Privacy Policy
Effective Date: 2nd September 2025
Website: www.aurayae.com
Business Name: Aurayae
Email: info@aurayae.com
Address: 77 Whitchurch Road, Romford, RM3 9EU, United Kingdom
Aurayae (“we,” “our,” or “us”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit or purchase from our website aurayae.com. We comply with the UK GDPR, EU GDPR, and applicable data protection laws.
1. Information We Collect
We may collect and process the following categories of personal data:
-
Personal Identification Information: Name, email address, phone number, billing and shipping addresses.
-
Transaction Information: Payment details (processed securely through third-party payment providers), order history.
-
Technical Data: IP address, browser type, device identifiers, operating system, referral sources, website navigation data.
-
Marketing & Communications Data: Preferences for receiving marketing communications from us.
We do not knowingly collect data from children under the age of 16.
2. How We Collect Your Data
We collect data in the following ways:
-
Directly from you: When you register, place an order, subscribe to newsletters, or contact us.
-
Automatically: Through cookies, server logs, and analytics tools when you use our website.
-
Third Parties: Such as payment processors, shipping providers, and marketing platforms.
3. How We Use Your Data
We process your personal data only when we have a lawful basis under GDPR, such as contractual necessity, legal obligation, consent, or legitimate interests. Specifically, we may use your data to:
-
Process and fulfill your orders and payments.
-
Deliver your purchased products.
-
Communicate with you regarding orders, inquiries, or customer service requests.
-
Send marketing and promotional materials (only with your consent).
-
Improve our website, services, and customer experience.
-
Maintain legal, financial, and compliance records.
4. Legal Bases for Processing
We rely on the following legal grounds:
-
Contract: Processing necessary to fulfill your purchase.
-
Consent: When you opt in to receive newsletters or marketing.
-
Legal obligation: To comply with tax, accounting, and regulatory requirements.
-
Legitimate interest: To operate our business, prevent fraud, and improve services.
5. Sharing of Data
We will never sell your personal data. We may share your information with:
-
Payment processors (e.g., Stripe, PayPal) for secure transactions.
-
Shipping and logistics partners to deliver your orders.
-
IT and marketing service providers (e.g., email platforms, analytics tools).
-
Legal authorities if required by law or to protect our rights.
All third parties are bound by GDPR-compliant agreements and are only permitted to process data on our instructions.
6. Data Retention
We will retain your personal data only as long as necessary for the purposes set out in this policy:
-
Customer orders and transaction records: Up to 7 years (for tax and legal compliance).
-
Marketing data: Until you withdraw consent.
-
Technical logs: Typically up to 12 months, unless longer is required for security or legal obligations.
7. Data Security
We implement strict technical and organizational measures to protect your personal data, including:
-
Encrypted payment processing via third-party providers.
-
Secure servers, firewalls, and SSL encryption.
-
Limited access to personal data on a need-to-know basis.
-
Regular monitoring and staff training on data protection.
8. International Transfers
If we transfer your data outside the UK or European Economic Area (EEA), we ensure appropriate safeguards (e.g., Standard Contractual Clauses or adequacy decisions) to protect your privacy.
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
-
Right to Access: Request a copy of your data.
-
Right to Rectification: Correct inaccurate or incomplete data.
-
Right to Erasure (“Right to be Forgotten”): Request deletion of your data.
-
Right to Restrict Processing: Limit how we process your data.
-
Right to Data Portability: Obtain and reuse your data across services.
-
Right to Object: Object to processing for marketing or legitimate interests.
-
Right to Withdraw Consent: At any time for processing based on consent.
To exercise your rights, please contact us at info@aurayae.com.
10. Cookies & Tracking
We use cookies and similar technologies to enhance website functionality, analyze traffic, and personalize content. You can manage cookie preferences via your browser settings. For more details, please see our Cookie Policy (separate document).
11. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Effective Date.”
13. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or how we handle your personal data, please contact us at:
Aurayae
77 Whitchurch Road, Romford, RM3 9EU, United Kingdom
Email: info@aurayae.com
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) or your local data protection authority.