Privacy Policy
Effective Date: May 30, 2026
ArcoMage ("we," "us," "our") respects your privacy. This Privacy Policy describes the personal information we collect, how we use it, when we share it, and the rights you have under U.S. and EU/UK law. By using arcomage.org, the ArcoMage game client, the forum at forum.arcomage.org, our online store, or any related service (the "Services"), you agree to this Policy. For terms of use, see our Terms of Service.
1. Information We Collect
We collect the categories of information listed below. Not every category applies to every user; what we collect depends on how you interact with the Services.
1.1 Information You Provide
- Account data: email address, display name, optional avatar, password hash (if not using Google OAuth).
- Profile / player data: handle, Elo rating, match history, spellbook configurations, forum posts, public profile fields.
- Kickstarter / pledge data: pledge amount, reward tier, shipping address (when applicable), backer email — supplied by Kickstarter under your Kickstarter privacy settings.
- Order / payment data: billing email, order line items, shipping address. Payment-card data is collected directly by our payment processor (Stripe) and is never stored on our servers.
- Communications: support tickets, contact-form messages, email replies.
- SMS opt-in data: mobile phone number, opt-in timestamp, opt-in source (signup form, Kickstarter checkbox, text keyword, etc.), and your message preferences.
1.2 Information Collected Automatically
- Device & log data: IP address, user-agent, referrer, request paths, timestamps, error logs.
- Cookies & similar technologies: session cookies for login, CSRF tokens, preference cookies. We also use Google Analytics for aggregate traffic reporting (see Section 4).
- Game telemetry: match outcomes, deck contents, client version, anti-cheat signals.
1.3 Information from Third Parties
- Google OAuth: name, email, Google avatar URL — only what you authorize during sign-in.
- Discord OAuth (Linked Roles): Discord username and user ID — used only to push backer-status metadata back to Discord so the role auto-applies.
2. How We Use Information
- Create and operate your account; authenticate sign-in.
- Run matchmaking, leaderboards, and tournaments.
- Process and fulfill Kickstarter pledges and store orders.
- Send transactional messages (account, order, password, security).
- Send opt-in marketing messages (email and, separately, SMS) about campaign updates, tournaments, and new content.
- Respond to support requests.
- Detect, prevent, and investigate cheating, abuse, and security incidents.
- Comply with legal obligations.
3. Text Messaging (SMS) — Specific Notice
If you opt in to SMS, we collect your mobile phone number along with the timestamp and source of your consent. We use this information only to deliver the text messages you requested, to honor your STOP/HELP requests, and to keep an audit record of consent as required by U.S. telecommunications regulations (TCPA / CTIA / The Campaign Registry).
We do not sell, rent, lease, share, or otherwise disclose your SMS opt-in information (mobile number and the fact that you consented to receive text messages) to any third party for marketing or promotional purposes. SMS opt-in data is shared only with our messaging service provider (currently Twilio) strictly as necessary to deliver, route, and report on the messages you requested.
You can opt out at any time by replying STOP (or END, CANCEL, UNSUBSCRIBE, QUIT) to any ArcoMage text. Reply HELP or email legal@arcomage.org for assistance. Msg & data rates may apply. See Terms of Service §8 for full SMS-program detail.
4. Cookies, Analytics & Tracking
We use first-party session cookies for login state and CSRF protection. We use Google Analytics 4 to measure aggregate site traffic; GA sets its own cookies and may transfer pseudonymous data to Google in the United States. You can opt out by installing the Google Analytics Opt-Out Browser Add-on or by sending us a request under Section 7. We do not use cross-site advertising trackers and we do not participate in real-time-bidding ad exchanges.
5. When We Share Information
We share personal information only in these cases:
- Service providers who help us operate the Services, under written contracts limiting their use: Hostinger / VPS hosting, Google (OAuth + Analytics), Discord (Linked Roles), Kickstarter (pledges), Stripe (payments), Twilio (SMS), and our email delivery provider.
- Public profile data (handle, Elo, match history, forum posts) is visible to other users by design. You can choose a pseudonymous handle.
- Legal compliance when required by law, subpoena, or to protect rights, safety, or property of ArcoMage or others.
- Business transfers in the event of a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal information (as that term is defined under California, Virginia, Colorado, or Connecticut law), and we do not "share" personal information for cross-context behavioral advertising.
6. Data Retention
We retain personal information for as long as needed to provide the Services and for the periods listed below, then delete or anonymize it.
- Account & player profile: while your account is active, plus 30 days after deletion (to allow restore).
- Order & pledge records: 7 years (tax / accounting).
- SMS opt-in audit log: at least 4 years after opt-out (carrier / TCR audit requirement).
- Web server / application logs: 90 days.
- Support tickets: 2 years.
7. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your information (subject to legal retention).
- Receive a portable copy of your information.
- Opt out of marketing communications at any time.
- Withdraw consent (where processing relies on consent).
- Lodge a complaint with a data-protection authority.
7.1 California (CCPA / CPRA)
California residents have the rights to know, delete, correct, and portability, plus the right to opt out of sale or sharing (we do neither). We do not discriminate against users who exercise these rights. To exercise, email legal@arcomage.org. We respond within 45 days (extendable once by 45 days if necessary).
7.2 EU / UK (GDPR / UK GDPR)
Articles 15–22 of the GDPR give you rights of access, rectification, erasure, restriction, portability, and objection. Our lawful bases for processing are: (a) contract — to operate your account; (b) legitimate interest — security, anti-cheat, aggregate analytics; (c) consent — marketing email and SMS; (d) legal obligation — tax and recordkeeping. The data controller is ArcoMage. We respond to requests within 30 days.
7.3 How to Make a Request
Email legal@arcomage.org with "Privacy Request" in the subject. We will verify your identity before acting on requests that affect another user's data.
8. Children's Privacy (COPPA)
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn we have collected personal information from a child under 13 without verifiable parental consent, we will delete it. Parents who believe their child has provided us with information may contact legal@arcomage.org.
9. International Transfers
ArcoMage is based in the United States; personal information you provide is processed in the U.S. If you are located in the EU/UK/EEA, transfers rely on the EU Standard Contractual Clauses or equivalent safeguards through our processors.
10. Security
We use TLS for all data in transit, hashed and salted passwords, least-privilege database access, segmented production credentials, regular software updates, and access logging. No system is perfectly secure; if you suspect a vulnerability, please report it to security@arcomage.org.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced here (with a new effective date) and, where required, by email or in-app notice at least 14 days in advance.
12. Contact
ArcoMage
Privacy / Legal: legal@arcomage.org
Toll-free: (833) 319-3160
See also: Terms of Service.