Privacy Policy
This policy explains exactly what AuraVita collects when you visit or buy, why we're allowed to, who else touches the data, how long we keep it, and how to make us stop. It covers auravitapatches.com and our embedded checkout.
Who is responsible for your data
AuraVita is the data controller for the personal information described here. For any privacy question, request or complaint, email hello@auravita.com — a person reads that inbox, and we reply within 30 days as the GDPR requires (usually much sooner).
What we collect
Order data: name, delivery address, email, phone if you give it, the items ordered, and a payment confirmation token from Stripe. Account and delivery data: your login email, an encrypted password, and your recurring-delivery schedule. Support data: the emails you send us and our replies. Marketing data: your email address and consent flag if you join our list. Device and behaviour data: pages viewed, referring link, approximate location derived from your IP address, device and browser type, and the funnel steps you complete on our quiz and checkout. We do not collect health records, and you should never send us diagnostic or medical details — we don't need them.
Why we're allowed to use it
Contract: everything needed to take payment, ship your order and run your recurring delivery. Legal obligation: keeping invoice and tax records. Legitimate interests: fraud checks, fixing site errors, and measuring which pages work — balanced so it never overrides your interests. Consent: marketing email, and non-essential analytics and advertising cookies where consent is required. You can withdraw consent at any time without affecting anything we already did lawfully.
Payments
Card details are collected inside Stripe's embedded checkout, which runs on Stripe's own infrastructure even though it appears on our page. Full card numbers never reach our servers or our database — we receive a token, the card brand, the last four digits and the payment result. Stripe acts as an independent controller for fraud prevention and its own compliance obligations; see stripe.com/privacy.
The tracking vendors we actually load
We don't load a long tail of trackers, and we list every one so you can check us. Currently:
- Meta Pixel and Meta Conversions API — measures which ads and pages lead to purchases. It runs in your browser and, for key events, is also sent server-to-server from us to Meta with the same event ID so the two are de-duplicated. Marketing consent category.
- Google Analytics 4 and Google Ads tags — traffic and conversion measurement and ad attribution. Analytics and marketing categories.
- TikTok Pixel — conversion measurement for TikTok campaigns, loaded only when a TikTok pixel is configured. Marketing category.
- Microsoft Clarity — aggregated heatmaps and session replay used to find broken layouts and dead ends. Analytics category.
- Stripe — payment processing and fraud signals during checkout. Strictly necessary.
- Supabase — our own database and authentication, hosting your account, orders, recurring deliveries and newsletter record. Strictly necessary.
- Our own funnel logging — first-party step events (quiz question reached, checkout started) written to our own database, with no third party involved. Analytics category.
Each vendor, its category and how to change your mind is set out on our Cookie Policy page, which is the canonical list — if the two ever disagree, the Cookie Policy is more current.
Who else we share data with
Only the suppliers that make the store work: Stripe (payments), Supabase (database, auth and email delivery infrastructure), our shipping carriers and fulfilment partner (name, address and parcel contents), our email platform (address and delivery status), and the measurement vendors listed above. Each is bound by a contract that limits them to our instructions. We may also disclose data where the law requires it, or to a buyer if the business is ever sold — in which case you'd be told first. We do not sell your personal information, and we never share it for someone else's independent marketing.
International transfers
Some of those suppliers process data outside the UK and EEA, mainly in the United States. Where they do, transfers rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, plus the supplier's own supplementary safeguards. You can ask us which mechanism applies to a specific vendor.
How long we keep it
Order and invoice records: six years after the order, to satisfy UK and EU tax and consumer-protection law. Account and recurring-delivery data: until you ask us to delete the account, then removed within 30 days apart from the invoice records above. Support emails: two years. Newsletter records: until you unsubscribe, plus a suppression entry so we don't accidentally re-add you. Analytics and advertising identifiers: at most 14 months, or the vendor's shorter default.
Marketing email
We only email marketing to people who ticked the consent box, and every message has a one-click unsubscribe. Transactional email — order confirmation, dispatch, renewal reminders, guarantee correspondence — is part of the contract and continues while you have an active order or delivery, whatever your marketing preference.
Your rights
You can ask us for a copy of your data, correct it, delete it, take it elsewhere in a portable format, restrict how we use it, or object to processing based on legitimate interests or direct marketing. Email hello@auravita.com and we'll verify who you are before acting. There's no fee, and you can complain to your data protection authority — the UK Information Commissioner's Office, or your national authority in the EU — if you're unhappy with our answer.
Children
Our products and this site are for adults. We don't knowingly collect data from anyone under 18; if we learn we have, we delete it.
Security
Data is encrypted in transit, our database enforces row-level access rules so one customer's records can't be read by another, admin access is limited to the people who need it, and payment data stays with Stripe. No system is perfect — if a breach ever affects your rights, we'll notify you and the regulator within the statutory deadline.
Changes and contact
We'll update this page when our vendors or practices change, and email active customers about anything material. Questions, requests or complaints: hello@auravita.com.
Last updated: 2026.