Provider: SALESARENA HQ LLC.
Contact: support@salesarenahq.com
This Privacy Policy explains what personal data SalesArena HQ collects, how we use it, who we share it with, and your choices. This policy applies to the SalesArena HQ web application and related services (the "Service").
This policy is drafted in plain language and has not been reviewed by an attorney. Consult legal counsel before relying on it for compliance with GDPR, CCPA, HIPAA, or other regimes.
1. Data We Collect
Account & Profile
- Name, email address, hashed password (bcrypt), role within your Company
- Optional: avatar image, personal accent color, biographical text
- Login timestamps, session tokens (secure HTTP-only cookies)
Sales & Gamification Data
- Sales entries you or your team log (lines, segment, optional notes)
- Points, streaks, badges unlocked, cosmetic frames earned, level and tier progression
- Duel and team-war participation, wins/losses, activity feed entries
Content You Upload
- Announcement text, image and GIF attachments (auto-compressed and size-limited), reactions, comments
- Custom badge and challenge definitions created by your Owner
Technical Data
- IP address, browser type, device information, error logs (used for security and debugging)
- Stripe payment tokens (we do not store full card numbers — Stripe holds those directly)
2. How We Use Data
- To operate the Service: authenticate you, display leaderboards, award points, run challenges
- To provide customer support (Owner-invited support sessions may include impersonation — see §5)
- To process payments and manage subscriptions (via Stripe)
- To send transactional emails (invites, password resets, weekly digests — via Resend)
- To improve the Service (aggregated, anonymized analytics)
- To comply with law and enforce our Terms
We do not sell your personal data. We do not use your data to train AI models.
3. Data Sharing & Sub-processors
We share limited data with the following sub-processors strictly to operate the Service:
- Stripe — payment processing (US) — stripe.com/privacy
- Resend — transactional email delivery (US) — resend.com/legal/privacy-policy
- Emergent Object Storage — image/attachment hosting
- Google (OAuth) — optional sign-in via your Google account
- SARA Plus — optional dealer-sales sync (only for Premium Companies who opt in and provide credentials)
We do not share data with advertisers or data brokers.
4. Cross-Company Isolation
Every Company account is logically isolated at the database and API layer. Users in Company A cannot see any data belonging to Company B. Cross-company challenges are opt-in and only expose team names, member names, and match scores — not the underlying sales entries or client details.
5. Support Access & Impersonation
To resolve support tickets, SalesArena HQ platform administrators may occasionally "act as" a Company Owner to reproduce the reported issue. Every impersonation session is:
- Restricted to platform-admin users (not your Company admins)
- Logged in your Company Activity Feed as
impersonation_start/impersonation_end - Read-only where possible; write actions taken during impersonation are attributed to the platform admin in the audit trail
If you wish to opt out of impersonation access, email support@salesarenahq.com. Note that this may limit our ability to reproduce and fix bugs on your behalf.
6. Data Retention
We retain data while your subscription is active and for 30 days after cancellation to allow reactivation. After 30 days, personal data is permanently deleted from primary systems; encrypted backups are purged on a rolling 90-day cycle. Sales entries older than 3 years may be archived to cold storage but remain accessible on request.
7. Your Rights
Depending on your jurisdiction, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Export your data in a portable format
- Object to certain processing
To exercise any of these rights, email support@salesarenahq.com from the address on file. We will respond within 30 days.
8. Security
We use industry-standard practices: HTTPS for all traffic, bcrypt for password hashing, HTTP-only secure cookies for sessions, chunked-upload guardrails to prevent oversized uploads from exhausting memory, and role-based access control at the API layer. No system is 100% secure — please report vulnerabilities to support@salesarenahq.com.
9. Children
The Service is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided data, contact us to have it removed.
10. International Users
Our servers are located in the United States. By using the Service outside the U.S., you consent to the transfer of your data to the U.S. for processing.
11. Changes
Material changes to this policy will be announced by email to Company Owners and via an in-app banner at least 30 days before taking effect.
12. Contact
Questions or requests: support@salesarenahq.com.