About Aura OS
Aura OS is a software service for sports academies, venues and related organisations. This policy explains how Aura OS processes information when customers use the service and when authorised administrators connect third-party provider accounts.
Information we process
Depending on the features enabled, Aura OS may process account and administrator identifiers; organisation, location and staff records; customer, parent, athlete and contact information supplied by a customer; bookings, enquiries, attendance, communications and other operational records; and device, service, security and audit information.
Google integrations
When an authorised customer connects Google services, Aura OS may process authorised Google Business Profile data and performance metrics, Search Console property and search-performance data, Google Analytics property and reporting data, Google Ads account or planning data, and related identifiers needed to provide the connected feature. Google OAuth credentials are handled server-side.
Aura OS uses Google user data only to provide or improve the customer-facing features for which access was granted. We do not sell Google user data, use it for unrelated advertising or retargeting, or use it to train general-purpose AI models. Use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including applicable Limited Use requirements.
Meta, Facebook, Instagram and WhatsApp
For authorised Meta integrations, Aura OS may process business asset identifiers, Facebook Page and Instagram professional-account data, posts, comments, insights, capability status, advertising-account metadata and related provider identifiers. For WhatsApp Business, Aura OS may process message content, message identifiers, sender and recipient information, timestamps, delivery/read status, media references, templates and conversation-routing records needed to provide the messaging service.
When an authorised organisation connects LinkedIn, Aura OS may process organisation/Page identifiers, authorised administrator identifiers, content and engagement data, analytics, advertising-account metadata and other data permitted by the approved LinkedIn products and scopes used by the customer.
How we use information
- Provide and operate the features selected by the customer.
- Connect, validate and manage provider assets selected by an authorised administrator.
- Route and display authorised customer communications and engagement.
- Provide reporting, analytics and customer-facing decision support.
- Maintain security, tenant isolation, reliability, auditability and troubleshooting.
- Comply with applicable legal obligations and valid requests.
Sharing and service providers
Aura OS may transmit information to connected providers when necessary to perform a customer-authorised action and may use infrastructure, database, communications and security providers needed to operate the service. We do not sell provider platform data or customer message content.
Data roles
For operational data supplied by an academy or other customer, that customer generally determines the business purpose for the data it places in Aura OS. Aura OS processes that information to provide the contracted service. Provider-specific roles may vary according to the provider terms and the feature being used.
Children and participant records
Sports organisations may maintain records relating to children or young participants. Aura OS is a business-facing platform and does not require children to connect external provider accounts. Customers are responsible for having the authority and permissions required for participant data they enter into Aura OS.
Retention
Information is retained for as long as reasonably necessary to provide the enabled service, maintain security and audit records, meet legal obligations, resolve disputes or honour valid deletion requests. Provider-derived data may also be subject to provider-specific storage and refresh restrictions.
Security
Aura OS uses server-side credential storage, access controls, tenant isolation and audit mechanisms. No online service can guarantee absolute security. Security concerns can be reported through our Security page.
Your choices and requests
Customers can disconnect provider integrations from Aura OS. Requests for access, correction or deletion may be sent to support@aura-os.in. Please provide enough information to identify the relevant account or organisation and verify authority. Do not send passwords, access tokens or app secrets.
Deleting data from Aura OS does not automatically delete information held independently by Google, Meta, LinkedIn or another provider; use the provider's own controls for provider-side deletion.
Policy updates
We may update this policy as the service, integrations or requirements change. The current version will be published here with its updated date.
Contact
Email: support@aura-os.in