Legal
Privacy Policy
AuraScope Limited (AuraScope, we, us or our) is the New Zealand privacy agency responsible for the personal information described in this Policy.
We handle personal information under the New Zealand Privacy Act 2020 and other privacy laws that apply to a particular service or individual.
Effective
1. Scope
This Policy applies to the AuraScope Travel website at aurascope.travel, the linked AuraScope platform, AI Bookability Audits, related paid services, and our business, sales and support communications. It applies to website visitors, customer personnel, account users and business contacts.
The Service is business-to-business. It is not intended to collect traveller personal information. Customers must not provide traveller or sensitive personal information unless a signed agreement expressly permits it and the affected individuals receive any required privacy notice.
Providing personal information is generally voluntary, but we may be unable to create an account, provide an audit, respond to a request or supply a paid service without the information reasonably needed for that purpose.
2. Information you provide
Depending on how you deal with us, we may collect information directly from you.
- Your name, work email address, organisation, role and account profile.
- Authentication, identity-provider and access information needed to sign you in and administer authorised users.
- Websites, brands, competitors, markets, prompts, strategic notes and other information submitted for an audit or analysis.
- Support, sales, feedback, complaint and contractual communications.
- Billing, order and transaction records where a paid service is arranged. AuraScope Travel does not collect payment card details through the public website.
- Your analytics choice, stored locally in your browser where the Google Analytics consent control is active.
3. Information generated through use
We may create or receive information when you or your organisation uses the Service.
- Audit runs, prompts, AI outputs, citations, scores, recommendations, implementation status and reports.
- Feature interactions, usage records and account-administration activity.
- Security, diagnostic and access records, which may include IP address, browser or device information, timestamps and requested URLs.
- Website pageview information described in section 7.
4. Information from other sources
We may collect information from publicly available websites, metadata, search results, AI-platform responses and other public sources needed to provide visibility monitoring, source analysis and recommendations.
We may also receive business contact or account information from an authorised employer, agency administrator, customer, identity provider or service provider, and delivery information from infrastructure, AI and content-retrieval providers.
When we collect personal information from someone other than the individual, Information Privacy Principle 3A may require us to take reasonable steps to notify that individual as soon as reasonably practicable. We will do so where required unless the individual was already made aware or another lawful exception applies, including where the information is publicly available or is not used in an identifiable form.
5. Why we use personal information
We use personal information where reasonably necessary for the purpose for which it was collected or another purpose authorised by you or by law.
- Authenticate users, administer accounts, organisations and authorised access.
- Provide audits, monitoring, source analysis, reports, recommendations and related services.
- Retrieve and analyse authorised public web content and AI responses.
- Communicate about the Service, provide support and respond to enquiries or complaints.
- Secure, diagnose, maintain and improve the Service.
- Measure public-site use and product adoption.
- Arrange paid services, issue invoices, keep business records and enforce legal rights.
- Comply with law and respond to lawful requests.
6. AI, retrieval and infrastructure providers
We use service providers to operate the Service. The information sent to a provider depends on the feature, customer configuration and provider route. We do not assume that account identity is sent with every prompt or retrieval request.
- Supabase for authentication and database services.
- Railway for application hosting.
- OpenAI, Google Gemini and Perplexity for AI processing and monitored responses.
- OpenRouter for routing some AI requests to model providers.
- Firecrawl, Crawl4AI and DataForSEO for public web and search retrieval.
- Resend for service email, and supported identity providers for authentication.
- AuraScope Analytics and Google Analytics for the website measurement described in section 7.
7. Website analytics and your choices
AuraScope Analytics is AuraScope's first-party pageview measurement service. Its public-site tracker sends the page URL, referring URL, event time, navigation type and viewport dimensions, together with technical event and site identifiers. Network requests may also expose an IP address and browser information to the service. The tracker does not read form fields, and the public website has no form endpoint.
Google Analytics is separate and loads only after you choose Accept analytics on a production AuraScope Travel site. It may use cookies and collect page and interaction information. Advertising storage, advertising personalisation, advertising user data and Google Signals remain disabled.
Your Google Analytics choice is stored in your browser for up to 180 days. You can choose Essential only or reopen Privacy settings in the footer at any time. Withdrawing consent stops future Google Analytics measurement from that browser and removes accessible Google Analytics cookies for the AuraScope Travel domain. It does not remove information already received by Google or AuraScope.
8. When we disclose personal information
We may disclose personal information to the providers described above, authorised Customer administrators and personnel, professional advisers, insurers, auditors and prospective transaction counterparties who need it for a permitted purpose and are expected to protect it.
We may also disclose information where you authorise us, where law requires or permits it, to protect rights or safety, or as part of a genuine financing, reorganisation, merger or sale subject to appropriate confidentiality protections.
We do not sell personal information.
9. Overseas processing
Some providers may hold or process information outside New Zealand. Locations can change as providers operate international infrastructure.
Where Information Privacy Principle 12 applies to an overseas disclosure, we will take reasonable steps to use a recipient that is subject to the New Zealand Privacy Act 2020, comparable privacy safeguards or contractual protections, or otherwise use a lawful basis for the disclosure.
10. Retention and deletion
We retain personal information only for as long as reasonably required to provide and secure the Service, meet a signed customer agreement, resolve disputes, keep accounting and business records, enforce rights and comply with law.
Retention periods vary by information type and service context. If you ask us to delete information, we will assess the request under applicable law and contractual obligations. Deletion may not remove information that we must retain, information that has been de-identified, or copies that remain temporarily in protected backups until their normal replacement cycle.
11. Security
We use reasonable technical and organisational safeguards designed to protect personal information against loss, unauthorised access, use, modification or disclosure. Access controls, authentication, service isolation, monitoring and provider safeguards are applied according to the relevant component and risk.
No internet transmission or storage system is completely secure. Tell us promptly at hello@aurascope.co if you believe personal information or an account may have been compromised.
12. Access and correction
You may ask for access to personal information we hold about you and ask us to correct it. We may need to verify your identity and authority before responding. New Zealand law permits us to withhold information in limited circumstances; if that applies, we will explain the basis where the law allows.
You may also ask us to delete personal information or restrict a particular use. Those requests are not absolute and will be assessed under applicable law, the reason it was collected, any signed agreement and our lawful retention obligations.
13. Complaints
Send a privacy complaint to hello@aurascope.co with enough detail for us to understand and investigate it. We will acknowledge and assess the complaint within a reasonable period.
If you are not satisfied with our response, you may complain to the New Zealand Office of the Privacy Commissioner through privacy.org.nz.
14. Changes to this Policy
We may update this Policy when our services, providers or legal obligations change. We will publish the current version and effective date on this page. If a change materially affects how we use personal information already collected, we will take further reasonable steps to notify affected people where required.
15. Contact
AuraScope Limited is the agency collecting and holding the personal information described in this Policy. Contact AuraScope Limited at hello@aurascope.co, Auckland, New Zealand, for privacy requests, complaints or questions.
For legal terms governing the Service, read the Terms of Service.