ARQ INTELLIGENCE

Privacy Policy

Privacy Policy

Effective date: September 16, 2026 | Last updated: September 16, 2026

This Privacy Policy explains how Dream Jars LLC, doing business as ARQ Intelligence, collects, uses, discloses, and protects personal information when you visit our website, purchase or use ARQ services, or interact with us.

Dream Jars LLC, doing business as ARQ Intelligence (“ARQ Intelligence,” “ARQ,” “we,” “us,” or “our”), provides external intelligence and related business software and services. This Privacy Policy applies to personal information we process in connection with our website, ARQ Private Access, Founding 100 Annual Membership, customer portals, onboarding forms, payment and subscription workflows, support interactions, research and intelligence workflows, and related services (collectively, the “Services”).

  1. Scope and Roles

This Privacy Policy describes ARQ’s practices when we act as a business, controller, or similar responsible party for personal information. In some enterprise arrangements, ARQ may process information on behalf of a customer as a processor or service provider; in those cases, the applicable customer agreement or data processing agreement may also apply.

The Services are designed for business and professional use. The personal information we typically process relates to business users, prospective customers, customer representatives, partners, vendors, and people who communicate with us.

  1. Personal Information We Collect

2.1 Information you provide directly

We may collect information you provide through the website, Stripe checkout, onboarding forms, customer portal, support channels, meetings, emails, demos, surveys, or other interactions, including:

• contact information, such as name, business email address, business phone number if provided, and mailing or billing address;

• business information, such as company name, job title, role, industry, company size, and business context;

• account and onboarding information, such as login identity, selected vendors, APIs, platforms, dependencies, coverage requests, plan or membership information, Founding 100 status where applicable, and preferences;

• communications and feedback, such as support requests, meeting notes, survey responses, comments, product feedback, and correspondence;

• commercial information, such as subscription or membership type, billing cadence, transaction status, invoice information, and payment-related records made available to us by our payment provider;

• other information you choose to submit to us.

2.2 Payment information

ARQ currently uses Stripe Managed Payments and related Stripe/Link services for certain online purchases. Stripe and Sold through Link, LLC may collect and process payment-card details, tax identifiers, billing information, transaction data, and related payment information as merchant of record or payment provider. ARQ does not need to receive or store your full payment-card number in order to provide the Services.

Stripe, Link, banks, payment networks, and other payment providers process information under their own privacy notices and legal obligations.

2.3 Information collected automatically

When you use our website, forms, portal, emails, or Services, we and our service providers may automatically collect standard technical and usage information, such as IP address, browser type, device type, operating system, timestamps, referring URLs, pages or features viewed, interaction events, approximate location inferred from IP address, diagnostic information, and security logs.

Our website or service providers may use cookies, local storage, or similar technologies where configured to operate the Services, remember preferences, protect security, measure performance, or understand usage. Where legally required, we will provide consent or preference controls.

2.4 Information from third parties and public sources

ARQ may receive business-contact, company, vendor, product, market, technical, or public-source information from customers, service providers, business partners, public websites, vendor documentation, status pages, changelogs, announcements, APIs, news sources, and other lawful sources.

ARQ’s core intelligence product monitors and analyzes external vendor and platform information. Most monitored content is business, technical, commercial, or publicly available information rather than personal information, but incidental personal information may appear in public or third-party sources.

  1. How We Use Personal Information

We may use personal information for the following business purposes:

• provide, operate, maintain, personalize, and improve the Services;

• create and manage accounts, subscriptions, memberships, Founding 100 status, entitlements, vendor selections, onboarding, and customer access;

• process or support transactions, billing, invoices, renewals, cancellations, refunds, fraud prevention, and payment reconciliation;

• communicate about the Services, including onboarding, service updates, support, administrative notices, product changes, membership matters, and account matters;

• research, detect, classify, summarize, enrich, prioritize, and present external intelligence;

• use AI, machine learning, automation, research tools, and model providers to generate or improve intelligence, summaries, classifications, supporting evidence, and recommended actions;

• respond to customer requests, coverage requests, questions, complaints, and feedback;

• analyze product usage, activation, engagement, reliability, coverage demand, performance, and customer experience;

• secure the Services; authenticate users; detect abuse, fraud, attacks, errors, and unauthorized activity; and troubleshoot incidents;

• develop new products, features, models, taxonomies, workflows, and commercial offerings;

• manage sales, partnerships, business development, customer relationships, and corporate operations;

• comply with law, legal process, contractual obligations, tax requirements, sanctions, and regulatory requests;

• establish, exercise, or defend legal claims and enforce our agreements;

• carry out a merger, acquisition, financing, restructuring, sale of assets, or other corporate transaction.

  1. Legal Bases for Processing

Where laws such as the GDPR or UK GDPR require a legal basis, we process personal information as applicable based on:

• performance of a contract or steps requested before entering into a contract, including providing accounts, subscriptions, memberships, onboarding, support, and the Services;

• our legitimate interests, such as operating and improving ARQ, securing systems, understanding business usage, developing products, preventing abuse, supporting customers, and conducting ordinary B2B sales and relationship management, where those interests are not overridden by applicable rights;

• compliance with legal obligations, including tax, accounting, fraud-prevention, sanctions, regulatory, and recordkeeping requirements;

• consent, where required for a specific activity, such as certain cookies, marketing communications, or optional data uses.

  1. Artificial Intelligence and Automated Processing

ARQ uses AI-assisted and automated systems as part of the Services and internal operations. These systems may process business content, external source material, usage data, customer-selected dependencies, customer context, and other information needed to generate intelligence or operate the product.

ARQ may use third-party AI or model providers, research providers, workflow platforms, and automation tools to support these functions. We seek to limit the personal information submitted to such systems to what is reasonably necessary for the relevant purpose.

ARQ does not intend the Services to make legally binding or similarly significant decisions about individuals solely through automated processing. ARQ’s automated and AI-assisted outputs are designed primarily for business intelligence and decision support.

  1. How We Disclose Personal Information

We may disclose personal information to the following categories of recipients when reasonably necessary:

• service providers and subprocessors that support hosting, websites, forms, customer portals, databases, workflow automation, monitoring, research, AI/model processing, analytics, communications, security, support, and professional services;

• payment providers, merchants of record, banks, payment networks, fraud providers, and tax-related providers, including Stripe and Sold through Link, LLC, for transaction processing and related obligations;

• professional advisers, such as attorneys, accountants, auditors, insurers, and consultants, subject to appropriate duties of confidentiality where applicable;

• government authorities, regulators, courts, law enforcement, or other parties when disclosure is required or permitted by law or reasonably necessary to protect rights, security, users, ARQ, or the public;

• counterparties and advisers in connection with a merger, acquisition, financing, restructuring, due diligence, sale of assets, or similar corporate transaction;

• other parties at your direction or with your consent.

ARQ does not currently sell personal information for monetary consideration or share personal information for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws. If our practices change in a way that creates an applicable opt-out right, we will update this Privacy Policy and provide required controls.

  1. Current Technology and Service Provider Categories

ARQ currently uses a composable technology stack. Depending on the workflow, information may be processed by providers that support website hosting, domain and email services, intake forms, customer portal access, databases, workflow automation, monitoring, research/enrichment, AI-assisted analysis, payments, and communications.

Current providers may include, as applicable, Framer, GoDaddy/Microsoft 365, Tally, Softr, Airtable, Make, ChangeDetection.io/CO.io, Exa, Stripe/Link, and AI/model providers used in ARQ workflows. Providers and configurations may change as the Services evolve. We select providers based on operational need and may replace them with functionally similar providers.

For enterprise customers that require it, we may provide additional information about subprocessors or enter into appropriate data-protection terms.

  1. Cookies and Similar Technologies

Our website and service providers may use cookies, local storage, pixels, SDKs, or similar technologies for essential functionality, security, session management, preferences, analytics, and performance.

The specific technologies in use may change as our website and product stack evolves. Where applicable law requires consent for non-essential cookies or similar technologies, we will use an appropriate consent mechanism.

You can control cookies through browser settings and any consent tool we make available, although disabling necessary technologies may affect functionality.

  1. Data Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain customer and transaction records, preserve account and membership history, support security, resolve disputes, enforce agreements, improve the product, and comply with legal, tax, accounting, and regulatory obligations.

Retention periods vary based on the type of information, relationship, legal requirements, operational need, and whether information is required to establish or defend legal claims.

When personal information is no longer reasonably needed, we may delete, anonymize, or aggregate it, subject to backup, archival, legal-hold, fraud-prevention, and recordkeeping requirements.

  1. Security

We use reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, misuse, loss, alteration, or disclosure. These measures may include access controls, authentication, secure transmission, vendor controls, logging, backups, and least-privilege practices appropriate to the stage and nature of the Services.

No security system is perfect. We cannot guarantee absolute security or that unauthorized third parties will never defeat our safeguards. You are responsible for securing your own devices, credentials, accounts, and copies of data you download or share.

  1. International Data Transfers

ARQ and its service providers may process personal information in the United States and other countries. Those countries may have data-protection laws that differ from the laws where you live.

Where required by applicable law, we rely on appropriate transfer mechanisms, contractual protections, adequacy decisions, consent, or other legally recognized safeguards for cross-border transfers.

  1. Your Privacy Rights

Depending on where you live and subject to applicable law, you may have rights regarding personal information, such as the right to:

• request access to personal information we hold about you;

• request correction of inaccurate personal information;

• request deletion of personal information;

• request a portable copy of certain personal information;

• object to or request restriction of certain processing;

• withdraw consent where processing is based on consent;

• opt out of certain sale, sharing, or targeted-advertising practices where applicable;

• appeal certain denials of privacy requests where applicable state law provides an appeal right;

• lodge a complaint with an applicable data-protection authority.

To exercise a privacy right, contact us using the information in Section 18. We may need to verify your identity and authority before fulfilling a request. Authorized agents may submit requests where permitted by law, but we may require proof of authorization. We will not unlawfully discriminate against you for exercising applicable privacy rights.

  1. U.S. State Privacy Disclosures

Certain U.S. state privacy laws apply only to businesses that meet statutory thresholds. Whether a particular law applies to ARQ may depend on our size, revenue, data volume, activities, and the nature of the information involved.

Where an applicable U.S. state privacy law applies, this Privacy Policy is intended to provide required disclosures regarding categories of personal information, purposes of processing, categories of recipients, rights, and methods to submit requests.

ARQ does not currently sell personal information for monetary consideration or share it for cross-context behavioral advertising. We also do not intentionally use sensitive personal information for purposes that would trigger a right to limit under applicable state law.

If a future business practice creates an additional statutory notice or opt-out obligation, we will update our disclosures and provide the required mechanism.

  1. EEA, United Kingdom, and Switzerland

If you are located in the European Economic Area, United Kingdom, or Switzerland, you may have additional rights under applicable data-protection law. Dream Jars LLC, doing business as ARQ Intelligence, is generally the controller of personal information collected directly through our website, sales, subscriptions, memberships, onboarding, and business operations unless a separate agreement states otherwise.

You may contact us to exercise applicable rights. You may also have the right to complain to your local supervisory authority. We will provide additional transfer or processing information where required for a specific enterprise relationship.

  1. Business Customer Data

Customers may provide ARQ with information relating to their organization, users, vendors, dependencies, contracts, priorities, workflows, or business context. Customers are responsible for determining whether they are permitted to provide that information to ARQ and for giving any notices or obtaining any consents required by law.

Please do not provide payment card numbers, passwords, API keys, authentication secrets, protected health information, highly sensitive personal data, or other regulated information unless ARQ has expressly agreed in writing to receive and protect that category of information.

  1. Children

The Services are intended for business users and are not directed to children. We do not knowingly collect personal information from children under 13, or from children below any higher age threshold that applies in a relevant jurisdiction, through the Services. If you believe a child has provided personal information to us, contact us so we can review and address the issue.

  1. Changes to This Privacy Policy

We may update this Privacy Policy as our Services, technology, providers, legal obligations, or data practices evolve. We will post the updated policy with a revised “Last updated” date and, when required by law, provide additional notice of material changes.

  1. Contact Us

Dream Jars LLC d/b/a ARQ Intelligence

268 Post Road, STE 200, Fairfield, CT 06824, United States

Email: privacy@arqintelligence.ai

Website: https://arqintelligence.ai

For privacy requests, please use the email above and include “Privacy Request” in the subject line so we can route and track the request appropriately.