Munodha › Privacy

Privacy policy

This covers the Munodha website, the standalone CarryLeads web app, and the three Shopify apps. Each Shopify app also publishes its own policy inside the app, and where the two differ, the app policy governs that app.

This website

What munodha.com collects.

The website uses Google Analytics to count visits and understand which pages are read. That sets analytics cookies and shares usage data with Google. The site runs no advertising trackers, and it has no accounts and no logins, so it never collects passwords, postal addresses or payment details.

Most pages carry a short form, and this section changed when they were added. The email box asks for an address only, so we can tell you when something new ships. The form on the contact page also asks for a name, which is optional, and for the message you want to send. What you submit is stored on Munodha’s own server in Munodha’s own database, and is not passed to a mailing-list service, an advertising network or any other third party. It is not used for anything except the purpose the form states, every email sent from it can be unsubscribed from, and we keep it until you ask us to remove it: write to support@munodha.com from the address you used and we will delete it.

The COD and RTO calculator has input fields, but they are not a form we receive. The arithmetic runs in your browser, nothing is submitted, nothing is stored on your device, and the figures you type never reach us. Closing the tab discards them. The email box further down that page is a separate form, and it sends only the address you type into it.

Writing to support@munodha.com, or using the contact form, means we hold your email address and whatever you put in the message, for as long as needed to answer it and keep a record of the exchange.

CarryLeads on the web

What the standalone service uses.

You sign in with Google, so Munodha does not receive or store a Google password. The service verifies the Google sign-in token, keeps a signed session cookie in your browser for up to 30 days, and stores a one-way hash of your Google account identifier with the number of free prospect results you have used. The cookie contains the Google account identifier and email needed to maintain the session.

From the CarryLeads release that adds sign-in records, the service also keeps a private sign-in record keyed on that same one-way hash, not on your email. It holds when the service first and last observed you signing in, how many sign-ins it has seen, and the name, email address and email-verified flag exactly as Google supplied them at your latest sign-in, where Google supplied them. Google’s flag means Google verified the address at some point, not that you still control it. “First observed” means first seen by this record, not proof of a new signup, because earlier sign-ins are not backfilled. Sign-in uses the same Google button as before: no new Google permissions, no Gmail or Contacts access, and no Google access or refresh tokens are kept.

The same release keeps a timestamped log of successful sign-ins and of a fixed list of interactions: opening the app, clicking sign in, submitting a search, and using the email, text or copy hand-off buttons. Each entry records the server’s time of receipt, the hashed account key when you are signed in, and an opaque visit identifier. An entry for opening the app may also record the source, medium, campaign and content labels from the link you followed, limited in length and with anything that looks like an email address or phone number replaced. The log does not record your IP address, browser details, page address, what you type into the search form, or lead content. To connect a sign-in with the campaign and clicks earlier in the same browser visit, the service sets an HttpOnly visit cookie holding a random, signed identifier. A visit ends 30 minutes after its last event and at most 12 hours after it began, and signing in or out ends it. No IP, device or cross-browser matching is used, so these records are not a complete history of how you found or used CarryLeads.

Names and email addresses in these records stay private to Munodha in owner-only files on the service host. No web address reads them, and they are not written to server logs, Google Analytics or URLs. By default, reports cover the last 90 days of logged events, and name and email are cleared from accounts with no sign-in for 365 days, leaving only the hashed count. Removal by age is not automatic: it happens when Munodha runs a manual clean-up on the server, so older entries can remain until then. The interaction log is also capped at two files of about 5 MB each, and once that is full the oldest entries are removed, which can be sooner than 90 days.

Your search terms go to Google Places to find public business listings. Business and prospect context goes to OpenAI when you request editable outreach copy. If optional company enrichment is made available and you choose it, company name and location may go to Apollo. Search results and drafted copy are returned to your browser and are not retained by the current standalone service.

CarryLeads does not sell this data, use it for advertising, or send outreach for you, and signing in is not treated as permission to send you marketing email. To request access to or deletion of your standalone records, email support@munodha.com from the Google account you used so we can verify the request. Deletion removes your sign-in record, your logged events, and the anonymous events of visits linked to your sign-ins. It keeps the hashed quota record of how many free results you have used, so the allowance is not reset, and a backup of the earlier hashed-only sign-in record (times and counts, no name or email) may remain until it is removed by hand.

Shopify apps

What each app reads from Shopify.

All three request read-only access. None request customer names, email addresses, phone numbers, billing or shipping addresses, or payment details. None sell data or share it with advertising networks.

CarryLeads

Reads: shop name, shop contact email, and product titles, types, vendors and tags.

Stores: OAuth session records, plus lead metadata such as Google Place IDs, score, stage, notes and campaign status, along with settings, credit ledger entries and generated copy.

Third parties: your search inputs go to the Google Places API to find matching businesses, and your business and product context goes to OpenAI to draft outreach copy. No customer data is sent to either.

Munafa

Reads: order, product and inventory data, via read_orders, read_products and read_inventory.

Stores: your cost settings, saved as an app-owned metafield inside your own Shopify store, and an OAuth session token. Profit is computed on demand, so no copy of your order history is kept.

Third parties: none.

Dhandha

Reads: recent order totals and line items, product titles, status and prices, and inventory quantities.

Stores: OAuth session records. Growth metrics are generated from Shopify on request rather than stored.

Third parties: none.

Shopify deletion

Uninstalling removes your store data.

When you uninstall an app, or when Shopify sends a shop redaction request, that app deletes the data it holds for your store and removes its OAuth session records. For CarryLeads that includes leads, settings, credit ledger, campaigns and generated copy. The Munafa cost settings live in your own store as a metafield and go with the app.

All three honour Shopify privacy webhooks, including customers/redact and shop/redact. To request access to or deletion of your data at any other time, email support@munodha.com.

Changes

If this changes, it changes here first.

Material changes to this policy will be reflected on this page and in the in-app policies. Questions about anything here go to Munodha support.