Last updated: 25 July 2026
Margifi ("we", "us", or "our") operates a D2C profit analytics platform for Indian direct-to-consumer brands. This Privacy Policy applies to Clients (business entities subscribing to the Service) and their Users (individuals accessing the Service on the Client's behalf). It is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Margifi is operated by Margifi Limited, registered at 230, Ayodhyapuram Residency, Nr Valak Patiya, Valak, Surat City, PO: Sarthana, Dist: Surat, Gujarat 395006, India.
Margifi is a B2B profit analytics platform. We connect to your Meta, Shopify, and delivery accounts to show you your real delivered ROAS and net margin — and we take how we handle that data seriously. This policy tells you exactly what we collect, why, who we share it with, and how you can control it. Questions? Email admin@margifi.com.
When a Client registers for Margifi, we collect:
When the Client connects their third-party platforms to Margifi, we collect:
When you use the Margifi dashboard, we automatically collect:
Margifi is designed for B2B analytics. We take deliberate steps to limit the collection of personal data relating to the Client's end-customers:
The table below sets out every purpose for which we process personal data, the data category used, and the legal basis under the DPDP Act 2023.
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the Service — ingesting platform data and generating analytics | Integration Data, Account Data | Contract performance (Data Processor acting under Client instruction) |
| Account authentication and security | Account Data, Technical Data | Contractual necessity; legitimate interest (security) |
| Billing and subscription management | Account Data (payment via Razorpay) | Contractual necessity |
| Product improvement and bug resolution | Usage Data, Technical Data (PostHog, Vercel Analytics) | Legitimate interest |
| Customer support | Communications Data, Account Data | Contractual necessity; legitimate interest |
| Legal compliance and fraud prevention | All categories as required | Legal obligation; legitimate interest |
| Sending transactional emails (onboarding, invoices, alerts) | Account Data (email address) | Contractual necessity |
In relation to data received through Integrated Platforms that may include identifiers relating to the Client's end-consumers, Margifi processes such data as a Data Processor acting under the instructions of the Client as Data Fiduciary, as described in our Data Processing Agreement.
Margifi uses the following third-party service providers. Each receives only the data necessary for their specific function. Margifi requires all sub-processors to maintain appropriate data protection and security standards.
| Service | Function | Data received |
|---|---|---|
| Supabase Auth | Authentication, multi-factor authentication, and user session management | Name, email address, password hash, session tokens |
| Supabase (PostgreSQL) | Primary database and data storage | All Client Data, Integration Data, Account Data |
| DigitalOcean | Cloud hosting infrastructure | All data hosted on platform servers |
| Vercel | Application hosting, edge network / CDN, TLS termination, DDoS protection, and cookieless performance analytics | IP addresses, request metadata, aggregated page-performance metrics |
| Razorpay | Subscription billing and payment processing | Client name, email, payment method details (PCI-DSS compliant) |
| Meta (Meta Marketing API) | Read-only access to Client's ad account data | API credentials; Margifi reads ad performance data on the Client's behalf |
| Google (Google Ads API) | Read-only access to Client's Google Ads data | API credentials; Margifi reads campaign performance data on the Client's behalf |
| Shopify (Shopify Partner API) | Read-only access to Client's Shopify store data | API credentials; Margifi reads order and product data on the Client's behalf |
| Meta (WhatsApp Business Cloud API) | Delivering scheduled reports, alerts, and Client-configured WhatsApp messages; powering the team Inbox | Recipient phone number and message content, sent on the Client's instruction |
| OpenRouter | Routing requests to large language models that generate written insights and report narratives | Aggregated business metrics supplied as prompt context — no end-customer identifiers are sent |
| Google (Google Analytics 4) | Traffic analytics on the margifi.com marketing website | IP address, page views, referrer, device and browser metadata |
| PostHog | Product analytics and session recording | User interaction data within the dashboard (anonymised user IDs, feature usage, page views) |
| Resend | Transactional email delivery | Client email address; email content for onboarding, invoices, and alerts |
| Delhivery, Shiprocket, iThink Logistics, Bluedart, Shipmozo, ExpressFly | Shipping data ingestion via APIs | API credentials; Margifi reads shipment and delivery status data |
Client Data is stored in Supabase (PostgreSQL) databases hosted on cloud infrastructure. All data in transit between the Client's browser and the Margifi Platform is encrypted using TLS 1.2 or higher. Data stored in the database is encrypted at rest.
Personal data is stored and processed on cloud infrastructure located in India and Australia, in each case under contractual data-protection safeguards.
No system is completely secure. Margifi cannot guarantee absolute security of data transmitted over the internet.
| Data category | Retention period |
|---|---|
| Account Data | Duration of active subscription + 30 days post-cancellation |
| Integration Data (ad, order, catalogue, delivery) | Duration of active subscription + 30 days post-cancellation |
| Usage and Technical Data | Up to 12 months for product improvement and debugging |
| Billing records | 7 years as required under applicable Indian tax and accounting law |
| Support correspondence | 3 years from the date of the last correspondence |
At the expiry of the applicable retention period, data is either permanently deleted or anonymised such that it can no longer be attributed to the Client or any individual.
Clients may request early deletion of their data at any time — see Section 7: Data deletion for the full instructions.
In the event that Margifi becomes aware of a personal data breach likely to result in risk to the rights of individuals, Margifi will:
Clients who become aware of any suspected data breach or security vulnerability in connection with Margifi must promptly notify Margifi at admin@margifi.com.
Margifi processes personal data of individual Users on the following legal bases under the DPDP Act 2023: consent (obtained at account registration for service-related communications), contractual necessity (processing necessary to provide the subscribed Service), and legitimate interest (improving the platform, maintaining security, and preventing fraud).
As a data principal, you have the following rights:
How to exercise your rights: submit a written request to admin@margifi.com from your registered account email address. Margifi reserves the right to decline requests that are manifestly unfounded, repetitive, or that would require retention of data under a legal obligation.
If you are not satisfied with Margifi's response, you may raise a complaint with the Data Protection Board of India once such Board is constituted and operational under the DPDP Act.
You can ask us to delete your data at any time, and we will. This section is the single place that explains how.
Email admin@margifi.com from your registered account email address with the subject line "Data deletion request". Tell us whether you want your entire account deleted, or only the data from a specific connected platform. No form and no account required beyond the email itself.
You do not have to close your account to remove the data from a single connected platform. Name the platform in your email request and we will revoke the stored credentials, stop all further ingestion from it, and delete the data already ingested — on the same 7-business-day timeline. You may also revoke Margifi's access directly from that platform at any time (for example, removing the Margifi app in your Shopify or Meta Business settings), which stops ingestion immediately; email us if you also want the already-ingested data deleted.
We acknowledge every deletion request within 48 hours and complete it within 7 business days. We will confirm by email once deletion is complete.
Billing and invoice records are retained for 7 years as required under Indian tax and accounting law, and cannot be deleted on request. These records contain your business name, billing address, and transaction amounts — no Integration Data. We may also retain data where required to comply with a legal obligation or to resolve a live dispute; where that applies, we will tell you which data and why.
Margifi acknowledges that some third-party sub-processors — including Supabase, Vercel, DigitalOcean, PostHog, OpenRouter, Resend, Meta, and Google — operate infrastructure outside India. By using the Service, the Client acknowledges and consents to such international data transfers to the extent necessary for the delivery of the Service. Margifi ensures that such transfers are made under appropriate contractual protections as required under applicable law.
Margifi transfers personal data only to countries that are not restricted by the Central Government under Section 16 of the DPDP Act, 2023, under contractual data-protection safeguards.
Margifi does not use Client Data, Integration Data, or any personal data accessed through the Service for the purpose of serving targeted advertising to the Client's customers or for building advertising audiences. Client Data will not be shared with Meta, Google, or any other advertising platform for advertising targeting purposes — except as strictly necessary to execute the read-only API calls that fetch the Client's own advertising data from those platforms.
Margifi's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through the Google Ads API, Google Analytics Data API and Google Search Console API is used solely to provide and improve the reporting features the Client has connected, is never sold or transferred to third parties for advertising or any other purpose, and is never used to serve advertisements. Margifi does not allow humans to read this data except with the Client's explicit permission, to resolve a support issue the Client has raised, for security purposes, or where required by law.
Margifi uses cookies and similar tracking technologies on the platform. Full details — including which cookies we set, their purpose, and how to manage them — are set out in our Cookie Policy.
The Service is not directed at individuals under the age of 18. Margifi does not knowingly collect personal data from minors. If Margifi becomes aware that personal data of a minor has been inadvertently collected, it will be deleted promptly.
Margifi may update this Privacy Policy from time to time. When material changes are made, Margifi will notify Clients via email and/or dashboard notice at least 14 days before the changes take effect. Continued use of the Service following the effective date constitutes acceptance of the revised policy. The most current version of this policy will always be available at margifi.com/privacy-policy.
Data Grievance Officer: The Grievance Officer, Margifi Limited
Email: admin@margifi.com
Address: 230, Ayodhyapuram Residency, Nr Valak Patiya, Valak, Surat City, PO: Sarthana, Dist: Surat, Gujarat 395006, India
To exercise any right or raise a data-related complaint, email us from your registered account email address. We will acknowledge your request within 48 hours and respond substantively within 7 business days.
Terms of Service · Data Processing Agreement · Cookie Policy · Refund Policy · Grievance Policy