Privacy Policy
Last updated: August 21, 2026
This document describes the data AURUM actually collects, what it is used for, and how long it is kept.
1Applicable framework
The processing of your data is governed by Ivorian law n° 2013-450 of June 19, 2013 on the protection of personal data. The competent supervisory authority is the Telecommunications Regulatory Authority of Côte d'Ivoire (ARTCI), with whom you can file a complaint.
Each processing activity described below rests on one of these bases: performance of the sales contract, a legal obligation — accounting in particular —, or the store's legitimate interest in protecting itself against fraud.
2Data collected
The service records:
- Account — email address, display name if you provide one, country, and your password's hash. The password itself is never stored.
- Orders — items, amounts, reference, delivery email address, progress status.
- Payments — provider, method, amount and reference. No bank details ever pass through or are stored by AURUM: they are entered directly with the provider.
- Sessions — an opaque token, its hash, the date of last activity, and the browser used.
- Balance — the ledger of your wallet's movements: top-ups, purchases, refunds, cashback, referral bonuses. Each entry carries its date, amount and reason.
- Referrals — the link between the inviting account and the invited one, and the hash of the IP address used at sign-up.
- Reviews — the rating, the comment, and the displayed name, truncated, if the review is published.
- Support — the content of tickets and messages exchanged.
3IP address
Your IP address is not stored in clear text. It is turned into an irreversible hash, used to limit the number of login attempts and detect abnormal orders.
This hash does not allow the original address to be recovered, but it does allow two requests coming from the same address to be recognized. It is precisely this property that is used to detect an account created from the same connection as its referrer, in which case the bonus is not paid.
This matching is the only use of the mechanism beyond technical purposes. It never leads to an irreversible automated decision: a refused bonus is explained and can be contested with support.
4Purchased codes
The codes for the cards you buy are encrypted before being stored, with a key separate from the one protecting sessions. They are only decrypted to be shown to you.
The support team only sees the last four characters of a code, never the whole code.
5Cookies
AURUM sets a single cookie, necessary for the service to function: it carries your session or cart token. It cannot be read by scripts, is not shared with third parties, and is not used for advertising purposes.
No third-party tracker or audience-measurement tool is installed.
6Recipients
Your data is shared only with:
- the payment provider, to collect and verify payment;
- the card supplier, to obtain a code — without your identity;
- the email provider, to send you messages related to your orders and account.
7Retention periods
- Account — until you request deletion.
- Orders, payments and balance ledger — ten years, the accounting document retention period set by the OHADA Uniform Act. These entries survive deletion of the account, in a form disconnected from your identity where possible.
- Published reviews — for as long as they remain online, with a truncated name. Their removal can be requested.
- Support tickets — three years after closing, a period that covers the statute of limitations for commercial complaints.
- Sessions — 30 days after the last activity, or immediately upon logout.
- Password reset and confirmation links — 30 minutes and 24 hours respectively, then purged.
8Your rights
You can request access to your data, its correction, its deletion, or object to its processing. Deleting your account does not erase the accounting history of orders already paid for.
These requests go through support.
9Security
Passwords are protected with Argon2id. Sessions rely on opaque tokens that can be revoked server-side. Purchased codes are encrypted at rest. Exchanges with the site are enforced over HTTPS.
None of these measures replace a password that only you know and that you use nowhere else.