Privacy Policy
Version 2026-08-18
Etúviel Studios (ABN 76 319 792 038) — "we", "our", "us" — respects your privacy. This policy sets out what we collect, who else handles it, how long we keep it, and how to have it deleted. It applies to this website, the client portal and the services we provide through them.
1. What we collect
We only collect what a job needs. In full, that is:
- Enquiries. When you use the contact form: your name, email address, company name if you give one, the service you are interested in, and your message.
- Your account. Your email address and the name you enter. Passwords are handled by Google Firebase Authentication and are never seen or stored by us — we cannot read your password.
- Agreement records. When you accept these terms we record which version you accepted, the date and time, and a one-way hash of your IP address and your browser’s user-agent string. The hash cannot be turned back into an address; it exists so two acceptances can be told apart, not so you can be located.
- Billing. If you subscribe: your Stripe customer and subscription identifiers, the plan, its status, and the dates of billing periods. Card numbers are entered on Stripe’s systems and never reach ours — we cannot see your card.
- Client and invoice records. If the studio works for you: the business details you provide for invoicing, and the invoices themselves.
- Abuse prevention. A salted, one-way hash of the IP address of anyone submitting a form, used only to count submissions and stop automated abuse. Raw addresses are not stored.
2. What we do not collect
There is no tracking on this site. No analytics, no advertising pixels, no session recording, no fingerprinting, and no tracking cookies. We do not build profiles of visitors, we do not follow you across other websites, and we have never sold, rented or traded personal information — nor will we.
We do not ask for and do not want sensitive information: no health information, no government identifiers, no financial account details beyond what you enter directly into Stripe.
3. Who else handles your information
We run the studio on a small number of service providers. They process information on our instructions in order to provide their service, and for no other purpose. They are not advertisers or data brokers, and none of them receives your information in order to market to you.
- Google Firebase / Google Cloud — Authentication, database and file storage. Google Cloud infrastructure is certified to ISO/IEC 27001, the international standard for information security management. That certification is Google’s, covering the infrastructure our data sits on.
- Stripe — Payment processing and subscription billing. Stripe holds your card details under its own privacy policy. We never receive them.
- Vercel — Website hosting and delivery. Serves the site and runs its server-side code.
- Resend — Sending transactional email such as invoices. Receives the address an email is sent to and its contents.
Some of these providers store or process data outside Australia. By using the site you agree to that transfer. We will add to this list only when a service genuinely requires it, and this page is updated when we do.
4. Artificial intelligence
This website contains no AI features. There is no chatbot, no assistant, no recommendation engine and no automated decision-making. Nothing on this site profiles you, scores you, or decides anything about you without a person involved.
Your personal information is not used to train AI models, and it is not sold or supplied to anyone who trains them.
The site offers no advice of any kind — medical, psychological, financial or legal — and has no feature that invites you to discuss personal or sensitive matters with a machine. If you are in distress, please contact a qualified service; in Australia, Lifeline is available on 13 11 14.
The studio does use AI-assisted tools in its own design and development work, in the way a word processor or a code editor is a tool. Where such tools are used, client personal information is not put into them.
5. How long we keep it, and deleting it
You can ask us to delete your account and your personal information at any time, by writing to the address at the bottom of this page. We will action it within 30 days and confirm when it is done. There is no charge, and you do not have to give a reason.
On deletion we remove:
- your sign-in account and profile;
- enquiries you have sent through the contact form;
- the contact details held against your client record.
What we cannot delete: invoices, payment records and the tax records attached to them. Australian law requires a business to keep its financial records for five years, so these are retained for that period and then disposed of. Records of your agreement to these terms are kept for as long as we have a contract with you, and for five years afterwards, because they are the evidence of what was agreed. Neither is used for anything else.
Cancelling a subscription is separate from deleting your data — cancel first, or your card will continue to be charged by Stripe. See section 6.
6. Payments and cancelling
Subscription payments are collected by Stripe. Starting, changing, pausing or cancelling a subscription, and updating the card on file, are all handled through Stripe's billing portal — reachable from "Manage billing" in your client portal — or by asking the studio to do it for you.
Cancelling stops all future payments. Cover continues to the end of the period you have already paid for. See the Terms of Service for the full billing terms.
7. Accessing and correcting your information
You can ask us for a copy of the personal information we hold about you, and ask us to correct anything that is wrong. Much of it is already visible to you in the client portal. Write to us and we will respond within 30 days.
If you are unhappy with how we have handled your information you may complain to us first, and then to the Office of the Australian Information Commissioner at oaic.gov.au.
8. Security
Access to the portal requires a confirmed email address. Studio records are readable only by the account they belong to and by studio staff, enforced on the server rather than in the browser. Data is encrypted in transit and at rest by the providers listed in section 3. No system is perfectly secure, but if a breach ever affects your information we will tell you and the Commissioner, as the Notifiable Data Breaches scheme requires.
9. Changes
If this policy changes materially we will tell account holders by email before the change takes effect. The version above changes whenever the wording does.
10. Contact us
For access, correction, deletion, or any question about this policy, write to david.merxhushi@etuviel.studio.
