Legal
Privacy policy
- Effective
- September 12, 2026
- Last updated
- September 12, 2026
- Version
- 1.0
In plain language
Aura Integrated Solutions is a United States based digital agency located in Detroit, Michigan, United States. We collect only the information reasonably needed to respond to inquiries, deliver contracted services, operate and secure our website, process business transactions, and meet legal obligations. Aura does not store full payment card numbers or card security codes in its systems. Card payments, when offered, are handled directly by a third-party payment processor. We do not sell personal information.
This summary is provided for convenience. If it conflicts with the detailed sections below, the full policy controls.
1. Who is responsible for your information
Aura Integrated Solutions is a United States based digital agency located in Detroit, Michigan, United States. We are responsible for the information described in this policy.
For any privacy question or request, write to hello@auraintegrated.studio. We will respond from a monitored business address.
2. Scope of this policy
This policy applies to:
- Our public website and the pages that link to this policy
- Contact and proposal inquiries
- Client onboarding and project communications
- Support requests
- Billing and transaction administration
Products and websites we build for clients are operated by those clients. Those products may have their own privacy policies and are not automatically governed by this one.
3. Information we collect
We collect only what is reasonably needed to respond to inquiries, deliver contracted work, secure our systems, administer payments, and meet legal obligations.
| Category | Examples | Source | Purpose | Retention |
|---|---|---|---|---|
| Contact information | Name, business email, optional phone | You | Respond to inquiries, prepare proposals | 24 months after last contact |
| Company information | Company name, website, role | You | Understand the engagement | 24 months after last contact |
| Inquiry and project details | Project type, budget range, timeline, message | You | Scope and quote the work | 24 months, or project term plus 3 years |
| Client communications | Email, meeting notes, support requests | You and our team | Deliver and support the project | Engagement plus 3 years |
| Technical and security data | Server and application logs, error reports | Automatic | Operate, secure and debug the site | 90 days |
| Abuse-prevention identifier | Keyed hash derived from IP address and browser identifier | Automatic on form submission | Rate limiting and spam prevention | 30 days or less |
| Billing and transaction records | Invoice number, amount, payment status, card brand and last four digits | You and our payment processor | Invoicing, reconciliation, accounting | 7 years or longer where required |
We do not collect categories that are not listed here. We do not ask for government identification numbers, health information, or card numbers through this website.
4. How we use information
Depending on your relationship with us, we use information to:
- Respond to inquiries and prepare proposals
- Enter into and perform contracts
- Deliver, test, launch and support projects
- Issue invoices, process payments and reconcile accounts
- Maintain tax and accounting records
- Secure our systems and prevent fraud, spam and abuse
- Diagnose technical problems and improve the website
- Comply with law and establish or defend legal claims
- Send marketing only where that is lawfully permitted
For visitors outside the United States, the legal bases we rely on include your consent, the necessity of performing a contract, our legitimate business interests in operating and securing our services, and compliance with legal obligations. Not every basis applies to every activity.
5. Payment information
Aura does not store full payment card numbers, card security codes, PINs, or magnetic-stripe data in its systems. We do not request card details by email, contact form, text message, social media, or project chat.
When card payment is available, payment information is submitted directly to the third-party payment processor identified on the invoice or checkout page. That provider processes payment information under its own privacy policy and security obligations.
We may retain limited transaction records, such as:
- Payer or billing name, and billing address where required
- Card brand and the last four digits
- Amount, currency, payment date and payment status
- Transaction identifier, invoice number, refund status
- Bank transfer references and related accounting records
This limited transaction information is not the same as storing card credentials. Using a payment processor does not make Aura PCI certified, and we do not claim that certification.
6. Cookies, storage and analytics
This website does not run advertising trackers, third-party analytics, or cross-site profiling tools. It uses only storage that is strictly necessary for the site to work: your browser may hold a short-lived session value that records whether the opening animation has already played during this visit.
If we later add analytics or any non-essential storage, we will identify the provider and purpose here, add consent controls where they are required, and provide a way to change your choice. We will not load non-essential tools before consent where consent is required.
7. Sharing and service providers
We do not sell personal information. We do share limited information with providers who support our operations, including:
- Hosting, cloud infrastructure and database services
- Email delivery and business communication tools
- Project management and customer relationship tools
- Security, logging and abuse prevention services
- Payment processing and accounting
- Professional advisers and approved subcontractors
Providers receive only what they reasonably need for their role and are expected to handle it under contractual or legal obligations. We may also disclose information where required by law, where necessary to protect rights, safety or system security, or in connection with a merger, financing, acquisition or sale of business assets.
8. How long we keep information
- Unsuccessful inquiries and proposals: 24 months after the last meaningful contact
- Abuse-prevention identifiers: no more than 30 days
- Routine technical and security logs: 90 days, unless held for an active incident
- Client project files and ordinary project communications: the active engagement plus 3 years, unless the signed agreement states otherwise
- Contracts, invoices, transaction metadata and essential accounting records: 7 years, or longer where the law requires it
- Rotating backups: aged out within 90 days
- Marketing subscriptions: until you unsubscribe, plus a minimal suppression record
- Records connected to a dispute, investigation or legal hold: until the matter is resolved
Deleting a live record does not instantly remove encrypted backup copies. Backups are not used for ordinary operations and age out under the schedule above.
9. Security
Measures we apply include:
- HTTPS/TLS for all traffic
- Server-side validation of every submitted form
- Least-privilege and role-based access, with database row-level security
- Multi-factor authentication on administrative systems
- Managed secrets rather than credentials in code
- Dependency patching, logging, monitoring and rate limiting
- Encrypted backups and a documented incident-response process
- Vendor review and secure credential transfer with clients
No method of transmission or storage can be guaranteed completely secure. We do not claim that our systems are impenetrable, and we do not publish sensitive architectural detail.
10. International visitors
We are based in the United States. Information we hold may be processed in the United States and in other countries where our approved providers operate. Where applicable law requires safeguards for those transfers, we will use appropriate measures. Your rights depend on your location and the law that applies to you. We do not claim certification under the GDPR, UK GDPR, Canadian privacy law, or any state privacy program.
11. Your privacy choices
Subject to applicable law, you can ask us to:
- Provide access to the information we hold about you
- Correct information that is inaccurate
- Delete information we no longer need
- Restrict or object to certain processing
- Withdraw a consent you previously gave
- Remove you from marketing messages
- Tell you about disclosures we have made
Send requests to hello@auraintegrated.studio. We may need to verify your identity before acting, and we may keep information where a contract, accounting rule, fraud-prevention need, or legal claim requires it.
12. Children
Our website and services are directed to businesses and to people aged 18 or older, and are not intended for children under 13. We do not knowingly collect information from children. We do not perform age verification. If we learn that we have collected a child's information improperly, we will take appropriate steps to delete it.
13. Data incidents
We maintain an incident-response process covering detection, containment, assessment and notification. Where a security incident triggers a legal notification duty, including under the Michigan Identity Theft Protection Act and other applicable breach-notification laws, we will notify affected individuals, regulators, or other required parties within the time frames the law sets. We do not promise a fixed notification window outside those requirements.
14. Changes and contact
If we make a material change, we will post the revised policy here and update the effective date and version at the top of this page. The date changes only when the policy itself changes.
Aura Integrated Solutions
Detroit, Michigan, United States
hello@auraintegrated.studio
Related documents: Terms and Accessibility statement.