Who we are and what this policy covers
Aurato operates Atlas, Graph and Hub: a source-linked reference platform for payment methods, markets, schemes, systems, operators, PSPs, standards, regulations, identifiers, banks and cards. This policy explains how Aurato (“Aurato”, “we”, “us”) handles personal data when you visit aurato.io, create or use an account, contact us, or use the Aurato API or MCP service.
Aurato is the controller of the personal data described here unless a different role is stated. Questions and privacy requests can be sent to contact@aurato.io.
Personal data we collect
Depending on how you use Aurato, we may process:
- Account and identity data: name, email address, profile photo, authentication-provider identifier, sign-in method, account ID, plan, role, language or locale, and timezone.
- Authentication data: session and token data needed to keep you signed in. Email-password authentication is handled by Supabase; Aurato does not receive or store your password in readable form.
- Account activity: favorites, API and MCP key names, prefixes, hashes and scopes, token or service usage, and security or account-management events. A newly created API secret is shown once; Aurato stores a cryptographic hash rather than the full secret.
- Contact data: the name, email address, company or topic, selected Aurato record, message and other information you submit through our support, feedback or partnerships forms or by email.
- Usage and technical data: page path, selected tab, external referrer hostname, campaign labels, country, device category, performance measurements, request metadata, and information needed to protect the service and enforce rate limits.
Google sign-in data
When you choose Sign In with Google, Aurato requests only the standard OpenID Connect scopes openid, email and profile. This may provide your Google account identifier, name, email address and profile photo, together with the session data needed to complete sign-in.
We use this Google user data only to authenticate you, create or locate your Aurato account, prevent duplicate accounts, display your name and profile photo, and secure the sign-in process. Aurato does not request access to your Gmail, Google Drive, Contacts, Calendar, payment information or other Google product content.
Where Aurato needs to retrieve a current Google profile photo, the Google provider token is used transiently by our profile-sync endpoint and is not stored by that endpoint. We do not sell Google user data, use it for advertising, or allow people to use it for credit, insurance or other eligibility decisions. We disclose it only to service providers that support authentication and hosting, when you direct us to do so, or when legally required.
Aurato’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How and why we use personal data
We use personal data to provide and secure accounts; authenticate users; deliver Atlas, Graph and Hub features; operate favorites, API and MCP keys and plan access; answer support and partnership requests; understand service usage; diagnose performance and availability; prevent abuse; comply with law; and improve the platform.
Where applicable, our legal bases are performance of our agreement with you, our legitimate interests in operating and improving a secure service, compliance with legal obligations, and consent where the law requires it. You may withdraw consent at any time, without affecting earlier lawful processing.
Analytics, browser storage and cookies
Aurato uses a small first-party analytics system. It does not use analytics cookies, third-party analytics scripts or advertising trackers. For a page view, we may record the page path, tab, external referrer hostname, campaign labels, country and device category. We may associate an account event with a signed-in account.
To estimate daily visitors, an IP address and user-agent string are used transiently to create a pseudonymous key that rotates each day; the source IP address and full user-agent string are not stored with the analytics event. Optional performance monitoring may collect sampled web-vital timings, page paths, device category, release identifier and data-quality status. Aurato does not send these events when your browser signals Do Not Track or Global Privacy Control.
We use browser storage where needed to remember your light or dark theme, preserve selected catalog filters, and maintain an authenticated Supabase session. Authentication providers and infrastructure providers may use their own cookies or storage under their policies when you interact with their services.
International transfers
Aurato and its service providers may process data in countries other than the one where you live. Where required, we use recognised safeguards for international transfers, such as adequacy decisions, standard contractual clauses or another lawful transfer mechanism. You may contact us for more information about the safeguards relevant to your data.
How long we keep data
We keep personal data only for as long as needed for the purposes described in this policy. Account and feature data is generally retained while your account is active and for a limited period afterwards to complete deletion, resolve disputes, prevent fraud and meet legal obligations. Contact messages are kept for as long as needed to handle the request and maintain appropriate business records.
Analytics and performance data is retained only as long as useful for aggregate reporting, security and service improvement, then deleted or de-identified. Backups and security logs may persist for a limited additional period before they are overwritten. Retention periods may be longer where law requires it or a claim makes it necessary.
Security
We use technical and organisational safeguards designed to protect personal data, including encrypted connections, access controls, row-level database security, token hashing, scoped credentials and server-side verification for sensitive account actions. No online service can guarantee absolute security. Please keep your credentials confidential, revoke any exposed API or MCP key, and contact us if you suspect unauthorised access.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, obtain a portable copy of data, withdraw consent, and complain to a data-protection authority. Aurato does not sell personal data or share it for cross-context behavioural advertising.
To make a request, email contact@aurato.io from the address connected to your account. Use the subject Privacy request or Delete my account. We may need to verify your identity and may retain limited information where required by law or needed to protect the service.
You can also revoke Aurato’s Google access from your Google Account connections. Revoking Google access stops future Google sign-in but does not by itself delete your Aurato account; contact us if you want the account deleted as well.
Children
Aurato is a professional reference service and is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact us and we will take appropriate steps.
Changes and contact
We may update this policy when Aurato’s services, providers or legal obligations change. We will publish the revised policy here, change the effective date, and provide additional notice where a change materially affects how we use personal data.
For questions or requests, email contact@aurato.io or use the Aurato contact page.