Data minimization

Privacy Notice

Draft for final legal and operational review before paid public launch

Entertainment and informational content

Aura’s assessments and personalized materials are for entertainment and general informational purposes only. This does not remove Aura’s privacy, payment, tax, consumer-protection, security, or operational responsibilities.

What remains in the browser

Free assessment and paid intake answers are processed in the browser. Short assessment results may remain in session storage; generated paid-plan inputs may remain in session storage so the same browser session can reopen the plan. Closing the session, clearing browser data, changing devices, or using another browser can remove that local copy. Customers are instructed to print or save completed plans as PDFs.

What Stripe processes

Stripe processes payment details, billing address, and location information needed for payment, fraud prevention, and possible future tax determination under Stripe’s own terms. A declared country code is sent to Stripe metadata to enforce the preview sales-region gate. Aura does not receive full card details. Complete addresses are not placed in Stripe metadata or client-side logs.

What Aura stores server-side

Aura stores only necessary test purchase and fulfillment information in private, context-separated Netlify Blobs: Stripe session/payment references, offer, amount/currency, status, customer email, timestamps, acknowledgment status and timestamp, optional marketing-consent boolean, and fulfillment/delivery/refund status. Sensitive intake answers are not sent to Stripe, stored in Blobs, placed in logs, or included in email links.

Secure return links

Transactional emails are designed to contain a signed, expiring access token. The token identifies the purchase but contains no intake answers. It is a bearer link: forwarding it may allow another person to access the plan until expiry. Refunds revoke access. A new link requires support verification from the purchase email address.

Email

Required purchase, reminder, delivery, refund, and support messages will use Resend only after activation and domain testing. They are separate from optional Mailchimp marketing. Reminder design is limited to 24 hours and 72 hours after purchase, then stops. Abandoned-checkout messaging is disabled.

Retention, choices and support

A final retention/deletion schedule and staff access controls must be approved before launch. Requests should be sent to support@aurainnovations.co. Do not email sensitive health details. No online system can guarantee absolute security.