Aura Customizer
Home/Privacy
Trust and data

Privacy, explained clearly.

How Aura handles merchant, configuration, and uploaded data across the Shopify app experience.

Last updatedApril 23, 2026

Plain-language summary for merchants using Aura Customizer.

01

Introduction

Aura Customizer ("the App") is built by Outsource In Karachi to help Shopify merchants create product configurators. This policy explains how we collect, use, store, and handle data when you use Aura through the Shopify App Store.

02

Information we collect

When you install Aura, we access and store the information required to operate the app:

  • Shop information: store domain, shop name, and Shopify plan details.
  • Session tokens: authentication tokens and relevant staff identifiers for online sessions.
  • Product data: product, collection, and variant IDs assigned to configurators.
  • Configurator data: steps, options, pages, rules, pricing, layouts, rendering profiles, and display settings.
  • App settings: visual customization preferences such as colors, fonts, and spacing.
  • Order data: the minimum order information needed to connect configurations and support production workflows.
  • Uploaded files: images and artwork used in product options and rendering.

We do not collect customer information beyond what is needed to provide the configured-product workflow.

03

How we use information

We use collected information only to:

  • Provide, operate, secure, and maintain Aura Customizer.
  • Authenticate stores and staff sessions inside Shopify Admin.
  • Save and retrieve configurators, designs, rendering recipes, and settings.
  • Process subscriptions through Shopify's Billing API.
  • Respond to support requests, diagnose issues, and improve performance.

We do not sell, rent, or share personal information for third-party marketing.

04

Data storage and processors

App data is stored in a secure PostgreSQL database hosted on Supabase infrastructure in the US East region. Supabase acts as a data processor under its security and privacy commitments.

Data in transit is encrypted with HTTPS/TLS, and data at rest is protected through the storage provider's encryption controls.

05

Sharing information

We disclose information only where it is required to operate Aura or comply with law:

  • Supabase: hosted PostgreSQL database infrastructure only; Aura does not use Supabase Auth, Storage, Realtime, or Edge Functions.
  • Shopify: platform APIs, billing, authentication, and app operation.
  • Legal requirements: a valid law, regulation, or legal process.
06

Your rights

Depending on your jurisdiction, you may request access, correction, deletion, restriction, or objection to processing and may lodge a complaint with a supervisory authority.

Contact us using the details below to make a data request.

07

Data retention

We retain store data while Aura remains installed. Session data is removed when the app is uninstalled. Remaining store data is permanently deleted within 48 hours in response to Shopify's required compliance webhooks.

Applicable customer data is deleted when Shopify sends a valid customer-redaction request.

08

Changes to this policy

We may update this policy to reflect changes in our practices, technology, or legal obligations. The updated date on this page indicates the latest revision.

09

Contact us

For privacy questions or data requests, email support@outsourceinkarachi.com. Aura Customizer is operated by Outsource In Karachi.