1. Summary
AURORA is a free cruise decision and price-monitoring service. In plain language:
AURORA collects the preferences and trackers you create, plus contact details you provide for alerts. AURORA uses them to score sailings, watch prices, and notify you. AURORA makes money from referral commissions when you choose to book through its links, and — only with your consent — from aggregated, privacy-protected demand reports that never identify you. You can opt out of demand reporting and keep free price monitoring. You can access, correct, or delete your data.
2. What we collect
You provide:
- Cruise Passport data: prior sailings, visited ports and counts, favorite and avoided ports, liked and trusted cruise lines, ship preferences, cabin type, party size, repeat-tolerance rules, and fit weights.
- Trackers and watches: sailing or listing URLs from supported sources, target prices, price lines, and intent signals (watch, compare, serious candidate, ready-if-target-hit).
- Contact details: email address used for sign-in and alerts.
- Feedback on recommendations.
Generated by the service:
- Price observations for tracked sailings from approved sources.
- Derived scores: fit scores, deal confidence, route novelty and overlap, booking-readiness state.
- Consent records: what you agreed to, when, which notice version, jurisdiction, and capture source.
- Booking attribution records when you use a referral link: internal attribution ID, tracker, source, offer, timestamp, and attribution status. Partners receive the internal attribution ID, not your user ID or tracker ID.
- Service logs and, only when you opt in, coarse product-usage events. Product analytics excludes ports, ships, cruise lines, tracker URLs, email, party details, and exact prices.
We do not collect: payment card data (AURORA takes no payments), and AURORA does not scrape or store forum or community posts, usernames, or roll-call travel plans.
Beta note: the web demo can run entirely on your device. The configured native beta can sync private account data to AURORA's development backend. Demo fares are labeled and are not live inventory.
3. How we use data
- Operate the service: score sailings against your Passport, run trackers, detect target hits, send alerts you requested.
- Improve the product: debug and, only after explicit product-analytics opt-in, measure coarse feature usage. Individual Cruise Passport and price signals are not product-analytics properties.
- Referral attribution: reconcile commissions using internal attribution IDs.
- Aggregated demand intelligence, with consent — see section 4.
- Legal compliance and safety.
AURORA does not sell or share your individual data with partners. Cruise lines and partners never see your identity, your exact target price, your tracker URLs, or your notification behavior.
4. Aggregated demand intelligence (consent-based)
With your data-use consent, AURORA may include your eligible trackers in cohort-level demand reports for cruise industry partners. Protections:
- Cohort-level records only; never user-level records.
- Minimum cohort size before reporting; smaller simulated cohorts are internal demo-only and labeled as such.
- Target prices bucketed to bands no narrower than $500.
- Suppression of rare ship/date/cabin/region/party-size/target combinations that could re-identify anyone.
- No tracker URLs, user IDs, contact details, exact target prices, exact creation timestamps, or notification behavior in any report.
- Partner contracts prohibit re-identification, user-level targeting, and onward resale.
Your controls: you can decline or withdraw consent at any time and keep core free monitoring. Withdrawal stops future inclusion in partner-facing aggregates. Deleting a tracker removes it from future cohorts unless retention is legally required.
These reports are aggregated and privacy-protected. We do not claim they are "anonymous" in the legal sense unless that standard is confirmed.
5. Notifications
In-app activity is the permanent alert record. Email is used for alerts and digests you enable, and can be disabled per watch. Native push is optional, requested contextually, and can be disabled per device. Push lock-screen copy omits exact prices and Cruise Passport details. Alert email and push are transactional; marketing messages, if ever introduced, will be separate with their own opt-in/opt-out.
6. Sharing
- Service providers: hosting, email delivery, push delivery, and optional analytics infrastructure under contract, processing only on our instructions. The processor list will be published before hosted launch.
- Booking partners: internal attribution ID only, when you click a referral link or engage an offer. Engagement is always your choice.
- Demand-report customers: aggregated cohorts only, as in section 4.
- Legal: when required by law or to protect rights and safety.
- Business transfer: if AURORA is acquired or reorganized, data may transfer under this policy's protections with notice.
7. Your rights
You may request access, correction, deletion, a copy of your data, and opt-out of demand intelligence (and of "sale/share" where state law defines these terms that way). To exercise rights, use the in-app controls or email legal@auroracruising.com. We will verify requests and respond within legally required windows. You will not be penalized for exercising rights; core free monitoring continues after demand-intelligence opt-out.
Region-specific disclosures — including applicable US state privacy laws and, if in scope, GDPR/UK GDPR — will be added here following legal review.
8. Retention
- Passport, trackers, watches: until you delete them or your account.
- Consent records: for the period required to demonstrate compliance, including after withdrawal.
- Attribution records: as needed for commission reconciliation.
- Redacted failure evidence for source adapters: per retention policy.
- Aggregate cohorts already delivered to partners cannot be recalled, but future cohorts exclude deleted or opted-out trackers.
9. Security
Access controls, encryption in transit, row-level security on user tables in the planned hosted backend, and least-privilege partner reporting. No system is perfectly secure; we will notify affected users of breaches as legally required.
10. Children
AURORA is not directed to children under 18 and does not knowingly collect their data.
11. Changes
We will post updates with a new version identifier and effective date, and notify you of material changes before they take effect. Your consent records always reference the version you actually saw.
12. Contact
- Website: auroracruising.com
- Customer support: support@auroracruising.com
- Privacy, rights, and legal requests: legal@auroracruising.com
The operating legal entity name and mailing address will be inserted after attorney review and before this policy takes effect.