top of page

Privacy Policy

Mahi Mahi Tech Solutions Private Limited ("Mahi Mahi", "we", "our" or "us") operates mahimahi.in and mAIven, our marketing technology platform. This Privacy Policy explains how we handle information in connection with our website, mAIven and related marketing services.

mAIven supports the managed marketing services delivered by Mahi Mahi. Our authorised team uses its analytics dashboard to review connected marketing data, prepare reports and develop recommendations. Clients may receive viewing access to their dashboards or reports.

This policy covers website visitors, business contacts, clients, authorised viewers and information processed through authorised integrations. Visiting our website does not authorise access to a Google account. Google connections require a separate authorisation process.

1. Our role in handling information

For website enquiries, business contact details, billing, service administration and our own security records, Mahi Mahi determines how and why information is processed.

For personal information contained in client data processed through mAIven on a client's instructions, the client generally acts as the controller or data fiduciary, and Mahi Mahi acts as its processor or service provider. The client is responsible for the notices, permissions and lawful instructions needed for its data. We remain responsible for our own obligations and handle that data under the applicable service agreement and law.

2. Information we collect

  • Business and contact information- This includes names, work email addresses, telephone numbers, company details, billing information, enquiry details, service instructions and correspondence supplied by you or your organisation.

  • Client-provided materials- We may receive business briefs, brand materials, documents and other information supplied for the services you request. Please do not provide unnecessary personal information, passwords or sensitive records such as government identification or health information.

  • Connected Google data- With authorisation, mAIven reads data from Google Analytics 4 (GA4) and Google Search Console (GSC). This includes relevant account or property identifiers, website/property names and reporting data described in Section 5. We also process connection status, authorisation tokens and the analytics or reports derived from that data.

  • Technical and usage information- We may collect IP addresses, browser and device information, timestamps, pages or dashboard features used, session identifiers, errors and diagnostic records when you interact with our website or services. These records are distinct from the traffic metrics imported from a client's GA4 property.

Analytics reports generally contain metrics and dimensions rather than named visitor records. However, page URLs, queries or client-supplied fields can contain identifying information. We do not assume that all analytics data is anonymous merely because it appears in a report.

3. How we use information

We use information to deliver the services you request, administer client relationships, provide authorised dashboard viewing, analyse marketing performance, prepare reports and recommendations, respond to enquiries, manage billing, maintain service reliability and meet legal obligations.

We use technical and product-usage information to identify errors, protect access and improve usability. Any use of connected Google data is subject to Sections 5 and 6; this general improvement purpose does not authorise unrelated reuse of client analytics.

Where we send business or promotional communications, you may ask us to stop. Necessary service, security and legal communications may continue.

4. Google Analytics and Search Console integrations

Authorisation and read-only access

An authorised Google account holder grants access through Google's OAuth authorisation process. We request these read-only permissions for the integrations selected:

  • Google Analytics 4: analytics.readonly, to read website traffic and engagement reports, including page-level performance and relevant acquisition metrics.

  • Google Search Console: webmasters.readonly, to read search-performance reports, including queries, pages, clicks, impressions, click-through rates and average position.

  • The permissions are granted at Google's scope level; the properties to be used for your service are designated during setup. mAIven limits reporting to those designated properties and the data needed for the agreed service. We may read property identifiers and names to establish the connection.

  • These integrations do not create, modify or delete data in your Google account. They do not grant access to Gmail, Google Drive or other unrelated Google services. We never receive or store your Google password.

 

Purpose and storage

We use the connected data to populate your dashboard, compare reporting periods, assess website and search performance, and prepare client-specific insights and recommendations. We store encrypted refresh tokens to support scheduled retrieval while a connection remains authorised, together with relevant reporting metrics and derived analytics. mAIven is hosted using Google Cloud.

Access by our team

Because the service includes analysis by Mahi Mahi personnel, we obtain affirmative permission identifying the relevant properties and data before our team views Google data for this purpose. Access is limited to authorised personnel who need it for the agreed service and are subject to confidentiality requirements. This permission can be withdrawn by contacting us.

Disconnecting a source

The Google account holder can revoke access through Google Account connections. You can also ask Mahi Mahi to disconnect a source by emailing business@mahimahi.in. You do not need editing or administrative access to mAIven to make this request.

Once a disconnection is processed or revocation is detected, we stop scheduled retrieval and promptly revoke, where applicable, and delete the stored tokens. Reconnection requires fresh authorisation. Revocation alone does not erase reports already held by Mahi Mahi; Section 9 explains their retention and deletion. Deleting our copies does not delete the original data in your Google account.

 

5. Google API Limited Use commitments

mAIven's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

We do not sell Google data, use it to serve or target advertisements, disclose it to data brokers, or use it for credit or lending decisions. We do not use it to train shared or general-purpose AI models. Aggregation or anonymisation does not remove these restrictions.

Transfers are limited to consented delivery of the disclosed service, necessary security or legal purposes, or a business transfer with the user's prior explicit consent. Apart from the affirmative permission described above, human access is limited to Google's permitted security, legal and internal aggregated-data exceptions.

These protections also apply to derived data and take priority over broader provisions in this policy. We do not repurpose one client's Google analytics for another client's reports or for unrelated benchmarking.

6. AI and automated analysis

Customer data is never used to train shared AI models. For the current mAIven analytics service, we do not send customer content, Google data or derived analytics to third-party AI providers for processing, inference, training or fine-tuning. Cloud hosting is separate from sending data to an AI model service.

Any automated analysis is used to support the agreed marketing service. If we introduce a feature that changes these data flows, we will explain the change and obtain any required authorisation before using data in the new way.

7. When information is disclosed

Information may be made available to authorised Mahi Mahi personnel and to the client's authorised representatives or viewers as needed to deliver the service.

We use service providers for functions such as cloud hosting, storage, technical support, business communications and billing administration. Google Cloud provides mAIven's hosting infrastructure. Providers receive only information needed for their assigned work and are subject to appropriate confidentiality and data-protection obligations. You may contact us for details of providers relevant to your service.

 

We may also disclose necessary information to professional advisers, to comply with lawful requests or protect security, or in connection with a merger, acquisition or business reorganisation, subject to applicable safeguards. Google data remains subject to Section 6, including its stricter consent requirement for business transfers.

 

We do not sell personal information or share it for cross-context behavioural advertising.

 

8. Retention and deletion

 

We retain information only while needed for the disclosed purpose, the client's lawful instructions or applicable legal requirements. An active service relationship does not justify keeping every category of information indefinitely.

 

  • Connection tokens. Tokens are retained only while required for an authorised connection. They are promptly revoked, where applicable, and deleted when the connection ends. The one-year period below does not apply to usable connection tokens.

  • Routine offboarding. When a source is disconnected or the relevant service ends, imported metrics, derived analytics and associated reports are retained only where needed for agreed historical reporting, service handover or another permitted, documented purpose. The routine retention period is no more than one year from that event, unless a shorter period is required by the client agreement or law. We delete data sooner when there is no continuing need. Retention does not authorise new data collection or new uses.

  • Deletion requests. You may request deletion at any time using Section 12. We process valid requests without undue delay and within applicable legal deadlines. The routine one-year period is not a waiting period for such requests. Where we act for a client, we coordinate with that client and follow its lawful instructions.

  • Backups. Residual copies may remain temporarily in restricted backups pending scheduled deletion, where legally permitted. They are not used for routine service delivery. Our deletion schedule includes backup expiry within the applicable maximum retention period; a separate extra year is not added for backups. If a backup is restored for recovery, applicable deletion instructions are reapplied.

  • Required records. Limited billing, tax, security, consent or legal-claim records may need a different retention period. Any exception is limited to the information and duration justified by the relevant requirement. It does not automatically extend retention of the client's entire analytics dataset. We explain material limits on a deletion request unless legally prohibited.

 

9. Cookies and similar technologies

Our website and services use essential cookies and limited product-analytics technologies for functions such as session management, security, preferences and understanding product performance. We do not use advertising or retargeting cookies, and we do not authorise third-party tracking of individuals across unrelated websites for advertising through these services.

Product analytics is not automatically treated as strictly necessary. Where consent is required for a non-essential technology, we obtain it before use. Browser controls let you block or delete cookies, although blocking essential cookies can affect service functionality.

Our use of these technologies does not itself authorise a connection to your GA4 or GSC property.

 

10. Storage, international processing and security

 

mAIven uses Google Cloud infrastructure. The primary hosting and backup locations are: [Insert verified countries/regions]. Our authorised team processes service data in India. Depending on the service-provider arrangement, information may also be processed in other countries with different privacy laws. Where required, we use appropriate contractual protections and other safeguards for international transfers.

We maintain reasonable administrative, technical and organisational safeguards, including protection of data in transit and at rest, encrypted authorisation tokens, access restrictions and confidentiality controls. Access is limited according to service responsibilities. No system is completely secure.

If a security incident affects personal information, we investigate and take appropriate action, and notify affected clients, individuals or authorities as required by applicable law and our agreements.

 

11. Your choices, requests and privacy rights

 

You can ask us to explain our processing, correct contact information, stop optional communications, disconnect an integration or delete information. Depending on the law that applies, you may also have rights to access or receive a copy of personal information, restrict or object to processing, withdraw consent, obtain portability, appeal a decision or complain to a relevant authority.

Send requests to business@mahimahi.in, identifying your organisation and the information or property concerned. We may reasonably verify your identity and authority. Please do not send passwords, tokens or unnecessary identity documents. An authorised agent may submit a request where permitted by law.

If the information belongs to a client-controlled dataset, we may refer the request to that client and assist it with a response. A visitor to a client's website should normally contact that website operator first. This does not limit our own obligations.

Rights under Indian law and applicable US state laws, including California law, apply according to their scope and commencement. We do not discriminate for exercising applicable privacy rights. Withdrawal of access may prevent us from delivering the affected analytics features; it does not retrospectively invalidate lawful processing already carried out.

Our grievance contact is listed below. We address complaints within applicable deadlines, including the one-month period where India's SPDI Rules require it. If we cannot fulfil a request, we explain the reason and any available review or complaint route.

12. Children's information

Our services are intended for business users aged 18 and over, not for children. We do not knowingly seek personal information directly from children. If you believe a child has supplied information to us, contact us so we can investigate and take appropriate action. Clients remain responsible for lawful collection through their own websites; aggregate reporting does not establish the age of every underlying visitor.

13. Third-party services

Google and other third parties operate their own services under their own privacy policies. This policy explains Mahi Mahi's handling of information, including copies we receive through authorised connections. Links to other websites do not place those websites under our control.

14. Changes to this policy

We may update this policy and revise the date shown above. We will notify affected clients of material changes through email or another appropriate service notice. Where a change requires consent or fresh integration authorisation, we obtain it before the new processing begins. Continued website use alone is not treated as consent to a new use of Google data.

 

15. Contact us

Mahi Mahi Tech Solutions Private Limited

Registered office: 48, Church St, Haridevpur, Shanthala Nagar, Ashok Nagar, Bengaluru, Karnataka 560001

Privacy and grievance contact: business@mahimahi.in

Telephone: +91-8660474712 | Website: www.mahimahi.in

© 2026 | mahi mahi tech solutions pvt. ltd.

48, Church St, Haridevpur, Shanthala Nagar, Ashok Nagar, Bengaluru, Karnataka 560001

+91-8660474712

bottom of page