Privacy Policy

Last updated: August 14, 2026

This Privacy Policy explains how NiLa Digital Strategy (“NiLa,” “we,” “us”) collects, uses, and protects information across our website, marketing outreach, and client Portal. It has two parts:

  1. Website & Marketing Outreach, covering niladigitalstrategy.com, contact forms, and Instagram/Facebook DM conversations.
  2. Client Portal, covering the invite-only dashboard at portal.nilastrategy.com used by active clients.

If you’re a visitor, prospect, or someone we’ve messaged, Part 1 applies to you. If you’re an active client using the Portal, both parts apply.

Part 1: Website & Marketing Outreach

This part covers niladigitalstrategy.com and our related marketing outreach, including Instagram and Facebook DM conversations, contact forms, and email. By using this site or messaging us, you agree to this policy.

Information we collect

  • Contact form submissions. Name, email, phone number, business name, and anything else you share when you fill out a form on our site.
  • DM conversations. If you message us on Instagram or Facebook, or interact with one of our ad campaigns, we collect what you share in that conversation (for example, your business type, whether you’re running ads, and your general marketing budget range) so we can point you to the right next step.
  • Email. If you subscribe to updates or reach out by email, we keep your email address and message history.
  • Website analytics. We use standard analytics tools to understand how visitors use the site (pages viewed, general location, device type). This data is aggregated and isn’t used to identify you personally.
  • Cookies. Our site uses essential cookies to run properly, plus analytics cookies to understand site traffic. You can control cookies through your browser settings.

How we use information

  • Respond to your inquiry and follow up about our services.
  • Send outreach messages relevant to what you’ve shared (for example, following up on a DM conversation).
  • Improve our website and marketing based on aggregate trends.
  • Keep records of prospect and client communication.

We do not sell your information to anyone, for any reason.

Service providers

We share information only with providers that help us run our outreach and website, under their own privacy terms:

  • Meta (Instagram and Facebook DMs and ads) and ManyChat (our DM automation tool), to manage and respond to conversations.
  • HubSpot, for contact forms, email follow-up, and keeping track of conversations with prospects and clients.
  • Bitly, for tracked links we share (for example, in PDFs or guides), so we know which resources people find useful.
  • Standard website analytics and hosting providers.

Your choices

  • Opt out of messages. Reply “stop” in any DM conversation, or unsubscribe from any email, to stop receiving further outreach from us.
  • Ask what we have. Email us to ask what information we have on file about you.
  • Request deletion. Email us to request that we delete your information from our systems.

Data retention

We keep prospect and client communication for as long as it’s useful for following up or for our own records, generally no more than 2 years after our last contact with you unless you become a client, in which case Part 2 of this policy applies. You can request deletion sooner at any time.

Part 2: Client Portal

This part covers the NiLa client Portal at portal.nilastrategy.com, an invite-only dashboard for active clients. By using the Portal you agree to this policy.

Information we collect

  • Account & identity. Authentication is handled by Clerk. We receive your name and email address to identify your account; we do not store passwords.
  • Engagement data. Business name, tasks, documents, invoices, and subscription status related to your engagement with NiLa.
  • Connected analytics (only if you connect them). If you connect Google, we read your Google Analytics, Search Console, and Google Business Profile metrics. If you connect Instagram, we read your Instagram Business account insights (reach, views, followers, top posts) through its linked Facebook Page. We request read-only access and never post on your behalf.
  • Files. Documents and creative you or NiLa upload, stored privately in DigitalOcean Spaces.
  • Payments. Billing is processed by Stripe. We do not collect or store card numbers.
  • Cookies. The Portal uses only essential cookies needed to keep you signed in and to remember basic session settings. We don’t use third-party advertising or tracking cookies on the Portal.

How we use information

  • Operate the Portal and show your performance metrics, tasks, documents, and billing.
  • Generate plain-language performance summaries from your connected metrics.
  • Send service notifications (invites, invoices) by email.
  • Maintain security and prevent abuse.

We do not sell your information to anyone, for any reason.

Service providers

We share data only with providers that help us run the Portal, under their own privacy terms:

  • Clerk (authentication), Stripe (payments), DigitalOcean (hosting & file storage), Resend (email).
  • Google APIs and Meta/Instagram APIs, to read the analytics you explicitly connect.

Google user data

NiLa’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data solely to display your analytics in the Portal, do not transfer it except as needed to provide that feature, do not use it for advertising, and do not allow humans to read it except with your consent, for security, or as required by law.

Meta / Instagram data

When you connect Instagram, we access your Instagram Business account’s insights through the Meta Graph API in accordance with the Meta Platform Terms and Developer Policies. We use this data only to display your social performance in the Portal. You can disconnect at any time from the Metrics page.

How we protect your information

Data in transit is encrypted (HTTPS/TLS). Files and account data are stored with our providers’ standard encryption at rest. Access to client data is limited to what’s needed to run the Portal and support your account. No system is completely immune to risk, but we take reasonable steps to keep your information secure.

Data retention

We keep engagement data for as long as you’re an active client, plus up to 7 years afterward for accounting and legal recordkeeping. Connected-account tokens (Google, Instagram) are stored only while connected and are deleted as soon as you disconnect. You can request deletion sooner at any time — see Data Deletion.

Your choices

  • Disconnect Google or Instagram at any time from the Portal’s Metrics page — this revokes our access and removes the stored tokens.
  • Request access to, a copy of, or deletion of your data via the contact below.

Children’s privacy

Neither our website, our outreach, nor the Portal are directed at anyone under 18. We don’t knowingly collect information from minors.

Changes to this policy

If we make material changes to this policy, we’ll update the “last updated” date above and notify active Portal clients by email. Continued use of our site, continued conversation with us, or continued use of the Portal after a change means you accept the updated policy.

Contact

Questions or requests: [email protected].