Privacy policy

Effective 30 August 2026 · This Privacy Policy is issued by Mukshree Design Studio, trading as mifoa, 801, Emaar Emerald Plaza, Sector 65, Gurugram – 122018, Haryana, India

In short

  • We collect information needed to operate the store, process payments, deliver orders, clear international shipments and provide support.
  • We do not receive or store your complete card number, CVV, UPI PIN, banking password or Apple Pay credentials.
  • We do not sell personal data for money.
  • We share data only with service providers and authorities that help us operate the store, process payments, prevent fraud, communicate with you or deliver your order.
  • International orders may require information to be shared with overseas couriers, customs authorities and service providers.
  • You may ask to access, correct, delete or obtain a copy of your data, withdraw consent or exercise other rights available under applicable law.

1. Who is responsible for your data

Mukshree Design Studio, trading as mifoa, is responsible for the personal data described in this policy except where another provider acts independently under its own privacy notice.

Mukshree Design Studio / mifoa

2. Information we collect

Information Examples Why we use it
Identity and contact information Name, email address, phone number and customer-account details Orders, account administration, communication, fraud prevention and support
Delivery information Shipping and billing address, country, state, postal code and delivery instructions Fulfilment, courier booking, tracking, delivery and returns
International-shipping information Destination country and any identification, tax or customs information lawfully required by a carrier or authority Customs documentation, import processing and cross-border delivery
Order information Products purchased, order value, discounts, invoices, returns, refunds and support history Fulfilment, customer service, accounting, fraud prevention and legal record-keeping
Payment-related information Payment status, transaction reference, payment-method type, masked payment details and fraud or risk signals Payment confirmation, reconciliation, refunds and payment-security checks
Device and usage information IP address, browser, device type, cookie identifiers, pages viewed, cart activity and referring source Store functionality, security, analytics, performance and permitted advertising
Communications Emails, support requests, WhatsApp messages, reviews, photographs and other information you send us Support, claim verification, service improvement and publishing authorised reviews
Marketing preferences Email, SMS or other communication preferences and consent records Sending and managing promotional communications where permitted

Please do not send sensitive personal information unless we or an authorised carrier specifically request it for a lawful purpose such as customs clearance or identity verification.

3. How we collect information

We collect personal data:

  • Directly from you when you browse, order, create an account, contact us, request a return, submit a review or subscribe to marketing;
  • Automatically through cookies, pixels, server logs and similar technologies when you use the store;
  • From payment providers, banks, fraud-prevention providers, couriers and Shopify in connection with an order or transaction; and
  • From another person who places an order for delivery to you, in which case we use the information only for the order and related support.

4. Why we process personal data

Depending on your location and the circumstances, we process personal data:

  • To perform our contract with you: accepting payment, fulfilling orders, arranging delivery, processing returns and providing support;
  • To comply with legal obligations: tax, accounting, customs, consumer-protection, fraud-prevention and lawful authority requirements;
  • For legitimate business interests: securing the store, preventing misuse, improving products and services, understanding store performance and resolving disputes, where those interests do not override your rights; and
  • With your consent: for optional marketing, non-essential cookies or other processing where consent is required. You may withdraw consent at any time without affecting processing already lawfully completed.

5. Payments

Payments may be processed through Shopify checkout, Razorpay, card networks, banks, UPI providers, Apple Pay or other payment methods displayed at checkout.

mifoa does not receive or store your complete card number, CVV, UPI PIN, online-banking password or Apple Pay credentials. We may receive a payment confirmation, transaction reference, payment-method type, masked account or card information and fraud-risk signals needed to verify, reconcile or refund the transaction.

Payment providers may process information as independent controllers under their own privacy notices. You can review:

6. Who we share information with

We disclose only the information reasonably necessary for the relevant purpose to:

  • Shopify, which hosts the store, checkout, customer accounts and order information;
  • Razorpay and other payment participants, including banks, card networks, UPI providers and wallets, for payment processing, refunds, reconciliation and fraud checks;
  • Couriers, fulfilment providers and delivery partners, which receive the contact and address information required to collect, transport and deliver orders;
  • Customs authorities, customs brokers and international carriers, where information is required for cross-border shipping or import clearance;
  • Communication providers supporting email, SMS, WhatsApp, order notifications and customer service;
  • Analytics and advertising providers enabled on our store, subject to applicable consent and opt-out requirements;
  • Professional advisers and service providers such as accountants, technology providers and security or fraud-prevention services, where reasonably necessary;
  • A purchaser or successor if all or part of the business is reorganised, sold or transferred, subject to appropriate confidentiality and legal requirements; and
  • Courts, regulators, law-enforcement bodies and other authorities where disclosure is lawfully required or reasonably necessary to protect legal rights, safety or the integrity of the store.

Some providers may act on our instructions, while others independently determine how they process information and provide their own privacy notices.

7. Cookies, analytics & advertising

Our store may use:

  • Essential cookies for checkout, cart, account, security and fraud-prevention functions;
  • Functional cookies for preferences and improved store functionality;
  • Analytics cookies or pixels to understand visits, store performance and customer journeys; and
  • Advertising cookies or pixels to measure campaigns and, where permitted, show more relevant advertising.

Where applicable law requires consent, non-essential cookies and pixels are used according to the choices available through our cookie or privacy banner. You may also limit cookies through your browser, although essential store functions may then stop working correctly.

Shopify’s banner governs Shopify cookies and Shopify Pixels. Cookies or pixels installed through other apps may be governed by those providers as well. We honour legally required consent and opt-out signals supported by our store platform.

8. Sale or sharing of personal data

We do not sell personal data for money.

Certain privacy laws use broader definitions of “sale,” “sharing” or targeted advertising that may include transferring cookie or device information to advertising partners. Where such laws apply, you may use the privacy choices presented on the store or contact support@mifoa.com to exercise an applicable opt-out right.

We do not knowingly sell or share the personal data of children for targeted advertising.

9. Communications

  • We send transactional messages about orders, payments, delivery, tracking, returns, refunds and support through email, SMS or WhatsApp as necessary to provide the service.
  • Marketing messages are sent only where permitted by law and according to your preferences.
  • You may unsubscribe from marketing email using the link in the message.
  • You may ask us to stop marketing SMS or WhatsApp messages by replying with an opt-out request.
  • Opting out of marketing does not stop essential transactional or service communications relating to an existing order.

10. International orders & data transfers

mifoa is based in India and ships to selected countries. When you order from outside India, personal data may be processed in India and in other countries where Shopify, Razorpay, payment networks, technology providers, couriers or customs authorities operate.

These countries may have privacy laws different from those in your country. Where applicable data-protection law requires safeguards for an international transfer, we rely on a recognised legal transfer mechanism, contractual protection, adequacy decision or another lawful basis appropriate to the transfer.

Some transfers are necessary to perform the order you requested, such as sending your name, delivery address and contact information to an international carrier and destination-country customs authorities.

You may contact support@mifoa.com for further information about the safeguards relevant to your personal data.

11. Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including:

  • Completing and supporting orders, returns, refunds and customer accounts;
  • Maintaining invoices and transaction records required by tax, accounting or other law;
  • Preventing fraud, enforcing agreements and resolving complaints or disputes; and
  • Maintaining marketing records until consent is withdrawn or the information is no longer required.

When information is no longer required, we delete, anonymise or securely dispose of it, subject to technical backup cycles and legal retention obligations.

12. Security

We use reasonable administrative, technical and organisational measures intended to protect personal data, including access controls, secure hosted infrastructure and limiting internal access to people who need the information for fulfilment, finance or support.

No internet transmission or storage system can be guaranteed completely secure. If we become aware of a personal-data breach, we will investigate and provide notifications required by applicable law.

13. Your privacy rights

Depending on your location and applicable law, you may have the right to:

  • Ask whether we process your personal data and request access to it;
  • Correct inaccurate or incomplete information;
  • Request deletion of information that is no longer lawfully required;
  • Request a portable copy of certain information;
  • Restrict or object to certain processing;
  • Withdraw consent for consent-based processing;
  • Opt out of certain targeted advertising, sale or sharing where applicable;
  • Nominate another person to exercise rights where applicable law provides this right;
  • Appeal or escalate an unresolved privacy request where applicable; and
  • Complain to an appropriate data-protection or consumer-protection authority.

To make a request, email support@mifoa.com. Describe the request and include enough information for us to locate the relevant account or order. We may need to verify your identity before disclosing or changing personal data.

These rights are subject to legal limitations. For example, we may need to retain invoices, transaction records or information connected with an unresolved dispute.

Your right to object: where we rely on legitimate interests, you may object to that processing. You may object to direct marketing at any time.

14. Automated fraud and security checks

Our payment, platform and security providers may use automated tools to identify suspected fraud, account misuse or payment risk. Where applicable law grants rights relating to a decision based solely on automated processing that has a legal or similarly significant effect, you may contact us to request information or appropriate human review.

15. Children

mifoa.com is intended for purchasers aged 18 and above. We do not knowingly collect personal data directly from children. If you believe a child has provided personal data without appropriate authorisation, contact us so we can investigate and take appropriate action.

16. Privacy and Grievance Officer

Grievance Officer

  • Dhananjay T — Mukshree Design Studio
  • Email: grievance@mifoa.com
  • Phone: +91 84474 10100
  • 801, Emaar Emerald Plaza, Sector 65, Gurugram – 122018, Haryana, India
  • Consumer complaints are acknowledged within 48 hours and addressed within one month, as required by applicable Indian e-commerce rules.

Questions or privacy requests

17. Changes to this policy

We may update this policy when our services, providers, technologies or legal obligations change. The effective date at the top identifies the latest version. Material changes will be communicated where applicable law requires notice or renewed consent.