Legal

Privacy Policy

Effective: August 16, 2026 Last updated: August 16, 2026 Applies to: Arcade Aid Pro app, website and QR report form

Arcade Aid Pro (“we”, “us”, “our”) helps arcade and family-entertainment venues keep their machines running. This policy explains what personal information we collect, why, who we share it with, how long we keep it, and what you can ask us to do about it.

It covers the Arcade Aid Pro mobile app used by venue staff and technicians, the guest report form reached by scanning the QR code on a machine, and the Arcade Aid Pro website.

Every section opens with a plain-language summary. Questions, requests or complaints go to support@arcadeaidpro.com.

1. Who this policy covers

In shortTwo groups: staff who sign in to the app, and guests who scan a QR code. Staff accounts are created by their employer, not by signing up.

  • Authorized users — employees, contractors and venue staff who sign in to the app or web dashboard. A venue operator or employer (the “Operator”) creates these accounts and decides what each one may see; the app has no self-service sign-up.
  • Guests — visitors who scan the QR code on a machine to report a problem. No account, and no app, required.

For authorized users we act as a service provider to the Operator, which decides why work data is processed. For guest reports and our website, we are the controller.

2. At a glance

In shortWe do not sell your data, advertise to you, track you, or read your location. What we collect exists to run maintenance tickets.

Do we sell your personal information? No. We never have.
Do we share it for advertising? No, including for cross-context behavioral advertising.
Do we track you across other apps and websites? No. The app performs no tracking as Apple defines it, so it shows no App Tracking Transparency prompt.
Do we collect your precise location? No. A machine’s venue comes from the QR code, never from your device.
Do we use analytics or advertising SDKs? No.
Do we use your data to train AI models? No.
Can you ask us to delete your data? Yes — sections 10 and 11 explain how.

3. Information we collect

In shortFrom the app: your account, your ticket activity, and photos you choose to attach. From the guest form: how to reach you and what went wrong. Nothing beyond that.

3.1 Authorized users of the app

What Where it comes from Why we need it
Name and work email address Your employer's records, synced to us Identify who reported, commented on or closed a ticket
Password You, at sign-in Authenticate you. Stored only as a salted one-way hash, which we cannot read
Two-factor secret and recovery codes, if you enable 2FA You Protect your account. Stored encrypted
Role, permissions and assigned venues Your employer's records Show you only what you are authorized to see
Session and API access tokens Generated at sign-in Keep you signed in. Revoked when you sign out
Push notification token and platform Your device, if you allow notifications Deliver ticket alerts
Ticket activity — tickets, comments, status changes, timestamps You, while using the app Maintain each machine's service history
Photos you attach Your camera or library, only for images you pick Document a fault so a technician can prepare
Technical logs — IP address, app and device version, request times, errors Automatically Security, abuse prevention and troubleshooting

The app does not access your contacts, calendar, health data, precise location, microphone, browsing history, or any photo other than the images you choose to attach.

3.2 Guests using the QR report form

What When Why we need it
First and last name, email address, phone number Always So the venue can tell you what happened with your report
The problem category and the outcome you ask for Always Route the report to whoever can resolve it
Preferred contact method, game card number, a description, a photo Optional Context that helps resolve the issue faster
The last four digits of your payment card Only if you ask for money back Locate your transaction. We never ask for a full card number, expiry date, security code or PIN, and we do not process payments
Machine and venue identifier, submission time, server logs Automatically, from the QR code These identify equipment, not you. No location is read from your device

3.3 Website, waitlist and cookies

If you join the early-access waitlist we collect your name, email address and any message you write, and use them only to contact you about Arcade Aid Pro. Ask us to remove you at any time.

Our website sets only strictly necessary cookies — one to keep you signed in and one to protect forms against cross-site request forgery. No advertising cookies, no cross-site trackers, no third-party analytics. The app uses no cookies for tracking.

4. Device permissions the app requests

In shortThree permissions, all optional, all revocable in system settings. The ticket workflow works without any of them.

Permission What we do with it If you decline
Camera Photograph a faulty machine to attach to a ticket. The image uploads only when you submit it. No video, no audio. Everything else works; you just cannot take a new photo in the app.
Photo library Attach an existing photo. We receive only the images you select — never your whole library. You can still use the camera, or attach nothing.
Notifications Alert you when a ticket is assigned to you or changes status. The app works normally; you check for updates by opening it.

Change or withdraw any of these in iOS Settings › Arcade Aid Pro, or the equivalent Android permission screen. Turning notifications off stops delivery immediately; signing out also deletes that device's push token from our servers.

5. How we use information

In shortTo run tickets, let a venue follow up with you, keep accounts secure, and fix bugs. That is the whole list.

  • Create, route, update and close maintenance tickets, and keep a service history per machine.
  • Let venue staff follow up with a guest about a report, using the contact method the guest chose.
  • Authenticate users, enforce what each account may access, and support two-factor authentication.
  • Send operational messages — push alerts about your tickets, plus emails such as password resets and report confirmations.
  • Give Operators aggregate reporting on issue volume and machine reliability. That reporting is about equipment, not individuals.
  • Keep the Service secure: detect and prevent fraud and abuse, and rate-limit sign-in and upload endpoints.
  • Diagnose failures, fix bugs and improve reliability.
  • Comply with legal obligations and enforce our terms.
  • Contact you about availability, if you joined the waitlist.

We do not build advertising profiles, train machine-learning or AI models on personal information, or make decisions with legal or similarly significant effects about you by solely automated means.

7. Who we share information with

In shortOnly the venue operator, its ticketing system, and the providers that host and deliver for us. Each is contractually bound to protect your data as we do.

Recipient What they receive and why
The venue Operator and your employer Authorized users: your account details and ticket activity, because they own the account and the maintenance record. Guests: your report and the contact details in it, so the venue can resolve the issue.
FEG ticketing system (FEG LLC) Reports and tickets are filed into the Operator's ERP ticketing system, including the reporter's name, email, phone, description and any attached photo. This is how a report reaches the people who can fix the machine.
Amazon Web Services Application hosting and photo storage, in the United States, on our instructions only.
Our email delivery provider Recipient address and message content, to send transactional email.
Apple Push Notification service and Google Firebase Cloud Messaging The device push token and notification payload, solely to deliver alerts.
Professional advisers and authorities Only where required by law, subpoena or court order, or to defend legal claims — and only the minimum necessary.
A successor entity On a merger, acquisition or sale of assets, information may transfer to the successor, which stays bound by this policy or gives notice before any material change.

Third-party protection commitment

Every third party with whom we share user data is contractually required to provide the same or equal protection of user data as stated in this Privacy Policy and as required by the Apple App Store Review Guidelines. Our providers may use the data only to perform services for us, under written instructions, and are prohibited from selling it, sharing it for advertising, or using it for their own purposes.

We do not sell personal information, do not share it for cross-context behavioral advertising, and do not disclose it to data brokers.

8. How long we keep information

In shortEach kind of data has an end date. Nothing is kept indefinitely, and photos that never get attached are deleted within a day.

Information Retention period
Authorized user account While active, then deleted or anonymized within 30 days of deactivation
Session and API access tokens Until you sign out or the token is revoked
Push notification tokens Until you sign out, uninstall the app, or turn notifications off
Tickets, comments and status history Up to 24 months after closing, as the machine's service record
Guest reports and the contact details in them Up to 24 months after the report is resolved
Photos attached to a ticket or report Deleted with the ticket or report they belong to
Photos uploaded but never attached Deleted automatically after 24 hours
Waitlist entries Until you ask to be removed, or 24 months after the last contact
Server and security logs Up to 90 days, except entries held for an active investigation

We may keep specific records longer where the law requires it, or where they are needed for an unresolved dispute or investigation. Those are isolated and used for nothing else. A ticket filed into an Operator's own system is also subject to that Operator's retention schedule.

9. How we protect information

In shortEncrypted in transit, passwords hashed and never readable, two-factor available, and every account scoped to its own venues.

  • All traffic between the app, the website and our servers is encrypted with TLS.
  • Passwords are stored only as salted one-way hashes; two-factor secrets and recovery codes are encrypted at rest.
  • Access is scoped by role and by venue, so an account only ever loads records it is authorized to see. Optional two-factor authentication is available to every account.
  • Photo uploads use signed URLs that expire in 15 minutes and are bound to the declared file type, so images are never exposed through a shared public path.
  • Sign-in, upload and report endpoints are rate-limited, and access tokens are individually revocable.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as applicable law requires.

10. Your rights and choices

In shortEmail us and you can find out what we hold, correct it, get a copy, have it deleted, or withdraw consent. Notifications and photo access you can switch off yourself.

Depending on where you live, you may have the right to:

  • Know and access what we hold about you and how we use it, and receive a copy in a portable format.
  • Correct information that is wrong or incomplete.
  • Delete your information — see section 11.
  • Object to or restrict processing based on legitimate interests, and withdraw consent at any time.
  • Not be discriminated against for exercising any of these rights.

Making a request

Email support@arcadeaidpro.com with the subject “Privacy Request”. So we do not hand your data to the wrong person, write from the work address on your account if you are an authorized user, or from the address you entered on the form if you are a guest — and in that case include the approximate date and the venue so we can find the submission.

We respond within 30 days, or 45 where a US state law allows an extension, and tell you if we need longer. An authorized agent may act for you with written proof. If we cannot verify your identity we will say so rather than guess. Unhappy with our answer? Reply to it to appeal, and you may also complain to your local data protection authority.

Turning things off yourself

Notifications, camera and photo access live in iOS Settings › Arcade Aid Pro. Waitlist emails have an unsubscribe link. Operational messages that are part of the Service — password resets, security alerts, confirmation of a report you filed — cannot be switched off separately while your account is active.

11. Account and data deletion

In shortBecause accounts are created by employers rather than in the app, deletion runs by email. We act within 30 days, and signing out already cuts that device off immediately.

Arcade Aid Pro accounts are not created inside the app. There is no sign-up: an Operator provisions accounts for people authorized to service its machines, and those accounts belong to that organization. Deletion therefore runs through the channel below rather than a button in the app.

Authorized users

Email support@arcadeaidpro.com from your work address with the subject “Delete my account”, or ask your venue administrator. Once verified we disable sign-in and revoke every access and push token, then delete or anonymize your account within 30 days. Tickets and comments you created stay in the machine's service record with your name removed, because the venue needs an intact maintenance history.

Guests

Filing a report creates no account. To have your report, contact details and any attached photo deleted, email support@arcadeaidpro.com from the address you used, with the approximate date and venue. We delete it within 30 days of verifying the request. If your report is still open, we will tell you what has to stay until it closes and delete the rest.

What you can do right now

Signing out of the app immediately revokes that device's access token and removes its push token from our servers. Deleting the app stops all further collection from that device.

We may retain a limited record where the law requires it or an unresolved dispute or investigation needs it; those are isolated, used for nothing else, and deleted once the need ends. Where your employer controls your work data, we notify them of a deletion request as we are required to do.

12. International transfers

In shortEverything is hosted in the United States. Transfers out of Europe rely on the Standard Contractual Clauses.

We operate from the United States, and our servers and photo storage are there. If you use the Service from elsewhere, your information is transferred to and processed in the United States, under laws that may differ from your own. For transfers out of the European Economic Area, the United Kingdom or Switzerland we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where applicable, plus additional safeguards where needed. Email us for a copy of the relevant safeguards.

13. Children's privacy

In shortThe app is a workplace tool for adults. If a child under 13 filed a report, a parent can email us and we will delete it.

The app is intended solely for adults authorized to service arcade equipment. It is not directed to children, and we do not knowingly collect personal information from children under 13. The guest report form is likewise meant to be completed by an adult. If you believe a child under 13 submitted a report, a parent or guardian may email support@arcadeaidpro.com and we will delete it promptly. Where local law sets a higher age of digital consent, we apply that age.

14. US state privacy rights

In shortCalifornia and other state residents can know, correct, delete and get a copy of their data. There is nothing to opt out of, because we neither sell nor share it.

Under the California Consumer Privacy Act, as amended, the categories of personal information we collected in the past twelve months are: identifiers (name, email, phone number, IP address, account identifiers); customer records; commercial information (the report or ticket you submitted, including partial card digits where a guest supplied them); internet or network activity (app and server log data); visual information (photos you attached); and, for authorized users, professional or employment-related information. Sections 3, 5 and 7 set out the sources, purposes and recipients for each.

In that period we did not sell personal information and did not share it for cross-context behavioral advertising, and we do not do so today. We do not knowingly sell or share the personal information of consumers under 16. We do not use or disclose sensitive personal information for purposes that carry a right to limit — in particular, we never use it to infer characteristics about you.

California residents may exercise the rights to know, access, correct, delete, obtain a portable copy, opt out of sale or sharing, and limit the use of sensitive personal information, without discrimination in price or service. Use the process in section 10. If you work for an Operator, that Operator also provides its own notice at collection for the work data it controls.

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws have comparable rights, including opting out of targeted advertising, sale and certain profiling — none of which we perform — and, in several states, appealing a refused request. Use the same process in section 10; our response will name the appeal route.

15. Changes to this policy

In shortThe date at the top always reflects the current version, and we give notice before a material change takes effect.

We may update this policy as the Service evolves or the law changes. If a change materially affects how we handle your personal information, we will give notice before it takes effect — by email, an in-app notice, or a prominent notice on this page — and ask for your consent where the law requires it. Continuing to use the Service after a change takes effect means you accept the updated policy.

16. How to contact us

In shortOne address for every privacy question or request, answered within 30 days.

Subject
“Privacy Request”

This is the privacy policy referenced in the Arcade Aid Pro App Store listing. It is publicly accessible without signing in, and is linked inside the app under Settings › Privacy Policy.