Skip to main content
AAurora Workspace
PlatformIntegrationsAboutComing soon
PlatformIntegrationsAboutComing soon
Contents
Scope and companyController and processorInformation collectedSourcesPurposes and lawful basesSharingInternational transfersCookies and local storageRetentionYour rightsAI and decisionsSecurityChildrenChangesContact and complaints

Aurora Workspace

Privacy Policy

Effective 6 September 2026 · Version 2026-09-06

This policy is for Aurora Workspace

It applies only to Workspace accounts, organisations, subscriptions, product features, and sites made using Workspace at or through auroraworkspace.net.

1. Scope and who we are

This policy explains how Auroraweb Collective Ltd (“Aurora”, “we”, “us” or “our”) collects and uses personal information when you create or use an Aurora Workspace account, join an organisation, subscribe, contact us, or interact with a site made using Workspace.

Auroraweb Collective Ltd is a private limited company registered in England and Wales under company number 17239668. Our registered office is F04 1st Floor Knightrider House, Knightrider Street, Maidstone, United Kingdom, ME15 6LU. For privacy questions, email team@auroraweb.co.

2. When Aurora is controller or processor

Aurora is the controller of personal information used to operate accounts, authenticate users, manage subscriptions, secure and support the Service, and meet our legal obligations. This means we decide why and how that information is used.

An individual or organisation using Workspace is normally the controller of personal information it places in workspace content, customer websites, messages, files or connected services (“Customer Data”). Where Aurora processes Customer Data only to provide the Service under that customer’s instructions, Aurora acts as processor. The customer is responsible for its own privacy notices, lawful basis and instructions to us.

If your account belongs to an organisation, its owner or administrator controls access to organisation content and may manage, export or delete it. Direct requests about Customer Data to that organisation first; contact Aurora about your account or our own use of your information.

3. Information we collect

Account and profile information

Name, email address, account type, password hash, account timestamps, accepted Terms version and date, and optional business details such as company name, role, company size and industry. We never store your password in readable form.

Organisation and collaboration information

Organisation name and logo, membership and role, invited email addresses, invitation status and timestamps, and the identity of the person sending an invitation.

Subscription and transaction information

Plan, subscription status and dates, billing name and address, Stripe customer and subscription identifiers, and invoice information. Stripe receives and processes complete card or payment credentials; Aurora’s servers do not store complete card details.

Content and service activity

Information you enter, upload, publish or ask the Service to process, including website content and settings, domains, organisation logos, messages, files, instructions, feedback and support correspondence. Please do not submit special-category or highly sensitive information unless it is necessary and you have a lawful basis to do so.

Technical and security information

IP address, request time, requested route, device or browser information, authentication and session identifiers, error and security events, and similar server logs. We also use the browser storage described in section 8.

4. Where information comes from

We receive information directly from you; from an organisation owner or colleague who invites you; automatically from your browser and requests to the Service; and from services you choose to connect. Stripe provides subscription, payment-status and invoice information, but not your full card number.

5. Why we use information and our lawful bases

Provide the Service

Create accounts, authenticate users, provide workspace features, process instructions, publish requested content and provide support. We rely on performance of our contract with you, or our legitimate interests in providing the Service under a contract with your organisation.

Operate organisations and subscriptions

Manage members, invitations, permissions, plans, payments, invoices, renewals and cancellations. We rely on contract and, where the contract is with your organisation, legitimate interests.

Keep Workspace secure and reliable

Prevent abuse and fraud, enforce usage limits, troubleshoot errors, protect users and maintain service performance. We rely on our legitimate interests in operating a safe and dependable service and, where applicable, legal obligations.

Meet legal and financial obligations

Keep appropriate accounting records, respond to lawful requests, establish or defend legal claims, and comply with tax, company and data-protection law. We rely on legal obligation and legitimate interests in protecting our legal rights.

Communicate and improve

Send transactional notices, answer requests, understand failures and improve usability. We rely on contract and our legitimate interests. We use consent where the law requires it, and you may withdraw that consent at any time.

Where we rely on legitimate interests, those interests are described above. We consider whether the use is necessary and balance it against your rights and reasonable expectations. You may object as described in section 10.

6. Who receives information

We share only what is reasonably necessary with:

  • Stripe, which processes payments and maintains customer, subscription and invoice records;
  • Amazon Web Services, when configured, for secure organisation-logo object storage;
  • our configured email provider, to deliver organisation invitations and essential service messages;
  • hosting, database, security and technical-support providers used to operate Workspace;
  • integrations you deliberately enable, to carry out your instructions;
  • organisation owners, administrators and authorised members according to workspace permissions; and
  • professional advisers, courts, regulators, law enforcement or a buyer in a corporate transaction where disclosure is lawful and necessary.

Providers acting for us are required to protect information and use it only for the contracted purpose. Some recipients, including Stripe, may also act as independent controllers for their own legal and operational purposes. We do not sell personal information.

7. International transfers

Aurora is based in the United Kingdom. Some service providers may process information in other countries. Where UK transfer restrictions apply, we use a lawful mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, together with a transfer-risk assessment where required. Contact us for information about the safeguard relevant to a particular transfer.

8. Cookies and browser storage

Workspace uses an essential HTTP-only cookie named aurora_refresh to keep you signed in. It is restricted with SameSite=Lax, is marked Secure in production, and normally expires after seven days. The short-lived access token is held in application memory.

Local storage remembers your theme and currently stores website-builder drafts, published-site copies and related event data on your device. A published site may create a pseudonymous visitor identifier and record page views or call-to-action events locally in that visitor’s browser. In the current implementation, those local website records are not sent to Aurora’s server unless a feature clearly tells you that it will upload or synchronise them.

We do not currently use non-essential advertising or third-party analytics cookies in Workspace. You can clear local data through your browser, but doing so may remove locally stored drafts, site data and preferences.

9. How long we keep information

We keep account, organisation and Customer Data while the relevant account or organisation is active and for a limited period afterwards where needed for account closure, recovery, security, disputes or legal compliance. We then delete or anonymise it. Routine backups are removed as they are overwritten. We do not keep identifiable information indefinitely merely because it may be useful.

  • the essential refresh cookie normally expires after seven days;
  • organisation invitation links expire after seven days;
  • financial and transaction records are generally retained for six years or longer where tax, accounting or legal rules require it;
  • security and request logs are rotated when no longer needed, unless an incident or legal claim requires longer retention; and
  • browser-local information remains until you clear it or the relevant product action removes it.

Retention may be extended by a legal hold or shortened when information is no longer needed. Contact us if you want details for a particular record.

10. Your rights

Depending on the circumstances, UK data-protection law gives you rights to request access to and a copy of your information; correct inaccurate information; request deletion; restrict processing; receive portable data; object to processing based on legitimate interests or direct marketing; and withdraw consent without affecting earlier lawful processing.

Email team@auroraweb.co to exercise a right. Tell us which account or organisation is involved and what you are requesting. We may need to verify your identity and may lawfully retain limited information or refuse a request in some circumstances. We will explain our response. There is currently no self-service account deletion, so please contact us if you want to close and delete an account.

11. AI and automated decisions

If you use an AI-assisted feature, we process the instructions and context you provide to generate the requested result. The interface will identify when information needs to be sent to a third-party AI provider. Do not include personal information that is not necessary for the task.

Aurora does not currently make decisions based solely on automated processing that produce legal or similarly significant effects about you. Customers must not use Workspace output as the sole basis for such a decision about another person.

12. Security

We use proportionate technical and organisational safeguards, including password hashing, short-lived access tokens, HTTP-only session cookies, access controls, restricted upload types and sizes, signed object-storage links, and Stripe-hosted payment fields. No system is completely secure. Keep your credentials confidential and contact us promptly if you suspect unauthorised access.

13. Children

Workspace is intended for people aged 18 or over. We do not knowingly collect account information from children. Contact us if you believe a child has provided account information so we can investigate and take appropriate action.

14. Changes to this policy

We will update this policy when our product or data practices change and show the new effective date and version. If a change is material, we will provide a prominent in-product or email notice before the new use begins where required by law. Earlier versions should be retained for reference.

15. Contact and complaints

Auroraweb Collective Ltd
F04 1st Floor Knightrider House
Knightrider Street
Maidstone, United Kingdom, ME15 6LU
team@auroraweb.co
+44 1622 958925

Please contact us first if you have a data-protection complaint so we can investigate. You also have the right to complain to the UK Information Commissioner’s Office. Current complaint guidance and contact methods are available at ico.org.uk.

Auroraweb Collective LtdCompany No. 17239668 - Registered in England & Wales
F04 1st Floor Knightrider House, Knightrider Street, Maidstone ME15 6LU, United Kingdom
team@auroraweb.co+44 1622 958925
Terms of ServicePrivacy PolicyCompany information

© 2026 Auroraweb Collective Ltd