Nilli Studio Creator Portal — Privacy Policy
Effective date: September 21, 2026
Last updated: September 21, 2026
1. Who we are and how to contact us
Nilli Studio Inc. (“Nilli Studio,” “we,” “us”) operates the Nilli Studio Creator Portal for its clients. This policy explains how we handle personal information associated with Portal accounts, invoice access, and the QuickBooks integration. It does not describe every activity on Nilli Studio's marketing website or every production service.
Privacy contact: Francis, CEO and person responsible for the protection of personal information
Email: info@nillistudio.com
Mail: 3905 rue Préfontaine, Montréal, Québec H1W 2P8, Canada
You may use this contact to ask questions, make a privacy request, or submit a complaint.
2. Information we handle and its sources
| Information | Source and use |
|---|---|
| Account and client details, such as email address, name where provided, authentication user identifier, and associated client | Provided by you or an authorized client/Nilli Studio representative; used to authenticate users, assign access, and provide support. Our authentication provider processes sign-in credentials. |
| Invoice information, including customer and invoice identifiers, invoice number, dates, currency, total, outstanding balance, and synchronization timestamps | Retrieved from Nilli Studio's QuickBooks company account to display the invoices assigned to your client account and keep their status current. |
| Invoice documents and their billing details | Retrieved from QuickBooks when an authorized user requests an invoice PDF. Documents may contain names, addresses, service descriptions, and tax or payment information included in the invoice. The current integration streams PDFs on request rather than storing them as public files. |
| Payment links | Entered by authorized Nilli Studio team members to direct clients to an external payment service. A link may contain a customer or transaction reference. |
| Connection and operational information | Accounting authorization tokens, connection identifiers, synchronization results, and technical error information used to operate and troubleshoot the integration. These are not shown to creators. |
| Technical and support information | Information in your support requests, and request or security information processed by our infrastructure providers, potentially including IP address, browser/device information, timestamps, and authentication events. Used for delivery, troubleshooting, and security. |
Nilli Studio authorizes the connection to its own QuickBooks company. Creators are not asked to give Nilli Studio their QuickBooks passwords. Although the provider's accounting authorization scope is broader, the current integration retrieves accounting information and does not create invoices, initiate charges, or modify accounting transactions.
Please do not send passwords, full payment-card details, or unrelated sensitive information through support messages.
3. Purposes and choices
We use this information to provide authorized account access, show relevant invoices, retrieve invoice documents, maintain the accounting connection, answer questions, correct records, secure the service, and meet applicable legal or accounting obligations.
Account identification and client mapping are necessary to provide private invoice access. If you do not provide the required information, we may be unable to provide a Portal account; contact us about another way to receive your invoices.
Where consent is required, we will seek it in the manner required by law. You may contact us to withdraw consent, subject to lawful restrictions and reasonable notice where applicable. We will explain any resulting service limitations. Withdrawal does not automatically require deletion of records we have another lawful reason to retain.
The current Portal is designed for account and invoice administration. Sponsorship matching and social-media analytics are not part of the processing described here. We will provide updated information and obtain any required consent before introducing materially different uses.
4. Who can receive information
Authorized Nilli Studio team members responsible for administration and operations can access information needed to manage your client account, resolve issues, and verify the creator view. These team members may include employees and contractors, with access limited to their account-management or support responsibilities. Portal permissions are intended to restrict creators to records assigned to their own client account.
We use service providers for hosting, authentication, databases, accounting, and technical delivery. The current deployment uses:
- Supabase: account authentication and database services.
- Vercel: hosting for Nilli Studio's production application and integration endpoints.
- Intuit QuickBooks: the underlying accounting system, accounting authorization, invoice information, and invoice documents.
- OpenAI Sites: hosting of the current creator-facing Portal. Access to a private hosted site may also involve a separate hosting-provider account or access process.
Providers receive information relevant to their role. Where they provide their own account or payment services directly to you, their own privacy notices also apply. Selecting an external payment link sends you to the selected provider; the Portal does not collect or store full payment-card credentials. Nilli Studio may receive payment-related accounting information in QuickBooks.
We may also disclose information where legally required, to professional advisers subject to confidentiality, or where lawfully necessary to address fraud or protect rights and security. The current Portal application does not include advertising or advertising-profiling features.
5. Processing locations
Information may be processed outside Quebec and Canada. The current deployment uses Canadian infrastructure for the separate creator-authentication project and United States infrastructure for the production database. Other providers and their subprocessors may process information in additional locations. The Portal does not promise Canada-only storage.
Information processed elsewhere may be subject to local laws and lawful access requests. Nilli Studio is responsible for assessing applicable requirements and safeguards for its transfers. Contact our privacy contact for questions about the providers and locations relevant to your information.
6. Sessions, cookies, and similar technologies
Authentication and hosting services may use cookies or similar technologies to manage access and protect their services. The current creator interface keeps its own sign-in tokens in browser memory; reloading can require another sign-in. This does not mean the hosting provider or other linked services use no cookies.
You can control cookies through your browser, although blocking necessary technologies may prevent access. The current creator interface does not install marketing cookies or analytics scripts. Hosting-provider technologies may operate separately from that interface.
7. Retention and closure
We retain information for the purposes described here for as long as needed, considering the client relationship, accounting and tax obligations, security needs, and actual or anticipated disputes. Different records may have different retention periods. Retention and deletion requests are reviewed manually by our privacy contact. There is currently no automatic account-closure deletion schedule. We review what must be retained for the purposes above and arrange deletion of information that is no longer needed, subject to applicable law. Contact us to ask about a specific record.
You can request that we disable Portal access and review information for deletion. Removing Portal access or disconnecting QuickBooks does not automatically erase previously synchronized records, accounting records in QuickBooks, or provider backups. Any retained information remains subject to applicable protections and retention requirements. We can explain the records affected and any lawful reason we cannot immediately delete them.
8. Safeguards
The current integration uses client-account authorization checks, restricted administrative access, encrypted stored accounting tokens, and checks on incoming accounting notifications. These measures support confidentiality but do not eliminate all risk. No online service can guarantee absolute security.
Protect your credentials, sign out on shared devices, and contact us promptly if you believe information has been accessed or disclosed improperly. We will assess incidents and provide notifications where required by applicable law.
9. Your rights and complaints
Depending on applicable law, you may request access to your personal information, correction of inaccurate information, deletion where available, withdrawal of consent, and provision of eligible computerized information in a structured, commonly used format. These rights can be subject to legal exceptions.
Send requests to our privacy contact. We may ask for information reasonably necessary to verify your identity or authority, and will respond within the period required by applicable law. Where we cannot fulfil a request, we will explain the applicable reason and available recourse as required.
You may complain to Nilli Studio and, where applicable, to the Commission d'accès à l'information du Québec at https://www.cai.gouv.qc.ca/ or the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca/.
10. Changes
We will update the effective date when this policy changes and notify affected users of changes as required by law. For material changes, we will provide a clear notice through the Portal or another appropriate channel. We will obtain additional consent where required; publishing an update alone does not replace that consent.