Privacy Policy

Last updated: August 25, 2026

This policy explains what personal data Arbiline processes, why, who it is shared with, how long it is kept and what rights you have. It applies to arbiline.com and to the Arbiline web application.

Arbiline is the controller of that data. For any privacy question or request, including the requests described in section 7, write to [email protected]. We may update this policy as the service changes; the date above is the current version.

1. Data we process

  • Account: the account identifier, email address, name and profile picture URL that Google returns when you sign in.
  • Credentials you add: exchange API credentials, proxy URLs, and the Telegram bot token and chat identifier used for alerts. These are stored encrypted.
  • Trading records: positions, orders, fills, realized profit and loss and funding, for both real and demo trading, together with the settings you configure.
  • Subscription and payments: your plan, its term and status, and for each invoice our payment reference, the amount, the currency and the status, plus the payment metadata the gateway returns, which for a crypto invoice includes blockchain details such as the pay-in address and transaction hash.
  • Telegram group: if your plan includes the members-only group, the invite link issued to you and the numeric Telegram account identifier of the member who joins.
  • Technical data: your IP address, your browser user-agent and request metadata (time, route, response status and duration) recorded in server logs.
  • Browser verification: to keep automated scrapers away from market data, a background check by Cloudflare Turnstile evaluates characteristics of your browser and connection while you use the application. We receive only the outcome of that check, never the characteristics themselves.
  • Marketing origin: if you arrive through an advertisement, a campaign link or another website, the campaign parameters in that link (including the Google click identifier) and the address of the referring page. These describe the link you followed, not you, and are stored once, when your account is created.
  • Product analytics, only if you allow it: pages you view, clicks and other interactions with the public pages, an anonymous identifier for your browser, approximate location derived from your IP address, and device and browser characteristics. Once you sign in, these are linked to your account identifier — never to your email address or name.
  • Session recordings, only if you allow analytics: a reconstruction of your visit to the landing page and the pricing page, showing cursor movement, scrolling and clicks. Text you type into any field is masked before the recording leaves your browser. No other page is recorded, and the trading application never is.
  • Support correspondence you send us.

2. Why we process it, and on what legal basis

To provide the service you signed up for: signing you in, showing market data, carrying out the trades you instruct, tracking positions, sending alerts you enabled and managing subscriptions. Legal basis: performance of our contract with you.

To keep the service secure and working: logging, rate limiting, debugging, verifying that requests come from a real browser rather than an automated scraper, prevention of fraud and abuse, and investigating payment disputes. Legal basis: our legitimate interests in operating a secure, reliable platform and in defending against misuse, weighed against your rights.

To meet accounting and other legal obligations, principally records of payments received. Legal basis: compliance with a legal obligation.

For optional integrations you switch on yourself, such as Telegram alerts. Legal basis: your consent, which you may withdraw at any time by removing the integration.

For product analytics and session recording, to see which pages work, where people get stuck and which parts of the service are used. Legal basis: your consent. Nothing is loaded before you give it, and you may withdraw it at any time in section 6.

To understand which advertisements and campaigns bring us customers, and to report a completed subscription back to the advertising platform that referred it. Legal basis: our legitimate interest in knowing whether our marketing spend works, weighed against your rights: the data records the link you followed rather than anything about you, it is stored once at sign-up, and it is never used to profile you or to target you with advertising.

Providing account data and exchange credentials is necessary to use Arbiline: without account data we cannot give you an account, and without exchange credentials we cannot execute trades for you. You are not obliged to provide them, but those parts of the service will not be available.

3. Who we share it with

We do not sell your personal data. We disclose it only to the following recipients, and only as far as the service requires:

  • Google, for sign-in only.
  • The crypto exchanges you connect: they receive your own API credentials and the orders and queries you make through Arbiline, routed through your proxy if you configured one.
  • Our payment provider, which runs the checkout page and receives the amount, the currency, our payment reference and a plan description.
  • Telegram, where alert content and your chat identifier pass through its Bot API, and the same for the members-only group.
  • Cloudflare, our content delivery and web security provider, which sits in front of the website and processes connection metadata including your IP address. It also performs the browser verification described in section 1 (Cloudflare Turnstile); the data that check processes is described in the Cloudflare Turnstile Privacy Addendum at cloudflare.com/turnstile-privacy-policy.
  • Our hosting provider, which runs the servers and stores the database.
  • PostHog, our product analytics provider, but only if you allowed analytics. It receives the interaction data and session recordings described in section 1, on its European infrastructure.
  • Google Ads, if you reached us through one of its advertisements: when a subscription is paid we report that a conversion took place for the click identifier that referred it, so the platform can measure the campaign. We do not send your email address, your name or any trading data.

We may also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend a legal claim.

4. Where your data is processed

Arbiline runs on servers in Finland, inside the European Union, and the database is stored there. Our analytics provider is on its European infrastructure, so analytics data stays in the European Union as well.

Some recipients in section 3 operate globally, so data may be processed outside the European Economic Area. Where we pass data to an exchange, to Telegram or to the payment provider, we do so to carry out what you asked us to do. For other transfers we rely on the safeguards those providers offer, such as standard contractual clauses.

5. How long we keep it

Account, trading and subscription data is kept for as long as your account exists. Records connected to payments are kept afterwards for as long as accounting and tax rules require.

Sessions expire on their own: 15 minutes for an access token, 7 days for a refresh token. Server logs are kept for a limited period for security and troubleshooting and are then deleted. Encrypted credentials are deleted as soon as you remove the exchange key, proxy or Telegram integration they belong to.

Marketing origin is kept for as long as your account exists and is deleted with it.

Analytics data and session recordings are kept by our analytics provider under its own retention schedule; recordings are kept for a shorter period than event data. If you withdraw consent, nothing further is collected, and you can ask us to delete what was already collected.

Backups are kept for disaster recovery and rotated. Data you asked us to erase can remain in a backup until that backup is rotated out.

6. Cookies and local storage

These cookies are strictly necessary to sign you in, keep you signed in and protect the service from automated access. None of them tracks you across other websites.

  • access_token — keeps you signed in; expires after 15 minutes.
  • refresh_token — renews your session; expires after 7 days.
  • arb_session — records only that a session exists, so the app stops asking to renew one that has ended; holds no information about you, and is removed together with the two cookies above when you sign out.
  • oauth_state — protects the sign-in round-trip against cross-site request forgery; expires after 10 minutes, used once.
  • oauth_return — remembers which page to return you to after sign-in; expires after 10 minutes, used once.
  • bt — confirms your browser passed the verification described in section 1, so market data keeps loading without repeating it; expires after 10 minutes.

One further cookie records where you came from:

  • arb_attr — holds the campaign parameters and referring page from the link you arrived through, so that if you later create an account we know which campaign brought you. It is set once, on your first visit, is not updated on later visits, expires after 90 days, and is read only when an account is created. It contains no information about you and is not shared with anyone.

If you allow analytics, our analytics provider sets its own cookie and local-storage entry to recognise your browser between page views and to group them into a session. Nothing analytics-related is set before you allow it, and declining leaves none of it behind.

The application also stores interface preferences in your browser’s local storage, together with your analytics choice. They stay in your browser, are not used as identifiers, and are cleared when you clear your browser data.

You are asked about analytics the first time you visit, before anything non-essential loads, and both answers are offered equally. You can change that answer at any time using the control at the bottom of this page; declining stops collection immediately. Your answer is stored per browser, so a different browser or device asks again.

7. Your rights

You have the right to obtain a copy of your personal data, to have inaccurate data corrected, to have your data erased, to restrict or object to processing, to receive your data in a portable format, to withdraw consent where processing is based on it, and to lodge a complaint with your data protection authority. We apply this section to all users regardless of where they live.

To exercise any of these rights, email [email protected] from the address on your account. We respond within 30 days, and we may ask for further information if we cannot confirm that the request comes from you.

You can remove individual exchange keys, proxies, the Telegram integration and individual positions yourself inside the application. To erase your whole account, email us and we will complete it within 30 days, retaining only the records we are legally required to keep, and subject to the backup rotation described in section 5.