Aurora Workspace
Privacy Policy
Effective 6 September 2026 · Version 2026-09-06
It applies only to Workspace accounts, organisations, subscriptions, product features, and sites made using Workspace at or through auroraworkspace.net.
1. Scope and who we are
This policy explains how Auroraweb Collective Ltd (“Aurora”, “we”, “us” or “our”) collects and uses personal information when you create or use an Aurora Workspace account, join an organisation, subscribe, contact us, or interact with a site made using Workspace.
Auroraweb Collective Ltd is a private limited company registered in England and Wales under company number 17239668. Our registered office is F04 1st Floor Knightrider House, Knightrider Street, Maidstone, United Kingdom, ME15 6LU. For privacy questions, email team@auroraweb.co.
2. When Aurora is controller or processor
Aurora is the controller of personal information used to operate accounts, authenticate users, manage subscriptions, secure and support the Service, and meet our legal obligations. This means we decide why and how that information is used.
An individual or organisation using Workspace is normally the controller of personal information it places in workspace content, customer websites, messages, files or connected services (“Customer Data”). Where Aurora processes Customer Data only to provide the Service under that customer’s instructions, Aurora acts as processor. The customer is responsible for its own privacy notices, lawful basis and instructions to us.
If your account belongs to an organisation, its owner or administrator controls access to organisation content and may manage, export or delete it. Direct requests about Customer Data to that organisation first; contact Aurora about your account or our own use of your information.
3. Information we collect
Account and profile information
Name, email address, account type, password hash, account timestamps, accepted Terms version and date, and optional business details such as company name, role, company size and industry. We never store your password in readable form.
Organisation and collaboration information
Organisation name and logo, membership and role, invited email addresses, invitation status and timestamps, and the identity of the person sending an invitation.
Subscription and transaction information
Plan, subscription status and dates, billing name and address, Stripe customer and subscription identifiers, and invoice information. Stripe receives and processes complete card or payment credentials; Aurora’s servers do not store complete card details.
Content and service activity
Information you enter, upload, publish or ask the Service to process, including website content and settings, domains, organisation logos, messages, files, instructions, feedback and support correspondence. Please do not submit special-category or highly sensitive information unless it is necessary and you have a lawful basis to do so.
Technical and security information
IP address, request time, requested route, device or browser information, authentication and session identifiers, error and security events, and similar server logs. We also use the browser storage described in section 8.
4. Where information comes from
We receive information directly from you; from an organisation owner or colleague who invites you; automatically from your browser and requests to the Service; and from services you choose to connect. Stripe provides subscription, payment-status and invoice information, but not your full card number.
5. Why we use information and our lawful bases
Provide the Service
Create accounts, authenticate users, provide workspace features, process instructions, publish requested content and provide support. We rely on performance of our contract with you, or our legitimate interests in providing the Service under a contract with your organisation.
Operate organisations and subscriptions
Manage members, invitations, permissions, plans, payments, invoices, renewals and cancellations. We rely on contract and, where the contract is with your organisation, legitimate interests.
Keep Workspace secure and reliable
Prevent abuse and fraud, enforce usage limits, troubleshoot errors, protect users and maintain service performance. We rely on our legitimate interests in operating a safe and dependable service and, where applicable, legal obligations.
Meet legal and financial obligations
Keep appropriate accounting records, respond to lawful requests, establish or defend legal claims, and comply with tax, company and data-protection law. We rely on legal obligation and legitimate interests in protecting our legal rights.
Communicate and improve
Send transactional notices, answer requests, understand failures and improve usability. We rely on contract and our legitimate interests. We use consent where the law requires it, and you may withdraw that consent at any time.
Where we rely on legitimate interests, those interests are described above. We consider whether the use is necessary and balance it against your rights and reasonable expectations. You may object as described in section 10.
7. International transfers
Aurora is based in the United Kingdom. Some service providers may process information in other countries. Where UK transfer restrictions apply, we use a lawful mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, together with a transfer-risk assessment where required. Contact us for information about the safeguard relevant to a particular transfer.
8. Cookies and browser storage
Workspace uses an essential HTTP-only cookie named
aurora_refresh to keep you signed in. It is restricted with
SameSite=Lax, is marked Secure in production, and normally expires after
seven days. The short-lived access token is held in application memory.
Local storage remembers your theme and currently stores website-builder drafts, published-site copies and related event data on your device. A published site may create a pseudonymous visitor identifier and record page views or call-to-action events locally in that visitor’s browser. In the current implementation, those local website records are not sent to Aurora’s server unless a feature clearly tells you that it will upload or synchronise them.
We do not currently use non-essential advertising or third-party analytics cookies in Workspace. You can clear local data through your browser, but doing so may remove locally stored drafts, site data and preferences.
9. How long we keep information
We keep account, organisation and Customer Data while the relevant account or organisation is active and for a limited period afterwards where needed for account closure, recovery, security, disputes or legal compliance. We then delete or anonymise it. Routine backups are removed as they are overwritten. We do not keep identifiable information indefinitely merely because it may be useful.
- the essential refresh cookie normally expires after seven days;
- organisation invitation links expire after seven days;
- financial and transaction records are generally retained for six years or longer where tax, accounting or legal rules require it;
- security and request logs are rotated when no longer needed, unless an incident or legal claim requires longer retention; and
- browser-local information remains until you clear it or the relevant product action removes it.
Retention may be extended by a legal hold or shortened when information is no longer needed. Contact us if you want details for a particular record.
10. Your rights
Depending on the circumstances, UK data-protection law gives you rights to request access to and a copy of your information; correct inaccurate information; request deletion; restrict processing; receive portable data; object to processing based on legitimate interests or direct marketing; and withdraw consent without affecting earlier lawful processing.
Email team@auroraweb.co to exercise a right. Tell us which account or organisation is involved and what you are requesting. We may need to verify your identity and may lawfully retain limited information or refuse a request in some circumstances. We will explain our response. There is currently no self-service account deletion, so please contact us if you want to close and delete an account.
11. AI and automated decisions
If you use an AI-assisted feature, we process the instructions and context you provide to generate the requested result. The interface will identify when information needs to be sent to a third-party AI provider. Do not include personal information that is not necessary for the task.
Aurora does not currently make decisions based solely on automated processing that produce legal or similarly significant effects about you. Customers must not use Workspace output as the sole basis for such a decision about another person.
12. Security
We use proportionate technical and organisational safeguards, including password hashing, short-lived access tokens, HTTP-only session cookies, access controls, restricted upload types and sizes, signed object-storage links, and Stripe-hosted payment fields. No system is completely secure. Keep your credentials confidential and contact us promptly if you suspect unauthorised access.
13. Children
Workspace is intended for people aged 18 or over. We do not knowingly collect account information from children. Contact us if you believe a child has provided account information so we can investigate and take appropriate action.
14. Changes to this policy
We will update this policy when our product or data practices change and show the new effective date and version. If a change is material, we will provide a prominent in-product or email notice before the new use begins where required by law. Earlier versions should be retained for reference.
15. Contact and complaints
Auroraweb Collective LtdF04 1st Floor Knightrider House
Knightrider Street
Maidstone, United Kingdom, ME15 6LU
team@auroraweb.co
+44 1622 958925
Please contact us first if you have a data-protection complaint so we can investigate. You also have the right to complain to the UK Information Commissioner’s Office. Current complaint guidance and contact methods are available at ico.org.uk.