Legal

Privacy Policy

Effective August 29, 2026 · version 2026-08-29. This Policy explains how Faris Akroush, operating as Made by Auren, handles information through madebyauren.com, customer dashboards, support, and hosted customer websites.

Our roles

Made by Auren controls information used to operate its own sales, accounts, billing, security, and support. For inquiry, appointment, wholesale, subscriber, analytics, purchase, shipping, and membership information collected on a customer’s hosted website, the customer business generally decides the purpose and Made by Auren processes the information to provide the tools. Visitors should also review that business’s linked privacy notice.

Information collected

We may collect account and contact details; business briefs; submitted images and content; clarification answers; reference URLs and written preferences; project, quote, acceptance, review, revision, domain, and support records; billing identifiers and limited card metadata; lead, appointment, wholesale, subscriber, campaign, analytics, order, shipping, refund, and membership records; consent choices; device and browser information; and IP-derived security identifiers. General forms are not intended for passwords, complete card numbers, government identification, financial credentials, or medical information.

Sources

Information comes from customers and website visitors, account and form activity, payment and connected-merchant providers, security and consent tools, domains and carriers, authorized customer team members, and service providers acting on our instructions.

Purposes

We use information to create previews and finished sites; calculate and preserve authoritative quotes; verify identity and consent; process staged and recurring payments; provide accounts, hosting, customer-site tools, support, exports, restoration, and deletion; send transactional or consented marketing messages; prevent abuse and fraud; investigate incidents; maintain audit evidence; improve quality; comply with law; and enforce agreements.

AI processing

Business answers, clarification responses, the single preview image, and materials selected for the finished website may be sent to OpenAI to assist with strategy, copy, design, builds, translations, security triage, and support. Preview requests are configured with limited inputs and store: false. OpenAI states that API data is not used to train its models by default unless the account opts in, but default abuse-monitoring logs may retain API content for up to 30 days unless separate Zero Data Retention controls apply. Made by Auren does not claim Zero Data Retention unless it is separately approved and configured.

Payments

Stripe receives complete payment-card details. Made by Auren receives customer and payment identifiers, status, billing contact, invoice information, and limited card metadata such as brand and last four digits, but does not store complete card numbers or security codes. Customer storefront transactions are direct transactions with the connected customer business as merchant of record.

Providers and subprocessors

Current provider categories include Vercel for application hosting, Supabase for database, authentication, storage, and backups; OpenAI for AI processing; Stripe for platform and connected-merchant payments; Resend for email; Upstash for shared abuse limits; Cloudflare Turnstile for bot protection; and optional Shippo services for carrier rates and labels. Providers may process information in the United States and other locations where they operate, subject to their contracts and safeguards. The current subprocessor schedule is available in the Data Processing Addendum.

Cookies, browser storage, and analytics

Essential cookies support authentication, security, and sessions. A draft brief and its selected image may be stored locally on the visitor’s device so work can resume after a refresh. Optional first-party customer-site analytics stay off until the visitor allows them; when allowed, the service records limited page paths, events, referrer and device categories, and pseudonymous visitor and session identifiers. Made by Auren does not knowingly use cross-context behavioral advertising.

Do Not Track and Global Privacy Control

Browser Do Not Track signals are not consistently defined across the industry. Optional customer-site analytics are controlled by the visible consent choice regardless of DNT. Where applicable law recognizes Global Privacy Control as an opt-out request, Made by Auren treats the signal as an opt-out of sale or sharing; Made by Auren currently states that it does not sell personal information or share it for cross-context behavioral advertising.

Disclosure

We disclose information to providers that perform the purposes above; to the relevant customer business when a visitor uses its website; to advisers and insurers under confidentiality; in a merger, financing, or business transfer with appropriate safeguards; to authorities or others when legally required or reasonably necessary to protect rights and safety; and at the customer’s direction. We do not sell personal information for money.

Retention

Configured defaults are: unpurchased previews and unclaimed preview jobs, 90 days; customer leads, appointments, and wholesale requests, 730 days; optional first-party analytics events, 400 days; low-severity security events, 180 days; and project activity records, 730 days. Subscriber consent and suppression records may be retained while needed to honor marketing choices; campaign and customer relationship records normally follow a 730-day operational period unless an active relationship, dispute, or legal requirement needs longer. Active project, billing, acceptance, review, order, tax, fraud, and dispute records are kept for the service relationship and applicable legal or accounting periods. Cancelled sites remain offline and normally restorable for 180 days; a customer-specific archive may then remain for up to 12 additional months before deletion. Backup copies expire through provider backup cycles. Retention deletion runs only through controlled scheduled jobs and may be paused for legal holds or security incidents.

Security

Controls include HTTPS, restricted storage, role-based access, server-side secrets, owner multi-factor authentication, request limits, bot protection, signed raw-body payment webhooks, authoritative server pricing, file validation, audit records, non-cacheable authenticated pages, backup review, and human publication gates. No service can guarantee absolute security.

Choices and rights

Depending on location and applicable law, a person may request access, correction, deletion, portability, restriction, or an applicable opt-out. Account customers can download an export and request reviewed deletion through the dashboard. Hosted-site visitors should first contact the business identified on that site; Made by Auren will assist the business where required. We verify requests and may retain information required for billing, security, tax, legal claims, or suppression of unwanted marketing.

California notice

California residents may have rights under CalOPPA, the CCPA/CPRA where its thresholds and roles apply, and other California law. Categories collected and disclosed are described above. Made by Auren does not knowingly sell or share personal information for cross-context behavioral advertising. Requests and appeals may be sent to support@madebyauren.com. We will not unlawfully discriminate for exercising an applicable privacy right.

Children

The Made by Auren service is intended for business customers and is not directed to children under 13. Child-directed projects and projects that knowingly collect children’s information are blocked from self-service activation pending specialist review. If you believe a child submitted information, contact support.

Changes

Material changes are posted with a new effective date and communicated directly when required. We do not use materially new practices before providing any notice or choice required by law.

Contact

Privacy requests may be sent to support@madebyauren.com. Written notices may also be sent to 11102 Pocono Way, Bakersfield, CA 93306.