GLINT · AURUMFLUX AI, INC.
Effective: July 2, 2026
Agency (you) is typically the data controller for your end-clients' commerce data. AurumFlux acts as a data processor providing Glint on your instructions. End-clients should authorize access via your agency (template).
Stripe (payments) · Shopify (commerce APIs) · Railway (database hosting) · Render (application hosting) · Resend (email, if enabled). List available on request.
Active account data retained while subscribed. Audit logs up to 3 years. Deleted accounts erased within 30 days of verified request.
API tokens encrypted with Fernet (application-level). Tenant isolation by agency ID. Approve-before-execute default.
Access, correction, deletion, portability, and objection where applicable. Email [email protected] or use POST /glint/legal/delete-account with your API key. EU/UK agencies may request a DPA (GDPR Art. 28).
We will notify affected agencies without undue delay and within 72 hours where GDPR applies, describing nature of breach and remediation steps.
Not intended for users under 18.
[email protected] · AurumFlux AI, Inc.