GLINT · AURUMFLUX AI, INC.

Privacy Policy

Effective: July 2, 2026

Key commitment: We do not sell your data. We do not use client payment credentials to train AI models. We encrypt stored API tokens at rest.

1. Roles

Agency (you) is typically the data controller for your end-clients' commerce data. AurumFlux acts as a data processor providing Glint on your instructions. End-clients should authorize access via your agency (template).

2. What we collect

2a. What we do NOT store

3. How we use data

4. Sub-processors

Stripe (payments) · Shopify (commerce APIs) · Railway (database hosting) · Render (application hosting) · Resend (email, if enabled). List available on request.

5. Retention

Active account data retained while subscribed. Audit logs up to 3 years. Deleted accounts erased within 30 days of verified request.

6. Security

API tokens encrypted with Fernet (application-level). Tenant isolation by agency ID. Approve-before-execute default.

7. Your rights (GDPR / CCPA)

Access, correction, deletion, portability, and objection where applicable. Email [email protected] or use POST /glint/legal/delete-account with your API key. EU/UK agencies may request a DPA (GDPR Art. 28).

8. Breach notification

We will notify affected agencies without undue delay and within 72 hours where GDPR applies, describing nature of breach and remediation steps.

9. Children

Not intended for users under 18.

10. Contact

[email protected] · AurumFlux AI, Inc.

← Back to Glint