Aroura
FeaturesHow it worksShowcasePricingFAQVisit store
Sign in
Back to home

Aroura

Privacy Policy

Last updated: July 2026. This policy explains how Aroura (“we”, “us”, “our”), operated by FutureDevSolutions, collects, uses, and protects information when you use the Aroura commerce platform (aroura.online) as a store owner, staff member, internal platform administrator, or as a customer shopping on a store built with Aroura.

Who this applies to and our role

  • Store owners (merchants) and staff members who use the Aroura admin dashboard to run their store.
  • Aroura platform administrators (support admins and super admins) who operate and support the platform.
  • Customers who create accounts, browse, and place orders on individual storefronts hosted on Aroura.
  • Visitors to aroura.online and our public marketing and legal pages.
  • For platform accounts (owners, staff, and administrators), Aroura is the data controller. For the personal data of a store's own customers (name, contact details, addresses, orders, reviews, and similar records entered through a merchant's storefront), the merchant is the data controller and Aroura acts as a data processor providing the hosting and processing infrastructure on the merchant's behalf. Storefront customers who want their data corrected or deleted should generally start with the merchant whose store they used; we assist merchants in fulfilling those requests through the dashboard and, where needed, directly.

Account and store information we collect

  • Platform account data: name, email address, hashed password, assigned role (owner, staff, support admin, or super admin), granular staff permission grants (product management, order handling, customer support, CMS editing, coupon management), last login time, and account status.
  • Store profile data: store name, subdomain, logo and favicon, default currency, timezone, contact email and phone, and storefront theme/branding settings.
  • Branch and location data: branch names, street addresses, delivery radius, fulfillment/shipping windows, opening hours, and map coordinates (latitude/longitude) captured when a merchant pins a branch location using Google Maps.
  • Catalog data merchants enter: products, variants, options, images, categories, pricing, cost and stock levels per branch, SKUs/barcodes, and digital file links.
  • Onboarding data: the information submitted when applying to become a merchant, including business/contact details, requested subscription plan and billing interval, chosen payment method, and (if applicable) the store's initial branch address and coordinates. Onboarding requests are reviewed by our team before a store is provisioned.

Storefront customer information we process on merchants' behalf

  • Customer account data: first and last name, email, phone number, hashed password, marketing consent, and push-notification opt-in status.
  • Shipping and billing addresses, including addresses captured through Google Maps' address search and geocoding (used to accurately fill in street, city, state, and postcode fields and, when the merchant enables map pinning, precise coordinates for delivery).
  • Shopping activity: cart contents, orders and order line items, order status history, coupon codes used, and product reviews and ratings a customer submits.
  • Device identifiers used only to deliver push notifications (Firebase Cloud Messaging tokens) when a customer opts in to storefront notifications.

Payment and billing information

  • Subscription billing for merchants is processed by Stripe. We store the Stripe customer and subscription identifiers, the selected plan, billing interval, and subscription status; we do not store full card numbers — Stripe handles and stores card data directly.
  • During onboarding, a merchant may instead choose to pay via bank transfer (HBL) or a mobile wallet (JazzCash). For these methods we record the selected payment method and any reference details the applicant provides for our team to manually verify the payment; we do not collect or store bank account numbers, card numbers, or wallet PINs/credentials.
  • Order payment fields (payment method label, payment reference, currency, and amounts) are stored against each order for bookkeeping; storefront checkout payment data itself is handled by the payment method the merchant has configured for their store.

Technical, security, and communications data

  • IP address, user agent, and action metadata recorded in our audit log whenever a meaningful account or store action occurs, for security monitoring and abuse prevention.
  • Uploaded media files (product images, videos, documents such as PDFs, Word files, spreadsheets/CSVs, and archives) that merchants add to their catalog, CMS pages, blog posts, or branding.
  • Notification history: in-app notifications and read/unread status for both platform users and storefront customers.
  • Support communications, account-deletion requests, and one-time verification codes (OTPs) sent by email for account registration and password resets.

How we use information

  • Provision and operate merchant stores, storefronts, and the admin dashboard, including multi-branch inventory, orders, coupons, reviews, CMS pages, blog posts, and shipping configuration.
  • Process and reconcile subscription billing with Stripe, including a daily automated job that keeps subscription status, plan, and billing period dates in sync with Stripe.
  • Review and approve merchant onboarding applications, including verification of manually submitted HBL/JazzCash payments.
  • Deliver transactional communications: order confirmations and updates, low-stock and subscription-renewal alerts, OTP verification codes, and password-reset emails, sent through our email provider, and real-time or push notifications through Socket.IO and Firebase Cloud Messaging.
  • Maintain audit logs and apply role- and permission-based access controls to detect and prevent fraud, unauthorized access, and abuse.
  • Provide aggregated analytics and reporting dashboards (order volume, revenue, and catalog performance) to merchants for their own store.
  • Respond to support requests and account/data-deletion requests, and comply with applicable legal obligations.

Real-time features and notifications

  • The Aroura dashboard uses Socket.IO to show merchants and staff live presence (who is online) and to push real-time order, inventory, and notification updates to the dashboard while they are connected. When Redis is configured, this real-time layer is synchronized across multiple servers for reliability at scale.
  • When a platform user or storefront customer is not actively connected, time-sensitive alerts (e.g., a new order or a subscription reminder) are instead delivered as a push notification through Firebase Cloud Messaging to the devices they have registered.
  • We do not offer in-app chat/messaging or a matching/discovery feature on this platform; Socket.IO here is used solely for the dashboard/storefront notification and presence functionality described above.

Third-party service providers

  • Stripe — processes subscription payments for merchants and (via mobile payment sheets) subscription upgrades, downgrades, renewals, and cancellations. Stripe's own privacy policy governs the payment data it processes directly.
  • HBL and JazzCash — used only as alternative, manually verified onboarding payment channels for merchants based in Pakistan who prefer bank transfer or mobile-wallet payment instead of a card via Stripe.
  • Firebase (Firebase Cloud Messaging, via the Firebase Admin SDK and the Firebase client SDK) — used exclusively to deliver push notifications to registered devices. We do not use Firebase for authentication, and we do not store application data in Firestore; all merchant, store, and customer data is stored in our own PostgreSQL database.
  • Google Maps Platform (Maps JavaScript API, Places Autocomplete, and Geocoding) — used to let merchants search for and pin their branch locations, and to let storefront customers search for and pin delivery/billing addresses, auto-filling street, city, state, and postcode from the selected location. Address search is scoped to Pakistan. We do not use Google Maps or any other service for continuous or live location tracking of any user or device.
  • Email delivery (SMTP) — used to send OTP verification codes, password-reset links, and transactional notifications.
  • Redis — used only to coordinate real-time presence and notification delivery across multiple application instances; it does not act as a system of record for personal data.
  • We do not sell personal information to third parties, and we do not share storefront customer data with advertisers.

Cookies and similar technologies

We use strictly necessary session cookies to keep you signed in to the Aroura dashboard or your storefront customer account. We do not currently use third-party advertising or cross-site tracking cookies on the platform.

Data retention

  • Platform account and store data is retained for as long as the account or store remains active.
  • After a verified account-deletion request, eligible personal data is deleted or anonymized from our active systems within a reasonable period.
  • Billing records tied to Stripe subscriptions or manually verified HBL/JazzCash payments, along with audit logs and other records we are legally required to keep, are retained for the minimum period required for accounting, tax, and legal compliance purposes even after an account is deleted.
  • Storefront order and customer data may be retained by a merchant, or anonymized, consistent with the merchant's own obligations to their customers and applicable law.

Your rights

  • Platform users (owners, staff, and administrators) can access and update most of their account information directly from the dashboard, and can request full account and store data deletion at any time via Dashboard → Settings or the Account Deletion Request page.
  • Storefront customers can review and update their profile, addresses, and notification preferences from their store account, and should contact the merchant whose store they shop on for store-specific data requests; merchants are the data controller for their customers' data and can reach us for processor-level assistance.
  • You can opt out of non-essential marketing/promotional push notifications and emails at any time while continuing to receive transactional messages related to your account, orders, or billing.
  • To exercise any privacy right not covered above, contact us using the details below.

Children's privacy

Aroura is intended for use by merchants, staff, and storefront customers who are at least 18 years old or the age of legal majority in their jurisdiction. We do not knowingly collect personal information from children, and we will delete any such information if we become aware it has been collected.

Security

  • Passwords are stored using one-way bcrypt hashing; we never store passwords in plain text.
  • Access to store data is scoped by role and, for staff, by the specific capabilities a merchant grants them; internal support-admin access to a merchant's store is limited to stores explicitly assigned to that support admin.
  • Every significant account and store action is recorded in an audit log capturing the actor, action, affected record, IP address, and user agent.
  • We run automated pre-deployment security scans of our codebase and use encryption in transit (HTTPS) across the platform. No method of transmission or storage is 100% secure, and we continue to invest in improving our safeguards.

Governing law

This policy is governed by the laws of Pakistan, reflecting where Aroura and FutureDevSolutions are based and where the platform's default currency (PKR), default timezone (Asia/Karachi), and supported local payment rails (HBL, JazzCash) are set.

Changes to this policy

We may update this Privacy Policy from time to time as the platform evolves. Material changes will be reflected by updating the "Last updated" date above, and we encourage you to review this page periodically.

Contact

Privacy questions, data requests, or account-deletion questions: [email protected], or via the Contact page. Account deletion can also be submitted directly through the Account Deletion Request page.

Aroura

The commerce OS for store owners who actually ship. Built for independent brands, priced for them too.

0324 4443370[email protected]

157-M Main Boulevard, Johar Town, Lahore 54770, Pakistan

Product

  • Features
  • Showcase
  • Pricing
  • Roadmap

Resources

  • How it works
  • Documentation
  • API reference
  • Status

Company

  • About
  • Customers
  • Careers
  • Press kit
  • Contact

Legal

  • Privacy policy
  • Terms of service
  • Acceptable use
  • Account deletion

© 2026 Aroura. All rights reserved.