At Mirha & Co., we take your privacy and the security of your personal data seriously. This Privacy Policy describes how we collect, use, store, and share your personal information when you visit or make a purchase on https://mirhaandco.com (the "Site").
1. Information We Collect
We collect information to provide a better, more personalized experience on our Platform:
- Account Credentials: Email address, username, and authentication details when you sign up.
- Routine and Journal Data: Skincare routines you save, product ingredients you search, and skin observations, notes, and photos you upload to your personal skin journal.
- Usage Data: Device details, browser version, IP address, timezone, and pages visited on the Site.
2. How We Use Your Information
We use the collected information for the following purposes:
- To provide and maintain the features of our Platform, including your customized routine logs.
- To analyze ingredient compatibility, answer queries via our AI Consultant, and run skin photo analyses.
- To process payments and manage Pro Plan subscriptions through our billing partners.
- To send service-related notifications, security updates, and newsletters (where opted in).
3. Information Sharing and Payments
We do not sell, rent, or lease your personal information. We only share data with trusted third-party services necessary for our Platform's operations:
- Payment Processing: We do not store credit card numbers. All payment transactions are handled securely by PCI-compliant payment gateways, including Paddle and Razorpay.
- Database and Hosting: Your account metadata and skin log records are securely hosted using cloud storage partners (such as Supabase).
4. Security and Data Retention
We implement industry-standard security measures to protect your account and skin logs. We retain your personal data for as long as your account remains active. If you wish to delete your account and associated skin data permanently, you may request deletion at any time.
5. Your Rights (GDPR & International Users)
Depending on your location, you may have specific rights regarding your personal information under the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA). These include:
- The right to access the personal information we hold about you.
- The right to correct or update any inaccurate data.
- The right to request the complete deletion of your account and personal records ("Right to be Forgotten").
To exercise any of these rights, please reach out to us at tanizcoldz@gmail.com.
6. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or operational, legal, or regulatory guidelines. The "Last Updated" date at the top of this page will be adjusted accordingly.