Legal
Privacy policy
Last updated: 11 August 2026
Aurum Cloud processes account identity, shop membership, device information, inventory, sales, invoice customer details, and Google Play subscription status to provide the service. Shop owners control the business and customer data entered by their staff. Invoice PDFs are stored privately in Amazon S3, while PostgreSQL remains the authoritative invoice index.
Use and sharing
Data is used to authenticate users, isolate shops, operate inventory and sales, deliver service email and requested invoices, prevent abuse, support billing, and maintain security. It is shared only with infrastructure providers needed to operate the service, including Aiven, Amazon Web Services, Google Play, and Meta when a customer requests WhatsApp invoice delivery. WhatsApp invoices are sent by Aurum POS from a shared Aurum business number on behalf of the originating store, so invoices from multiple Aurum stores may appear in the same customer conversation.
Security and retention
Traffic uses HTTPS and tenant data is isolated in PostgreSQL. Operational logs record request identifiers, routes, response status, duration, service revision, and safe provider error codes. Aurum POS does not include a mobile crash-reporting or diagnostic analytics SDK. Email bodies are redacted after delivery or terminal failure and completed outbox records are removed after 30 days. Confirmed account-deletion requests have a seven-day grace period. Deleted records may remain temporarily in provider-managed backups according to the configured retention policies.
Your choices
You can request account deletion in the app or from the account-deletion page, and contact us for a copy of your data. A sole shop owner must transfer ownership or explicitly request deletion of the owned shop. Customers can reply STOP to the shared Aurum WhatsApp sender to suppress further invoice delivery until they explicitly request delivery again.
Contact
Email privacy@aurumpos.net with privacy questions or data-access requests.