Vihax

Privacy Policy

Last updated: 23 September 2026 · Canonical URL: https://vihax.com/privacy/

Vihax is operated by VIHAX Marketing Solutions (“Vihax,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, store, share, transfer, and protect information when you use vihax.com and the application at app.vihax.com (together, the “Service”).

This policy is designed to align with India’s Digital Personal Data Protection Act, 2023 (DPDP) and, where applicable, the EU/UK GDPR. If you connect Google accounts or Google APIs, this policy also addresses Google user data in line with the Google API Services User Data Policy, including Limited Use requirements.

1. What Vihax is

Vihax is a profit analytics application for direct-to-consumer (D2C) ecommerce brands. Customers connect store and advertising accounts they control (including Shopify, Meta, and Google) so Vihax can compute contribution margin, attribution, RTO-aware profit, and related metrics inside that brand’s own dashboard.

2. Data we collect

2.1 Account data

Name, email address, company or brand name, role, country, currency, timezone, and authentication details when you create or manage an account.

2.2 Connected platform data (with your authorisation)

2.3 Tracking and cost data

First-party pixel and server-side events from your storefront; cost inputs you provide (COGS, shipping, fees); return and RTO outcomes used to compute delivered profit.

Vihax stores no raw email address, phone number, customer name or street address for your customers. Where an email or phone number is needed to match a storefront event to an order, it is SHA-256 hashed at the point of use and the plaintext is never written to our database. Matching is performed hash to hash. The hashes themselves are kept for 90 days and then removed.

Four fields that can identify a customer are stored against an order: the Shopify customer identifier, and the postal code, city and state of the delivery address. These are the fields the retention schedule in section 6 erases first.

Vihax reads each storefront visitor’s consent choice through Shopify’s Customer Privacy API. A visitor who declines analytics is not recorded. A visitor who declines marketing, or opts out of the sale or sharing of their data, is never sent to Meta or Google, and no advertising identifier is stored for them. Where no choice was recorded, nothing is sent for an order shipping to the EU, EEA, UK or Switzerland.

2.4 Usage and technical data

Limited diagnostics, security logs, and product usage data needed to operate, secure, and improve the Service. The public marketing site at vihax.com does not use third-party advertising trackers for behavioural ads.

We record sessions of the Vihax application itself, using Microsoft Clarity, to see where the product is failing. This covers your use of Vihax as a merchant, not your customers’ use of your storefront. Page content is masked by default: figures, tables and form fields are obscured in every recording, and only page structure and navigation are visible.

3. How we use data

We do not sell personal data or Google user data. We do not share one brand’s identifiable commerce or ads data with other brands. We do not use customer data to train public AI models unrelated to providing the Service to that customer.

4. Google user data

This section applies when you connect a Google account to Vihax (including Google Ads and related Google APIs via OAuth).

4.1 What Google data we access

Only the data needed to provide the Service, such as Google account identifiers, Google Ads customer/account structure needed to list and link accounts you control, campaign and spend metrics, conversion-related reporting fields, and OAuth refresh/access tokens required to keep the connection working. We request only the OAuth scopes required for these features.

4.2 How we use Google user data

Solely to display advertising, attribution, and profit analytics inside your Vihax workspace; to maintain and refresh your Google connection; to troubleshoot connection or reporting issues for your account; and to improve reliability of these features for you. We do not use Google user data for advertising to other people, for selling data, or for products unrelated to the Vihax Service you signed up for.

Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4.3 With whom we share, transfer, or disclose Google user data

We do not sell Google user data.

We do not share Google user data with other advertisers, data brokers, ad networks, or unrelated third-party marketing tools for their independent use.

We share, transfer, or disclose Google user data only as follows:

We do not transfer Google user data to third parties for their independent use, resale, or advertising.

4.4 Disconnect and deletion

You can disconnect Google at any time from Vihax connection settings. After disconnect, we stop new pulls from Google APIs. We delete or anonymise stored Google-derived data associated with that connection according to our retention practices, except where we must retain records for legal, security, or accounting reasons.

5. Sharing of other (non-Google) data

For account, Shopify, Meta, pixel, and usage data, we apply the same principle: we share only with processors needed to operate the Service, with your authorised workspace users, and when required by law. We do not sell this data or share one customer’s identifiable store/ads data with other customers.

5.1 Our sub-processors

Each of the following receives only what its stated purpose requires.

Meta, Google Ads and Anthropic receive data only for accounts that have connected those platforms or used the assistant. Shopify is the source of your store data rather than a sub-processor of ours; your relationship with Shopify is governed by your own agreement with them.

5.2 What we send to Meta

Where you connect Meta, Vihax sends conversion events for your orders through Meta’s Conversions API. Customer identifiers in those events are SHA-256 hashed before they leave our systems.

Two values are sent unhashed: the visitor’s IP address and their browser user agent. Meta’s Conversions API specification requires both in clear form and rejects hashed values for these two fields, so hashing them would not protect the visitor, it would stop the match working at all. They are browser and request signals rather than customer identifiers, and they are sent only for events on stores whose owner has connected Meta. You can switch off the sending of customer identifiers entirely in Vihax; IP address and user agent continue to be sent, because without them no conversion can be attributed at all. Nothing at all is sent for a visitor who declined marketing or opted out of the sale or sharing of their data (section 2.3).

5.3 Shopify protected customer data

Vihax reads order and customer records from your Shopify store to compute profitability. We request read-only access and never write to your orders, products, customers or settings; the single exception is that the app registers its own order webhook so it can receive new orders as they are placed.

Of the customer data Shopify returns, we retain only what the profit calculation needs: the customer identifier, the delivery postal code, city and state, and the order’s financial and delivery fields. Email addresses and phone numbers are hashed on receipt and the plaintext is discarded. Customer names are hashed in the same way and never stored in plaintext. The hashed values sent to Meta are kept with the record of that send for 90 days and then removed. We do not request street address lines at all.

We respond to Shopify’s customer data request, customer redaction and shop redaction webhooks. A data request produces the actual records we hold for that customer, assembled for you to give them. A redaction erases them.

6. Storage, location, and security

Application servers are hosted on Emergent. Primary database: MongoDB Atlas in Mumbai, India (AWS ap-south-1). Data is encrypted in transit (TLS) and at rest via our infrastructure providers.

Production access is limited to authorised personnel and to credentials scoped to the minimum required. Day-to-day diagnostic access to production data is performed through a read-only database credential, and changes to production data are made only by deployed, reviewed code rather than directly against the database. Access to your data inside the application is authenticated, and every opening of a single customer’s records is logged with who opened it, when, and which record; the log is kept for 400 days and the store owner can read it in Settings. Database-level audit logging is not currently enabled. Passwords must be at least 12 characters, and sign-in locks after 5 failed attempts in 15 minutes.

Retention. Directly identifying fields are erased at 90 days; a pseudonymous key and the order’s financial fields are retained for 24 months to compute cohort economics, then aggregated and deleted.

In practice: 90 days after an order, the postal code, city and state on it are erased and the Shopify customer identifier is replaced with a one-way pseudonym. The order’s money and delivery outcome remain, because your profit history is computed from them. At 24 months the pseudonym itself is removed, once the aggregate figures that depend on it have been computed and stored. Aggregates are published only where at least 20 customers fall into a group, so no individual can be recovered from them.

The pseudonym is a keyed hash. The key is generated per merchant, stored encrypted, and returned by no part of the Service, so the same person appearing in two merchants’ stores produces two unrelated pseudonyms and no correlation across merchants is possible from the stored keys alone. The transformation is one-way: once a customer identifier has been replaced, we cannot recover it.

Backups. Encrypted database backups are taken daily and retained for 7 days, with weekly snapshots retained for 4 weeks. No backup is kept longer than 28 days, which is well inside the 90-day erasure schedule above: a backup cannot contain identifying fields that the schedule has already erased, because every backup expires long before that point is reached.

Account data is retained while the account is active and for a limited recovery period after deletion, unless a longer period is required by law. If you uninstall the Vihax app from Shopify, we stop collecting immediately and delete your store’s data in line with Shopify’s shop redaction webhook.

What we commit to as the processor of your customers’ data is set out in our Data Processing Addendum, which forms part of our Terms.

7. Your rights

Depending on applicable law (including DPDP and, where applicable, GDPR), you may request access, correction, export, or deletion of personal data we hold about you as a customer contact; withdraw consent where processing is based on consent; and contact us with privacy questions.

Email vivek@vihax.com with subject line Data request. We aim to respond within 30 days.

8. Children

The Service is directed at businesses, not individuals under 18. We do not knowingly collect personal data from children.

9. International transfers

Primary processing for the application is in India. If a processor or support function involves another region, we take steps appropriate to the risk and applicable law so that personal data remains protected.

10. Changes

We may update this policy. The “Last updated” date will change when we do. Material changes may also be communicated by email to account owners.

11. Contact

VIHAX Marketing Solutions
Faridabad, Haryana, India
Email: vivek@vihax.com