Privacy policy

Last updated: 16 September 2026
This version effective from: 16 September 2026

1. Who we are

Mythed Lifestyle Private Limited ("Mythed", "we", "us", "our") is a private limited company incorporated in India, operating the online store at mythed.co.

  • Legal name: Mythed Lifestyle Private Limited
  • CIN: U18129WB2026PTC288966
  • Registered office: 334/B, Acharya Jagadish Chandra Bose Road, Post – Thakurpukur, Kolkata – 700063, West Bengal, India
  • Website: https://mythed.co
  • Contact: hello@mythed.co

For the purposes of the Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for personal data collected through mythed.co. You are the Data Principal.

2. Scope

This policy covers personal data we collect through mythed.co, our order and delivery process, our email communications, our customer support channels, and our advertising on Facebook and Instagram. It does not cover third-party websites or platforms we link to, such as a courier's tracking page or Facebook and Instagram themselves. Those have their own privacy policies.

3. What personal data we collect

3.1 Data you give us directly

  • Contact and delivery details — full name, delivery address, city, state, PIN code, mobile number, email address. Collected at checkout.
  • Billing details — billing name and address, if different from delivery.
  • Order details — products ordered, design name, size, colourway, quantity, order value, discount codes used, order date.
  • Account details — email address and a password (stored by Shopify in hashed form; we never see it), saved addresses and order history. Only if you choose to create an account.
  • Communications — emails to hello@mythed.co, contact form submissions, messages sent to our Facebook Page or Instagram account, and anything you choose to include in them.
  • Product reviews — if you choose to review a purchase: your name as you enter it, email address, star rating, review text, and any photos or videos you upload. Reviews you submit are published on mythed.co and may also appear in Shopify's Shop app.
  • Returns and exchange data — reason for return or exchange, size or fit feedback, and any photographs you send us of the product.
  • Marketing preferences — whether you have opted in to marketing emails, and your unsubscribe status.

3.2 Data collected automatically

  • Device and connection data — IP address, browser type and version, device type, operating system, screen resolution, language setting.
  • Usage data — pages and products viewed, time on page, referring website, on-site search terms, items added to and removed from cart, checkout steps reached.
  • Advertising data — whether you arrived at mythed.co from a Facebook or Instagram ad (an ad-click identifier), and store events such as product views, add-to-cart, checkout started and purchases completed. See Sections 6 and 7.
  • Cookie identifiers — session, analytics and advertising identifiers set by cookies and similar technologies. See Section 6.

Your IP address gives an approximate geographic region, typically at city level. We do not collect precise GPS location.

3.3 Data we receive from third parties

  • Razorpay (payment gateway) — payment status, payment method type, a masked reference such as the last four digits of a card or a UPI handle, transaction reference number, and refund status.
  • Huepress Fashion Private Limited, operating as Qikink (production and fulfilment) — production status, dispatch confirmation, AWB or tracking number, delivery status, and return-to-origin status.
  • Courier partners — delivery attempts, delivery confirmation, and failure reasons.
  • Meta Platforms (Facebook and Instagram advertising) — aggregated reports on ad reach and performance, and conversion reporting showing whether an ad led to a visit or a purchase. These reports do not identify you to us by name.

3.4 What we do not collect

  • Full payment credentials. Your complete card number, CVV, card PIN, UPI PIN, net-banking password and OTP are entered directly in Razorpay's secure environment. They are never transmitted to or stored on our systems, and they are never shared with advertising platforms.
  • Government identifiers. We do not ask for Aadhaar, PAN, passport or any government ID for a retail order.
  • Sensitive personal data such as health information, biometric or genetic data, caste, religion, sexual orientation, or political affiliation.
  • Cash-on-Delivery verification data. We do not offer Cash on Delivery, so no COD-related identity or phone-verification data is collected.

4. Why we use your personal data

  • To process your order, produce the garment, and deliver it.
  • To take payment, issue refunds, and screen for fraudulent transactions.
  • To send transactional messages — order confirmation, dispatch notification, tracking link, delivery confirmation, refund confirmation — and your GST tax invoice.
  • To ask for a review after delivery, and to publish the reviews you choose to submit.
  • To handle returns, exchanges, and return-to-origin shipments.
  • To respond to your questions and complaints.
  • To send marketing about new drops, restocks and offers — only if you have opted in.
  • To measure whether our Facebook and Instagram ads lead to visits and purchases, to show our products on Facebook and Instagram, and to show relevant ads to people who have visited our store — subject to your cookie choices.
  • To understand how the store is used and improve it.
  • To comply with tax, accounting and company-law obligations.
  • To protect the store against fraud, abuse and security incidents.

We do not use your personal data for automated decision-making that produces legal effects for you, and we do not build behavioural profiles for sale or transfer to anyone else. Using Meta's advertising tools to reach people who have visited our store is not a sale of your personal data.

5. Our legal basis for processing

India's data protection framework is currently in transition. The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 apply today. The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and their substantive obligations take effect on 13 May 2027. We are aligning our practices with them ahead of that date.

On that basis we process your data:

  • With your consent — for marketing communications, and for non-essential cookies, including analytics and advertising cookies.
  • For the performance of our contract with you — to fulfil, deliver and support the order you have placed.
  • To comply with legal obligations — retention of invoices and books of account under tax and company law.

You can withdraw consent at any time (Section 10). Withdrawing marketing consent does not affect transactional messages about an order you have already placed, which we must send to fulfil the contract.

6. Cookies and similar technologies

A cookie is a small text file placed on your device by a website. We use the following categories:

  • Strictly necessary — keeps your cart contents, maintains your session, secures checkout, and records your cookie preferences. The store cannot function without these. Examples: cart, cart_sig, _secure_session_id, secure_customer_sig, keep_alive, _tracking_consent. Session to 1 year.
  • Functional — remembers preferences such as language and currency. Examples: localization, cart_currency. Session to 2 weeks.
  • Analytics and performance — counts visits, measures which products and pages get attention, and identifies where checkout is failing. Used in aggregate. Examples: _shopify_y, _shopify_s, _shopify_sa_t, _shopify_sa_p. 30 minutes to 2 years.
  • Marketing and advertising — set through the Meta Pixel. Measures whether a Facebook or Instagram ad led to a visit or a purchase, and allows us to show ads to people who have visited our store. Examples: _fbp, _fbc (set on mythed.co), and fr (set by Meta on its own domains). Up to 90 days.

Cookie names and lifespans are set by Shopify and Meta and may change when they update their platforms.

6.1 How to control cookies

  • In your browser: all major browsers let you block or delete cookies through their settings. Blocking strictly necessary cookies will break the cart and checkout.
  • On our store: where we display a cookie preferences control, you can change your choice through it at any time.
  • Global Privacy Control: where your browser sends a GPC signal, we honour it as an opt-out of non-essential tracking.
  • Advertising preferences on Facebook and Instagram: you can control how Meta uses activity from other websites, and which ads you see, in your Facebook or Instagram account under Accounts Centre > Ad preferences.

7. Third parties we share data with

We share personal data only with the service providers below, only to the extent each needs it, and only under contractual terms that require them to protect it. We do not sell your personal data, and we do not share it with data brokers.

  • Shopify Inc. / Shopify International Ltd. — storefront hosting, checkout, order database, customer accounts, store analytics and transactional email. Receives contact, delivery, billing, order, account, usage and cookie data. Processed in Canada, the United States, Ireland, Singapore and other Shopify regions.
  • Razorpay Software Private Limited — payment gateway: authorisation, capture, settlement and refunds. Receives name, email, phone, order reference and amount. Your card, UPI and bank credentials go directly to Razorpay and never pass through our systems. Processed in India.
  • Huepress Fashion Private Limited (Qikink) — print-on-demand production, quality check, packing, dispatch and return handling. Receives name, delivery address, PIN code, phone number, order line items and sizes. Processed in India.
  • Courier partners — assigned per PIN code, typically Delhivery, Blue Dart, XpressBees, Ekart, DTDC or Shadowfax. Receive name, delivery address, PIN code and phone number. Processed in India.
  • Google LLC / Google India Private Limited — business email hosting for hello@mythed.co via Google Workspace. Receives the content of emails you send us. Processed in India, the United States and other Google regions.
  • Astral (developer of the GST Pro app), Kochi, India — generates GST-compliant tax invoices and GST reports, and emails your invoice to you. Receives name, email address, phone number, billing and delivery address, and order details. Processed on behalf of Mythed.
  • Judge.me Ltd — product reviews: sends review-request emails after delivery, collects and displays reviews, and shares published reviews with Shopify's Shop app. Receives name, email address, order details (products purchased and order date), and the content of any review you submit. Acts as our data processor. Processed outside India. You can unsubscribe from review-request emails using the link in any such email.
  • Meta Platforms, Inc. — advertising on Facebook and Instagram, ad measurement, and our product catalogue on those platforms. Through the Meta Pixel and Shopify's server-side connection to Meta, it receives cookie and device identifiers, IP address, browser information, the pages and products you view, add-to-cart, checkout and purchase events (including the products and order value), and your email address and phone number in hashed (encrypted, irreversible) form, which Meta uses to match store activity to Facebook and Instagram accounts. It never receives your payment credentials. Meta's own use of this data is also governed by Meta's Privacy Policy. Processed in the United States and other Meta regions.

We may also disclose personal data where legally required — for example to a tax authority, a court, or a law enforcement agency acting under lawful authority — and to our accountants and legal advisers, who are bound by professional confidentiality obligations.

If we add further processors, such as another analytics or advertising platform, an email marketing platform or a messaging provider, we will update this section before those tools go live.

8. Transfers outside India

Some providers above, notably Shopify, Google, Meta and Judge.me, process data on servers outside India. The DPDP Rules, 2025 permit transfers of personal data outside India except to countries or territories specifically restricted by notification of the Central Government. As at the date of this policy, no such restricted list has been notified. Where transfers occur, we rely on the contractual data protection terms in our agreements with those providers.

9. How long we keep your data

  • Order records, tax invoices and books of account — 8 years from the end of the relevant financial year, as required under the Companies Act, 2013 and the Central Goods and Services Tax Act, 2017.
  • Customer account data — until you delete your account, plus up to 90 days in backups.
  • Marketing subscriber data — until you unsubscribe. We then retain your email address on a suppression list indefinitely, solely so that we do not email you again.
  • Customer support correspondence — 3 years from the date of the last message.
  • Returns, exchange and RTO records — 3 years from the date of the order.
  • Analytics and cookie data — per the cookie lifespans in Section 6, and up to 14 months for aggregated analytics reports.
  • Product reviews — for as long as the review is published. You can ask us to remove your review at any time.
  • Advertising audiences — audiences of store visitors in our Meta ad account keep a person for no more than 180 days after their last visit. Data received by Meta is retained by Meta under its own policies.

Once a retention period ends, we delete the data or irreversibly anonymise it.

10. Your rights

You have the right to:

  • Access a summary of the personal data we hold about you and how we process it.
  • Correct, complete or update inaccurate or incomplete data.
  • Erase personal data where it is no longer needed and we are not required by law to keep it.
  • Withdraw consent at any time. For marketing, use the unsubscribe link in any marketing email or write to us. For advertising cookies, see Section 6.1. For review-request emails, use the unsubscribe link in the email.
  • Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
  • Raise a grievance with us (Section 14) and, if unresolved, with the Data Protection Board of India.

How to exercise a right: email hello@mythed.co with the subject line "Privacy Request". Tell us which right you are exercising and include the email address or order number associated with your account so we can identify you.

We aim to respond within 7 working days. The maximum period in which we will respond is 90 days, as set out in Rule 14(3) of the DPDP Rules, 2025.

Some requests cannot be fully honoured. For example, we cannot delete an invoice we are legally required to keep, and we cannot erase data already transferred to a courier for a delivery in progress.

11. How we protect your data

  • mythed.co runs over HTTPS with TLS encryption across the entire site, including checkout.
  • Payments are processed by Razorpay, a PCI-DSS Level 1 certified payment gateway. No card, UPI or banking credentials are stored on our systems at any point.
  • Account passwords are hashed and salted by Shopify and are not visible to us in readable form.
  • Email addresses and phone numbers shared with Meta for ad matching are hashed before they are sent.
  • Access to the Shopify admin, which holds order and customer data, is limited to authorised personnel and protected by two-factor authentication.
  • We share only the minimum data each provider needs. Our production partner receives what is required to make and ship the parcel, not your payment or browsing data.

No method of transmission or storage is completely secure. While we take these measures seriously, we cannot guarantee absolute security.

12. Data breaches

If a personal data breach occurs, we will notify the Data Protection Board of India and the affected individuals in the manner and within the timelines required under Rule 7 of the DPDP Rules, 2025. Our notification will describe what happened, what data was affected, what steps we are taking, what you can do to protect yourself, and how to contact us.

13. Children

mythed.co is intended for people aged 18 and over. We do not knowingly collect personal data from children, and we do not direct advertising at children. Indian law requires verifiable parental consent before processing a child's personal data and prohibits tracking, behavioural monitoring and targeted advertising directed at children. If you believe a child has provided us with personal data, contact hello@mythed.co and we will delete it.

14. Grievance Officer

In accordance with the Information Technology Act, 2000 and the Consumer Protection (E-Commerce) Rules, 2020:

  • Name: Santosh Naskar
  • Designation: Director
  • Email: hello@mythed.co
  • Address: 334/B, Acharya Jagadish Chandra Bose Road, Post – Thakurpukur, Kolkata – 700063, West Bengal, India
  • Support hours: Monday to Saturday, 10:00 to 17:00 IST, excluding public holidays

We will acknowledge your complaint within 48 hours of receipt and endeavour to resolve it within one month. If you are not satisfied with our response, you may escalate to the Data Protection Board of India once its complaint mechanism applies to your matter, or to the National Consumer Helpline at 1915.

15. Changes to this policy

We may update this policy as our business, our service providers or the law changes. The "Last updated" date at the top will always reflect the current version. If we make a material change to how we use your personal data, we will tell you by email or by a prominent notice on the store before it takes effect.

16. Contact us

Mythed Lifestyle Private Limited
Email: hello@mythed.co
Registered office: 334/B, Acharya Jagadish Chandra Bose Road, Post – Thakurpukur, Kolkata – 700063, West Bengal, India

This policy should be read together with our Terms of Service, Shipping Policy, and Return & Refund Policy.