Scope
This Privacy Policy applies to the website at ariintegratedholdings.com and any subdomains (the “Site”), operated by Ari Integrated Holdings Inc. (“Ari”, “we”, “us”). It covers the public informational pages, the contact form, the investor-alert email list, and the password-protected investor portal.
It does not cover third-party websites we link to, including the pages of the ETF issuers whose products are described on the Site, or any meeting-scheduling pages hosted by Calendly. Those services have their own privacy policies.
Information we collect
We collect four kinds of information, and only when you give it to us or your browser sends it.
Contact form
When you submit the contact form we receive the fields you complete: your full name, your email address, the company you represent (optional), the investor type you select, and the message you write. The submission is not stored in the Site’s database. It is delivered by email to Mitchel Carson, Chief Technology Officer, and retained in that mailbox as correspondence, together with any other detail you choose to include in the message.
Investor alerts
When you sign up for investor alerts we store your email address, the date and time of signup, the page or form on the Site where you signed up (the “signup source”), and whether the address is active. We use the signup source to understand which parts of the Site are useful and to confirm that a request was made on our own forms. Each alert we send is recorded in a broadcast log: the subject, the message, the Ari staff member who sent it, when it was sent, and how many addresses it went to. The log does not list individual recipients.
Portal accounts
Portal accounts are created by Ari, not by self-registration. For each account we store a name, an email address used as the login, an assigned role that determines which pages the account can see, and a password. Passwords are stored only as salted cryptographic hashes; we cannot read them and do not transmit them in plain text. We do not record the date or time of individual logins.
Technical logs
Like any website, our hosting provider records standard server logs: the IP address of the requesting device, the browser type and version, the pages requested, the time of the request, and any error that occurred. These logs exist to keep the Site running and secure. We do not combine them with your name or email address except when investigating a security incident.
How we use it
- To read and answer contact-form messages, which are delivered to Mitchel Carson, Chief Technology Officer.
- To send the investor alerts you asked for: company updates, investor documents, and meeting announcements.
- To authenticate portal users, keep their sessions open, and limit each user to the pages their role allows.
- To detect, investigate, and prevent abuse, unauthorized access, and technical faults.
- To meet record-keeping duties that apply to a company communicating with its shareholders.
We do not use your information for advertising, we do not build profiles for marketing, and we do not sell, rent, or trade personal information to anyone.
Legal bases and consent
Where a legal basis is required for processing, we rely on the following:
- Consent for the investor-alert list. You may withdraw consent at any time (see Your rights).
- Performance of a contract, or steps taken at your request before one for answering contact-form inquiries and operating portal accounts.
- Legitimate interests for security logging, fraud prevention, and keeping the Site available. We balance these interests against your rights and collect no more than the purpose needs.
- Legal obligation where a law or regulator requires us to keep or disclose records.
Service providers
We use four service providers to run the Site. Each processes data only on our instructions and only for the purpose described. We do not share your information with any other third party unless the law requires it.
- Vercel
- Hosts the Site and serves its pages. Vercel handles the technical logs described above.
- Neon (PostgreSQL)
- Stores the Site’s database: the investor-alert list, portal account records (with hashed passwords), and the broadcast log of investor alerts we have sent. Contact-form submissions are not stored in the database.
- Resend
- Delivers transactional email: the message that carries your contact-form submission to the CTO, the confirmation sent when you sign up for alerts, and the investor alerts themselves. Resend processes the recipient address and message content in order to deliver each email.
- Calendly
- Provides the meeting-scheduling embed when online booking is offered on the Site. When you book a meeting you enter your details into Calendly’s form, which is governed by Calendly’s privacy policy; Calendly then shares the booking details with us so we can hold the meeting.
Cookies
The Site sets cookies for one purpose only: keeping you signed in to the investor portal. Our authentication library (NextAuth) sets a session cookie and a small number of supporting cookies (for example, a cross-site-request-forgery token) when you log in. These cookies are strictly necessary for the portal to function. They are marked HTTP-only and, in production where the Site is served over HTTPS, secure. The login cookie holds a signed token (a JWT) that persists for up to 30 days from the time you sign in, or until you sign out or clear your browser’s cookies. The token is validated by its signature rather than against a server-side session record, so it is not revoked centrally before it expires.
We do not use advertising cookies, analytics trackers, social-media pixels, or fingerprinting of any kind. Because we set no optional cookies, the Site does not show a cookie banner. If you block cookies in your browser the public pages will work normally; the portal login will not.
Retention
- Contact-form messages are delivered to the CTO’s mailbox and kept there for as long as needed to answer the inquiry and afterwards as a record of correspondence, unless you ask us to delete them sooner.
- Investor-alert addresses are kept until you unsubscribe or ask for deletion. When an address is unsubscribed or deactivated by Ari it is marked inactive rather than erased, so that a later signup from the same address does not re-enable it by mistake; you can ask us to erase the record entirely.
- Broadcast logs are kept as a record of what was sent to shareholders and when.
- Portal account records are kept while the account is active and for a reasonable period after it is closed, as required by our record-keeping duties toward shareholders.
- Technical logs are kept by our hosting provider for a short rolling period and are then discarded.
Your rights
Regardless of where you live, you can ask us to do any of the following. We will respond within two business days and will not charge for a reasonable request.
- Access: receive a copy of the personal information we hold about you.
- Correction: have inaccurate or incomplete information corrected.
- Deletion: have your information deleted, subject to any record we must keep by law or to maintain your shareholder account.
- Unsubscribe: stop receiving investor alerts. Reply to any alert with the word “unsubscribe”, or email the CTO directly. We will remove you promptly and confirm by email.
- Objection and restriction: object to processing based on legitimate interests, or ask us to restrict processing while a dispute is resolved.
To exercise any of these rights, email Mitchel Carson at mitchelcarson@ariintegratedholdings.com from the address we hold for you, or tell us how we can verify that the request is yours. If you are in a jurisdiction with a data-protection authority you also have the right to lodge a complaint with it.
Security
The Site is served over HTTPS only. Portal passwords are hashed with a modern, salted algorithm and are never stored in readable form. Session cookies are HTTP-only and, in production, secure. The contact form and the alert signup are rate-limited and include a hidden trap field that rejects automated submissions. Database access is limited to the application and to the Ari personnel who administer it, and connections to the database are encrypted in transit. Portal accounts are created and revoked by Ari, so no one can register for access on their own.
No method of transmission or storage is perfectly secure. If we become aware of a breach that affects your personal information we will notify you and any relevant authority as the law requires, using the email address we hold for you.
International transfers
Our service providers operate data centres in the United States and may process information there or in other countries where they have infrastructure. If you access the Site from outside the country where the data is stored, your information will be transferred across borders. Each provider commits, in its terms with us, to protect personal information in line with recognised data-protection standards.
Children
The Site is intended for adults: accredited investors, family offices, partners, and other professional contacts. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided information to us, email the CTO and we will delete it.
Changes to this policy
We may update this policy when the Site, our service providers, or the law changes. The date at the top of this page shows when it was last revised. If a change materially affects how we use information already collected, we will tell investor-alert subscribers and portal users by email before it takes effect. Continued use of the Site after a change means you accept the revised policy.
Contact
Questions, requests, and notices about privacy go to Mitchel Carson, Chief Technology Officer, at mitchelcarson@ariintegratedholdings.com. You can also use the contact form.
See also our Terms of Service and Disclaimer.