Privacy Policy
How Arena collects, uses, shares and protects personal data when you coordinate high-value transactions on the platform.
Last updated: 12 June 2026
Overview
Arena is operation-coordination infrastructure for high-value transactions. This policy explains what we do with personal data across three surfaces: the public website, the product (your operations), and the accountless links we send to participants.
Who is the data controller
Arena is the controller for account and website data. For the content you place inside an operation (participant details, amounts, documents), you act as the controller and Arena processes it on your behalf under our Terms and Data Processing Addendum.
Data we collect
We practise data minimisation: we ask only for what an operation genuinely needs to move forward.
- Account data
- Name, work email, password hash, role, preferred language and currency, country.
- Operation data
- Operation title, type, amounts, currency, tax configuration, payment schedule and the distribution you define.
- Participant data
- Names, contact channel (email or phone) and role for each party you invite. Provided by the operation owner.
- Identity & KYC
- When an operation requires it, verification status and the minimum identity signals needed to release funds. Sensitive documents are held by our regulated payment and verification partners, not in Arena's core database.
- Documents
- Files you upload to an operation (e.g. passports, vet reports, contracts), stored encrypted in object storage.
- Usage & device
- IP address, browser, and product interactions, used for security, fraud prevention and reliability.
How we use data
- Run operations end to end: invitations, confirmations, distribution, invoices and payouts.
- Enforce confidentiality — showing each participant only what their role permits.
- Verify identity and prevent fraud, money laundering and abuse.
- Send transactional emails (sign-in codes, proposals, reminders, receipts). These are not marketing.
- Maintain an immutable audit timeline of material actions for accountability and dispute resolution.
- Keep the service secure, available and continuously improved.
Legal bases (GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the product to you | Performance of a contract |
| Identity verification & AML checks | Legal obligation / legitimate interest |
| Security, fraud prevention, audit | Legitimate interest |
| Optional analytics & preferences cookies | Consent |
| Product update emails | Consent (opt-in, withdrawable) |
Data retention
We keep operation records for as long as needed to provide the service and to meet legal, tax and anti-money-laundering obligations — typically several years after an operation completes. Draft operations you abandon are periodically purged. You can request deletion of personal data that we are not legally required to retain.
Your rights
- Access a copy of your personal data.
- Correct inaccurate data.
- Delete data we are not obliged to keep.
- Object to or restrict certain processing.
- Port your data to another service where applicable.
- Withdraw consent (e.g. for analytics or product emails) at any time.
To exercise any right, contact info@tryarena.tech. We respond within statutory timeframes.
Common questions
No. Participants start accountless and act through a secure, single-purpose link. Identity is resolved later, only when required to release funds.
Only what their role allows. Arena enforces role-based visibility on every operation — for example, a broker may see both legs of a back-to-back deal while the underlying parties do not.
Sensitive KYC documents are held by our regulated payment/verification partner. Arena's core database stores verification status, not the raw documents, wherever possible.
Related documents
Questions about this document? Our team is here to help.
