v3.0 · 26 February 2026
aurumrates.com · Privacy Policy · v3.0 · 26 February 2026

Privacy Policy

This policy explains what personal data AURUM collects, why, and your rights under GDPR, UK GDPR, India DPDPA, UAE PDPL, PIPEDA, PDPA, POPIA, and other applicable privacy laws.

1. Who We Are (Data Controller)

AURUM operates aurumrates.com — a real-time commodity price intelligence platform. For GDPR and equivalent purposes, AURUM is the data controller for personal data processed through this website.

Contact: privacy@aurumrates.com
Data Protection Officer / Privacy contact: legal@aurumrates.com

Children's Data

AURUM does not knowingly collect personal data from individuals under the age of 18. If you are under 18, please do not use this website or provide any personal data. If we become aware we have collected data from a minor, we will delete it promptly.

2. Data We Collect

Data TypePurposeLegal BasisRetention
IP addressCountry/city detection to show local gold prices in your currency and unitsLegitimate interest (geo-pricing); passed to geojs.io / ipinfo.io — not stored by AURUMSession only — not persisted
Browser timezoneFallback geo-detection if IP APIs are unavailableLegitimate interestSession only
Google Analytics cookies (_ga, _gid)Aggregate traffic analysis — page views, sessions, device type. IP is anonymised before storage.Consent (where required by GDPR/UK GDPR/DPDPA/PDPA)26 months (_ga) / 24 hours (_gid)
Microsoft Clarity cookies (_clsk, _clck)Heatmaps and aggregate session behaviour analysis. No individual user identification.Consent1 year
aurum_geo (localStorage)Remembers your preferred region/currency so you don't need to re-select on each visitLegitimate interest (functional)30 days
aurum_portfolio (localStorage)Stores your portfolio holdings locally in your browser — never transmitted to our serversConsent / functional necessityUntil you clear browser data
_aurum_ab (sessionStorage)A/B test assignment for pricing display — anonymous, no personal data linkedLegitimate interestSession only
Email address (alerts)Sending you price alerts you have subscribed toConsent / contract performanceUntil you unsubscribe or delete account
Server logsSecurity, error monitoring, DDoS protection (via Netlify)Legitimate interest30 days (Netlify standard)

3. Third-Party Data Processors

We share limited data with the following processors who act on our behalf:

ProcessorPurposeData SharedLocationSafeguards
Netlify, Inc.Website hosting and CDNServer logs, IP addressesUSA / Global CDNNetlify DPA; SCCs for EEA transfers
Google Analytics 4 (Google LLC)Aggregate traffic analyticsAnonymised usage data, device infoUSA (IP anonymised)Google DPA; EU-US Data Privacy Framework
Microsoft Clarity (Microsoft Corp.)Heatmaps & session analysisClick/scroll data (anonymised)USAMicrosoft DPA; SCCs
geojs.ioIP-based country/city detectionIP address (single API call)USAOpen public API; minimal data; not stored
ipinfo.ioIP geo-detection (fallback)IP address (single API call)USAipinfo.io privacy policy; not stored by AURUM
Stripe (planned)Payment processing for Pro subscriptionsPayment data, email, nameUSA / EUStripe DPA; PCI-DSS Level 1

4. International Data Transfers

AURUM is hosted on Netlify's global CDN. Data may be processed in the United States and other countries that may not have data protection laws equivalent to those in your jurisdiction. Where we transfer data from the EEA or UK, we rely on:

For India (DPDPA): geojs.io and ipinfo.io receive your IP address for a single lookup. This constitutes a cross-border transfer under the DPDPA. We minimise this by using timezone-based detection as a fallback that involves no external network call.

5. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

RightWho it applies toHow to exercise
Right of access — see what data we hold about youEU/UK (GDPR), India (DPDPA), UAE (PDPL), Canada (PIPEDA), Singapore (PDPA), Australia (Privacy Act), South Africa (POPIA), all othersEmail privacy@aurumrates.com
Right to rectification — correct inaccurate dataAll jurisdictionsEmail privacy@aurumrates.com
Right to erasure / deletionEU/UK, India, California (CCPA), South Africa, ThailandEmail privacy@aurumrates.com
Right to data portabilityEU/UK, India, CaliforniaEmail privacy@aurumrates.com
Right to object / opt outEU/UK (object to legitimate interest), California (opt out of sale — we do not sell data), India (withdraw consent)Email privacy@aurumrates.com or use cookie settings
Withdraw consent — for analytics cookiesAll jurisdictionsUse the cookie preference centre (footer link) or email us
Lodge a complaint with a regulatorAll jurisdictionsSee Section 6 below

We will respond to rights requests within 30 days (or 1 calendar month for EU/UK GDPR). We may ask you to verify your identity before acting on a request.

6. Supervisory Authorities

If you are unhappy with how we handle your data, you can complain to your national data protection authority:

7. Data Security

We implement appropriate technical and organisational measures to protect your data including:

8. Data Breach Notification

In the event of a personal data breach affecting your data, we will notify the relevant supervisory authority within the timeframes required by applicable law (72 hours under GDPR; 72 hours under India DPDPA rules; promptly under UAE PDPL and Singapore PDPA). We will notify affected individuals where there is a significant risk of harm to your rights and freedoms.

9. Changes to This Policy

We may update this policy periodically. The "last modified" date at the top of this page indicates when it was last revised. Significant changes will be highlighted via a notice on the homepage. Continued use of the site after changes constitutes acceptance of the updated policy.

Policy reference: AURUM-POLICY-001 v3.0 · Effective 26 February 2026 · Contact: privacy@aurumrates.com