Privacy Policy
Last updated: 28 August 2026
This Privacy Policy explains how Aurora SS Group ("we", "us", "our") collects, uses, shares, and protects your personal data when you use the Ionex platform and website (the "Service"), and the rights you have. Aurora SS Group is the controller of your personal data. For any privacy question or request, contact us at ionikasupport@gmail.com.
1. Scope
This Policy applies to personal data we process through the Service. It does not apply to third-party websites, gift-card brands, or partner applications, which have their own privacy practices.
2. Personal data we collect
- Account data — your email address, and your password stored only as a strong one-way hash (we never see or store your actual password). We also store your interface/email language, account status and role, and timestamps for email verification and your acceptance of the Terms.
- Activity and transaction data — your internal, non-cash Balance and the immutable ledger of credits and debits (operation type, amounts, timestamps); promo and redemption codes associated with your account, including an opaque external user identifier when a code is issued to you by a partner application; and your gift-card orders (product, provider, status, and a masked hint of the code). The gift-card redeem code itself is encrypted at rest.
- Support data — the subject and free-text content of support tickets and messages you send us.
- Technical and security data — your IP address (recorded when you sign in, each time your session is refreshed, and for administrative actions), your device/browser identifier (user-agent), and server log data (such as a request identifier, your account identifier, and timestamps). We also keep short-lived anti-abuse counters.
- Consent and preferences — your cookie-consent choice (stored in your browser's local storage, not in a cookie) and, if you opt out of marketing, the time you did so.
We do not collect your name, postal address, phone number, or date of birth, and we do not currently collect payment-card data because the Service takes no payments (see §6).
3. How we collect it
We collect data directly from you (when you register, use the Service, or contact support), automatically (technical and security data generated as you use the Service), and from partner applications of the Ionika project (an opaque external identifier used to issue you a promo or redemption code).
4. Why we use your data and our legal bases
- To provide the Service — create and secure your account, credit and spend Balance, redeem codes, deliver gift cards, and handle support. Legal basis: performance of a contract.
- To keep the Service secure and prevent fraud and abuse — authentication, rate-limiting, lockouts, captcha, monitoring, and enforcing our Terms. Legal basis: our legitimate interests in protecting the Service and users.
- To comply with law — meeting accounting, record-keeping, and other legal obligations, and responding to lawful requests. Legal basis: legal obligation.
- To communicate with you — service (transactional) emails such as email verification, password reset, security notices, and support replies. Legal basis: contract / legitimate interests.
- Marketing — we may send marketing emails to existing users about the Service; you can opt out at any time. Optional analytics, if we ever introduce them (see §7), would run only with your consent. Legal basis: legitimate interests / your consent.
5. Automated controls
We use automated anti-abuse measures — such as temporary lockouts and rate limits triggered by failed logins or suspicious activity — to protect the Service. These are not decisions that produce legal or similarly significant effects on you, and you can contact us for a human review of any action affecting your account.
6. Payments
The Service currently takes no monetary payment, so we do not collect or store payment-card details. If we introduce paid purchases in the future, card payments will be handled by a third-party payment processor; we will not store your full card number, and we will update this Policy to describe that processing before it begins.
7. Cookies and local storage
We use a single, strictly-necessary cookie: an httpOnly authentication cookie, scoped to the sign-in path, that keeps you securely logged in. Your cookie-consent choice is stored in your browser's local storage, not in a cookie. We do not currently use any analytics, advertising, or tracking cookies. If we introduce optional analytics in the future, we will ask for your consent first and you will be free to decline; strictly-necessary cookies do not require consent.
8. Marketing and how to opt out
Transactional emails (verification, password reset, security notices, support replies) are part of the Service and are always sent. Marketing emails clearly identify us as the sender, include a one-click unsubscribe link and our contact details, and honour opt-outs promptly (in line with the US CAN-SPAM Act and equivalent EU rules); you can opt out at any time and we will then exclude you from future marketing. You can also contact us to update your preferences.
9. Who we share data with
We do not sell or rent your personal data, and we do not "sell" or "share" it as those terms are defined under California law. We share limited data with service providers that process it only on our instructions:
- Email delivery provider — your email address and message content, to send you Service and marketing emails.
- Bot-protection provider (Cloudflare Turnstile) — your IP address and a challenge token, to distinguish humans from bots.
- Gift-card providers — order details only (such as a product identifier); we do not send them your identity, email, or IP address.
- Hosting and infrastructure providers — to run the platform and load-balance traffic, and to store encrypted database backups.
- Operational alerting — support-ticket content may be relayed to our internal operators (for example via a messaging channel) so we can respond.
We may also disclose data where necessary to comply with law, enforce our Terms, or protect the rights, property, safety, or security of Aurora SS Group, our users, or the public. If we are involved in a merger, acquisition, or asset sale, data may be transferred subject to this Policy.
10. International transfers
Some of our providers may process data in countries outside your own, including outside the European Economic Area. Where required, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to protect your data.
11. How long we keep data
We keep your account and transaction data while your account is active and afterwards for as long as needed for fraud prevention, security, dispute resolution, and legal and accounting obligations. In particular:
- application server logs are retained for around 90 days;
- database backups are retained for a limited period (local copies roughly two weeks; off-site encrypted copies per the storage provider's lifecycle, e.g. around 30 days);
- inactive sign-in sessions are removed after around 90 days; email verification and password-reset codes expire within minutes;
- promo codes expire around 90 days after issuance;
- security and administrative audit records are kept for a longer period for accountability and fraud prevention.
When data is no longer needed, we delete or anonymise it.
12. How we protect your data
We use strong technical and organisational measures, including: argon2id password hashing (we never store plaintext passwords); AES-256-GCM encryption of gift-card codes at rest; TLS encryption in transit; httpOnly, path-scoped session cookies with instant session revocation; brute-force lockouts, rate limiting, and captcha; least-privilege administrative access with an audit log; and encrypted backups. No system can be guaranteed 100% secure, but we work continuously to protect your data.
13. Your rights
Depending on where you live, you may have some or all of the following rights.
- EEA / UK (GDPR): access your data; correct it; erase it; restrict or object to processing (including to processing based on our legitimate interests and to direct marketing); data portability; and withdraw consent at any time. You also have the right to lodge a complaint with your local data-protection authority.
- United States (California and other state privacy laws — e.g. Virginia, Colorado, Connecticut, Utah): to know and access the personal information we hold, to delete it, to correct it, to data portability, to opt out of the "sale" or "sharing" of personal information and of targeted advertising and profiling (we do not sell or share your data, serve targeted advertising, or profile you), and not to be discriminated against for exercising your rights. Where available, you may appeal a decision on your request. You may use an authorized agent.
To exercise any right, email us at ionikasupport@gmail.com. We may need to verify your identity, and we will respond within the time limits required by law (for example, one month under the GDPR or 45 days under the CCPA, subject to permitted extensions). Please note we may have to retain certain data even after a deletion request where the law or fraud-prevention and audit needs require it.
Where required, we honour browser opt-out preference signals such as the Global Privacy Control (GPC); because we do not sell or share personal information, such a signal does not change how we process your data.
14. Children
The Service is intended for adults (18 years or older) and is not directed to children. We do not knowingly collect personal data from anyone under 18; if we learn that we have, we will delete it.
15. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date above shows when it last changed, and we will take reasonable steps to notify you of material changes.
16. Contact
Privacy questions and data requests: ionikasupport@gmail.com. If you are in the EEA or UK, you may also contact your local data-protection supervisory authority.