Privacy Policy

Last updated: 25 July 2026

Margifi ("we", "us", or "our") operates a D2C profit analytics platform for Indian direct-to-consumer brands. This Privacy Policy applies to Clients (business entities subscribing to the Service) and their Users (individuals accessing the Service on the Client's behalf). It is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

Margifi is operated by Margifi Limited, registered at 230, Ayodhyapuram Residency, Nr Valak Patiya, Valak, Surat City, PO: Sarthana, Dist: Surat, Gujarat 395006, India.

Margifi is a B2B profit analytics platform. We connect to your Meta, Shopify, and delivery accounts to show you your real delivered ROAS and net margin — and we take how we handle that data seriously. This policy tells you exactly what we collect, why, who we share it with, and how you can control it. Questions? Email admin@margifi.com.

1. What data we collect

1.1 Account data

When a Client registers for Margifi, we collect:

  • Full name of the account holder
  • Business email address
  • Company or brand name
  • Subscription and billing information — payment processing is handled by Razorpay; Margifi does not store raw card numbers or UPI credentials

1.2 Integration data

When the Client connects their third-party platforms to Margifi, we collect:

  • Meta Ads data: advertising spend, impressions, reach, clicks, conversions, ROAS, campaign and ad set names, and other performance metrics accessible via the Meta Marketing API
  • Google Ads data: advertising spend, impressions, clicks, campaign and ad group performance metrics, ROAS, and related analytics accessible via the Google Ads API
  • Shopify data: order IDs, order amounts, product details, fulfilment status, order source, and sales channel data accessible via the Shopify Partner API
  • Product catalogue data: product, variant, and catalogue identifiers from Meta Catalogue / Commerce Manager, used to attribute advertising performance to specific products
  • Shipping and logistics data (Delhivery, Shiprocket, iThink Logistics, Bluedart, Shipmozo, ExpressFly): shipment IDs, AWB numbers, delivery status, return and RTO outcomes, and NDR (non-delivery report) data
  • Web analytics data (Google Analytics 4, Google Search Console, Microsoft Clarity): aggregated session, traffic-source, and search-performance metrics for the Client's own storefront, where the Client connects these accounts

1.3 Usage data

When you use the Margifi dashboard, we automatically collect:

  • Pages and features accessed within the dashboard
  • Button clicks, navigation patterns, and session duration
  • Dashboard configuration preferences
  • Timestamps of feature interactions

1.4 Technical data

  • IP address at the time of login and during active sessions
  • Browser type and version
  • Operating system and device type
  • Session identifiers held in authentication cookies issued by Supabase Auth
  • Application error logs and diagnostic data generated by our hosting platform

1.5 Communications data

  • Email correspondence with Margifi support
  • Any information the Client provides when submitting support tickets or feedback

2. What we do not collect

Margifi is designed for B2B analytics. We take deliberate steps to limit the collection of personal data relating to the Client's end-customers:

  • Margifi does not collect or store the full names, email addresses, phone numbers, home addresses, payment card numbers, or other directly identifying personal data of the Client's end-customers beyond what is strictly necessary for attribution matching — for example, anonymised or hashed identifiers used to match conversions to ad campaigns.
  • Margifi does not build individual consumer profiles of the Client's end-customers for Margifi's own commercial purposes.
  • Margifi does not use Integration Data for advertising targeting, re-targeting, or audience building on any advertising platform.
  • Margifi does not sell, rent, or trade any Client Data or personal data to data brokers or third parties for commercial gain.

3. Why we collect it — purposes and legal bases

The table below sets out every purpose for which we process personal data, the data category used, and the legal basis under the DPDP Act 2023.

PurposeData usedLegal basis
Providing the Service — ingesting platform data and generating analyticsIntegration Data, Account DataContract performance (Data Processor acting under Client instruction)
Account authentication and securityAccount Data, Technical DataContractual necessity; legitimate interest (security)
Billing and subscription managementAccount Data (payment via Razorpay)Contractual necessity
Product improvement and bug resolutionUsage Data, Technical Data (PostHog, Vercel Analytics)Legitimate interest
Customer supportCommunications Data, Account DataContractual necessity; legitimate interest
Legal compliance and fraud preventionAll categories as requiredLegal obligation; legitimate interest
Sending transactional emails (onboarding, invoices, alerts)Account Data (email address)Contractual necessity

In relation to data received through Integrated Platforms that may include identifiers relating to the Client's end-consumers, Margifi processes such data as a Data Processor acting under the instructions of the Client as Data Fiduciary, as described in our Data Processing Agreement.

4. Third-party sub-processors

Margifi uses the following third-party service providers. Each receives only the data necessary for their specific function. Margifi requires all sub-processors to maintain appropriate data protection and security standards.

ServiceFunctionData received
Supabase AuthAuthentication, multi-factor authentication, and user session managementName, email address, password hash, session tokens
Supabase (PostgreSQL)Primary database and data storageAll Client Data, Integration Data, Account Data
DigitalOceanCloud hosting infrastructureAll data hosted on platform servers
VercelApplication hosting, edge network / CDN, TLS termination, DDoS protection, and cookieless performance analyticsIP addresses, request metadata, aggregated page-performance metrics
RazorpaySubscription billing and payment processingClient name, email, payment method details (PCI-DSS compliant)
Meta (Meta Marketing API)Read-only access to Client's ad account dataAPI credentials; Margifi reads ad performance data on the Client's behalf
Google (Google Ads API)Read-only access to Client's Google Ads dataAPI credentials; Margifi reads campaign performance data on the Client's behalf
Shopify (Shopify Partner API)Read-only access to Client's Shopify store dataAPI credentials; Margifi reads order and product data on the Client's behalf
Meta (WhatsApp Business Cloud API)Delivering scheduled reports, alerts, and Client-configured WhatsApp messages; powering the team InboxRecipient phone number and message content, sent on the Client's instruction
OpenRouterRouting requests to large language models that generate written insights and report narrativesAggregated business metrics supplied as prompt context — no end-customer identifiers are sent
Google (Google Analytics 4)Traffic analytics on the margifi.com marketing websiteIP address, page views, referrer, device and browser metadata
PostHogProduct analytics and session recordingUser interaction data within the dashboard (anonymised user IDs, feature usage, page views)
ResendTransactional email deliveryClient email address; email content for onboarding, invoices, and alerts
Delhivery, Shiprocket, iThink Logistics, Bluedart, Shipmozo, ExpressFlyShipping data ingestion via APIsAPI credentials; Margifi reads shipment and delivery status data

5. Data storage, security and retention

Storage

Client Data is stored in Supabase (PostgreSQL) databases hosted on cloud infrastructure. All data in transit between the Client's browser and the Margifi Platform is encrypted using TLS 1.2 or higher. Data stored in the database is encrypted at rest.

Personal data is stored and processed on cloud infrastructure located in India and Australia, in each case under contractual data-protection safeguards.

Security measures

  • Encryption in transit: TLS 1.2 or higher, terminated at the Vercel edge network
  • Encryption at rest: Supabase (PostgreSQL) database data is encrypted at rest
  • Access controls: access to production data and infrastructure is restricted to authorised Margifi personnel on a need-to-know basis, with role-based access controls enforced
  • Authentication security: all Margifi employee and User authentication is managed via Supabase Auth, with support for multi-factor authentication and row-level security enforced at the database
  • Error monitoring: application and platform logs are monitored to detect application errors and enable rapid incident response
  • Dependency and vulnerability monitoring: Margifi performs periodic reviews of software dependencies and applies security patches in a timely manner

No system is completely secure. Margifi cannot guarantee absolute security of data transmitted over the internet.

Retention periods

Data categoryRetention period
Account DataDuration of active subscription + 30 days post-cancellation
Integration Data (ad, order, catalogue, delivery)Duration of active subscription + 30 days post-cancellation
Usage and Technical DataUp to 12 months for product improvement and debugging
Billing records7 years as required under applicable Indian tax and accounting law
Support correspondence3 years from the date of the last correspondence

At the expiry of the applicable retention period, data is either permanently deleted or anonymised such that it can no longer be attributed to the Client or any individual.

Clients may request early deletion of their data at any time — see Section 7: Data deletion for the full instructions.

Data breach notification

In the event that Margifi becomes aware of a personal data breach likely to result in risk to the rights of individuals, Margifi will:

  1. Notify affected Clients at their registered email address within 72 hours of becoming aware of the breach
  2. Provide details of the nature of the breach, the categories of data affected, and the steps being taken to address it
  3. Report the breach to the Data Protection Board of India, as and when required under applicable regulations

Clients who become aware of any suspected data breach or security vulnerability in connection with Margifi must promptly notify Margifi at admin@margifi.com.

6. Your rights under the DPDP Act 2023

Margifi processes personal data of individual Users on the following legal bases under the DPDP Act 2023: consent (obtained at account registration for service-related communications), contractual necessity (processing necessary to provide the subscribed Service), and legitimate interest (improving the platform, maintaining security, and preventing fraud).

As a data principal, you have the following rights:

  • Right to access: Request confirmation of whether your personal data is being processed and receive a summary of it. Response within 7 business days.
  • Right to correction: Request correction of inaccurate or incomplete personal data held by Margifi. Response within 7 business days.
  • Right to erasure: Request deletion of personal data where there is no legitimate basis for continued processing. Response within 7 business days — see Section 7: Data deletion.
  • Right to grievance redressal: Raise complaints about data processing and receive a substantive response. Acknowledgement within 48 hours; response within 7 business days.
  • Right to nominate: Nominate another person to exercise rights on your behalf in the event of death or incapacity, as required by the Act.

How to exercise your rights: submit a written request to admin@margifi.com from your registered account email address. Margifi reserves the right to decline requests that are manifestly unfounded, repetitive, or that would require retention of data under a legal obligation.

If you are not satisfied with Margifi's response, you may raise a complaint with the Data Protection Board of India once such Board is constituted and operational under the DPDP Act.

7. Data deletion

You can ask us to delete your data at any time, and we will. This section is the single place that explains how.

How to request deletion

Email admin@margifi.com from your registered account email address with the subject line "Data deletion request". Tell us whether you want your entire account deleted, or only the data from a specific connected platform. No form and no account required beyond the email itself.

What gets deleted

  • Account Data — your name, business email, brand name, and dashboard configuration
  • Integration Data — all advertising, order, catalogue, and delivery data ingested from your connected platforms, together with the derived analytics built from it
  • Stored credentials — the encrypted API keys and OAuth tokens for every platform you connected, which are revoked and destroyed
  • Usage and Technical Data — session records and product-analytics events associated with your account

Deleting one platform's data

You do not have to close your account to remove the data from a single connected platform. Name the platform in your email request and we will revoke the stored credentials, stop all further ingestion from it, and delete the data already ingested — on the same 7-business-day timeline. You may also revoke Margifi's access directly from that platform at any time (for example, removing the Margifi app in your Shopify or Meta Business settings), which stops ingestion immediately; email us if you also want the already-ingested data deleted.

Timeline

We acknowledge every deletion request within 48 hours and complete it within 7 business days. We will confirm by email once deletion is complete.

What we must retain

Billing and invoice records are retained for 7 years as required under Indian tax and accounting law, and cannot be deleted on request. These records contain your business name, billing address, and transaction amounts — no Integration Data. We may also retain data where required to comply with a legal obligation or to resolve a live dispute; where that applies, we will tell you which data and why.

8. International data transfers

Margifi acknowledges that some third-party sub-processors — including Supabase, Vercel, DigitalOcean, PostHog, OpenRouter, Resend, Meta, and Google — operate infrastructure outside India. By using the Service, the Client acknowledges and consents to such international data transfers to the extent necessary for the delivery of the Service. Margifi ensures that such transfers are made under appropriate contractual protections as required under applicable law.

Margifi transfers personal data only to countries that are not restricted by the Central Government under Section 16 of the DPDP Act, 2023, under contractual data-protection safeguards.

9. No advertising use

Margifi does not use Client Data, Integration Data, or any personal data accessed through the Service for the purpose of serving targeted advertising to the Client's customers or for building advertising audiences. Client Data will not be shared with Meta, Google, or any other advertising platform for advertising targeting purposes — except as strictly necessary to execute the read-only API calls that fetch the Client's own advertising data from those platforms.

Margifi's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through the Google Ads API, Google Analytics Data API and Google Search Console API is used solely to provide and improve the reporting features the Client has connected, is never sold or transferred to third parties for advertising or any other purpose, and is never used to serve advertisements. Margifi does not allow humans to read this data except with the Client's explicit permission, to resolve a support issue the Client has raised, for security purposes, or where required by law.

10. Cookies, children, policy changes and contact

Cookies

Margifi uses cookies and similar tracking technologies on the platform. Full details — including which cookies we set, their purpose, and how to manage them — are set out in our Cookie Policy.

Children's data

The Service is not directed at individuals under the age of 18. Margifi does not knowingly collect personal data from minors. If Margifi becomes aware that personal data of a minor has been inadvertently collected, it will be deleted promptly.

Changes to this policy

Margifi may update this Privacy Policy from time to time. When material changes are made, Margifi will notify Clients via email and/or dashboard notice at least 14 days before the changes take effect. Continued use of the Service following the effective date constitutes acceptance of the revised policy. The most current version of this policy will always be available at margifi.com/privacy-policy.

Contact and Grievance Officer

Data Grievance Officer: The Grievance Officer, Margifi Limited
Email: admin@margifi.com
Address: 230, Ayodhyapuram Residency, Nr Valak Patiya, Valak, Surat City, PO: Sarthana, Dist: Surat, Gujarat 395006, India

To exercise any right or raise a data-related complaint, email us from your registered account email address. We will acknowledge your request within 48 hours and respond substantively within 7 business days.

Related legal documents

Terms of Service · Data Processing Agreement · Cookie Policy · Refund Policy · Grievance Policy