
Your privacy and security are important to us
Last Updated: September 17, 2026
This privacy policy (the "Arly Policy") describes how The B.E.L.L. Foundation, Inc. d/b/a Arly ("Arly," "we," "us," or "our") processes information through the Arly Platform, including go.arly.com and the related applications and services our customer organizations use to run their programs (the "Services"). If you are browsing our public websites, signing up for a newsletter, or making a donation, the BellXcel Privacy Policy applies instead.
Here is the most important thing to understand about how Arly works. Schools, camps, YMCAs, nonprofits, and parks & recreation departments use Arly to run their programs. When one of those organizations puts information into Arly about its programs, staff, participants, or families, that organization generally decides what to collect and why. We primarily process that information on the organization's behalf and in accordance with its instructions and our agreement with it. We may also process information as permitted under that agreement to operate, secure, support, maintain, and improve the Services, including through product analytics and the use of aggregated or de-identified information.
What that means for you in practice: if you are a parent, guardian, participant, authorized adult contact, or staff member, your organization is generally the right first stop for questions about program information, corrections, or deletion. We will help the organization respond as described below and in our Data Processing Addendum.
There is one limited exception at the beginning of the self-service sign-up flow. Before an organization account is established, Arly determines how the information collected through that sign-up flow is used and is responsible for that information directly. Once the organization completes sign-up and establishes its Arly account, personal information processed through the Platform on the organization's behalf is governed by the customer relationship described above.
This Arly Policy describes:
1. Information We Process
If you create or activate an account in connection with the Services, we collect information needed to maintain that account. This may include your name, contact information, role, and the organization or program you are associated with. If your organization uses Arly to run programs, we also process information the organization enters or collects about program participants and their families - for example, names, ages or dates of birth, guardian and household contact information, program and session registration, enrollment and attendance records, forms and survey responses, staff and instructor information, and, where the organization chooses to collect it, details such as race and ethnicity, health-related information (such as allergies), and grades or class information. We process this program-related information as described in this Arly Policy, our agreement with the organization, and applicable law, including FERPA where applicable.
Payments Card and bank payment information you enter is captured and tokenized by our payment processors before it reaches Arly's systems, so we do not see or store your raw card or bank account number. We retain transaction-related information, such as the amount, status, and payer identifiers, for billing, reconciliation, fraud prevention, and support. Payment processors may also process information under their own applicable terms and privacy notices.
Messaging and communications Customer organizations can use the Services to send messages to parents, guardians, participants, and authorized adult contacts through the Arly Connect app, email, and text message. When they do, we process the message content (including text, photos, and attachments), recipients' names and contact information (including mobile phone numbers), message delivery and status information, communication preferences and opt-out records, and replies sent to Arly-managed messaging channels, such as STOP or HELP responses to text messages. We process this information to deliver messages on the organization's behalf, honor recipients' preferences and opt-out requests, comply with applicable messaging laws and carrier requirements, and operate, secure, and support the Services.
AI-enabled features Certain Services include AI-enabled features, including Arly Compass. When you use an AI Feature, Arly may process information you submit, relevant Platform data available within your existing permissions, outputs, tool calls, and related technical information to provide the feature; perform user-confirmed actions; maintain security; prevent abuse; meter usage; troubleshoot issues; evaluate performance; and improve Arly's prompts, retrieval, orchestration, tools, and guardrails. Arly does not use Customer Data, Inputs, Outputs, or AI interaction data to train, retrain, or fine-tune any AI or machine-learning model. AI interaction data may contain personal information and may be retained for up to six months as described in the Arly AI Terms.
Self-service sign-up If you begin signing up for Arly through our self-service flow, we collect the information you enter to create an account and establish an organization account. The first part of that flow may happen before you are signed in. When you arrive from one of our ads or marketing campaigns, the link you clicked may carry campaign information in the web address - such as the campaign, source, or ad that brought you to the sign-up flow - and we may record that information with what you have entered so far. We use it to understand the source of the sign-up and, if you start sign-up but do not finish, to follow up about the sign-up process. You can opt out of those messages using the unsubscribe mechanism in the message or by emailing privacy@bellxcel.org.
Campaign attribution information is limited to the self-service sign-up and related follow-up process. Arly does not use Platform account, participant, family, program, or other Customer Data to build advertising profiles or for targeted advertising.
Usage, logging, and device information When you use the Services, we automatically receive and record technical information from your device and browser, such as your IP address, browser type and version, operating system, pages and features used, and the date and time of activity. We use this information for security, troubleshooting, support, operations, and service improvement.
Product analytics We use a third-party product analytics service and our own analysis of operational log data to understand how the Services are used - for example, which features people rely on, where workflows get stuck, and how the product performs. We use this information to operate, support, secure, and improve the Services. We do not sell this information or disclose it to third parties for their own advertising purposes. Our analytics providers process information for us under contract where they act as our subprocessors.
Cookies, analytics, and advertising The Arly Platform uses cookies and similar technologies that are necessary to operate the Services, keep users signed in, remember preferences, maintain security, and support product analytics. We do not use advertising cookies, advertising IDs, or third-party ad tracking in authenticated Platform activity, and we do not use Customer Data from the Platform for advertising. Campaign attribution information collected in connection with self-service sign-up is limited to the sign-up and related follow-up process described above.
Aggregated and de-identified information We may create aggregated or de-identified information from Platform activity and use it for analytics, benchmarking, product development, historical reporting, and other business purposes permitted by our agreements. When we do, we maintain reasonable measures designed to prevent re-identification, do not attempt to re-identify the information, and require recipients to follow substantially similar restrictions where applicable. This information is not intended to identify you or your organization.
2. How We Use and Process Information
We process information in the Arly Platform to provide, operate, secure, support, maintain, and improve the Services; perform our agreement with your organization; follow the organization's configuration and documented instructions; prevent fraud, abuse, and security threats; provide product analytics; and comply with applicable law. We will not process Customer Personal Data for materially different purposes unless instructed or authorized by the customer organization, permitted by our agreements, or permitted or required by law.
We also place some firm limits on ourselves. Other than the sign-up follow-up described in Section 1 and marketing communications about Arly sent to customer administrators as described in the Arly Terms of Service, we do not:
These limits apply to Arly's own use of information. When a customer organization uses the Services to send messages to its participants and families, including announcements, reminders, and fundraising or promotional messages, Arly processes that information on the organization's behalf and at its direction. The organization decides the content, recipients, and purpose of those messages and is responsible for them. Arly does not use messaging content or recipient contact information for its own marketing.
If we ever conclude we can no longer meet a legal obligation under our data processing terms, we’ll tell your organization and work with them on reasonable steps to stop and remediate the issue.
3. Who We Share Information With
We use a limited set of third-party service providers (our "subprocessors") to help deliver the Services. They support functions such as cloud hosting and infrastructure, network security and content delivery, authentication, email, text message, and push notificiation delivery, content and program delivery, product analytics and system monitoring, customer support, and AI infrastructure. When a provider processes Customer Personal Data on our behalf, we require it by contract to protect the information and process it only for the services it provides to us, subject to the terms of our Data Processing Addendum.
We maintain a current list of our subprocessors at. We provide notice of new subprocessors that will materially process Customer Personal Data and give customer organizations an opportunity to object as provided in our Data Processing Addendum.
We put written agreements in place with our subprocessors that require data protection obligations appropriate to the nature of the processing and, where applicable, no less protective in material respects than the commitments we make to customer organizations.
Payment processors We use third-party payment processors to facilitate card and bank payments. Depending on the payment flow, a payment processor may process information under its own terms and privacy notice and may have legal or regulatory obligations independent of Arly. To the extent a payment provider processes Customer Personal Data solely on Arly's behalf, we treat it as a subprocessor under our Data Processing Addendum.
Legal requests We may disclose information when required by law or a legally binding government demand. Where legally permitted, we will notify the affected customer organization before disclosure and disclose only information we reasonably determine is legally required.
Business transfers If Arly is involved in a merger, acquisition, reorganization, financing, or sale of assets, information may be transferred as part of that transaction, subject to protections consistent with this Arly Policy and applicable contractual obligations.
4. Privacy Rights and Requests
If your program information is managed by an organization that uses Arly, that organization generally controls the information and is best placed to respond to your request. If you contact us directly about Customer Personal Data, we may refer the request to the organization and will assist it as required by our Data Processing Addendum and applicable law.
Depending on where you live and the context in which Arly processes your information, you may have rights to access, correct, delete, or obtain a copy of personal information, or other privacy rights provided by applicable law. Where Arly processes information on behalf of a customer organization, we provide commercially reasonable assistance to that organization in responding to requests using the functionality available in the Services.
To reach us about an Arly Platform privacy question, email privacy@bellxcel.org. If you’re asking on your own behalf and we can’t act without your organization’s instruction, we’ll tell you and point you in the right direction.
Communication choices Messages that a customer organization sends through the Services come from that organization. You can choose the channels on which you receive those messages, and opt out of non-essential messages, using the communication preferences in the Services. Your choices apply to each organization separately. An organization may continue to deliver urgent or operational messages, such as closure or safety notices, through the Arly Connect app. Some service, security, and account messages from Arly are necessary to operate the Services and may not be optional while your account is active.
Text messages If you receive text messages through the Services, you can reply STOP at any time to opt out or HELP for help, and you may also opt out through your communication preferences or by contacting privacy@bellxcel.org. Message and data rates may apply. Mobile phone numbers and text messaging opt-in information will not be shared with third parties or affiliates for their marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except service providers that deliver messages on our behalf.
5. Security
We maintain administrative, technical, and organizational safeguards designed to protect information in the Arly Platform against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access. These include encryption of data in transit over public networks and encryption and key-management safeguards for data stored in our cloud-hosted production environment; role-based and least-privilege access controls; multi-factor authentication and single sign-on for administrative access; peer review and vulnerability scanning of code changes; regular vulnerability scanning and annual third-party penetration testing; security monitoring, centralized logging, and alerting; a documented incident response process; and tested business continuity, disaster recovery, and backup procedures.
We periodically obtain independent assessments of our security control environment and may provide our then-current report to eligible customers and prospects under appropriate confidentiality restrictions. Our contractual security commitments are described in the Data Processing Addendum and its security measures exhibit.
If we experience a Security Incident involving Customer Personal Data, we notify the affected customer organization in accordance with the timing and procedures described in our Data Processing Addendum.
No security measures can eliminate all risk. If you believe your account or information may have been compromised, please contact us promptly at privacy@bellxcel.org.
6. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Arly Policy, our agreements, or as required or permitted by law. For Arly Platform accounts, we generally delete or de-identify Customer Personal Data from active systems within 120 days after an account is closed, unless a longer period is required or permitted for legal, security, fraud-prevention, accounting, dispute-resolution, or similar purposes. If an organization uses an AI Feature, AI interaction data may be retained for up to six months as described in the Arly AI Terms. Copies may persist for a period in routine backups and age out according to our standard backup retention practices. If you opt out of receiving messages, we may keep a limited record of your contact information and opt-out choice for as long as needed to continue honoring it, including after other information about you is deleted. We do not use backup copies except as necessary for disaster recovery, business continuity, incident response, or legal obligations. Aggregated or de-identified information that is no longer intended to identify you or your organization may be retained indefinitely. When information is deleted from active systems, we use reasonable technical and organizational measures designed to prevent unauthorized recovery or reconstruction.
7. Student and Children’s Data
A significant amount of information processed through Arly relates to children and youth programs, and we treat that information accordingly. Arly user accounts are currently intended for adults, including customer administrators and staff, parents and guardians, Adult Participants, and Authorized Adult Contacts. Minor Participants do not currently activate their own Arly user accounts. Customer organizations and authorized adults may nevertheless enter information about minors into the Services in connection with program administration.
Messages that customer organizations send through the Services may include photos or other content about minors. The customer organization is responsible for obtaining any media, photo, or other consent required for that content and for sending messages only to authorized adults. Arly does not send customer organization messages to Minor Participants.
When a customer organization is a school or other educational agency or institution subject to FERPA and Customer Personal Data includes education records, Arly acts as a school official with a legitimate educational interest for the purpose of providing the Services, remains under the organization's direct control with respect to the use and maintenance of those records, and uses or discloses them only as permitted by the organization's agreement, FERPA, and applicable law. Where an organization collects or provides information about a child under 13, the organization is responsible for obtaining any parental consent or authorization required by law unless Arly has expressly agreed in writing to perform that function.
Where K-12 student privacy laws apply to Arly, we will not knowingly use student information for targeted advertising, sell student information, or use it to create a student profile for purposes unrelated to the Services, except as permitted by law. We provide commercially reasonable assistance, using available Service functionality, to support a school's obligations relating to access, amendment, disclosure records, and deletion of education records. We will revisit this section before launching functionality designed for minors to submit information directly to Arly.
8. Where Information Is Processed
Arly's primary production environment is currently hosted in Microsoft Azure regions located in the United States. Arly and its service providers may process or access information from other locations as necessary to provide the Services and as described in our Data Processing Addendum and subprocessor information. This section is informational and is not a fixed data-residency commitment unless an applicable Order expressly states otherwise. If a law that applies to the processing requires a specific cross-border transfer mechanism, we will work with the affected customer organization in good faith to implement an appropriate lawful mechanism.
9. Changes to This Policy
If we change this Arly Policy, we’ll post the updated version here and update the “Last Updated” date above. If a change materially affects how we handle personal information, we’ll provide notice as appropriate — by email, in the Services, or by posting a notice — but you should check back periodically. Your organization’s agreement with us governs how changes to our contractual data processing terms take effect.
10. Contact Information
If your organization has a services agreement with us, our Data Processing Addendum, Arly AI Terms, and current subprocessor list describe our contractual commitments and service provider relationships in more detail. The Data Processing Addendum controls to the extent it conflicts with this Arly Policy regarding Customer Personal Data processed on a customer organization's behalf.
If you have any questions about this Arly Policy or our privacy practices, you may contact us using our webform or by email at privacy@bellxcel.org.