How Mugikari collects and handles data. Last updated: September 2026.
Mugikari operates an e-commerce software platform providing hosted storefronts (/store/name), embeddable shopping cart widgets, seller management dashboards, and order notification processing.
With respect to seller account data, Mugikari acts as the Data Controller. With respect to buyer order information submitted during checkout through a seller's storefront or embeddable widget, Mugikari acts as a Data Processor on behalf of the seller (the Data Controller).
Seller Account Data: Name, email address, password hashes, store name, notification email settings, and custom storefront configuration.
OAuth Sign-in Data: If you authenticate using Google Sign-in, we receive basic profile information including your email address, full name, and unique Google ID.
Buyer & Order Data: When a customer places an order via a hosted storefront or widget, we collect their name, email address, phone number, delivery address, ordered items, and shipping preferences on behalf of the seller.
Technical & Operational Data: IP addresses, session security cookies, rate-limiting metadata, and transactional email logs.
To provision and maintain your seller account, secure dashboard access, and route automated order notification emails.
To calculate store metrics, order status tracking, and revenue analytics for sellers.
We do not sell, rent, trade, or monetize personal data or customer records to any third-party advertisers.
Mugikari facilitates Mobile Money (MTN MoMo / Airtel Money) checkout instructions and payment logs for sellers.
Mugikari never requests, accesses, or stores buyer Mobile Money PINs or confidential banking secrets. All payments are processed directly between the buyer and seller or through secure payment gateway partners.
Cloudinary: Product image assets uploaded by sellers are hosted and optimized via Cloudinary's secure media storage.
Transactional Email Service (Brevo/Nodemailer): Order receipt notifications and account verification emails are dispatched via enterprise email delivery networks.
Google Authentication: Google OAuth manages federated sign-in tokens for sellers opting into Google login.
We utilize essential httpOnly, signed session cookies ('token') expiring after 7 days to maintain secure dashboard access.
Embeddable cart widgets utilize minimal client-side browser storage solely to preserve a buyer's cart items during active browsing sessions.
Sellers are solely responsible for complying with consumer protection laws, fulfilling customer orders, managing returns, and maintaining their own customer privacy disclosures.
Mugikari provides software infrastructure 'as is' and is not liable for merchant inventory disputes, undelivered physical goods, or transactional disputes between buyers and sellers.
We retain seller account and order records while your account remains active.
Sellers can request store deletion and full data erasure at any time via the Seller Settings dashboard or by contacting support. Upon account deletion, all associated store products, customer lists, and API keys are permanently purged.
We may update this Privacy Policy periodically. Continued use of Mugikari after notice of changes constitutes acceptance of the revised terms.
For privacy inquiries, data export requests, or erasure requests, contact: mugikari.app@gmail.com