Studio OS
Privacy Policy
Last updated: 12 July 2026
1. Who we are
Studio OS(“we”, “us”, “our”) provides a software service that lets boutique owners manage their business — products, orders, enquiries, customers, and sales — from one dashboard, and publish product posts to their own connected social media accounts. This policy explains what personal data we collect, why, how we use and share it, and the rights you have over it. We are the data controller (or, under the Digital Personal Data Protection Act, 2023, the “Data Fiduciary”) for the data described here.
2. Who this policy covers
This policy applies to two groups of people:
- Boutique owners who sign in and use the dashboard.
- Customersof those boutiques, whose contact and order details an owner may record, and who may browse a boutique’s public storefront or submit an enquiry or order request.
3. Information we collect
Account information. You sign in with Google. From Google we receive your name and email address to create and identify your account. We do not receive or store your Google password.
Business content you enter.Your boutique details (name, description, logo, WhatsApp number), products (names, descriptions, prices, images, stock), orders, enquiries, sales, and the customer records you choose to add (such as a customer’s name, phone number, and measurements).
Instagram data.If you connect an Instagram account (via “Instagram API with Instagram Login”), we receive and store your Instagram Business/Creator account ID and an access token that lets us publish a post only when you choose to. We use this solely to publish the product content you initiate. We do not read your direct messages, followers, comments, or existing posts, and we do not post anything without your action.
Images.Product and brand images you upload are stored in our hosting provider’s storage. Because social platforms require a publicly reachable image URL to publish a post, product images are stored with public read access.
Customer submissions.When a customer submits an enquiry or order request on a boutique’s public storefront, we collect the details they provide (such as name, contact number, and the message or product requested).
4. How we use your information
- To provide, operate, and secure the dashboard and storefront.
- To publish product posts to your connected Instagram account when you initiate a post.
- To keep each boutique’s data isolated so that you only ever see data belonging to your own boutique.
- To respond to your requests and provide customer support.
- To comply with legal obligations and enforce our terms.
We do not use your data for advertising and we do not sell your personal data.
5. How we share your information
We share data only with the service providers needed to run the product, and only as necessary:
- Google — for sign-in (authentication).
- Meta / Instagram — only to publish the specific posts you choose to publish to your connected account, through the Instagram Graph API.
- Supabase — our database, authentication, and file storage provider, which hosts your data on our behalf.
- Vercel — our application hosting provider.
We may also disclose data if required by law, or to protect the rights, safety, and security of our users or the public.
6. Data retention
We keep your data for as long as your account is active or as needed to provide the service. Instagram access tokens are stored only while your account remains connected and are removed when you disconnect. When you delete your account or ask us to erase your data, we delete it within a reasonable period, except where we are required to retain certain records by law.
7. Your rights & deleting your data
Under the Digital Personal Data Protection Act, 2023, you have the right to access, correct, and erase your personal data, to nominate another person to exercise your rights, and to grievance redressal. You can exercise most of these directly in the app:
- Disconnect Instagram / revoke access. Go to Dashboard → Settingsand disconnect Instagram. This deletes the access token we hold and stops all publishing. You can also remove our app from Instagram’s side under Instagram → Settings → Apps and websites → Active.
- Edit or delete content. You can edit or delete your products, orders, enquiries, customers, and sales from the dashboard at any time.
- Delete your account and all data. Email us at manager.ish999@gmail.com with the subject “Data deletion request” from the email address on your account. We will verify the request and delete your account and associated personal data.
8. Security
We protect your data with row-level security in our database so that each boutique’s data is isolated and accessible only to its own members, encrypted connections (HTTPS), and access controls on our hosting providers. No method of transmission or storage is completely secure, but we work to protect your data using reasonable safeguards.
9. Children
The service is intended for business owners and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above. Significant changes will be communicated through the service where appropriate.
11. Contact us
For any privacy question, request, or grievance, contact us at manager.ish999@gmail.com. We are based in Punjab, India, and this policy is governed by the laws of India.