Privacy Policy
Effective August 19, 2026
This policy explains how Mithra E-Commerce Solutions (“Mithra,” “we,” “us,” or “our”) handles personal information through this website, its contact and booking tools, client project briefs, payment-request workflow, and private business CRM. Mithra is the controller or business for website inquiries. A signed client agreement defines roles for client projects.
Information we collect
Information you provide. Contact and booking forms may collect your name, company, business email, phone, revenue range, service need, message, appointment time, and notes. A privacy request collects your name, email, jurisdiction, request type, and details. Do not submit identity documents through public forms.
Business and service records. If we work together, our CRM may contain company contacts, communications, notes, tasks, project status, payment-request status, refund records, and a history of staff actions. Card numbers are entered on Square- or Stripe-hosted pages and are not received or stored by Mithra.
Client project briefs and files. After a project begins, an authorized client contact may use an expiring private link to provide business operations, audience, content, brand, system, integration, priority, and project information and to upload authorized logos, brand files, business photography, and visual references. Draft answers remain on that person's device until submission. Submitted answers and files become private project records available to authorized Mithra staff.
Client project workspaces. An authorized client contact may receive a random private link showing project summaries, dates, milestones, updates, and approval requests. We record approval responses, optional response notes, and limited access activity needed to operate and protect the workspace. Links can be replaced or revoked and are excluded from search indexing.
Optional website engagement measurement. Only after you allow analytics, our first-party tool records a random browser identifier, page, active visible time, maximum scroll percentage, a count of broad interactions, conversion status, referral and campaign details, broad device class, timestamps, and approximate city/region/country supplied by the hosting edge. Time pauses when the page is hidden or the visitor has been inactive for 30 seconds. It does not record form-field values, typed text, element text, click coordinates, raw IP addresses, user-agent strings, advertising identifiers, browser fingerprints, or cross-site profiles.
Optional Google Analytics. Only after consent, Google Analytics may receive page, device, browser, referral, cookie, and approximate-location information under Google’s terms. We do not send contact-form contents to Google Analytics.
Security and error records. For authorized staff, we store derived password verifiers, hashed recovery and session tokens, and access events. We may also record shortened technical error messages, affected pages, authentication activity, and abuse-prevention results. We minimize these records and do not intentionally include public-form contents.
Consent records. When you make or withdraw an analytics choice, we store a random receipt ID, your choice, notice version, time, page, and whether Global Privacy Control or Do Not Track was active. The receipt contains no name, raw IP address, user agent, or browser fingerprint.
Why we use information
We use information to answer inquiries, take steps you request before a contract, provide services, schedule meetings, administer client relationships, request and reconcile payments, secure and debug the service, keep legal and audit records, defend rights, and comply with law. Optional analytics is based on consent. Operational processing is based on a requested service or contract, legal obligations, or legitimate interests such as security and business administration, where permitted.
Sharing and service providers
We disclose only what is reasonably necessary to providers supporting hosting and databases, staff authentication, email delivery, security and spam prevention, optional analytics, and hosted payment processing. See the current service-provider register. We may also disclose information to professional advisers, authorities when legally required, or in a business transaction with appropriate safeguards. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.
Retention
We generally review inquiry and booking records after 24 months without meaningful activity, while client project briefs, authorized project assets, active client, contract, tax, payment, dispute, and legal records may be kept for the active relationship and longer where required. Optional engagement data is scheduled for deletion after 13 months, resolved technical errors after 90 days, and closed privacy-request and consent-receipt records after 36 months. We may retain de-identified aggregate information that cannot reasonably identify a person.
Your privacy rights
Depending on your location, you may request access, correction, deletion, portability, restriction, objection or opt-out, or an appeal. Submit the dedicated privacy request form. We will verify a request proportionately, respond within the period required by applicable law, and generally target one month. Authorized agents may submit requests where law permits, subject to verification.
EEA and UK residents may withdraw consent without affecting earlier lawful processing and may complain to their local supervisory authority. U.S. residents may appeal a denial where applicable. Because we do not sell personal information or use targeted advertising, an opt-out signal does not change those practices; Global Privacy Control and Do Not Track nevertheless keep optional analytics off. See the U.S. State Privacy Notice for category-level disclosures.
Cookies and privacy choices
Essential storage supports security, forms, authentication, and your privacy choice. Optional first-party and Google analytics remain off until you allow them. You can reopen “Privacy choices” on any page and withdraw consent as easily as you gave it. The preference expires after about six months. See the Cookie Notice.
Security and breach response
We use data minimization, encrypted HTTPS transport, restricted staff access, activity logging, security headers, hosted payment pages, backups and exports, retention controls, and other reasonable safeguards. We review suspected incidents and provide notices required by applicable law. No system can be guaranteed completely secure.
Children and restricted data
This business service is not directed to children under 13, and we do not knowingly collect their personal information. Public forms and the CRM are for ordinary business contact and project information only. Do not submit patient or health information, clinical or adverse-event records, payment-card data, nonpublic financial information governed by GLBA, government identifiers, passwords, manufacturing or batch records, quality-system records, regulated signatures, or other regulated records.
International processing
Information may be processed in the United States or other countries where our providers operate. Where required, we use contractual or other recognized safeguards for restricted transfers. Customers needing specific data residency or regulated processing must arrange it in a written agreement before sending data.
Automated decisions
We do not use website or CRM information to make solely automated decisions that produce legal or similarly significant effects.
Changes and contact
We may update this policy when practices or laws change and will post a new effective date. Questions may be submitted through the contact form. This policy is a transparency statement, not a claim that the site is certified under every law.
