Clear purpose
We use information to provide services, process transactions, support clients, improve the website, and protect our systems.
This Privacy Policy explains what information Nishstudios collects, why we use it, when we share it, and the choices available to you when you visit our website, request a strategy review, purchase a service, or use the Client Portal.
We use information to provide services, process transactions, support clients, improve the website, and protect our systems.
Payments are processed by Stripe. Nishstudios does not receive or store your complete payment card number.
You may ask to access, correct, or delete certain personal information, subject to applicable law and valid exceptions.
Nishstudios ("Nishstudios," "we," "us," or "our") provides website design, website care, search engine optimization, strategy, and related digital services. This Privacy Policy applies to personal information processed through nishstudios.com, our checkout, forms, communications, and Client Portal.
This Policy does not apply to third-party websites, platforms, or services that maintain their own privacy policies. When you follow a link to another service, review that service's privacy practices before providing information.
The information we collect depends on how you interact with Nishstudios. It may include:
We may use personal information to:
We and our service providers may use necessary, preference, analytics, and—if enabled—advertising cookies or similar technologies. Necessary technologies help the website, checkout, security features, account login, and Client Portal function. Analytics technologies help us understand website performance and visitor interactions.
You can manage cookies through available website controls and your browser settings. Blocking some cookies may affect checkout, login, saved preferences, or other website features. Browser-based "Do Not Track" signals are not interpreted consistently across the industry, so our website may not respond to every DNT signal. Where required by applicable law, we will process recognized opt-out preference signals, such as Global Privacy Control.
We may disclose personal information only as reasonably necessary for the purposes described in this Policy, including to:
Payments and recurring subscription charges are processed by Stripe or another payment processor identified at checkout. The payment processor collects and handles payment card details under its own privacy policy and security standards. Nishstudios may receive limited transaction information, such as the card brand, last four digits, billing status, transaction identifier, and payment or renewal status.
Nishstudios does not receive or store your complete credit or debit card number. Your purchase and subscription are also subject to our Terms & Conditions, Cancellation Policy, and Refund Policy.
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing services, maintaining business and transaction records, resolving disputes, enforcing agreements, and meeting legal or tax obligations. Typical retention criteria include:
| Information category | Typical retention approach |
|---|---|
| Account and Client Portal records | While the account or client relationship remains active, plus a reasonable period for support, security, and legal needs. |
| Orders, invoices, and transaction records | Generally up to seven years, or longer if required by tax, accounting, chargeback, or legal obligations. |
| Inquiries, proposals, and communications | Generally up to 24 months after the last interaction, unless a longer period is needed for an active relationship or legal purpose. |
| Analytics and cookie data | According to the applicable cookie lifetime or provider settings, generally no longer than 26 months unless aggregated or de-identified. |
| Security and technical logs | Generally up to 12 months, unless needed longer to investigate fraud, abuse, or a security incident. |
We may retain de-identified or aggregated information that cannot reasonably be linked to you. We may also delete information earlier when it is no longer needed.
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including access controls, secure connections, service-provider controls, backups, authentication measures, and monitoring appropriate to the information and services involved.
No website, transmission, storage system, or security control can guarantee absolute security. You are responsible for protecting your account credentials and for notifying us promptly if you believe your account or information has been compromised.
Depending on your location and applicable law, you may have the right to request access to, correction of, or deletion of certain personal information; obtain information about how it is used or disclosed; withdraw consent where processing relies on consent; or appeal a decision regarding a privacy request.
To protect your information, we may need to verify your identity and authority before completing a request. We may deny or limit a request where permitted by law, such as when information must be retained for legal, security, transaction, or contractual purposes.
California residents may have rights under the California Consumer Privacy Act, as amended (CCPA), when that law applies to the business processing their information. These may include rights to know, access, correct, or delete personal information; obtain information about categories of information collected and disclosed; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service without unlawful discrimination for exercising privacy rights.
During the preceding 12 months, the categories of personal information we may have collected are identifiers; customer records; commercial information; internet or electronic network activity; approximate geolocation derived from IP address; professional or employment-related information submitted in a business inquiry; account login information; communications; and inferences based on service interests or website activity. We collect these categories from you, your devices, your business, service providers, and transaction partners for the purposes described above.
We do not sell personal information for money and do not knowingly sell or share the personal information of consumers under 16. We do not currently share personal information for cross-context behavioral advertising. If this practice changes, we will provide the notices and opt-out mechanisms required by applicable law.
Email info@nishstudios.com with the subject line "California Privacy Request." An authorized agent may submit a request where permitted by law, but we may require proof of authorization and identity verification. We will not unlawfully discriminate against you for exercising an applicable privacy right.
Our website and services are intended for business owners and adults and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, please contact us so we can review and, where appropriate, delete it.
We may update this Privacy Policy to reflect changes to our services, technologies, vendors, or legal obligations. The "Last updated" date at the top shows when the Policy was most recently revised. If a change is material, we may provide additional notice where required by law.
For questions about this Privacy Policy or to submit a privacy request, contact Nishstudios using the email address below. Please do not include passwords, complete payment card numbers, or other highly sensitive information in your email.