Arcavanta policies

Privacy notice

How Arcavanta uses business-contact, account and order information, and how you can exercise your data rights.

GRACE INTERACTIVE ENTERTAINMENT LIMITED is the controller for personal data processed to operate Arcavanta. This notice covers website visitors and people acting for business customers; it does not replace Microsoft’s privacy notice for a recipient’s Microsoft account.

Last updated

Controller and scope

Arcavanta is the trading name of GRACE INTERACTIVE ENTERTAINMENT LIMITED, a company incorporated in England and Wales with company number 13246173. Our registered office is The Old Bridge House, St. Peter Street, Marlow, England, SL7 1NQ, United Kingdom.

This notice explains our processing of personal data, including information about business representatives. The data involved depends on your interaction: browsing the catalogue, using an account, placing an order or contacting us. Gift-card recipients’ Microsoft accounts are administered by Microsoft, not Arcavanta.

Information we use

Account records include your email address, authentication records, session information and the business-profile details you supply. Order records include the selected product, quantity, price version and order history. Technical and security records can include IP address, browser information, time and the action taken.

If you contact us, we use your message, contact details and relevant order evidence. Payment records may include the asset, network, amount and transaction reference; a public blockchain reference can expose transaction history beyond Arcavanta. Do not send us a private key, seed phrase, password or authentication code.

Purposes and legal bases

We use account and order information to take steps you request and perform our agreement where you are the contracting individual. For employees and other representatives of a business customer, we rely on legitimate interests in administering that relationship.

Our legitimate interests also include protecting accounts, preventing fraud, resolving disputes and maintaining reliable records. Where processing is required for tax, accounting or other applicable legal duties, we rely on that obligation. Optional analytics or marketing that requires consent must have that consent; it is not a condition of placing an order.

Payment and fulfilment information

An order may require payment reconciliation and a request to a code supplier. The relevant provider receives only the information needed for its role. A supplier does not need your account password or an unrestricted copy of your profile.

Payment references and delivery records are distinct from the gift-card code itself. Do not include codes or wallet secrets in a support screenshot. Blockchain transactions can be public and irreversible; deleting an Arcavanta record does not erase a public blockchain.

Recipients and service providers

Relevant recipients can include hosting and database providers, payment and fulfilment providers, security and communications services, professional advisers, and authorities where disclosure is legally required. Access must be limited to the service or obligation involved.

A provider acting on our instructions is subject to appropriate data-processing terms. A payment provider or issuer may also act as a separate controller under its own notice. We do not sell personal data or disclose customer lists for another business’s advertising.

How long records are kept

Retention depends on the purpose and the record. We need account information while administering the business relationship, transaction records for accounting and applicable legal duties, and relevant communications while resolving a request or dispute. Security records are retained for proportionate fraud and incident investigation.

When a purpose ends, the record must be deleted or anonymised unless a legal obligation, unresolved claim or lawful hold requires retention. Closing an account does not automatically erase records needed for those reasons. You may ask which retention rule applies to your information.

International transfers

A provider or authorised recipient may process information outside the United Kingdom. A restricted transfer requires a lawful mechanism, such as an applicable adequacy regulation or approved contractual safeguards, together with any required assessment.

You may ask which countries and safeguards apply to a particular processing activity and request information about the relevant safeguard. A link to an overseas issuer is not, by itself, a transfer of your account data to that issuer.

Account security

Account passwords are stored as hashes, not readable passwords. Sessions expire and administrative access is role-restricted. These measures reduce risk but no online service can promise that a security incident is impossible.

Use a unique password, keep your authentication details private and email [email protected] promptly about suspected account misuse. Provide the time and nature of the problem, not the secret that may have been exposed.

Your rights and complaints

Subject to the applicable conditions, you may request access, correction, erasure, restriction or portability of your personal data, or object to processing based on legitimate interests. Where consent is used, you may withdraw it without affecting earlier lawful processing.

We may ask for proportionate identity information to protect your account. A data-rights request does not require a working login. We respond within the period required by applicable law and explain any permitted extension or refusal. You may complain to the UK Information Commissioner’s Office or another competent supervisory authority.

Cookies and browser storage

The account uses essential authentication cookies. Planning tools can save your chosen product and quantity in your browser. The Cookie Notice identifies the storage and explains how to clear it.

We do not use advertising cookies. Optional analytics, if introduced, requires an updated storage notice and the applicable user choice before collection. Passwords, gift-card codes, message content and wallet secrets must not be sent to analytics.

Contact and notice changes

Email [email protected] for privacy questions or to exercise your data rights. You do not need to sign in. Describe the information or right involved and provide enough information to identify the request. We may need proportionate identity checks before disclosing or changing personal data.

You can also write to GRACE INTERACTIVE ENTERTAINMENT LIMITED, Arcavanta, The Old Bridge House, St. Peter Street, Marlow, England, SL7 1NQ, United Kingdom, marked “Privacy request”. Include a reply address. Do not send passwords, authentication codes, wallet secrets or gift-card codes.

The date above identifies this notice revision. Material changes affecting your data use will be communicated where required.

Questions worth checking

01

Are my passwords stored in plaintext?

No. Passwords are stored as hashes. Arcavanta does not need your password or authentication code in a support request.

02

Does a local browser plan contain gift-card codes?

No. Planning entries contain the selected product or market, denomination and quantity. They are separate from delivered-code records.

03

Can I make a privacy request without signing in?

Yes. Email [email protected] or write to the registered office above, marked “Privacy request”. Explain your request and provide a reply address, without credentials or codes. We may need to verify your identity before releasing personal data.