AurenWellLog in

Privacy Policy

Last updated: May 8, 2026

1. Overview

This Privacy Policy explains how Wild West Labs LLC(“AurenWell,” “we,” “us”) collects, uses, and shares information when you use the AurenWell application (the “Service”). AurenWell is an invoicing and business management tool for independent contractors. We act as a data controller for information about our account holders and as a data processor for the information our account holders upload about their own clients and business records.

If you have questions, email us at support@aurenwell.com.

2. Information we collect

2.1 Information you give us

  • Account information: name, email address, password (stored as a cryptographic hash, never in plaintext), and business profile details such as business name, address, phone number, logo, tax ID, and default currency.
  • Business records you upload: client records, invoices, estimates, contracts, signatures, time entries, expenses, receipts, attachments, and signed PDFs. This is Your Content under our Terms.
  • Support messages: anything you send us when you contact support.

2.2 Information we collect automatically

  • Usage and device data: pages visited, features used, device type, browser, operating system, approximate geographic location (derived from IP address), and timestamps.
  • Log data: IP address, referring URL, and error traces, used for security, debugging, and abuse prevention.
  • Cookies and similar technologies: we use first-party cookies for authentication and session management, a limited set of analytics cookies through PostHog, and Meta Pixel cookies or similar technologies to measure page views, purchases, and advertising performance.

2.3 Information from third parties

  • Stripe: when you connect Stripe to accept payments, Stripe shares account status, payout details, and transaction metadata (but not full card numbers) with us so we can display payment history and compute platform fees.
  • Authentication providers: if you sign in using an identity provider we support, we receive the basic profile information the provider shares with us based on your consent.

2.4 Information about your clients

Your clients are your contacts, not ours. When you create a client record, send an invoice, or share an estimate or contract, we process that information solely on your behalf as a data processor. We do not email your clients for our own marketing purposes.

3. How we use information

We use the information described above to:

  • Provide and operate the Service, including invoicing, payments, and document generation;
  • Process the one-time purchase and any platform fees;
  • Send transactional messages (receipts, password resets, invoice notifications);
  • Respond to support requests;
  • Detect, investigate, and prevent fraud, abuse, and security incidents;
  • Improve the Service and develop new features, including aggregate or de-identified analytics;
  • Measure marketing and advertising performance, including whether ads lead to purchases;
  • Comply with legal obligations and enforce our agreements.

We do not sell your personal information. We do not use Your Content to train third-party machine-learning models.

4. Legal bases (EEA / UK users)

If you are in the European Economic Area or the United Kingdom, the legal bases we rely on to process your personal data are:

  • Contract: to provide the Service you purchased.
  • Legitimate interests: to secure the Service, prevent fraud, improve the product, and communicate with you about your account.
  • Legal obligation: to meet tax, accounting, and anti-fraud requirements.
  • Consent: where we ask for it specifically (for example, optional analytics cookies).

5. How we share information

We share information only in these circumstances:

5.1 Subprocessors

We rely on a small number of vetted subprocessors to run the Service. Each is bound by contractual confidentiality and security obligations.

  • Supabase Inc. — database, authentication, and file storage (United States).
  • Vercel Inc. — application hosting and edge delivery (United States, global edge).
  • Stripe, Inc. — payment processing and Stripe Connect (United States, global).
  • Resend Inc. — transactional email delivery (United States).
  • PostHog, Inc. — product analytics (United States, EU data residency option).
  • Meta Platforms, Inc. — advertising measurement, including Meta Pixel and Conversions API events (United States, global).

If we add or change subprocessors, we will update this page.

5.2 At your direction

When you send an invoice, estimate, or contract to a client, we share the content with the recipient on your behalf. When you connect Stripe, we share information with Stripe needed to process payments.

5.3 Legal and safety

We may share information when we believe in good faith that disclosure is required to comply with a legal obligation, valid legal process, or lawful government request; to enforce our Terms; to protect the rights, property, or safety of AurenWell, our users, or the public; or to detect, prevent, or address fraud or security issues.

5.4 Business transfers

If Wild West Labs LLC is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction. We will notify affected users and give them a meaningful opportunity to object or delete their account before any change in the controller of their data takes effect.

6. International data transfers

We operate from the United States. If you access the Service from outside the U.S., your information will be transferred to, stored in, and processed in the U.S. Where personal data of EEA, UK, or Swiss residents is transferred, we rely on Standard Contractual Clauses and equivalent safeguards required by applicable law with our subprocessors.

7. How long we keep data

We retain information only as long as needed for the purposes described in this policy:

  • Account and business records — for as long as your account is active.
  • Account deletion — when you delete your account, your active records are removed from the Service. Financial records (payment history, invoices, tax-relevant data) may be retained for up to 180 days in a limited-access archive to meet legal, accounting, and fraud-prevention obligations, after which they are deleted or irreversibly anonymized.
  • Backups — routine backups may contain data for up to 30 days after deletion before being overwritten.
  • Logs and analytics — typically retained for 12 to 24 months.

8. Security

We take security seriously. Measures include encryption in transit (TLS), encryption at rest for database and storage, row-level access controls so one account cannot see another’s data, password hashing, webhook signature verification, and operational practices such as least-privilege access to production systems. No system is perfectly secure; if you believe your account has been compromised, contact us immediately at support@aurenwell.com.

9. Your rights (EEA / UK)

If you are in the EEA or UK, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data, subject to the retention periods above;
  • Restrict or object to certain processing;
  • Port your data to another service in a structured, machine-readable format;
  • Withdraw consent at any time where processing is based on consent.

You can exercise these rights by emailing support@aurenwell.com. You also have the right to lodge a complaint with your local supervisory authority.

10. Your rights (California residents)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights:

  • Right to know what personal information we collect, use, disclose, and retain, and the categories of sources and recipients;
  • Right to delete personal information we collected from you, subject to legal exceptions;
  • Right to correct inaccurate personal information;
  • Right to opt outof the “sale” or “sharing” of personal information. We do not sell personal information. Our use of Meta advertising measurement may be considered “sharing” under some privacy laws;
  • Right to limit use of sensitive personal information — we do not use sensitive personal information for purposes that would require this opt-out;
  • Right to non-discrimination for exercising your rights.

To exercise any of these rights, email support@aurenwell.com. We may ask you to verify your identity before acting. You may designate an authorized agent to submit a request on your behalf; proof of authorization will be required.

11. Children

AurenWell is not directed to children under 13 (or under 16 in the EEA / UK). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

12. Cookies and tracking

We use cookies and similar technologies for authentication (strictly necessary), session management, and limited product analytics via PostHog. We also use Meta Pixel and related server-side conversion events to measure advertising performance, including page views and purchases. Most browsers allow you to block or delete cookies; note that blocking strictly necessary cookies will break login and core features.

We currently do not respond to “Do Not Track” browser signals in a way that differs from this policy. We honor the Global Privacy Control (GPC) signal as an opt-out of sale/sharing where applicable under state law (we do not sell or share in any case).

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through the Service before the changes take effect. The “Last updated” date at the top of this page reflects the most recent revision.

14. Contact

Privacy questions, requests, or complaints? Email us at support@aurenwell.com, or write to:

Wild West Labs LLC
Attn: Privacy
2028 E Ben White Blvd #240-2206
Austin, TX 78741
© 2026 Wild West Labs LLC
TermsPrivacyRefundssupport@aurenwell.com