify — including our hosting provider, Supabase (authentication and file storage) and Stripe (payments) — each bound by contracts that meet UK GDPR requirements. We do not sell personal data, and we only disclose it where the law requires us to.
How long we keep it
Account data is kept while your account is open and for a short period after it closes, so you can come back and so we can meet our legal obligations. Billing records are kept for the periods UK tax law requires. Business data you store in the suite is yours: it is retained under your control while your account is open, and removed when your account is deleted, subject to the retention rules your business configures.
Your rights
Under UK GDPR you can ask us to:
- show you the personal data we hold about you (access);
- correct data that is wrong (rectification);
- delete data we no longer need (erasure);
- limit what we do with it (restriction);
- give you your data in a portable format (portability);
- stop processing based on legitimate interests or for marketing (objection).
To exercise any of these, email support@arcify.co.uk. If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk — though we would welcome the chance to put it right first.
Cookies
We use only the cookies the service needs to work — there are no advertising or analytics cookies. The full list is in our cookie policy.
Changes and contact
If we change this policy in a way that matters, we will say so on this page and, for significant changes, tell account holders directly. Questions about privacy at Arcify: support@arcify.co.uk.