Privacy Policy
Last updated: August 28, 2026
Introduction
This Privacy Policy describes how OneArbitrage ("we," "us," or "our") collects, uses, and shares information when you visit our public marketing website (including legal pages and the FAQ), create or sign in to a OneArbitrage account, or use our subscription software: the customer dashboard (on the web or in our native iOS and Android apps) where you can connect a supported U.S. brokerage account and run reverse stock split arbitrage ("RSA"). Our principal place of business is Texas, USA.
For how we use cookies and similar technologies on our sites, see our Cookie Policy. This policy may be updated from time to time; we will revise the "Last updated" date when we make material changes.
Information we collect
Depending on how you interact with us, we may collect the following:
- Website and device. When you browse our marketing site, our hosting and infrastructure providers may log technical data such as IP address, user agent, and request metadata as part of normal service operation. Our marketing site stores your display theme preference in browser local storage (for example, to remember light or dark mode). We use Google Analytics 4 on the marketing site to understand aggregate traffic and page usage; Google may process device and usage data under its policies. When we run Meta (Facebook/Instagram) advertising, we may use the Meta Pixel on the marketing site to measure ad performance and actions such as starting sign-up; Meta may process device and usage data under its policies. Where required by law, we will obtain consent before non-essential measurement or advertising cookies are used.
- Authentication (Amazon Cognito). When you sign in or sign up, we use Amazon Cognito Hosted UI with the Authorization Code flow with PKCE. For that flow, short-lived values (such as the PKCE verifier and OAuth state) may be held in session storage on our marketing origin until the sign-in completes. Cognito processes your authentication according to your login method and issues tokens; default requested scopes include openid and email, so we may receive identifiers and email from your identity provider as reflected in those tokens.
- Account provisioning. After authentication, our services verify your Cognito ID token and create or update your customer record. We store at least your Cognito subject identifier (sub) and email address, allocate a customer referral code, and may record referral attribution when you arrive with an inviter code (for example from a ?ref= link stored in session storage until first provisioning). Attribution for referrals is applied only when your account is first created, consistent with our product rules.
- Subscriptions (Stripe). We use Stripe for checkout, recurring subscription billing, payment method updates, and related notices. Stripe collects the payment details you provide to Stripe; we receive identifiers, subscription and invoice metadata, and status information needed to show billing in the customer dashboard and keep your plan in sync with what Stripe records.
- Session with the customer application. On the web customer dashboard, we may set an HttpOnly session cookie on the customer application's domain and use credentialed requests (for example, to confirm session status). The marketing site may send a background request to the customer application to detect whether you are already signed in. In our native iOS and Android apps, we keep sign-in tokens in the device's secure storage (for example, the platform keychain or encrypted keystore) and send authenticated API requests to the same customer-dashboard backend as the web app.
- Native mobile apps (iOS and Android). Our OneArbitrage apps (bundle identifier com.onearbitrage.customer) connect to the same services described in this policy. Depending on how you use the app, we and our providers may process:
- Device and app data. Technical data such as device type, operating system version, app version, and network metadata needed to operate the app and diagnose issues.
- Authentication (system browser). Sign-in and sign-up open Amazon Cognito Hosted UI in your device's system browser (the same OAuth with PKCE flow as the web). Short-lived OAuth values are handled in that browser context; long-lived tokens are stored in secure storage on the device after sign-in completes.
- Billing and broker flows (system browser). Stripe subscription checkout, payment-method updates, and supported brokerage authorization or token refresh open in the system browser. Payment card details are entered on Stripe's pages; we receive subscription status and identifiers from Stripe as on the web dashboard.
- Referral deep links. If you open the app from an invite link (for example onearbitrage://join?ref=), we may store the referral code on the device until your customer account is first provisioned, consistent with our web referral rules.
- Onboarding and product analytics (Meta). On production app builds, we may use the Meta (Facebook) App Events SDK to measure onboarding steps and subscription actions (such as starting checkout or a trial) so we can understand funnel performance and ad effectiveness. We also send matching server events to Meta's Conversions API with a shared event identifier so Meta can deduplicate client and server events. Meta may process device and usage data under its policies. On iOS, we may request permission through Apple's App Tracking Transparency prompt before enabling certain advertising measurement; you can decline and still use the app. Where required by law, we will obtain consent before non-essential measurement.
- Legal pages opened from the app. When the app opens this marketing site for Privacy, Terms, or similar pages, we may receive a ?from=app query parameter and hold a short-lived flag in browser session storage so in-page navigation stays in an app-appropriate layout. This does not change what account data we collect beyond normal site logging.
- Customer dashboard, brokerage link, and RSA. After you sign in, we process profile and account identifiers, subscription state (including from Stripe), referral fields where applicable, brokerage authorization and connection information your broker shares with us for the link you enable (we do not ask you to send brokerage passwords by email), and operational data needed to run and display the RSA workflow on accounts you connect, consistent with our agreements and in-product notices.
- Communications you send us. If you contact us (for example by email), we receive the content of your message and associated contact details.
How we use information
We use information for purposes such as:
- Providing, operating, and improving OneArbitrage, including subscription access on the web and in our iOS and Android apps, Stripe-backed billing, brokerage-linked RSA automation, and referrals;
- Measuring onboarding and marketing performance (for example through Google Analytics on the marketing site and Meta measurement on the web and in app builds, as described above);
- Authenticating you and maintaining secure sessions;
- Processing referrals and understanding how users discover OneArbitrage;
- Detecting, preventing, and responding to fraud, abuse, or security issues;
- Communicating with you about the service and responding to requests;
- Complying with legal obligations and enforcing our terms.
How we share information
We may share information with:
- Service providers who assist us; for example, identity services (such as Amazon Cognito), payment processing and subscription billing (Stripe), analytics and advertising measurement (such as Google Analytics and Meta), cloud hosting, databases, and communications, under contractual terms that limit use to providing services to us.
- Legal and safety recipients when we believe disclosure is required by law, legal process, or government request, or to protect rights, safety, and security.
- Business transfers in connection with a merger, acquisition, or sale of assets, subject to applicable law.
We do not sell your personal information for monetary consideration. Where required by law, we will provide additional notices (for example, regarding targeted advertising or "sharing" as defined under U.S. state laws).
Cookies and similar technologies
We use cookies and similar technologies on our websites for essential functions (such as maintaining your session on the web customer dashboard where applicable) and preferences (such as theme). Our native mobile apps use secure device storage rather than browser cookies for sign-in. Details for the marketing site and web dashboard are described in our Cookie Policy.
Retention
We retain information for as long as necessary to provide the services, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type and context; authentication and account records are typically kept for the life of your account and a limited period afterward for backups and legal requirements.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to opt out of certain processing (such as "sale" or "sharing" under U.S. state laws, where those terms apply). If you are in the European Economic Area, the United Kingdom, or Switzerland, you may have additional rights under applicable data protection law, including the right to lodge a complaint with a supervisory authority.
To exercise privacy rights, contact us at privacy@onearbitrage.com. We may need to verify your request before responding.
To delete your OneArbitrage account and associated product data, sign in to the customer dashboard, open Settings, and use Delete account (type DELETE MY ACCOUNT to confirm). You can also email support@onearbitrage.com for other privacy requests or if you need help, as described on our Contact page.
Children
OneArbitrage is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us and we will take appropriate steps.
International users
We may process and store information in the United States and other countries where we or our service providers operate. Those countries may have different data protection rules than your country. Where required, we use appropriate safeguards for cross-border transfers.
Contact
For questions about this Privacy Policy or our privacy practices, contact OneArbitrage at privacy@onearbitrage.com.
This policy describes our current practices; it is not legal advice. Have your counsel review before relying on it for regulatory or contractual purposes.