Privacy Policy
Last updated: 2026-09-22
This policy explains what information Arenza collects when you use our AI Visibility / GEO platform (the “Service”), what we do with it, and the rights you have over it. We aim for plain English. If anything is unclear, email hello@arenza.ai and we’ll explain.
1. Who we are
Arenza is the controller of personal data collected via arenza.ai, app.arenza.ai, mcp.arenza.ai, and our REST API. Contact: hello@arenza.ai.
2. What we collect
- Account data: email address, name, organization name, and authentication identifiers from our auth provider (Clerk).
- Billing data: if you subscribe to a paid tier, payment-method tokens (we never store card numbers — Stripe holds them) and invoice history.
- Brand-tracking data: the brand names, domains, competitor lists, and prompts you configure for AI visibility scans. This is product data, not personal data.
- Scan results: the AI answers we collect on your behalf when probing ChatGPT and Google AI Mode. Stored against your account.
- Free AI-visibility check (/score) leads: you don’t need an account to run the free check at arenza.ai/score. If you give us an email address there to unlock the full report, we store that address together with the domain you checked, the score we calculated, the report link, your IP address, browser user-agent, referring page, and the exact consent sentence you were shown. We use it to email you the report and the follow-ups described in section 3.
- Usage data: page views, feature interactions, errors. Used to improve the product.
- Cookies: a session cookie for authentication, plus minimal first-party analytics. We do not use third-party advertising cookies.
3. How we use it
- To deliver the Service (run scans, render dashboards, send reports).
- To bill you (if you’re on a paid tier).
- To send transactional email (account confirmation, billing receipts, security alerts).
- To email your free /score report, and after it two follow-up messages — what your score means, and a last note inviting you to sign up. That is marketing email, not transactional email. The form you gave your address at says so before you submit it, every message carries a one-click unsubscribe link, and we stop after the second follow-up. There is no newsletter after that. Unsubscribing here never affects transactional email for an account you hold.
- To improve the product based on aggregate usage patterns.
- To detect abuse and prevent fraud.
- To comply with legal obligations.
We do not sell your data. We do not use your scan results to train generic AI models. We do not share your customer-list to third parties for marketing.
4. Third parties we share data with
- Clerk — authentication. Receives your email + sign-in events. clerk.com/privacy
- Stripe — payment processing. Receives payment-method data when you subscribe. stripe.com/privacy
- Google Cloud (Cloud Run, Cloud SQL, GCS) — hosting + storage. Data resides in asia-southeast1 region by default (Singapore); enterprise customers can request EU or US regions.
- OpenAI, Google — AI assistants we probe on your behalf. We send prompts (which you configured); we don’t send your account data. Perplexity — web-search grounding used to research your brand and category (brand name and public site content only; never your account data).
- Resend — email delivery: transactional mail, and the /score report sequence described in section 3. Receives the recipient address and message content. resend.com/privacy
We sign Data Processing Agreements (DPAs) with each subprocessor where required by GDPR.
5. Google user data (Google Merchant Center)
If you connect your Google account from our Shopify app (the “Connect Google” button), Arenza requests the Google Merchant API scope (https://www.googleapis.com/auth/content) plus your basic profile email (openid, userinfo.email), strictly to act on your behalf. With this access we only:
- Create and configure a Google Merchant Center account that you own.
- Upload and update your product data (title, description, price, availability, images) from your connected store, so your listings stay accurate and eligible for Google’s Shopping and AI surfaces.
- Read your product and account status (approvals and item issues) to surface and help you fix problems inside the app.
We store the Google OAuth refresh token encrypted and use it solely to make these Merchant API calls on your behalf. We never use Google user data for advertising, never sell it, and never transfer it to others except as needed to provide this feature to you. You can disconnect at any time, which revokes Arenza’s access.
Limited Use disclosure. Arenza’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. How long we keep it
- Account data: while your account is active, plus 30 days after deletion.
- Billing data: 7 years (tax + accounting requirements).
- Scan results: while your account is active, plus 90 days after deletion (in case you reactivate).
- Usage logs: 90 days, then aggregated.
- /score leads (email, domain, score, consent record): 24 months from capture, then deleted. If you unsubscribe or your address bounces, we keep the address on a suppression list indefinitely — that list exists only to make sure we never email you again.
7. Your rights
If you are in the EU, UK, or California (GDPR / UK GDPR / CCPA jurisdictions), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Delete your account and personal data (right to erasure).
- Export your data in a portable format.
- Object to processing for analytics purposes.
- Lodge a complaint with your local data-protection authority.
Regardless of where you are: you can stop our /score emails at any time with the one-click unsubscribe link in any of them, or by emailing hello@arenza.ai. You do not need an account to ask us to delete a /score lead — email us from the address you gave us.
To exercise any right, email hello@arenza.ai. We respond within 30 days.
8. Security
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Production access is restricted to a small engineering team with audit logging. We do not have SOC 2 certification yet (we’re a 2026-vintage startup); we’re working toward SOC 2 Type II for the Enterprise tier. Security questions: hello@arenza.ai.
9. International data transfers
The Service is operated from Google Cloud’s asia-southeast1 region (Singapore). EU customers’ data may be transferred outside the EEA; we rely on Standard Contractual Clauses for these transfers. Enterprise customers can request EU or US regional residency.
10. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children.
11. Changes to this policy
When we make material changes we’ll email account holders and update the “Last updated” date above. Continued use of the Service after a change means you accept the updated policy.
12. Contact
Questions, requests, or complaints: hello@arenza.ai