Privacy policy
Effective 30 July 2026
Working draft, pending legal review. This document describes what the software actually does today and is written to be accurate rather than reassuring. It is not legal advice and should be reviewed by a qualified lawyer before Auraz is offered publicly.
This policy sets out what the Auraz service collects, where it is stored, which other services can see it, and what can be requested about it. Auraz is operated from Manama, Bahrain. Questions about anything here go to support@auraz.cloud.
1. Three kinds of people, three sets of rules
Auraz serves three different people and the rules differ for each. The one that applies to you is the one to read.
- Business owners and their staff — you sign in to a workspace. Auraz acts as the processor of the records you put in it; your business is the controller of that data.
- Shoppers — you buy from a store running on Auraz. That store is the controller of your order; Auraz hosts it on the store's behalf.
- Studio clients — you asked for an application to be built. Auraz is the controller of that request and the correspondence around it.
2. What is collected
- Account details. Name, email address, phone number and business name. Passwords are never stored or seen by the service — authentication is handled by the identity provider, which keeps only a hash.
- What you provide at signup. Country, industry, approximate team size, what Auraz will be used for, and how you heard about it. This shapes what gets built next. None of it is required in order to keep using the service.
- Business records you enter. Products, orders, customers, suppliers, stock movements, invoices, ledger entries, employee records, payroll and storefront content. This data is yours. It is not sold, mined for advertising, or used to train models.
- Storefront and marketplace activity. Where a shopper orders from a store, the order, the delivery or pickup address and contact details are processed on that store's behalf. Reviews are tied to a verified purchase.
- Studio requests. What you described, the options selected, the estimate produced, and any brief, mockup or document attached.
- Support messages. Anything you send, kept so the reply has the context behind it.
- Technical records. IP address, browser type and timestamps, for security, rate limiting and diagnosing faults. Administrative sign-ins are written to an audit trail.
Card numbers and national ID numbers are not requested, wanted, or knowingly stored. Card payments are handled entirely by the payment provider; card details never reach the Auraz servers.
3. Cookies and similar storage
You are asked once, and nothing beyond the necessary category is switched on until you choose it. That choice can be changed at any time from Cookie settings in the footer.
- Necessary — sign-in sessions, the security token that blocks request forgery, and the shopping cart. These cannot be switched off without breaking the service, and no marketing cookie is set in this category.
- Functional — language, chosen display currency, theme, and table column preferences. Convenience only.
- Analytics — aggregate counts of which pages and features get used, to decide what to build next. Off unless allowed.
4. Email
- Service email — order confirmations, quotes, trial notices, receipts and security alerts. These are part of the service rather than marketing, so they carry no unsubscribe.
- Follow-up email — where an account is registered but no request is ever sent, up to three messages may follow over about three weeks, sometimes carrying a discount code. Every one has a one-click unsubscribe, and unsubscribing is permanent. Placing an order also stops them.
5. Where the data lives, and what else touches it
Each workspace is stored in a managed PostgreSQL database in a schema of its own. Separation between businesses is enforced by the database itself through a per-tenant role, rather than by a filter in application code that could be forgotten.
A small number of external services are involved. Each sees only what it needs:
- Supabase — database hosting and authentication.
- Hostinger — application hosting and outbound email.
- Google (Gemini) — the AI features. Where an AI answers a question about a business, the relevant records are sent so the answer can be produced. Where free text is typed into a Studio quote, that text is sent to be categorised and priced. It is not used to train the model.
- Tap Payments — card and Benefit payments, where enabled.
Some of these operate outside Bahrain. They are used because they are the right tools for the job; if that matters to your business, ask before committing.
6. How long it is kept
- While the account is open — for as long as Auraz is in use.
- If a workspace is closed — it stops serving immediately but stays recoverable for 30 days, so a mistake can be undone. After that it is unregistered, which is the point it stops existing as far as Auraz is concerned. Erasing the underlying database is a separate, deliberate step carried out by hand rather than automatically, because it cannot be undone; it follows within 30 days of unregistration. Ask at privacy@auraz.cloud if you need confirmation of the date for a particular workspace.
- Discount codes and follow-up records — kept while valid, then only as long as needed to honour or audit them.
- Audit and security logs — kept longer, since their whole purpose is answering questions about the past.
7. What you can ask for
Email support@auraz.cloud; a reply follows within 30 days:
- A copy of your data in a portable format.
- Correction of anything wrong.
- Deletion of the account and its workspace.
- An end to follow-up email — instant, through the link in any of them.
A shopper asking about an order will usually be pointed to the store, since the order belongs to that store. If the store does not respond, come back here.
8. Security
Traffic is encrypted in transit. Administrative access needs a token that is stored only as a hash, is rate limited, and is logged. Stored integration credentials are encrypted. Suspending a business removes its database write access rather than just hiding a button.
No system is perfect. If a breach affecting your data comes to light, you will be told what happened, what was exposed, and what was done about it — without waiting for a more comfortable version of the story.
9. Children
Auraz is for businesses and is not directed at anyone under 18. Their data is not knowingly collected; say so if you believe otherwise.
10. Changes
If this policy changes materially, account holders are emailed and the date above is updated, rather than it being changed quietly.