1Introduction
This Privacy Policy explains how MindArena ("Company," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use MindArena's websites, applications, platforms, and digital products (collectively, the "Services").
We are committed to protecting your privacy and handling your data responsibly. This policy describes your privacy rights and how the law protects you.
By using the Services, you consent to the collection and use of your information as described in this Privacy Policy.
2Information We Collect
2.1 Information You Provide Directly
Account Information:
- Email address
- Password (encrypted)
- Name (optional)
- Company name (for B2B users)
- Job title (optional)
Payment Information:
- We do NOT directly collect or store credit card numbers
- Payment processing is handled by LemonSqueezy
- We receive: transaction ID, purchase date, amount, and billing country
Profile Information:
- User preferences and settings
- Communication preferences
Communications:
- Emails you send to our support team
- Survey responses and feedback
- Any other information you choose to provide
2.2 Information Collected Automatically
Usage Data:
- Scenarios completed and scores
- Time spent on scenarios
- Techniques practiced and mastery levels
- Progress and learning analytics
- Features used and interactions
Device and Technical Information:
- IP address
- Browser type and version
- Device type (desktop, mobile, tablet)
- Operating system
- Screen resolution
- Referring URL
- Pages visited
- Date and time of access
2.3 Information from Third Parties
Payment Processor (LemonSqueezy):
- Transaction confirmation
- Billing country
- Subscription status
Authentication Providers:
If you sign in via Google or other OAuth providers, we receive your email and basic profile information.
3How We Use Your Information
3.1 Providing the Services
- Create and manage your account
- Process payments and transactions
- Deliver scenario content and training
- Track your progress and learning outcomes
- Provide customer support
3.2 Improving the Services
- Analyze usage patterns to improve content
- Identify which scenarios are most effective
- Develop new features and techniques
- Fix bugs and technical issues
- Personalize your learning experience
3.3 Communications
- Send transactional emails (account creation, password reset, purchase receipts)
- Send product updates and new feature announcements
- Send marketing communications (with your consent)
- Respond to your inquiries and support requests
3.4 Safety and Security
- Detect and prevent fraud
- Protect against unauthorized access
- Enforce our Terms of Service
- Investigate violations and abuse
3.5 Legal Compliance
- Comply with applicable laws and regulations
- Respond to legal requests and government inquiries
- Protect our legal rights
4Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:
| Purpose | Legal Basis |
|---|---|
| Providing the Services | Contract Performance - Necessary to fulfill our agreement with you |
| Processing payments | Contract Performance - Necessary to complete transactions |
| Customer support | Contract Performance - Necessary to provide the service |
| Product improvements | Legitimate Interest - Improving our Services |
| Security and fraud prevention | Legitimate Interest - Protecting our Services and users |
| Marketing communications | Consent - Only with your explicit opt-in |
| Legal compliance | Legal Obligation - Required by law |
| Analytics | Legitimate Interest - Understanding usage |
You have the right to object to processing based on legitimate interest. Contact us to exercise this right.
6Data Retention
6.1 Active Accounts
We retain your personal information for as long as your account is active and as needed to provide you the Services.
6.2 Inactive Accounts
If your account is inactive for more than 24 months, we may send you a reminder email and delete your account and associated data.
6.3 After Account Deletion
When you delete your account or request deletion:
- Account data is deleted within 30 days
- Backup systems may retain data for up to 90 days
- Some information may be retained as required by law (e.g., transaction records for tax purposes)
6.4 Specific Retention Periods
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 30 days |
| Transaction records | 7 years (legal/tax requirement) |
| Support communications | 3 years |
| Usage analytics | 2 years (aggregated/anonymized indefinitely) |
| Server logs | 90 days |
8Your Rights
8.1 Rights for All Users
Regardless of where you are located, you have the right to:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your account and data
- Portability: Request your data in a machine-readable format
- Objection: Object to certain processing activities
- Withdraw Consent: Withdraw consent for marketing communications
8.2 Additional Rights for EU/UK Users (GDPR)
If you are in the European Economic Area or United Kingdom:
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data
- Right to Restrict Processing: Request that we limit how we use your data
- Right to Data Portability: Receive your data in a structured, commonly used format
- Right to Object: Object to processing based on legitimate interest
- Right to Lodge a Complaint: File a complaint with your local data protection authority
Data Protection Authorities: UK - ICO (ico.org.uk), France - CNIL (cnil.fr)
8.3 Additional Rights for California Users (CCPA/CPRA)
If you are a California resident:
- Right to Know: What personal information we collect and how we use it
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out of Sale: We do NOT sell personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
- Right to Correct: Request correction of inaccurate information
8.4 How to Exercise Your Rights
To exercise any of these rights, contact us at privacy@mindarena.ai with subject line "Privacy Rights Request - [Your Request]".
We will respond within 30 days for GDPR requests and 45 days for CCPA requests.
Summary of Your Rights
| Right | Description | How to Exercise |
|---|---|---|
| Access | Get a copy of your data | Email us |
| Correction | Fix inaccurate data | Email us or update in app |
| Deletion | Delete your account and data | Email us or delete in app |
| Portability | Export your data | Email us |
| Object | Stop certain processing | Email us |
| Withdraw Consent | Opt out of marketing | Unsubscribe link or email us |
9Data Security
9.1 Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption: Data encrypted in transit (TLS/HTTPS) and at rest
- Access Controls: Limited access to personal data on a need-to-know basis
- Authentication: Secure password hashing and optional two-factor authentication
- Monitoring: Regular security monitoring and vulnerability assessments
- Vendor Security: Evaluation of third-party security practices
9.2 Your Responsibilities
You are responsible for:
- Keeping your login credentials confidential
- Using a strong, unique password
- Logging out from shared devices
- Notifying us if you suspect unauthorized access
9.3 Data Breach Response
In the event of a data breach that poses a high risk to your rights, we will notify affected users within 72 hours, notify relevant data protection authorities as required, and take immediate steps to mitigate the breach.
10International Data Transfers
10.1 Where Data Is Stored
Your data may be stored and processed in the European Union (primary data storage) and United States (some service providers).
10.2 Transfers from EEA/UK
If we transfer personal data from the EEA or UK to countries without adequate data protection, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and ensure service providers maintain appropriate safeguards.
10.3 UAE Data Protection
The UAE has enacted federal data protection laws (Federal Decree Law No. 45 of 2021). We comply with applicable UAE data protection requirements.
11Children's Privacy
Age Restriction
MindArena is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18.
If we learn that we have collected personal information from a child under 18, we will delete that information promptly and terminate the associated account. If you believe a child under 18 has provided us with personal information, please contact us immediately at privacy@mindarena.ai.
12Third-Party Links and Services
The Services may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party websites you visit. This Privacy Policy applies only to MindArena.
13Marketing Communications
13.1 Types of Communications
Transactional Emails (Cannot Opt-Out)
- Account creation confirmation
- Password reset
- Purchase receipts
- Access instructions
- Critical service updates
Marketing Emails (Opt-In Required)
- New feature announcements
- Tips and best practices
- Promotional offers
- Newsletter
13.2 Opt-Out
You can opt out of marketing communications by clicking "Unsubscribe" in any marketing email, updating your preferences in account settings, or contacting us at privacy@mindarena.ai. Opt-out requests are processed within 10 business days.
14Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
For material changes, we will:
- Update the "Effective Date" at the top of this policy
- Provide notice via email or prominent website notice
- Give you the opportunity to review changes before they take effect
Your continued use of the Services after changes take effect constitutes acceptance of the updated Privacy Policy.
15Contact Us
For questions, concerns, or requests regarding this Privacy Policy or your personal data:
MindArena
Privacy Contact Email
privacy@mindarena.aiWhen contacting us, please include:
- "Privacy" in your subject line
- Your name and email associated with your account
- A clear description of your question or request