← Back to Auraz

Privacy policy

Effective 30 July 2026

Working draft, pending legal review. This document describes what the software actually does today and is written to be accurate rather than reassuring. It is not legal advice and should be reviewed by a qualified lawyer before Auraz is offered publicly.

This policy sets out what the Auraz service collects, where it is stored, which other services can see it, and what can be requested about it. Auraz is operated from Manama, Bahrain. Questions about anything here go to support@auraz.cloud.

1. Three kinds of people, three sets of rules

Auraz serves three different people and the rules differ for each. The one that applies to you is the one to read.

2. What is collected

Card numbers and national ID numbers are not requested, wanted, or knowingly stored. Card payments are handled entirely by the payment provider; card details never reach the Auraz servers.

3. Cookies and similar storage

You are asked once, and nothing beyond the necessary category is switched on until you choose it. That choice can be changed at any time from Cookie settings in the footer.

4. Email

5. Where the data lives, and what else touches it

Each workspace is stored in a managed PostgreSQL database in a schema of its own. Separation between businesses is enforced by the database itself through a per-tenant role, rather than by a filter in application code that could be forgotten.

A small number of external services are involved. Each sees only what it needs:

Some of these operate outside Bahrain. They are used because they are the right tools for the job; if that matters to your business, ask before committing.

6. How long it is kept

7. What you can ask for

Email support@auraz.cloud; a reply follows within 30 days:

A shopper asking about an order will usually be pointed to the store, since the order belongs to that store. If the store does not respond, come back here.

8. Security

Traffic is encrypted in transit. Administrative access needs a token that is stored only as a hash, is rate limited, and is logged. Stored integration credentials are encrypted. Suspending a business removes its database write access rather than just hiding a button.

No system is perfect. If a breach affecting your data comes to light, you will be told what happened, what was exposed, and what was done about it — without waiting for a more comfortable version of the story.

9. Children

Auraz is for businesses and is not directed at anyone under 18. Their data is not knowingly collected; say so if you believe otherwise.

10. Changes

If this policy changes materially, account holders are emailed and the date above is updated, rather than it being changed quietly.

Terms of service · About Auraz · support@auraz.cloud