Kebijakan Privasi / Privacy Policy
Terakhir diperbarui / Last updated: 25 Juli 2026
AuraGlow Pro PWA is a serverless, offline-first booking and financial management software (SaaS) developed and operated officially by PT DOFIT DEV TEKNOLOGI (registered business under computer programming activities category). We are deeply committed to protecting your privacy and security. Below, we outline our strict policies regarding your Google user data, in compliance with the Google API Services User Data Policy.
1. Data Akses Pengguna Google (Google User Data Access)
AuraGlow requests authorization to access the following Google scopes directly from your device:
- Email Address (`https://www.googleapis.com/auth/userinfo.email`): Accessed only to read the user's primary email address for license verification and display account identification within the Settings panel.
- Google Calendar Events (`https://www.googleapis.com/auth/calendar.events`): Accessed to create, read, update, and delete calendar events for MUA bookings managed inside the app.
- Google Drive (`https://www.googleapis.com/auth/drive.file`): Accessed only to create and edit files created by AuraGlow, specifically:
- The spreadsheet database export ledger (`Auraglow_order`) containing booking details and transaction logs.
- The CRM folder (`AuraGlow_CRM` & `AuraGlow_Data`) for client metadata and backup persistence.
- The JSON sync backup file (`aura-sync.json`) for data persistence.
2. Penggunaan Data Pengguna Google (Google User Data Usage)
AuraGlow uses the accessed Google user data strictly for the following operational features:
- To show the current active logged-in Google Account in the settings menu, making sure the user knows which account is being synced.
- To dynamically create, modify, or remove calendar events corresponding to client appointments, preventing double-bookings.
- To write transaction ledgers and client records to a Google Sheet under your own Google Drive for easy backup, printing, and sharing.
3. Pengungkapan & Pembagian Data (Data Sharing & Disclosure)
AuraGlow DOES NOT share, transfer, or disclose Google user data with any third-party apps, services, servers, or external marketing entities.
All data transactions and APIs are called directly from your local browser client to Google APIs via secure HTTPS connections. There is no middleman or app server involved.
4. Proteksi & Pengamanan Data (Sensitive Data Protection)
To ensure the safety of your sensitive data, AuraGlow utilizes the following protection mechanisms:
- Google OAuth 2.0 Access Tokens are stored locally on your device within the secure IndexedDB database of your browser.
- Tokens are transmitted exclusively using secure HTTPS encryption protocols when making requests directly to Google endpoints.
- No tokens, credentials, or Google user details are ever transmitted to or stored on any external host or remote server owned by AuraGlow.
5. Retensi & Penghapusan Data (Data Retention & Deletion)
You have full control over the lifecycle of your data:
- Local Data: You can permanently delete all local IndexedDB data and access tokens at any time by clicking the "Hapus Semua Data Lokal" button inside the Settings page, or by clearing your browser site data.
- Google OAuth Session: Clicking the "Disconnect" or "Putus" button in Settings immediately destroys the local OAuth token, ending your session and severing the connection between AuraGlow and your Google Account.
- Cloud Data: Google Drive files and spreadsheets created by AuraGlow are retained in your Google Drive until you choose to delete them manually via Google Drive.
6. Informasi Kontak Bisnis & Kebijakan Transaksi (Business Contact & Currency Policy)
Seluruh transaksi langganan dan layanan AuraGlow diproses menggunakan mata uang sah Rupiah (IDR / Rp) dan diamankan langsung di dalam sistem aplikasi tanpa mengarahkan pengguna ke situs pihak ketiga yang tidak aman.
