arvald

Privacy

What Arvald collects about coaches and players, where it is stored, and what can be deleted.

Last updated: 24 August 2026.

This page says what Arvald actually does with data today, including the parts that are awkward. It describes two different people: a coach, who has an account, and a player, who books a session with a coach.

What is collected about a coach

  • Your identity. Your email address and name, held by the sign-in system that Arvald runs.
  • Your brand. The name, web address, headline, biography, location, languages and credentials you publish, plus any photos you upload to your page.
  • Your business setup. Your services and prices, sessions, locations, and cancellation policies.
  • Payment connection. A reference to your account with the payment processor, and whether it is able to take payments and receive payouts. Arvald does not hold your bank details. The processor does.
  • API keys, if you create any.

If you joined the waitlist rather than having an account, what is held is your email address and which page you submitted it from. Nothing else.

What is collected about a player

  • Your name, email address and phone number, as given at booking.
  • Your bookings: which session, how many people, the amount, and whether it is paid, pending, cancelled or refunded.
  • Your account, if you make one, which links your bookings across different coaches so you can see them in one place.

Card details are never stored by Arvald. Payment happens on the processor's own hosted page. What comes back to Arvald is a reference to the payment, not the card.

A coach sees the players who have booked with them. A coach cannot see that a player has also booked with a different coach, and this is enforced deliberately rather than by convention: the identifier that links one person's bookings across coaches is never returned to a coach.

Technical data

The server keeps request logs, which include IP addresses. Caller IP addresses are also held briefly in memory to rate limit the two endpoints that anyone can reach without signing in, and are discarded when they go quiet.

If you have allowed analytics, Google also receives your IP address as part of measuring the visit. Google Analytics does not store it, but it does reach Google to work out roughly where the visit came from.

Cookies and analytics

Until 24 August 2026 this page said Arvald used no analytics of any kind. That is no longer true, and the previous version of this page said it would change if it changed. This is that change.

Arvald uses Google Analytics on the marketing site (arvald.com, including coach booking pages) and on this documentation site. It is not used on the coach dashboard.

What that does and does not mean:

  • There is no advertising and no remarketing. Arvald does not buy ads, and the advertising parts of Google Analytics are switched off in the code itself rather than merely left unused: ad storage, ad personalisation and sharing your data for ad purposes are refused on every page load, for everybody, whatever you choose below. Google Signals, which would link your visit to your Google account across devices, is off.
  • No booking, no payment and no signed-in page is measured. The page you land on after paying sends no address to Google, because that address contains your booking reference. The same goes for a player's own account pages and the sign-in page. A coach's public page address is measured, because telling a coach how their page is doing is the point of using this at all.
  • Web addresses are stripped before they are sent, on every measurement and not just page visits. Only campaign tags survive; anything else in a link's query, including anything a payment page adds on the way back, is dropped. Everything Google measures automatically beyond the page visit itself (scrolling, clicks on links, interacting with a form) is switched off, so the only measurements sent are the ones written by hand and listed above.

Whether you are asked first

If you are in the EU, the EEA, the UK or Switzerland, you are asked before anything is stored on your device, and Google Analytics is not loaded at all until you answer. Declining is one click and is exactly as easy as accepting. Nothing is remembered about you if you decline, beyond the fact that you declined.

Everywhere else, including Australia, analytics is on by default and you are not shown a banner. That is a deliberate choice rather than an oversight: Australia has no law requiring it, and a banner on every visit is a poor trade for a visitor who was going to be asked to click through it anyway. You can still turn it off at any time, from the "Cookie settings" link in the footer of any page on arvald.com, or here. Your choice is remembered for six months and applies across arvald.com and this site.

The cookies themselves

CookieWhat it doesHow long
SessionKeeps you signed inUntil you sign out
Sign-in stateHolds the login request while you complete itMinutes
Active brandRemembers which brand a coach is currently working inUntil changed
ModeRemembers whether a coach is in live or test modeUntil changed
Cookie choiceRemembers whether you allowed analytics6 months
RegionRecords whether you need to be asked for consent at all1 day
_ga, _ga_*Google Analytics, and only if you allowed itUp to 2 years

The first six are functional: without them the site cannot sign you in, cannot keep you in the right mode, and cannot remember that you said no. Only the last row depends on your choice.

Email

The only email Arvald sends is the six-digit code you use to sign in, and it comes from the sign-in system rather than from the product.

There are no booking confirmation emails, no reminders, and no email to a coach when a booking is made. This is a real gap rather than a policy choice, and it is being worked on. It is stated here because a player who has just paid for something reasonably expects a receipt, and should know that none is coming from Arvald. Whether the payment processor sends its own receipt depends on the coach's settings with that processor.

Arvald sends no marketing email, because it has no way to send any.

Where the data is

In Australia. The servers and the database run in Google Cloud's Sydney region. Coach page photos are stored with Vercel, which hosts the website itself.

The one exception is analytics. If you allowed it, what Google Analytics measures about your visit goes to Google and is handled on Google's own infrastructure, which is not in Australia and is not under Arvald's control. Nothing a coach or a player enters into Arvald is sent there: it sees which pages were visited, not what was typed or booked.

Arvald is operated from Australia and stores its data there. If you are outside Australia, that is where your information goes. Arvald has no EU establishment and makes no claim here to operate a European data protection framework, because it does not have one. If you are in the EU or the UK and this matters to you, write to hello@arvald.com before you sign up rather than after.

The full list of companies that process data on Arvald's behalf is on the sub-processors page.

How long it is kept, and what can be deleted

This is the section most likely to differ from what you expect, so it is written plainly.

Closing a brand does not erase it. The brand disappears from the public internet and from the dashboard, but the record stays. Its bookings, payments and refunds are kept, because they are also the players' record of what they paid for and the coach's accounting. Its web address is retired permanently so that nobody else can take a link that old booking confirmations point at.

A player is never hard deleted from a coach's client list. A player can be archived, which removes them from the working list, and their booking history stays attached.

Corrections leave a trace. When a record changes, for example a corrected phone number, the database keeps the previous value in a history table. There is currently no mechanism that purges those. So a correction going forward is possible; erasing the fact that the earlier value existed is not, with the tools that exist today.

There is no self-serve account deletion and no data export. Neither exists in the product yet. Both are intended.

So in practice, today: write to hello@arvald.com and ask. Requests to see what is held about you, to correct it, or to remove what can be removed are handled by hand. You will be told plainly what was done and what could not be, rather than being told a request was completed when part of it was not possible.

Waitlist addresses are kept until you ask for yours to be removed.

Security

Access tokens are never exposed to the browser. Live data and test data are separated in the database rather than by convention. Arvald has not had a security audit, and no backup restore has been tested end to end, so this page does not claim either.

Changes

This page changes when the product does, with a new date at the top.

Contact

hello@arvald.com for anything on this page, including a request about your own data.

On this page