Privacy Policy

Last updated: 2026-08-12

This Privacy Policy describes how HAKISTOP LTD., doing business as Haki Studios ("Haki Studios," "we," "us"), collects, uses, and shares information in connection with the Pipeline application (the "Service") at app.haki-studios.com.

1. Who this applies to

Pipeline is provided to organizations on an invitation basis. This policy applies to individuals who have been invited by an organization administrator to use the Service ("Users") and to data that organizations connect to or store within the Service ("Customer Data").

2. Information we collect

Account information. When an administrator invites you, we receive and store your email address, a display name (optional), and the role and permissions your administrator assigns. We do not collect a password unless you choose to set one; authentication uses email magic links by default.

Customer Data from third-party integrations. At your organization's direction, the Service reads business data from the following connected applications. We connect through each provider's official OAuth or API and only access data within the scopes your organization authorizes.

  • QuickBooks Online (Intuit): bank account balances, accounts receivable aging, accounts payable aging, profit-and-loss summaries, and company information. Read-only — Pipeline never writes to QuickBooks.
  • Shopify: product catalog, variants, inventory levels, and order line items (for sales velocity). Read-only.
  • Gusto: employee roster (display name only) and projected upcoming payroll figures, used to forecast cash outflows. Read-only.
  • Monday.com: product workflow status. Bidirectional — your administrator may authorize Pipeline to write back limited status updates.
  • Instagram (Meta): your organization's own Instagram Business or Creator account, plus limited information about people who publicly mention or message that account. Read-only. Described in detail in Section 3.

Usage information. We log routine application events (sign-ins, requests, errors) for operational reliability. We do not use third-party analytics, advertising trackers, or session-recording tools.

3. Instagram and Meta Platform Data

Haki Studios is a clothing brand that works with independent creators: we send creators product, and creators post about it. Pipeline connects to our own Instagram accounts through Business Login for Instagram so that this collaboration is recorded in one place instead of being tracked by hand. We request only read permissions. Pipeline does not post, comment, or send messages on anyone's behalf.

What we receive about our own accounts. The account's username, account type, media we have published, and aggregate insights about that media (reach, saves, profile visits). This is our own business data.

What we receive about other people. Only when someone chooses to interact with our accounts publicly or directly:

  • Mentions and tags. When someone mentions or tags our brand account in a post, reel, or story, we record their Instagram username, the media type, the permalink where available, and the caption text. This creates or updates an entry in our creator records so we can thank them, credit them, and keep track of the collaboration.
  • Direct messages. When someone messages our magazine account, we record their Instagram-scoped sender ID, username, display name, the message text, and a short summary of stated interests (for example, a city or what they collect) so we can reply with context.

Story media. When someone mentions us in an Instagram story, our live detection does not download or keep a copy of it. Story content is reachable only through a temporary link that expires in about 24 hours; a notification carries that link so a person can view the story inside Instagram before it expires, and nothing further is retained from that point onward.

We do hold an archive of creator media, including stories, collected before August 2026. Until then we used a third-party creator-listening service that kept copies of the posts and stories in which people mentioned us. When we moved that work in-house we transferred that archive — 145 items — into our own private storage rather than lose the record of collaborations we had already made. It is not published, not publicly addressable, and visible only to authorized staff of our organization. If you appear in it and would like your content removed, see Section 6; we will delete it on request, and you do not need to give a reason.

We do not use Platform Data for advertising targeting, do not sell it, do not use it to train machine-learning models, and do not combine it with data from other sources to build profiles of people who have not interacted with us. Creator content is only used in advertising when the creator has separately and explicitly granted us the right to do so, and such ads run with Instagram's paid-partnership label.

Access is limited to authorized staff of our organization. Platform Data is retained only while it remains relevant to an active or past collaboration, and is deleted on request — see Section 6.

4. How we use information

  • To provide the Service and the integrations you have authorized;
  • To authenticate Users and enforce role-based access controls;
  • To compute the dashboards, projections, and decision aids the Service is designed to produce;
  • To investigate and respond to security or operational incidents;
  • To comply with applicable legal obligations.

We do not sell Customer Data. We do not use Customer Data to train machine-learning models. We do not share Customer Data with advertisers.

5. Sharing with service providers

We share data only with the infrastructure providers needed to operate the Service:

  • Supabase — database hosting and authentication. Data is stored in their US-East region.
  • Railway — application hosting (US-East).
  • Resend — transactional email delivery (sign-in links, password resets).
  • Anthropic — optional AI-assistant feature. When an organization enables it, conversation content and queried data are sent to Anthropic's API solely to generate the response and are not retained for training under our agreement.

We may also disclose information if required by law, regulation, or valid legal process.

6. Data retention and deletion

We retain Customer Data for as long as your organization maintains the connection or membership. You or your organization's administrator may disconnect any integration at any time from the integrations admin page, which removes the stored OAuth tokens. To request deletion of your account or Customer Data, email devindas98@gmail.com from the address on file; we will respond within 30 days.

Instagram users: how to have your data deleted. If you have mentioned, tagged, or messaged one of our Instagram accounts and you want the record of that removed, email devindas98@gmail.com with the subject line "Instagram data deletion request" and the Instagram username you posted or messaged from. You do not need an account with us and you do not need to explain why. We will delete the stored record — username, display name, message text, captions, post links, and any copy of your photo or video held in the archive described in Section 3 — within 30 days and confirm by reply. Removing the mention or message on Instagram itself, or blocking our account, also stops any further collection, though it does not by itself erase what was already recorded; email us for that.

7. Security

Access to Customer Data is restricted by row-level security: each organization's data is isolated at the database layer, and authentication is required for every request. OAuth tokens are stored in dedicated columns and scoped to a single organization. We do not represent that the Service meets any specific certification (SOC 2, ISO 27001, etc.) at this time; we improve security continuously and disclose material incidents promptly.

8. International users

Our infrastructure is located in the United States. If you access the Service from outside the United States, you consent to the transfer of your information to the United States for processing under this policy.

9. Children

The Service is not directed to individuals under 16. We do not knowingly collect information from children.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be posted to this page with an updated date.

11. Contact

Privacy questions, data access, or deletion requests: devindas98@gmail.com.

Privacy Policy · Pipeline