Arcvue LLC
Privacy Policy
Effective August 21, 2026.
1. Who We Are
Arcvue LLC ("Arcvue," "we," "us") is a Virginia limited liability company that operates the Arcvue financial intelligence platform at arcvue.ai. Our contact email is info@arcvue.ai.
2. What Data We Collect
Account Information. When you sign up for Arcvue, we collect your name, email address, company name, and role. This information is used to create your account and communicate with you about the Service.
Financial Data from Your ERP. When you connect your accounting system (QuickBooks Online, UNANET, Costpoint, Sage Intacct, or other supported ERPs), Arcvue imports financial data including: general ledger transactions, chart of accounts, contract and project records, invoice and revenue data, cost pool and indirect rate information, and employee time records. This data is read-only—Arcvue never writes data back to your ERP. Your financial data is stored in a dedicated database that is physically separate from every other customer's data.
Banking Data. When you link a bank or credit card account, Arcvue receives the account details and transaction history for the accounts you link—account identifiers and balances, and the date, amount, and description of each transaction—together with the identity information you submit while authenticating with your financial institution. Linking runs through Plaid, which reaches your institution on Arcvue's behalf. Arcvue never receives or stores your online banking credentials: you enter those with Plaid, which returns only the account and transaction data described here. This data is read-only and is held in the same dedicated database as the rest of your financial data.
Usage Telemetry. Arcvue collects anonymous, aggregated usage telemetry to improve the platform. This includes: which modules are accessed and how frequently, feature usage counts (e.g., number of exports, syncs, or searches), error events and sync success/failure rates, and session counts. Telemetry never includes actual financial values, account numbers, contract names, employee names, or any content from AI assistant queries. Telemetry collection can be disabled by your account administrator in the Admin Console at any time.
Demo Environment. Anonymous usage telemetry is collected during demo sessions on the same basis described above—module access, feature usage counts, and error events. No personally identifiable information is collected from demo visitors. The demo dataset is synthetic and does not contain real customer financial data. AI assistant queries in the demo are processed by Anthropic Claude under the same terms described in Section 6.
Demo Requests and Sales Inquiries. There is no demo request form on this site—deliberately, because a form collects a name and an address and has to store them somewhere. Requests reach us by email at info@arcvue.ai, and what we hold is the email you sent: your name, your address, and whatever you chose to put in it. It is not written to any customer database, and we use it solely to contact you about your request.
3. Arcvue Mobile
Arcvue Mobile is an app your employer provides. Employees use it to record their own timecards, expenses, and business mileage. Accounts are issued by the employer and there is no public sign-up. Your employer decides what happens with these records; Arcvue processes them on your employer's behalf.
Location, Including in the Background. If you turn on automatic mileage tracking, the app detects when you are driving and records the distance, so you do not have to start and stop a timer at the wheel. To do that it watches your device's motion sensors for a drive starting, and turns location on only while the vehicle is moving. Detection runs on your device, and only the finished trip—its distance and its start and end points—is sent to Arcvue. The route in between is never stored or transmitted. Automatic tracking is off until you turn it on, and turning it on requires you to grant your device's “Always” location permission. Every trip arrives as a draft you classify, and any trip you mark personal is never reimbursed.
We Treat Precise Location as Sensitive. Precise geolocation is sensitive personal information under California law and under the other state privacy laws that use that category. We collect it only for the purpose described here, and it is held under the same protections as the rest of your records.
What It Is Used For, and What It Is Not. Location is collected for one purpose: to work out the mileage on your business trips so that you do not have to. It produces a draft figure for you to check, correct and submit for expense reimbursement—you remain responsible for the mileage you submit, and the app decides nothing on your behalf. We do not use it for advertising, for profiling, or for measuring your productivity, your attendance, or your hours. It is not used to train any model. It is excluded from any aggregated or de-identified data we derive, so it never contributes to benchmarks, statistics, or product analytics.
Turning It Off. You can turn automatic tracking off at any time in the app, and you can withdraw the location permission at any time in your device settings. Either one stops collection from that point forward. Neither affects anything else in the app, which works without location.
Camera and Photo Library. Used to photograph receipts, or to attach ones you already have, and the images are stored with your expense records.
Microphone and Speech Recognition. Used only for voice time entry, and only while you are holding the button. What you say becomes a draft time entry that you then confirm. Your device's operating system does the transcription: on iPhone the app asks for on-device recognition, and the audio reaches Apple only if your device cannot do it; on Android the audio is sent to Google. Arcvue stores the text that comes back, never the audio, and the app never listens in the background. If you start voice entry by asking Siri, Apple processes what you said to Siri.
Face ID and Touch ID. Used only to unlock the app on your device. Your operating system performs the check and returns a pass or a fail. Arcvue never receives or stores biometric data.
Account Information. Your name, work email, employee ID, organization, and role come from the account your employer issued. They sign you in and attach your entries to you.
The Records You Create. Your time, expense, and mileage entries are the purpose of the app. Your supervisor and your employer can see them.
Notifications. A device notification token is stored so the app can send you reminders and approval notices. Delivery runs through Expo's push service and then Apple's or Google's.
Crash and Diagnostic Data. Collected through Sentry so we can find and fix failures. A crash report carries the error, your employee ID, and your organization—never your financial records.
What We Do Not Do. We do not sell your data. We do not share it with advertisers or data brokers. We do not track you across other companies' apps or websites. Your location is never used for anything other than mileage on trips you confirm.
Who Else Handles This Data. Your employer, which is the purpose of the app. Beyond that, only the providers that make it work: Amazon Web Services for hosting and storage, Apple and Google for distributing the app and delivering notifications, Expo for relaying those notifications, Apple's and Google's speech recognition for voice entry, and Sentry for crash reporting.
Keeping and Deleting Data. Time, expense, and mileage entries are business records. Your employer keeps them as long as its own retention rules and federal contracting requirements demand. Because they are your employer's records, ask your employer to see, correct, or delete them.
4. How We Use Your Data
We use your data solely to provide and improve the Arcvue platform. Specifically: to render your dashboards, forecasts, financial statements, and reports; to run nightly ERP syncs and keep your data current; to send email alerts (sync failures, monthly reports) when configured; to diagnose and fix technical issues; and to improve the platform based on aggregated, anonymous usage patterns.
We do not sell your data to third parties. We do not use your financial data for advertising. We do not share your data with other Arcvue customers.
5. Data Isolation and Security
Per-Tenant Databases. Each customer's data is stored in a dedicated, physically separate database file on our servers. Your data is never commingled with another customer's data in a shared database. There is no row-level filtering—complete physical isolation.
Encryption. All data is encrypted at rest using AES-256 volume encryption on AWS infrastructure. All data in transit is encrypted using TLS 1.2 or higher.
Access Controls. Only authorized Arcvue personnel have server-level access. Customer users access data only through the authenticated web application. All administrative access is logged.
Authentication. The platform supports multi-factor authentication (MFA), password complexity requirements, account lockout after failed attempts, and role-based access controls (RBAC) that limit what each user can see and do.
6. Third-Party Services
Arcvue uses the following third-party services in the operation of the platform. The authoritative register of sub-processors, customer-directed integrations, and public data sources—including our fourteen (14) day notice commitment before any new sub-processor begins processing—is published at arcvue.ai/subprocessors.
Amazon Web Services (AWS). Our servers and databases are hosted on AWS infrastructure in the United States (us-east-1, Northern Virginia). AWS provides the underlying compute, storage, and network infrastructure.
ERP APIs. When you connect your accounting system, Arcvue communicates with that system's API using credentials you authorize. We store OAuth tokens securely on the server and use them to sync data on your behalf. For QuickBooks Online customers, Intuit Inc. acts as a sub-processor—your financial data flows through Intuit's API during each synchronization. For UNANET customers, data is synced via ODBC connection to the UNANET DataLake. Other supported ERPs (Costpoint, Sage Intacct, JAMIS, D365) connect via their respective APIs. PROCAS is the exception and involves no connection at all: it is a manual CSV export you upload, so there is no credential, no token and no automated pull—your data reaches Arcvue only when you send it.
Bank Aggregation. Plaid Inc. is the only route by which Arcvue connects to a financial institution, and it acts as a sub-processor. Arcvue holds the Plaid integration account, so your institution is reached on Arcvue's behalf rather than your employer's. Because of that, the obligation to tell you what is collected and to obtain your consent before an account is linked rests with Arcvue and not with your employer. Our sub-processor register records the data categories and Plaid's current status.
LLM APIs (Optional). If you use the optional AI Assistant feature, your natural language queries are sent to a large language model API (currently Anthropic Claude) to generate responses. The queries are sent alongside relevant context from your data to answer your question. No financial data is retained by the LLM provider after the response is generated. You may opt out of the AI Assistant entirely.
Microsoft Graph API (Optional). If you configure email alerting, Arcvue uses the Microsoft Graph API to send reports and alerts from your authorized email address. We store the OAuth credentials securely and use them solely for sending authorized email communications.
7. Data Retention and Deletion
Your data is retained for the duration of your subscription. Upon termination, we will provide a complete data export (SQLite database file or CSV) on request within thirty (30) days. After the export period, we permanently delete your dedicated database and its associated backups, with one exception required by government contracting regulation.
Certain cost accounting records are subject to mandatory retention. Because our customers are government contractors, a defined set of records—timecard entries and their change history, indirect cost allocation records, posted and period-closed general ledger entries, and the audit trail of changes to those records—must be retained to satisfy Federal Acquisition Regulation 52.215-2 and Defense Contract Audit Agency requirements. Our platform enforces this at the database level, and these records cannot be deleted on request, including by us. We retain them for three years from final payment on the relevant contract and then dispose of them.
Records retained under this exception remain encrypted, remain subject to the same access controls and confidentiality obligations as your other data, and are never used for any purpose other than preserving them for the required period. We will confirm in writing what has been deleted and what has been retained.
8. Your Rights
You may request at any time: a copy of all data we hold about your organization; correction of inaccurate account information; deletion of your data (subject to the termination process and the regulatory retention exception described in Section 7); or information about what data we collect and how it is used. Contact info@arcvue.ai to exercise any of these rights.
Most of the information in the Arcvue platform is provided by our customers about their own business and personnel. For that information, our customer is the controller and we act as a processor or service provider on their instructions. If you are an employee or contractor of an Arcvue customer and you want to exercise a privacy right in relation to data held in the platform, please contact your employer, who can act through their platform administrator or by contacting us. We will assist our customer in responding.
For information we hold in our own right—for example, if you contact us, subscribe to updates, or visit our website—the following applies depending on where you live. You may have the right to know what personal information we hold about you, to request a copy of it, to ask us to correct it, to ask us to delete it, and not to be discriminated against for exercising any of these rights. Residents of some states may also have the right to opt out of the sale or sharing of personal information and of targeted advertising, and to appeal a decision we make about a request.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We have never done so.
Where we collect sensitive personal information—precise location, collected only through the mobile app and only where you have turned on automatic mileage tracking—we use it solely to provide that feature. We do not use or disclose it for any purpose that would give rise to a right to limit its use under California law, and we do not sell or share it.
To make a request, contact info@arcvue.ai. We will verify your identity before responding, respond within the period required by applicable law, and will not charge a fee except where the law permits it. If we decline a request you may ask us to reconsider by replying to our response.
9. Cookies and Tracking
The Arcvue web application maintains your authenticated login session using a secure session token (JSON Web Token) stored in your browser's local storage rather than a traditional session cookie. We do not use advertising cookies, third-party tracking pixels, or analytics scripts that track you across other websites.
10. Children's Privacy
Arcvue is a business-to-business service and is not intended for use by individuals under 18 years of age. We do not knowingly collect information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to your account administrator. The effective date at the top of this page reflects the most recent update.
12. Contact
For questions about this Privacy Policy or our data practices, contact us at info@arcvue.ai.