Privacy Policy
Last updated: 9 August 2026
Aury ("we", "us") operates the Aury platform at https://tryaury.com. This policy explains what we collect, why, and what we do with it.
Contact: dhruvkumar9115@gmail.com
Who this covers
Aury is a business tool for merchants. This policy covers merchants who create an Aury account. Shoppers who buy from a store built on Aury are covered by that merchant's own privacy policy; we process their data on the merchant's behalf.
What we collect
Account data. Email address and authentication details, so you can sign in and we can reach you about your account.
Store data. Everything you create or import: products, descriptions, images, prices, inventory, collections, pages, orders and customer records belonging to your store.
Connected service credentials. API keys and access tokens you give us for payment processors, analytics, advertising and commerce platforms. These are encrypted at rest and used only to perform the actions you ask for.
Usage data. Standard server logs - IP address, timestamps, pages requested - retained for security and debugging.
Google user data - what we access and why
When you connect Google Analytics, Google asks you to approve specific permissions. We request:
- https://www.googleapis.com/auth/analytics.readonlyto read your Google Analytics traffic and conversion figures and display them in your Aury dashboard.
- openid / userinfo.emailto identify the Google account you connected so the right Analytics property stays linked to your store.
Note for maintainers: this list must match MERCHANT_SCOPES in agentos/analytics_ga.py exactly.
We use Google user data only to:
- List the Google Analytics properties your account can access, so you can choose which one this store reports on.
- Read metrics from the property you chose and show them in your Aury console.
We do not use Google user data for advertising, sell or rent it, transfer it to third parties except as described below, or use it to train generalized artificial intelligence or machine learning models.
How it is stored. We store the refresh token Google issues, encrypted at rest. Analytics figures are fetched on demand and cached only briefly to keep the dashboard responsive.
How to revoke. Disconnect Google Analytics in your Aury console at any time, which deletes the stored token. You may also revoke access directly at myaccount.google.com/permissions.
Limited Use disclosure
Aury's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Shopify data
If you migrate a store from Shopify, you approve a read-only connection. We read your products, content and inventory once in order to rebuild your catalogue on Aury. We never write to, modify, unpublish or delete anything in your Shopify store. The access token is discarded and revoked as soon as the import finishes, whether it succeeded or failed. We do not request access to your Shopify orders or customers.
Who we share data with
We use these processors, each limited to its stated function:
| Provider | Purpose |
|---|---|
| Amazon Web Services | Hosting, databases and file storage (US region) |
| OpenAI | Generating product copy, page content and imagery |
| Dodo Payments | Your Aury subscription billing |
| Stripe / Razorpay | Payments to your store - funds settle directly to your own account; Aury never holds them |
| SendGrid / Amazon SES | Transactional email |
| Composio | Instagram and Meta Ads connections, where you enable them |
| Google Analytics | Traffic analytics, where you connect it |
We do not sell personal data. We disclose data otherwise only where legally compelled, and will tell you unless prohibited.
Retention
Account and store data is kept while your account is active. On deletion we remove it within 30 days, except where law requires us to keep records longer. Connected-service tokens are deleted as soon as you disconnect.
Your rights
Depending on where you live you may request access to, correction of, export of, or deletion of your personal data, and may object to or restrict processing. Write to dhruvkumar9115@gmail.com and we will respond within 30 days.
Security
Data is encrypted in transit and credentials are encrypted at rest. Access to production systems is restricted. No system is perfectly secure; we will notify you and any required regulator of a breach affecting your data without undue delay.
Children
Aury is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
Changes
We will post any change here and update the date above. Material changes will be emailed to account holders before taking effect.