Privacy Policy

Last updated: July 5, 2026

This policy explains what Avora ("we", "us") collects and how we use it. It covers two groups: the businesses that use Avora to run their operations, and those businesses' own clients who interact with a business through Avora (e.g. paying an invoice, booking an appointment, signing a contract, or using a business's client portal).

Each business is the controller of its own client data; we process that data on the business's behalf to provide the Service.

1. Information we collect

  • Account data — for business users: name, email, username, business profile (name, industry, phone, website, logo), and team-member roles.
  • Client & contact data — the client records a business creates or imports: names, emails, phone numbers, and notes.
  • Transaction & document records — payment requests, invoices and line items, bookings and appointment times, memberships/subscriptions, event ticket purchases, quotes, expenses, reviews, and lead-form submissions.
  • E-signatures — when a client signs a contract, we record the typed signer name, the drawn signature image, the date and time signed, and — as a fraud-prevention audit trail — the signer's IP address and browser user-agent.
  • Files & messages — documents uploaded by a business or client (e.g. via the client portal or contracts), and the contents of messages exchanged between a business and its clients or with our support team (support tickets).
  • Authentication data — for both business users and portal clients. Clients sign in to a business's client portal with a one-time email code (no password); we link a client's login to the client records that share their email address.
  • Usage, logs & error data — technical logs, in-app activity, product-analytics events, and error reports used to operate, secure, and improve the Service.
  • Cookies — see “Cookies & sessions” below.

We do not collect or store payment card numbers or bank account numbers. Payment details are handled entirely by Stripe on Stripe-hosted checkout or Stripe's secure elements.

2. How we use information

  • To provide the Service and process payments through Stripe.
  • To send transactional emails (receipts, reminders, booking confirmations, login codes, contract and invoice notifications) and, where a business enables them, automated emails and workflows the business configures (for example a thank-you after payment or a review request). These are sent on the business's behalf.
  • To operate the client portal, e-signatures, messaging, and support.
  • To secure the platform, prevent fraud and abuse, and meet legal obligations.
  • To measure and improve the Service using aggregated usage analytics.

We do not sell personal information.

3. Sub-processors

We share data with the following service providers strictly to run the Service:

  • Stripe — payment processing and Connect payouts
  • Supabase — database, file storage, and authentication (for business users and portal clients)
  • Resend — sending transactional and workflow email
  • Sentry — error monitoring (may capture request context, including limited personal data, in error reports)
  • Vercel — application hosting

4. Cookies & sessions

We use strictly-necessary cookies to keep you signed in and to remember your selected workspace and (for portal clients) which business you're viewing. We don't use advertising cookies.

5. Data retention & your rights

We retain data while an account is active and as required by law (for example, tax and financial records tied to payments and signed contracts). You may request access to, correction of, or deletion of your data, subject to those legal retention requirements. If you're a client of a business using Avora, direct data requests to that business; we'll assist them as their processor.

6. Security

We use per-business tenant isolation (row-level security), encryption in transit, signed/expiring links for shared files, and least-privilege access. No system is perfectly secure and we cannot guarantee absolute security.

7. Contact

Privacy questions: support@payavora.com.