- We process your website visitors' data only on your instructions, and never sell it.
- The tracker sets one first-party cookie and never reads form fields or records keystrokes.
- You choose EU (Frankfurt) or US (Oregon) data residency.
- You can access, export or delete your data at any time — email privacy@aurora.io.
Contents
Who we are#
This policy explains how Aurora Labs (“Aurora”, “we”, “us”) collects and uses personal data. It covers two different roles:
- Aurora as controller — for data about our own customers and website visitors: people who sign up, use the dashboard, contact us or read our website.
- Aurora as processor — for data about your website visitors, collected by the Aurora tracker you install. For that data, you are the controller, and our processing is governed by the Data Processing Agreement.
Information we collect#
Account and usage data
When you create an account or use the dashboard, we collect your name, work email, company, role, password (stored as a salted hash) or single sign-on identifier, billing details (processed by our payment provider; we never store full card numbers) and records of how you use the product, such as features used, settings changed and support conversations.
Visitor data processed for customers
When a customer installs the tracker, we process, on their behalf: page URLs, titles and referrers; active time on page; coarse device and browser information; a first-party visitor ID stored in the aur_vid cookie; company and approximate country resolved from the IP address, which is then truncated; and any traits or events the customer chooses to send with identify or track. The tracker does not read form fields, record keystrokes or capture session replays.
Website data
On aurora.io itself we use Aurora's own tracker to understand which pages are useful, and a small number of strictly necessary cookies. We don't use advertising cookies.
How we use information#
- To provide the service: calculate scores, route leads, sync with connected tools and send alerts.
- To secure the service: authentication, fraud and abuse prevention, and incident investigation.
- To support you and communicate about your account, billing, security and material product changes.
- To improve the product using aggregated and de-identified usage data.
- To meet legal obligations, such as tax, accounting and responding to lawful requests.
We use customer visitor data only to provide the service to that customer. We never use one customer's visitor data to benefit another customer.
Legal bases#
Where the GDPR or UK GDPR applies, we rely on: contract (to provide the service you signed up for); legitimate interests (security, product improvement and communicating with business contacts, balanced against your rights); legal obligation (tax and accounting); and consent where required, such as optional marketing emails, which you can withdraw at any time.
What we don't do#
- We don't sell or rent personal data, and we don't “share” it for cross-context behavioral advertising as defined by the CCPA/CPRA.
- We don't load advertising pixels in the tracker or share data with data brokers.
- We don't train general-purpose machine-learning models on customer data.
Cookies#
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
aur_vid | Aurora tracker (first-party, on customer sites) | Recognizes a returning browser across sessions | 13 months |
aur_session | Dashboard | Keeps you signed in | Session, or 30 days with “keep me signed in” |
aur_prefs | Dashboard | Remembers interface preferences | 12 months |
aur_doc_feedback | Aurora website (documentation) | Remembers your answer to “Was this page helpful?” so it stays selected when you return | 12 months |
Customers can run the tracker in consent-pending or cookieless mode. See Consent and cookies.
Sharing and subprocessors#
We share personal data only with service providers that help us run Aurora — hosting, email delivery, error monitoring, payments and customer support — under written agreements at least as protective as this policy. The current list is published in the DPA. We may also disclose data if required by law, to protect rights and safety, or as part of a merger or acquisition, in which case we'll notify you first.
International transfers#
Customers choose where their workspace data is stored: Frankfurt (EU) or Oregon (US). Where data is transferred outside the EEA, UK or Switzerland — for example, to a support engineer in another region — we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with supplementary safeguards such as encryption.
Retention#
Visitor data is kept according to the customer's plan and settings: 30 days of events on Starter, and configurable retention on Team and Scale. Account data is kept while your account is active and deleted within 30 days of closure, except where we must keep records for legal reasons, such as invoices for up to 10 years. Backups roll off within 35 days. Details are in the retention table.
Your rights#
Depending on where you live, you may have the right to access, correct, delete, export or restrict the use of your personal data, to object to processing based on legitimate interests, and to withdraw consent. California residents have the right to know, delete and correct, and to not be discriminated against for exercising these rights.
To exercise a right about your own Aurora account, email privacy@aurora.io. We respond within 30 days. If you were tracked on a website that uses Aurora, contact that website's owner — they control that data — and we'll help them respond. You can also complain to your local data protection authority.
Security#
We protect data with encryption in transit (TLS 1.2+) and at rest (AES-256), single sign-on and hardware keys for staff, least-privilege access and an annual SOC 2 Type II audit. Read more on our Security page.
Children#
Aurora is a business tool and isn't directed at children under 16. We don't knowingly collect their personal data.
Changes to this policy#
We'll post any changes here and update the date above. For material changes, we'll notify account owners by email at least 30 days before they take effect.
Contact#
Questions or requests: privacy@aurora.io. Our data protection officer can be reached at dpo@aurora.io. Postal address: Aurora Labs, Inc., 548 Market Street, Suite 23017, San Francisco, CA 94104, United States. EU representative: Aurora Labs Europe GmbH, Berlin, Germany.