Privacy policy

Aura Price suggests nightly rates. That requires data about your property and your market — it requires nothing about your guests, which is why we do not collect it. Below we set out exactly what enters our database, why, on what legal basis and for how long it stays.

Last updated: 28 July 2026

Who is responsible for your data

The controller is the entity operating the Aura Price service. Full company details and a correspondence address for data protection matters will be published here and on the contact page on the day the service launches publicly — before that the service takes no customers, so we process no data of people outside the team.

What data we process

Only what the service cannot run without. You can verify every item yourself by downloading a full copy of your data from account settings.

  • Account datae-mail address, password as an irreversible hash, account name, role (owner or front desk) and chosen language.
  • Property dataname, type, capacity, geographic coordinates, base price and min–max limits, optionally a portal rating and an iCal calendar address.
  • Completed bookings, if you import themstay date, amount, sales channel and your own reservation reference. No guest names, addresses or contact details.
  • Availability pulled from your iCal calendarthe bare free/busy status, without event titles and without details of the people booking.
  • Price recommendations together with your decisions (accepted, rejected) and a record of reports sent to you — this is what we measure the service's effect on.
  • A security event logwho performed an operation on the account and when. Used solely to investigate abuse and faults.
  • An e-mail address added to the waiting list, together with the market or town the request concerns.
  • A message from the contact formname, e-mail address, subject and text. It reaches our mailbox by e-mail; we do not store it in a database.

What we do NOT collect

This list matters as much as the previous one, because it marks the limits we will not cross without changing this policy:

  • Your guests' datanames, addresses, phone numbers, e-mail addresses.
  • Payment card detailsWe take no payments in the service.
  • Passwords to booking portalsAn iCal link is read-only.
  • Special categories of data (Art9 GDPR) — health, opinions, religion, membership. There is no field for them and we never ask.
  • Data about your behaviour on the siteWe have no analytics, no advertising pixels and no tracking tools.

Why, and on what legal basis

Each purpose has its own basis under Art. 6(1) GDPR. We state it plainly, because without it you cannot judge whether the processing is lawful:

  • Providing the servicecalculating recommendations, running your account, sending reports and alerts. Basis: performance of a contract — Art. 6(1)(b).
  • Billing and accounting recordsBasis: legal obligation — Art. 6(1)(c), in connection with accounting and tax law.
  • Service securityevent logging, rate limiting of login attempts, fault detection. Basis: legitimate interest — Art. 6(1)(f), namely protecting accounts from takeover.
  • The market waiting listBasis: your consent — Art. 6(1)(a), withdrawable with a single link in every message.

How long we keep data

We keep nothing “just in case”:

  • Account and property datafor as long as the account exists. Deleting the account removes them immediately and irreversibly, along with bookings, calendar and recommendations.
  • Accounting documents5 years from the end of the tax year — required by law and not something we can shorten on request.
  • Security event log12 months.
  • Waiting list entryuntil you unsubscribe or until we launch the market it concerned.

Market data — competitor prices and availability — is treated separately. It concerns neither you nor any natural person, so it remains in the database after your account is deleted; without it market history cannot be computed.

Who we entrust data to

We do not sell data and we do not share it for marketing — with anyone, at any price. We use only the technical providers the service needs: database and application hosting, an outgoing mail provider and optionally an application error reporting tool. All operate under data processing agreements and process data on servers within the European Economic Area. We will name them here at public launch, together with the date from which they apply.

We do not transfer data outside the European Economic Area. Should that ever change, we will state here which country and on what basis under Chapter V GDPR — before any transfer takes place.

Your rights

You have every right set out in Chapter III GDPR. Two of them you can exercise yourself, instantly, in account settings:

  • Access and a copythe “Download my data” button returns everything as a JSON file, without waiting for our reply.
  • Erasurethe delete account button removes everything immediately. There is no grace period and no “bin” to recover it from.
  • Rectificationaccount name and property details are editable in settings.
  • Restriction of processing and objection to processing based on our legitimate interestwrite to us and we will respond within one month.
  • Portabilitythe JSON export is machine-readable and you may hand it to another provider.
  • Withdrawal of consent at any time, without affecting the lawfulness of what we did beforehand.

If you believe we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland). We would rather you wrote to us first — we will fix it faster.

Automated price calculation and profiling

Our engine automatically computes a proposed price for your property. This is not an automated decision within the meaning of Art. 22 GDPR: the recommendation concerns a property rather than an assessment of you as a person, it produces no legal effects concerning you and — most importantly — it does not take effect by itself. You approve the price and you move it to your sales channel. With every proposal we show which factors affected it and by how much.

Cookies and browser storage

We use TWO cookies: they remember the language you chose and your light or dark theme. Both are strictly necessary for the site to open in the language and theme you selected, and they serve no other purpose. We run no analytics, embed no advertising pixels and no social plugins — which is why you will not see a consent banner here; a cookie strictly necessary to deliver the service does not require consent. Besides that we store a session token in your browser (gone when you close the tab or log out). None of it leaves your device for tracking purposes.

Country from your IP address

The network your request passes through adds a COUNTRY CODE derived from your IP address. We use it for one thing: to tell you whether we price nights in your country. This is not browser geolocation — we do not ask for permission because we do not reach into your device, and we know nothing finer than the country. We do not store the code, link it to an account, or pass it on. Your IP address never reaches an external geolocation service.

Security

Passwords are stored only as irreversible hashes — we do not know them and cannot reconstruct them. Each account's data is isolated from the rest at application level, and an attempt to reach someone else's resource returns “not found”, so as not to reveal even its existence. Decision links in e-mails are single-use and expire. Should a data breach threaten your rights, we will notify you without undue delay, independently of reporting it to the supervisory authority.

Changes to this policy

The date of the last change appears at the top of the page. For material changes — a new purpose, a new category of data or a new recipient — we will notify you by e-mail before they take effect. We will not quietly widen the scope of data.

Back