Privacy Policy
Last updated: September 11, 2026
Arcads.ai ("we", "our", or "us") respects and protects your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our AI video ad generation platform at https://arcads.ai (the "Service").
Please read this Policy carefully before using the Service. Using the Service means you have read and agree to this Policy. We may update this Policy from time to time; material changes will be communicated at least 15 days in advance via email or platform notice.
1. Data Controller
The data controller for this Service is:
- Company Name: Arcads.ai [Legal Entity Name]
- Registered Address: [Registered Business Address]
- Privacy Contact: privacy@arcads.ai
- Data Protection Officer: [Name/Contact — or "Not applicable"]
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, display name, password (encrypted)
- Payment Information: Transaction amount, payment status. We do not store full card numbers — card data is processed by our payment processor (see Section 5)
- Communication Records: Emails, support tickets, and feedback you send to us
- Billing Information: Billing address, business details (if provided)
2.2 Information We Automatically Collect
- Device & Network: IP address, device model, operating system, browser type, timezone
- Usage Behavior: Pages visited, features used, operation logs, session duration
- Log Data: Request timestamps, error logs, performance data
- Product URLs: URLs you submit for ad generation
- AI-Generated Content: Videos and assets created using our platform
3. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Provide and maintain the Service | Contract performance |
| Billing and payment processing | Contract performance |
| Customer support | Contract performance / Legitimate interest |
| Service notices (billing, security, policy updates) | Legitimate interest |
| Security and fraud prevention | Legitimate interest |
| Product optimization and analytics | Legitimate interest |
| Legal compliance | Legal obligation |
| Marketing communications (with consent) | User consent |
We may aggregate or de-identify data for statistical analysis. Such data cannot be linked to a specific individual.
4. Cookies and Tracking Technologies
| Type | Purpose | Can Be Disabled |
|---|---|---|
| Strictly Necessary | Maintain login, core functionality | No |
| Functional | Language preferences, personalized settings | Yes |
| Analytics | Anonymous usage statistics, product improvement | Yes |
| Marketing (if applicable) | Targeted advertising and performance measurement | Yes |
Analytics tools used: [e.g., Google Analytics — Google Analytics Privacy Policy]. You can adjust preferences via your browser settings or our Cookie Preference Center.
5. Information Sharing and Disclosure
We do not sell your personal information, including as defined under applicable laws such as CCPA. We share information only in the following circumstances:
- Service Providers: Cloud computing, payment processing, customer support, and analytics vendors bound by confidentiality agreements. Payment card data is processed exclusively by Waffo Pancake, our PCI-DSS compliant payment processor and Merchant of Record — card data is never stored on our servers
- AI Model Providers: We use third-party AI models including Flux, Kling, Seedream, GPT Image, and Gemini for video and image generation. Data processed by these providers is governed by their respective privacy policies
- Cloud Storage: Video files and generated content stored on [cloud provider] servers
- Legal Requirements: When required by law, court order, or legitimate government request
- Business Transfers: In the event of a merger, acquisition, or sale of assets, with advance notice and continued protection obligations
- With Your Consent: For any other purpose, only with your explicit prior consent
6. Data Security
- Transmission Encryption: TLS / HTTPS
- Storage Security: Passwords and sensitive data are encrypted or hashed
- Access Control: Principle of least privilege; employees sign confidentiality agreements
- Regular Security Audits: Periodic security audits and vulnerability scanning
- Incident Response: In the event of a security incident affecting your rights, we will notify you and relevant regulators within 72 hours of discovery
Please protect your account credentials and do not share them with others.
7. Data Retention
| Data Type | Retention Period | Disposal |
|---|---|---|
| Account Information | Active period + 2 years after closure | Deletion or anonymization |
| Transaction Records | 7 years (tax/accounting compliance) | Deletion or archival |
| Support Records | 3 years | Secure deletion |
| Security Audit Logs | 12 months | Secure deletion |
| AI-Generated Content | Active period + 90 days | Secure deletion |
8. Your Data Rights
To exercise any of the following rights, contact us at privacy@arcads.ai. We will process requests within 30 calendar days.
| Right | Description |
|---|---|
| Right to Know | Learn what data we collect and how we use it |
| Right to Access | Receive a copy of your personal data |
| Right to Rectification | Correct inaccurate or incomplete data |
| Right to Erasure | Request deletion under specific conditions |
| Right to Restrict Processing | Pause processing under specific conditions |
| Right to Data Portability | Receive data in a machine-readable format |
| Right to Object | Object to processing based on legitimate interest or marketing |
| Right to Withdraw Consent | Withdraw consent for processing based on consent at any time |
If you believe we have not properly handled your data, you have the right to lodge a complaint with your local data protection authority.
9. Marketing Communications and Opt-Out
With your consent, we may send marketing emails, SMS, or in-app notifications about [types of content]. You may unsubscribe at any time: click "unsubscribe" in any marketing email, disable marketing notifications in Account Settings, or contact us. Opting out does not affect service-related notices such as billing, security, and policy updates.
10. International Data Transfers
Our servers and service providers may be located in [countries, e.g., Singapore, United States]. When data is transferred internationally, we protect it through:
- Data Processing Agreements incorporating EU Standard Contractual Clauses (SCCs)
- Transfers only to recipients providing adequate protection
- [Other mechanisms such as adequacy decisions, BCRs]
11. Children's Privacy
The Service is intended for users who are at least 18 years old. We do not knowingly collect data from minors. If you believe your child has provided us with personal information, please contact us immediately at privacy@arcads.ai and we will promptly delete it.
12. Third-Party Links and Services
The Service may contain links to third-party websites or integrations with third-party services. This Policy applies only to information we directly collect. We are not responsible for third parties' data practices. We recommend reviewing their policies before use.
13. Policy Changes
Material changes to this Policy will be communicated at least 15 days in advance via platform announcement or email to your registered address, with the "Last Updated" date at the top of this page revised. Your continued use after the effective date constitutes acceptance of the updated Policy.
14. Contact Us
- Privacy Inquiries: privacy@arcads.ai
- Customer Support: support@arcads.ai
- Company: Arcads.ai [Legal Entity Name]
- Mailing Address: [Business Address]
- Service Hours: Monday to Friday, 09:00–18:00 UTC+8
This Privacy Policy is for informational purposes only and does not constitute legal advice. We strongly recommend consulting a qualified legal professional familiar with your target market before publishing.