Privacy policy
What MARG Ship collects, why, who it goes to, and how long it is kept.
Last updated 14 August 2026
MARG Ship is operated by Marka Modern Retail Private Limited ("MARG", "we"). It is shipping software for merchants: it turns an order into a booked courier shipment, follows the parcel, and reconciles what the merchant is owed.
The short version. A merchant's store data flows to MARG so that parcels can be booked and tracked. Buyer names, addresses and phone numbers are encrypted before they are stored, are shared only with the courier carrying that parcel, and are erased on request. MARG does not sell data, does not use it for advertising, and does not use it to train models.
1. Who controls the data
The merchant is the data controller for their buyers' personal data. MARG is a data processor acting on the merchant's instructions. We process personal data only to provide the shipping service the merchant has asked for.
2. What we collect, and why
| Data | Why it is needed |
|---|---|
| Order number, value, payment mode, items, weight | To choose a courier, price the shipment and reconcile cash on delivery |
| Buyer name, delivery address, phone number, email | A courier cannot deliver a parcel without them. These are printed on the shipping label and sent to the courier carrying that parcel. |
| Courier scan events | To show where a parcel is and to handle failed deliveries |
| Merchant staff email, name and role | To sign people in and record who did what |
We request the minimum access needed for this. We do not request or store payment card details, and we do not read a store's products, themes or customers beyond the orders being shipped.
3. Who we share it with
- Couriers — Delhivery, XpressBees, Blue Dart and Ekart. Each receives only the parcels it is carrying, and only the fields needed to deliver: name, address, phone, weight and any amount to collect.
- Meta (WhatsApp) — only where the merchant enables buyer notifications, and only the phone number and template values needed to send that message. This is off by default.
- Microsoft Azure — our hosting provider. Data is stored in the Central India region.
We do not sell personal data, share it with advertisers, or use it to train machine-learning models.
4. How it is protected
- Encrypted at rest. Buyer names, street lines and email addresses are encrypted with AES-256-GCM before they are written. The key is held in a separate key vault, so a copy of the database yields ciphertext.
- Encrypted in transit. HTTPS everywhere, and the database connection refuses to start without TLS.
- Separated per merchant. Every table is protected by database row-level security keyed to the merchant. The application proves this holds at every start-up and refuses to run if it does not.
- Encrypted backups. Backups are encrypted before they are written; the process refuses to produce a readable one.
- Limited staff access. MARG staff see aggregate figures for a merchant, never a buyer's name, address, phone or email. Every internal access is written to an access log, including refusals.
5. How long we keep it
- While the app is installed, order and shipment records are kept so the merchant can trace parcels, answer buyer queries and settle courier claims.
- Buyer personal data is erased 24 months after the last order for that buyer, or sooner on request.
- After uninstall, the store's access token is destroyed immediately. Remaining data is erased on request, and in any case when Shopify sends its shop redaction request 48 hours after uninstall.
- Operational records — order number, weight, courier, charge — are retained after erasure for tax and courier-billing purposes. They contain no personal data once the personal fields are cleared.
- Backups roll off after 14 days.
6. Buyer rights
A buyer's relationship is with the merchant they bought from, so requests should go to that merchant, who can pass them to us. We act on them within 30 days.
We also handle these automatically. When a buyer asks a merchant's store for their data or for erasure, that request reaches MARG directly and we act on it:
- Data request — we return what we hold about that buyer.
- Erasure — we clear that buyer's name, address, phone and email, and the raw order payload.
- Store closure — we clear buyer personal data for the whole store and destroy the access token.
Depending on where a buyer lives, they may also have rights of access, correction, erasure, portability and objection under laws including India's Digital Personal Data Protection Act 2023 and the EU/UK GDPR.
7. Cookies
MARG sets one cookie, to keep a signed-in merchant user signed in. There are no advertising or analytics cookies, and no third-party trackers. The public parcel tracking page sets no cookies at all and shows only a status and a city.
8. Children
MARG is business software and is not directed at children. We do not knowingly collect data from anyone under 18.
9. Changes
If this policy changes materially, the date at the top changes and merchants are notified before the change takes effect.
10. Contact
Questions, requests or complaints: tech@houseofmarka.com
Marka Modern Retail Private Limited, India.