Legal

Privacy & Cookies

How we handle data when you use Pendulum Arc.

Pendulum Development Ltd (Company No. 09572240) ("Pendulum", "we", "us") is the controller for personal data processed through Pendulum Arc at arc.pendulumdev.co.uk. This page explains what we collect, how we use it, which processors we rely on, and your rights under UK GDPR. For our separate marketing website, see pendulumdev.co.uk/privacy.

Contact for privacy requests: arc@pendulumdev.co.uk.

Who this covers

This policy applies to account holders, invited collaborators, people who visit public pages (sign-in, registration, invites, share links, and legal pages), report email recipients you configure, and anyone whose contact details are used for transactional email about Arc.

Lawful bases

  • Contract - creating and operating your account, studios, audits, schedules, share links, and paid subscriptions.
  • Legitimate interests - securing the Service, preventing abuse, diagnosing faults, and product analytics (Google Analytics with IP anonymisation) to understand how Arc is used and improve it. Analytics is not used for third-party advertising.
  • Consent - optional product-news emails about Arc features and related Pendulum services, only when you tick the box at register, invite accept, or Account → Product news. You can unsubscribe at any time.
  • Legal obligation - retaining records where tax, accounting, or other law requires it.

Data we collect

  • Account data - name, email address, and optional phone number you provide when registering, accepting an invite, or updating your profile. If you opt in to product news we also store that consent timestamp.
  • Organisation data - studio, client, and site records (names, slugs, URLs, configuration, feature flags, memberships, invites, workspace mode).
  • Audit and report data - crawl outputs, scores, findings, optional screenshots, and related artifacts from SEO, accessibility, and AI visibility jobs you run against sites you manage (see Audits below).
  • Scheduling and notifications - schedule settings and report email recipient addresses you configure for a site.
  • Billing data - subscription status, package lines, and Stripe customer / subscription identifiers. Card details are handled by Stripe and are not stored on our servers.
  • Usage and technical data - sign-in events, server and worker logs (IP, user agent), and - when analytics is configured - Google Analytics events with IP anonymisation.

How we use data

  • Provide magic-link authentication (Auth.js) and keep you signed in
  • Operate studios, clients, sites, schedules, invites, and report delivery
  • Run audit workers (including Playwright-based crawls) and store report artifacts
  • Process subscriptions, invoices, and entitlement changes via Stripe
  • Send transactional email via Brevo (magic links, invites, report notifications, email-change confirmation)
  • If you opt in, send product-news campaigns and mild inactivity nudges via Brevo (separate from transactional mail; same processor)
  • Secure the service, prevent abuse, and diagnose faults
  • Understand product traffic and conversions (Google Analytics; not for platform admins) and improve the experience

We do not sell personal data or share it for third-party advertising.

Audits and site crawling

When you generate a report, our worker fetches the URLs and targets you configure (and related resources those pages load). Jobs may use automated browsers (Playwright) for accessibility and related checks. Outputs can include structured findings, scores, optional full-page screenshots, and an Arc-wrapped report artifact stored for viewing, sharing, and email links.

  • SEO - crawl of configured pages / sitemap options for on-page and technical readiness findings.
  • Accessibility - automated checks against configured pages; optional screenshots.
  • AI visibility - crawl and heuristics for signals such as llms.txt, bot / crawler accessibility, and related page signals. This does not send your site content to third-party generative AI or LLM APIs (no OpenAI, Anthropic, or similar vendors are used for these jobs).
  • Analytics - optional Search Console / GA4 property pulls when you connect Google, bind a property, and run the Analytics service (API fetch only; not a site crawl).

You must only configure properties you are authorised to test. Share links make a report available to anyone with the URL until expiry or revocation. Report emails send links into Arc; they do not attach full report files.

Cookies and local storage

NamePurposeDurationType
Auth.js session cookies (e.g. authjs.session-token / __Secure-*)Keep you signed in to the portalSession / as configuredNecessary
arc_active_studioRemembers your active studio preferencePersistentNecessary
themeStores colour theme preferencePermanent (local storage)Necessary
pend-arc:developer-view-enabledRemembers developer report view on or off across reportsPermanent (local storage)Necessary
pend-arc:arc-key-openRemembers whether the Arc key panel is open or collapsedPermanent (local storage)Necessary
pend-arc:collapse:*Remembers whether a full-width page section (for example site Reports or Danger zone) is open or collapsedPermanent (local storage)Necessary
pend-arc:task-chip-filter:*Remembers search, list, and status filters on each report section task listPermanent (local storage)Necessary
cookie-notice-dismissedRemembers that you have seen the cookie noticePermanent (local storage)Necessary
_ga, _ga_*Google Analytics - usage and conversion data (not for platform admins)Up to 2 yearsAnalytics

Google Analytics loads on arc.pendulumdev.co.uk when our measurement ID is configured - on public pages and in the signed-in portal for non-admin users. It uses cookies such as _ga with IP anonymisation. We set non-identifying user properties such as user_type (anonymous, studio, client, or account) and access_package so we can understand how different audiences use the product. We may also send a technical user id (not your email) to stitch sessions. Analytics is not loaded for platform admin accounts and is not loaded on the admin area.

Our on-site cookie notice is informational. Dismissing it (or reopening it via the cookie button on public pages) stores cookie-notice-dismissed in local storage; it does not turn analytics off. You can also use browser controls or Google's tools to limit Analytics cookies.

Share links

When you create a share link for a report, anyone with the URL can view that report in read-only form until the link expires or is revoked. Treat share URLs as confidential.

Third-party services

ServicePurposeData shared
VercelHosting the portal UI and API (typically London region)Request data, server logs
AWS LightsailAudit worker, scheduler, and application database hostAccount / org data in Postgres, job metadata, worker logs
Amazon S3Report artifact storage (typically eu-west-2)Report JSON and related media (e.g. screenshots)
StripeCheckout, subscriptions, invoices, customer portalBilling contacts, plan, payment status; cards on Stripe
BrevoTransactional email delivery, and (only if you opt in) product-news list membership and campaignsRecipient email, name, and message content; opted-in contacts also receive plan / workspace attributes for segmentation
Google Analytics (GA4)Product usage and conversion analytics (excluding platform admins)Anonymised IP, page views, events, user_type / access_package
Google APIs (optional, per site)Search Console / GA4 data for Analytics reports when you enable the Analytics service, connect Google, and bind a propertyProperty metrics you configure for that site; stored in report artifacts

Processors act on our instructions for the purposes above. Stripe's own privacy notice covers payment card processing. Some processors may process data outside the UK; where they do, we rely on appropriate transfer mechanisms (such as the UK Extension to the EU-US Data Privacy Framework, adequacy regulations, or standard contractual clauses) as applicable to that provider.

Retention and deletion

We keep account and organisation data while your account or studio relationship is active. Portal remove actions soft-delete users, studios, clients, and sites (a tombstone timestamp hides them from normal use). Soft-deleted accounts may be revived if the same email accepts a new invite before hard purge.

We plan a retention janitor to hard-delete soft-deleted rows and related artifacts (memberships already cleared on user delete, invites, runs, share links, package lines, Stripe customer linkage, and stored report blobs) after a retention window - currently proposed as about 30 days after soft-delete, subject to change and to longer retention where billing, security, or legal obligations require it. You can ask us to delete personal data subject to those needs.

Your rights

Under UK GDPR you have the right to access, correct, or delete your personal data, and to object to or restrict certain processing (including objecting to processing based on legitimate interests, such as analytics, where applicable). To exercise these rights, email arc@pendulumdev.co.uk. See also our Terms and Conditions.

Changes

We may update this page from time to time. The latest version will always be available at this URL.

Last updated: August 2026

Privacy Policy and Cookies | Pendulum Arc