Privacy Policy
Zero Ad Profiling Guarantee: We do not sell or rent your personal information. We do not use your information to serve third-party ads, and we do not build advertising profiles from your 1-on-1 chat or order content.
What is this Privacy Policy and what does it cover?
We at MIracal (operated by Hindustaan Innovations Private Limited) want you to understand what information we collect, and how we use and share it. That's why we encourage you to read this Privacy Policy in full.
In this Policy, we explain how we collect, use, share, retain and transfer your information when you use our direct-to-chat storefront platform — whether you're a Shopper browsing and buying, or a Seller running a storefront. We also explain your rights and how to exercise them.
You can manage your information through your account settings at any time. This Policy applies to our website, storefront pages, QR-code entry points, and chat features connected to the Service.
What information do we collect?
The information we collect depends on how you use the Service — we collect different information from a Shopper placing an order than from a Seller managing a catalog.
If you're a Shopper:
- Contact details: Name, WhatsApp phone number, and optional email address.
- Chat messages & requests: Inquiries, negotiation exchanges, and specific order requests sent directly to Sellers.
- Order & delivery details: Shipping address, delivery landmark, pin code, and order history.
- Payment-related references: Transaction confirmation IDs and payment status (see below for our card-free storage policy).
- Device & usage info: Browser characteristics and interactions with storefront listings.
If you're a Seller:
- Business profile & catalog: Storefront handle, catalog listings, descriptions, INR pricing, and product photography.
- Login credentials: Encrypted account passwords, authentication tokens, and verified phone numbers.
- Transaction records: Order histories, sales logs, customer lead timelines, and receipts.
- Operations settings: Business hours, automated greetings, and away-responder rules.
- Verification details: GSTIN / business registration documents if applying for the verified storefront badge.
Automatically, from everyone who visits the Service:
- Device characteristics: Device type, operating system, screen dimensions, and browser version.
- IP address & approximate location: Approximate city-level geographic location and network provider.
- Entry origin & storefront interaction: How you arrived (e.g. physical QR code scan at a store counter vs. direct WhatsApp link click) and how you navigate catalog items.
- Cookies & session tokens: Essential session cookies for maintaining storefront cart and auth status.
What if you don't let us collect certain information?
Some information is required for the Service to work — for example, we cannot deliver a chat order without a way to contact you or confirm payment. Other information (like allowing precise location) is optional, but may limit certain features, such as showing instant hyper-local delivery options.
How do we use your information?
We use your information to provide, personalise, and improve the Service. This includes:
Zero Ad Monetisation Guarantee
We do not use your information to show you third-party ads, and we don't build advertising profiles from your chat content or commercial orders.
How do we handle payments?
We use certified third-party, PCI-DSS compliant payment gateways (such as Razorpay, UPI, and banking networks).
We share only what is strictly necessary to process a transaction (order amount, order reference ID, and customer billing name). Full credit/debit card numbers, CVVs, and banking PINs are handled directly by the PCI-compliant payment processor and are never stored on our servers.
How is your information shared within the Service?
When you chat with a Seller (or a Shopper), the message content and any order or contact details you choose to share are visible to the other party in that conversation — this is the core function of the Service.
What Sellers see:
Sellers can see the order history, product inquiries, and contact details of Shoppers who have messaged their storefront in order to answer questions and ship orders.
What Shoppers see:
Shoppers can see a Seller's public digital catalog, listed INR pricing, operating hours, delivery badges, and storefront descriptions.
How do we share information with third parties?
We don't sell or rent your information to anyone, and we never will. We only share information where necessary, and require any partner or vendor we work with to follow strict contractual rules about how they use and protect it.
| Who | What's shared | Why |
|---|---|---|
Payment processors | Transaction and billing details (amount, order reference, billing name) | To securely process and complete your purchase without storing full card numbers |
Delivery / logistics partners | Delivery address, recipient name, contact phone, and relevant order contents | To fulfill direct local or Pan-India physical order delivery, only when requested |
Hosting & infrastructure providers | Server telemetry, encrypted database records needed to run the Service | To maintain 99.9% platform uptime, high availability, and secure cloud storage |
Analytics / monitoring vendors | Aggregated, anonymized or de-identified platform usage and traffic telemetry | To identify performance bottlenecks, troubleshoot bugs, and improve system speed |
Customer support tools | Support conversation history, account profile details, inquiry messages | To promptly respond to customer questions and resolve technical storefront issues |
We also share information in response to legal requests, to comply with applicable law, or to prevent harm (see below) — and if we sell or transfer all or part of our business, your information may transfer to the new owner, only as the law allows.
How can you manage or delete your information and exercise your rights?
You can view, update, or delete much of your information directly in your account settings. Subject to applicable Indian and international laws, you may also have the right to:
Access
Obtain a copy of the personal information we hold about you.
Correct
Update inaccurate, incomplete or outdated personal records.
Delete
Request deletion of your data (subject to statutory tax retention).
Object / Restrict
Object to or request limitation of certain processing activities.
Port Data
Export your storefront catalog or order history in a portable format.
Withdraw Consent
Revoke consent previously given for optional data processing.
To exercise these rights, contact us using the details below. We may need to verify your identity first, and may decline certain requests where the law allows us to (for example, retaining records needed for tax and GST compliance).
How long do we keep your information for?
We keep information for as long as we need it to operate the Service, comply with legal obligations, or protect our or others' interests. We decide this case-by-case, considering:
When information is no longer needed, we safely delete or anonymise it.
How do we transfer information?
Depending on where our cloud infrastructure and service providers are located, your information may be transferred to, stored in, or processed in countries other than your own. Where this happens, we put appropriate safeguards in place — such as strict contractual protections with our cloud and telemetry providers — consistent with applicable data protection laws.
How do we respond to legal requests, comply with applicable law and prevent harm?
We may access, preserve, use, and share your information:
- In response to legal requests, such as search warrants, court orders, or subpoenas from law enforcement or other judicial government authorities.
- In accordance with applicable law and consumer protection mandates.
- To promote the safety, security, and integrity of the Service, our users, and the public.
In some cases, we may need to preserve information for an extended period to comply with a statutory obligation or ongoing fraud investigation.
How will you know that this Policy has changed?
We'll notify you before we make material changes to this Policy — for example, through an in-app notice on the Service or by email — and give you the opportunity to review the revised Policy before you continue using the Service. The "Effective from" date at the top will always reflect the latest active version.
How to contact us with questions
If you have questions, complaints, or requests regarding this Policy or your personal information, you can reach out to us at:
MIracal Support & Privacy Operations
Entity: Hindustaan Innovations Private Limited
Email: support@miracal.in
Registered Address: Raipur, Chhattisgarh - 492001, India
Why and how we process your information
The sections below set out, purpose by purpose, why we process your information and what categories are typically involved.1. Operating the chat and storefront experience
Why: To connect Shoppers and Sellers in real time, display catalogs and pricing, generate QR/storefront links, and power automated greetings and away-messages.
Information used: Chat content, order details, catalog data, contact information, device/usage data.
2. Processing orders and payments
Why: To let you complete a purchase, issue quotes, confirm orders, and track delivery.
Information used: Order details, delivery address, billing name, transaction reference (not full payment credentials).
3. Maintaining accounts and storefronts
Why: To create and secure Shopper and Seller accounts, and manage storefront profiles and catalogs.
Information used: Contact details, login credentials, business profile information.
4. Providing and improving the Service
Why: To troubleshoot issues, test new features, and understand aggregate usage to prioritise improvements.
Information used: Usage data, device information, crash/performance logs, optional survey responses.
5. Promoting safety, security, and integrity
Why: To detect and prevent fraud, spam, fake storefronts, and abuse; verify Sellers for badge programs; and enforce our Terms of Service.
Information used: Account activity, device signals, IP address, verification documents (if applicable).
6. Communicating with you
Why: To send order confirmations, respond to support requests, and notify you of policy or service changes.
Information used: Contact information, order/support history.
7. Complying with legal obligations
Why: To retain records for tax, accounting, or consumer-protection purposes, and respond to valid legal requests.
Information used: Transaction records, account and contact information, as required by the specific legal obligation.