Mahhala
Sign in

Privacy Policy

Last updated 12 September 2026

Effective date: 31 August 2026

This Privacy Policy explains how Mahhala ("Mahhala", "we", "us", "our") collects, uses, shares and protects your personal information when you use mahha.la and the related services, features, applications and emails we provide (together, the "Services").

Mahhala is a product-discovery platform. We help you find independent online stores and the products they sell, and we help those stores be found. We do not sell products ourselves. When you decide to buy something, you leave Mahhala and complete that purchase on the retailer's own website, under the retailer's own privacy policy.

By using the Services you agree to this Policy. Terms we use here without defining them have the meaning given in our Terms of Service.

Summary

  • We collect the information you give us (your account and profile), information about how you use Mahhala, and a small amount of technical information from your device.
  • We do not sell your personal information, we run no third-party advertising trackers, and nothing we do follows you to other websites.
  • Some products are promoted by the stores that sell them. Promoted placements are always labeled, and they are chosen by category, not by profiling you.
  • You can export your data at any time from your account settings. When you delete your account, your identity is erased immediately and everything that remains is destroyed within 30 days.
  • Mahhala is for adults. You must be 18 or older to hold an account.

Information we collect

Information you give us

Account information. To create an account we need an email address, a username and either a password or a connected Google or Facebook account, plus your confirmation that you meet our minimum age. Your display name starts as the part of your email address before the @ sign, and you can change it in your settings at any time. We store passwords only as a salted hash, so we never see or keep your actual password. If you sign in with Google or Facebook, the provider sends us your name, your email address, whether the provider has verified that address, a profile picture URL and an identifier for your account with them. We keep those and nothing else from the provider: no access token, no friends list, no posts, and we never post on your behalf. You can disconnect a provider from Security settings at any time. If you created an account by signing in with a provider and already had another Mahhala account, you can move that sign-in to the other account from Security settings; the account it came from is then closed and deleted as described under Deletion below, and nothing saved on it is carried over.

Profile information. Optionally: a display name, a short bio, an avatar image and whether your profile is public or private.

Optional demographic information. In your settings you may provide a date of birth, postal code and gender. These are optional and we would rather be exact about them than reassuring: today they are used for nothing except confirming your age and being included in your own data export. Our intention is to use them in aggregate, to understand which regions a store is popular in. If that ever extends further than aggregate reporting we will say so here first. They are not used to target promotions and they are not shared with anyone. Providing a date of birth also lets us confirm you meet the minimum age; if the date you provide is under our minimum age we do not store it, we suspend the account for review instead.

Store information. If you list or claim a store, we collect the store's name, website, description, logo, country and platform, plus the records of your verification attempts (domain match, DNS TXT record, or a file served from your domain).

Content you create. Favorites, collections, follows, blocks, product and store reports, support requests, and messages you send us or reply to.

Payment information, if you sell on Mahhala. Subscriptions and paid promotions are processed by Stripe. You enter your card details on Stripe's own hosted checkout, so we never see or store a full card number. What reaches us is the billing contact information and the last four digits Stripe returns, inside the event receipts we keep for 90 days so a payment cannot be processed twice and a dispute can be answered.

Waitlist requests. If a surface is not open yet and you ask to be told when it is, we keep the email address you gave us until we can invite you, and no longer than 180 days.

Communications. If you contact support or report a problem, we keep that correspondence so we can respond and improve.

Information we collect automatically

Usage and engagement. We record events such as a product being shown to you, viewed, clicked through to a retailer, shared, or saved, and views of profiles and collections. These events are what determine what counts as "trending" on Mahhala.

Each event is grouped under a random session identifier: the mhl_session cookie described in our Cookie Policy, set for mahha.la and its subdomains so that one visit is counted once even though shared links and the rest of the site are served from different hostnames. If you are signed in, the event also carries your account identifier, along with your IP address, browser user agent and the approximate location derived from that IP. We would rather say that plainly than describe these events as anonymous, because while your account exists they are not.

What that means in practice is set out under Data retention: these events are kept for a maximum of 400 days, and when you delete your account we erase your identifier and IP address from every event still held, so what remains counts toward the totals but is no longer connected to you.

Page views. Separately from the engagement events above, we record each page of Mahhala that is sent to your browser: the address of the page, the time, whether it loaded successfully, your browser user agent, and the approximate country, region and city derived from your IP address using an offline geolocation database. If you are signed in, the page view also carries your account identifier. We use this only to understand how much traffic the site gets and which pages people reach.

Two things about it are worth stating plainly. We do not store your IP address for this: the approximate location is worked out at the moment the page is sent and the address itself is discarded. And page views are grouped under a one-way hash of your session cookie rather than under a stable identifier, so a "visitor" here means a browsing session, not a person: if you come back tomorrow, or browse from a second device, that counts separately. These records are kept for a maximum of 400 days, and when you delete your account we erase your identifier, user agent and city-level location from every page view still held.

Searches. When a search finishes we record what was searched for, how many results it returned, and whether filters were applied, under the same identifiers as above. This is how we find out what people are looking for and cannot find, which is the single most useful signal we have for deciding which stores to bring onto the platform. We do not use it to build a profile of you or to target promotions.

Device and connection information. IP address, browser user agent, and the approximate location (usually city and country) we derive from your IP address using an offline geolocation database. We show this to you on your Security page so you can recognize your own sessions and revoke ones you do not.

Cookies and similar technologies. See our Cookie Policy for the full list. In short: cookies keep you signed in, protect forms against cross-site request forgery, remember trusted devices for two-factor authentication, group one visit's activity under a single anonymous session identifier, and remember whether you prefer the light or dark theme.

Security signals. We use Google reCAPTCHA Enterprise on the forms it protects: sign-up, sign-in, password recovery, password reset, and the waitlist. We do not load it anywhere else. Google's collection of information for that purpose is governed by the Google Privacy Policy and Terms of Service.

Information from other sources

If you claim a store, we may read publicly available information from that store's website, such as its title, description, logo, and similar metadata published in the page's own tags, to pre-fill the listing for you. We only ever read publicly published pages.

How we use your information

  • To provide the Services: your account, your feed, your favorites, your collections, and the stores you follow.
  • To rank and recommend: to work out which products, stores and collections are genuinely popular. Trending on Mahhala is earned from real engagement, not sold.
  • To choose promoted placements: promoted products are targeted by product category, not by building a profile of you.
  • To keep Mahhala safe: to detect fraud, spam and abuse, to act on reports, to enforce our Terms, and to confirm minimum age.
  • To communicate with you: verification emails, password resets, security notices, team invitations, export links, replies to your reports, and, for store owners, the operational notices about their store described below.
  • To take payment: to run subscriptions and paid promotions for store owners, and to answer chargebacks and disputes.
  • To improve the Services: aggregate statistics about how features are used, and what people search for and cannot find.
  • To comply with legal obligations and to establish or defend legal claims.

How we share your information

We do not sell your personal information. We do not share it with any third-party advertising network, we run no cross-site trackers, and nothing we do follows you to another website.

We share information only in these circumstances:

Publicly, at your direction. If your profile is public, your username, display name, avatar, bio, follower and following counts, and your public collections and favorites are visible to others. You control this: your profile can be made private, individual favorites can be marked private, and collections can be private. Store pages and store owner-facing information are public by their nature.

With store owners, in aggregate. Store owners see counts: views, click-throughs, shares, and saves for their own products. They do not see who you are.

With service providers. Companies acting on our instructions and bound to protect the data. The full list, and what each one gets:

Provider What it does What reaches it
Our hosting and storage provider Runs the servers, the databases, the file storage, and the encrypted off-site backups Everything the Services hold, as the infrastructure it runs on
Our email provider Delivers our email Your email address and the contents of the messages we send you
Google reCAPTCHA Enterprise Tells people apart from bots on the forms listed above The reCAPTCHA token, your IP address and browser signals
Google Sign-In and Facebook Login Let you sign in with an account you already have, only when you choose to Your choice to sign in, as any web request carries it; the provider then sends us the profile details listed under Account information above
Stripe Processes subscriptions and paid promotions for store owners The billing details you enter on Stripe's own checkout, plus the store's identifier
Anthropic Suggests a category for a product listing The product's title, brand and description. No user information is ever sent. Not your account, not your searches, not your activity

Our own ad delivery. Promoted products and paid placements are served by our own service at ads.api.mahha.la. Your browser fetches them directly, so that service receives your IP address and browser user agent as any web request carries them; it uses them to decide which country to serve and to avoid repeating the same promotion at you. It is sent no cookie and no account identity, it stores no profile, and it keeps the IP address and user agent for 90 days before clearing them. It is ours, not a third-party ad network, and it is why we can say there is nothing here that tracks you across the web.

When you leave Mahhala. When you click through to a retailer, that retailer's website receives the ordinary information any web request carries, and their privacy policy governs from that point.

For legal reasons. When we reasonably believe disclosure is required by law, or is necessary to protect the rights, property or safety of Mahhala, our users or the public.

In a business transfer. If Mahhala is involved in a merger, acquisition or sale of assets, your information may be transferred; we will give notice before your information becomes subject to a different privacy policy.

Your choices and rights

Access and export. You can request a copy of your data from your account settings. It contains your account record and demographics, your favorites, collections, follows and followed stores, your blocks, your store memberships, your notification settings, your sign-in history, remembered devices and connected sign-in providers, your correspondence with us, the reports and support requests you submitted, and the record of your own actions in our audit trail.

Three things are deliberately left out. Credentials, meaning your password, two-factor secrets, passkeys, session identifiers, and device tokens, because a file in your downloads folder should not be usable to sign in as you. Other people's personal information, beyond the usernames your own relationships already reference. And reports other people made about you, along with the identity of any staff member who acted on a report: reporting is confidential in both directions, and we will not let a request for your own data become the way around that. You will see that your account was acted on; you will not see who did it.

The export is prepared as a download link that stays valid for 24 hours, after which the file is deleted from our storage; you can request another at any time while your account exists. Store owners can export their store's data the same way, and an export already generated stays downloadable for its 24 hours even if the store is deleted in the meantime.

Correction. You can edit your profile, email address and store details at any time in settings.

Deletion. You can delete your account from your settings. It happens in two steps, and both of them are automatic.

Immediately, as you confirm it: your email address, username, display name, bio, avatar, location and demographics are erased and overwritten. Every credential is destroyed: your password, your sessions, your remembered devices, your trusted devices, your passkeys, your connected Google or Facebook accounts, and your two-factor secret. The account cannot be signed into again by anyone, including us. Your profile, collections and favorites disappear from Mahhala. Your name is removed from the audit trail, which keeps only the fact that some account performed the actions it records.

Within 30 days: everything that is left is destroyed. Your remaining rows are deleted, any data export you had generated is deleted from our storage, and your identifier and IP address are erased from the usage events described above.

We keep a small number of things beyond that, and only these: moderation records relating to reports made about content you posted (otherwise a pattern of abuse could be erased by deleting an account and making a new one), security audit entries recording what the account did, with no name attached, and any billing and tax records the law requires us to retain. Messages you sent to other people remain in their conversations, detached from you.

Deletion is permanent and there is no undo. If you want a copy of your data, export it before you delete.

Email. There are three kinds, and they are governed differently.

Transactional email is part of the Service and cannot be switched off while you hold an account: verification, password reset, security alerts, team invitations, export links, and replies to your reports.

Optional email about your activity, such as a new follower or a promotion from a store you follow, is off unless you turn it on, and every one of these carries an unsubscribe link.

Operational email for store owners is on by default, because a store owner who misses "your payment failed" loses the thing they are paying for. It covers a promotion started or ended, a placement approved or rejected, a payment that failed, and a team member who joined. You can turn any of it off from your store's notification settings. We send no product announcements or marketing mail today; if that ever changes, it will be opt-in.

Marketing. We do not sell your information and we do not send marketing email you have not asked for.

Do Not Track. We do not run cross-site behavioral advertising, so there is nothing for a Do Not Track signal to disable.

Region-specific rights. If you are in the European Economic Area, the United Kingdom or a US state with a comprehensive privacy law, you have rights to access, correct, delete, restrict and object to processing of your personal information, to data portability, and to lodge a complaint with your supervisory authority. Where we rely on consent you may withdraw it at any time. We rely on: performance of our contract with you (providing the Services), our legitimate interests (security, ranking, product improvement), consent (optional demographics, marketing email, and signing in through Google or Facebook, which happens only when you choose it), and legal obligation (including confirming minimum age). We will not discriminate against you for exercising any of these rights. To exercise them, use your settings or contact us at the address below.

Data retention

We keep your account information for as long as your account exists. Everything else is on a clock:

What How long
Usage, search and page-view events 400 days, then deleted automatically
Security and administrative audit records 400 days, then deleted automatically
Data exports you request 24 hours after the export is ready, then the file is deleted
Payment event receipts from Stripe 90 days
The IP address and user agent held by our ad delivery 90 days, then cleared
Waitlist requests Until we invite you, and no longer than 180 days
Session records on your Security page Until you revoke them, the session expires, or you delete your account

After you delete your account:

  • Your identifying information and every credential are erased immediately.
  • Everything remaining, including your export files and your identity within the usage events, is destroyed within 30 days.
  • Usage events that survive that erasure carry no identifier, IP address or user agent, and reach the 400-day limit above like any other.
  • Moderation records relating to reports are retained while the matter is open and for a reasonable period afterwards so that repeated abuse can be recognized.
  • Billing and tax records are retained for as long as the law requires.

Security

We protect your information with encryption in transit, encryption at rest for our databases and file storage, hashed passwords, encrypted message content, optional two-factor authentication, passkeys and sign-in with Google or Facebook, device and session management with the ability to revoke sessions, and an internal audit log of administrative actions. No system is perfectly secure, so we cannot guarantee absolute security. We do take it seriously, and we will notify you and any required regulator of a breach affecting your personal information as the law requires.

International transfers

Mahhala is operated from the United States, and your information is processed there. If you use the Services from outside the United States, you understand your information will be transferred to, stored and processed in the United States. Where required, we use appropriate safeguards such as the European Commission's standard contractual clauses.

Children

The Services are not directed to children. You must be at least 18 years old to hold a Mahhala account, and we ask you to confirm this before the account is created, whether you register with an email address or sign in with Google or Facebook for the first time. We do not knowingly collect personal information from anyone under 13. If we learn that we have, we delete it promptly. If you believe a child has provided us information, contact us at the address below.

Third-party links and embedded content

Mahhala links out to retailer websites, and some of our pages embed video from YouTube using its privacy-enhanced mode. We are not responsible for the privacy practices of those sites. Their policies govern the information they collect.

Changes to this Policy

We may update this Policy. When we make material changes we will update the effective date at the top and, where appropriate, notify you in the app or by email. Continuing to use the Services after a change means you accept the updated Policy.

Contact us

Questions, requests or complaints about this Policy or your personal information:

Mahhala Inc. Email: privacy@mahha.la

See also: Privacy Terms Cookies Help Center