Privacy Policy

Last updated: March 2026

F7 Software Inc ("Company", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Arc Cert welding equipment certification platform ("Service"). Please read this policy carefully. By using the Service, you consent to the data practices described in this policy.


1. Information We Collect

Personal Information

We may collect personal information that you voluntarily provide when using the Service, including:

  • Full name, email address, phone number, and job title
  • Company name, business address, and billing information
  • Account credentials (username and encrypted password)
  • Profile information and preferences
Certification and Business Data

In the course of using the Service, you may provide:

  • Equipment details, serial numbers, and manufacturer information
  • Certification test results, measurements, and calibration data
  • Customer records, job schedules, and service history
  • Reference instrument details and calibration certificates
  • Digital signatures and technician identifiers
Automatically Collected Information

When you access the Service, we may automatically collect:

  • Device information (type, operating system, browser type and version)
  • IP address, approximate geographic location, and time zone
  • Usage data (pages viewed, features used, actions taken, timestamps)
  • Cookies and similar tracking technologies (see Cookie Policy below)
  • Error logs, crash reports, and performance data

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, operate, and maintain the certification platform
  • Account Management: To create and manage your user account, process authentication, and manage subscriptions
  • Communication: To send technical notices, security alerts, support messages, and service updates
  • Billing: To process payments, generate invoices, and manage subscriptions
  • Improvement: To analyse usage patterns, diagnose technical issues, and improve the Service
  • Compliance: To comply with legal obligations and enforce our Terms of Service
  • Security: To detect, prevent, and address fraud, abuse, and security incidents

3. Cookie Policy

We use cookies and similar technologies to enhance your experience. The types of cookies we use include:

Type Purpose Duration
Essential Required for authentication, security, and core functionality. The Service cannot operate without these. Session / 30 days
Functional Remember your preferences, language settings, and display options. 1 year
Analytics Help us understand how you use the Service so we can improve it. Data is anonymised and aggregated. 2 years

You can control cookies through your browser settings. Disabling essential cookies may affect the functionality of the Service. We do not use advertising or third-party tracking cookies.


4. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:

  • Service Providers: With trusted third-party providers who assist us in operating the Service (hosting, payment processing, email delivery), bound by confidentiality agreements
  • Within Your Organisation: With other users on your company account as configured by your account administrator
  • Legal Requirements: When required by law, court order, or governmental regulation, or to protect the rights, property, or safety of F7 Software Inc, our users, or the public
  • Business Transfers: In connection with a merger, acquisition, or sale of all or a portion of our assets, with notice to affected users
  • With Your Consent: In any other case with your explicit consent

5. Connecting Your Gmail or Outlook Account

Certification companies using Arc Cert may choose to connect their own Gmail or Microsoft Outlook mailbox, so that certificates reach their customers from their own address rather than ours. Connecting a mailbox is entirely optional — the Service works without it.

What we request, and why
  • Google — gmail.send, which permits sending mail only. It grants no ability to read, search, delete, or modify anything in your mailbox. We also request userinfo.email solely to display which account you connected.
  • Microsoft — Mail.Send, which likewise permits sending only, plus sign-in scopes used to display the connected account.
How we handle the access
  • We use it for one purpose: sending the certificate emails you ask us to send to your customers.
  • Access tokens are stored encrypted, used only to send on your behalf, and never shared with other companies using Arc Cert.
  • We do not read your mailbox, and the permissions we request do not allow us to.
  • We do not use this data for advertising, and we do not sell it.
  • No human at F7 Software reads your Google or Microsoft user data, except where you have given specific permission (for example while helping you with a support request), where required by law, or where necessary for security purposes such as investigating abuse.
  • We do not use this data to develop, improve, or train generalised or non-personalised AI or machine learning models.
  • You can disconnect at any time under Settings > Email in the portal, or revoke access from your Google account permissions or Microsoft account. We delete the stored tokens when you disconnect.

Limited Use disclosure. Arc Cert's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.


6. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption of data in transit (TLS 1.2+)
  • Secure password hashing using industry-standard algorithms
  • Role-based access controls and multi-tenant data isolation
  • Automated daily backups, kept off the application server
  • Two-factor authentication, which a company can require of everyone
  • Servers operated by us in the United States, with access limited to authorised staff

While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to taking all reasonable steps to protect your data.


7. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Certification records and test data are retained for longer, as required by industry regulations and standards (IEC 60974-14) and because the companies your certificates were issued to rely on being able to verify them years later.

If you close your account, contact us and we will delete or anonymise the personal information we are not required to keep. Certification records themselves are retained, and our backups are kept on a rolling schedule for up to five years, so data in historical backups is removed as those backups age out rather than immediately.


8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete personal data
  • Deletion: Request deletion of your personal data, subject to legal retention requirements
  • Data Portability: Request an export of your data in a structured, machine-readable format
  • Restriction: Request that we restrict processing of your personal data in certain circumstances
  • Objection: Object to processing of your personal data for certain purposes
  • Withdrawal of Consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, please contact us using the details below. We will respond to your request within 30 days. We may need to verify your identity before processing your request.


9. International Data Transfers

Your information may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that are different from the laws of your country. We take appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy, including the use of standard contractual clauses and other transfer mechanisms approved by applicable data protection authorities.


10. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us and we will take steps to remove such information.


11. Third-Party Links

The Service may contain links to third-party websites or services that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. We encourage you to review the privacy policy of every site you visit.


12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we will provide additional notice via email or an in-app notification. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.


13. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about our data practices, please contact us at: