Privacy Policy
Last updated: January 2025
1. Introduction
a31 Labs ("we", "our", or "us") operates AuraReserve, a proof of reserve platform for physical assets. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Information We Collect
2.1 Information You Provide
- Account information (email address, name, organization)
- Reserve data you input into the platform (asset information, quantities, locations)
- Communication data when you contact us
- Payment information (processed by third-party payment providers)
2.2 Information Collected Automatically
- Log data (IP address, browser type, pages visited)
- Device information (device type, operating system)
- Usage data (features used, time spent on platform)
- Anonymous analytics data via self-hosted Plausible Analytics (no cookies, no personal data)
3. How We Use Your Information
We use the collected information for:
- Providing and maintaining the AuraReserve service
- Processing your transactions and managing your account
- Sending administrative information and service updates
- Responding to your inquiries and providing support
- Improving our platform and developing new features
- Protecting against fraudulent or unauthorized activity
- Complying with legal obligations
4. Data Security
We implement appropriate technical and organizational security measures to protect your data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Regular security assessments and penetration testing
- Access controls and authentication mechanisms
- Employee training on data protection
For self-hosted deployments, data security is the responsibility of the deploying organization.
5. Data Sharing
We do not sell your personal information. We may share data with:
- Service providers: Third parties that help us operate our service (hosting, payment processing, analytics)
- Legal requirements: When required by law or to protect our rights
- Business transfers: In connection with a merger, acquisition, or sale of assets
6. Your Rights (GDPR)
If you are located in the European Economic Area (EEA), you have certain rights under the GDPR:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Request transfer of your data to another service
- Restriction: Request limitation of data processing
- Objection: Object to processing based on legitimate interests
To exercise these rights, contact us at [email protected].
7. Cookies & Analytics
This website does not use cookies. We use self-hosted Plausible Analytics for anonymous, aggregate website usage statistics. Plausible does not use cookies, does not collect personal data, and is fully compliant with GDPR, CCPA, and PECR. No consent banner is required as no personal data is processed.
8. Data Retention
We retain your data for as long as your account is active or as needed to provide services. After account deletion, we may retain certain data for legal compliance, dispute resolution, or legitimate business purposes for up to 7 years.
9. International Data Transfers
Your data may be processed in countries outside of your residence. We ensure appropriate safeguards are in place for such transfers, including Standard Contractual Clauses approved by the European Commission.
10. Children's Privacy
AuraReserve is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us: