Last updated September 17, 2026
Privacy policy
How Pillar handles your information, who can access it, and your choices.
Who is responsible
Pillar is operated by Kevin Bastien, operating as Pillar, based in Brooklyn, New York, United States. For questions or requests, email support@pillar.nyc.
This notice covers Pillar’s website, account services, workspaces, and client status pages. We manage account information and the information needed to operate and protect Pillar. A studio chooses what client and order information it adds, who joins its team, and who receives its client links. We handle that workspace information to provide the service to the studio. The studio is responsible for its own notices, permissions, and instructions concerning that information. If you are a studio’s client, contact the studio first about its use of your information.
Information we collect
- Accounts and business registration: names, email addresses, company name, website, location, team roles, invitations, and approval or archive records.
- Orders and client information: client names, shipping addresses, order numbers, products, quantities, specifications, production dates and status, notes, shipping details, tracking numbers, and client updates entered by a studio.
- Files and catalog information: uploaded documents and photos, studio branding, product descriptions, specifications, and public website content imported at a studio’s request.
- Production sharing: published client-page versions, fabricator company and contact details, fabricator instructions, generated work-order PDF revisions, and outgoing messages with their recipients, senders, times, and delivery outcomes.
- Forwarded order emails: the sender address, subject, provider message identifier, import status and times, and information automatically extracted into draft orders from the subject and body when an eligible email is received. Pillar processes the body without saving a full copy in its database. It retains a source fingerprint to identify duplicate imports.
- Support and security information: support requests and permission records, administrator identity and stated reason for a support visit, visit times and pages viewed, sign-in and invitation records, and technical logs such as request details, IP addresses, browser information, and errors.
- Terms acceptance: a record linked to your account of the Terms of Service and Privacy Policy revision presented, the published operator and contact details, the acceptance time, the email verification time, and whether acceptance occurred when requesting or confirming a sign-in link. The acceptance record does not include your IP address or browser information.
Information comes from you, your studio and its team, emails forwarded for import, the public website selected for import, and your browser’s interactions with Pillar. Please include only information needed for the work and avoid putting unnecessary sensitive personal information in emails, notes, uploads, or support reasons.
How we use information
We use information to create and manage accounts, deliver sign-in emails, manage invitation links, operate order books, automatically create draft orders from forwarded emails, share client updates, import catalog content, answer support requests, prevent abuse, diagnose problems, record terms acceptance, and meet applicable legal obligations. Required account and order fields allow those features to work; optional details and uploads are chosen by the studio. If you do not provide information a feature requires, that feature may not be available.
Pillar does not sell personal information, serve advertising, or use marketing analytics or advertising trackers. We do not share personal information for cross-site targeted advertising. Website catalog cleanup helps organize product text; it does not make decisions about a person’s access, rights, or eligibility.
Where applicable law requires a legal basis for processing we control, we rely on performing our agreement with you for account and service features, our legitimate interests in operating and protecting the service and resolving support issues where those interests are not overridden by your rights, and compliance with legal obligations. For workspace content processed on a studio’s instructions, the studio is responsible for determining its legal basis. Accepting the Terms of Service and acknowledging this notice is not consent to every use of personal information.
Who can see workspace information
Authorized studio team members can view the workspace according to their roles. Owners manage settings and team access; owners and editors can change orders. Viewers can read orders, including internal notes and files. Pillar administrators can see the company registration and account details needed to manage the service, including company and team member names, email addresses, roles, website, and approval or archive status.
When an email sent to Pillar’s order address has a sender address matching a registered owner or editor of an approved, active workspace, Pillar automatically sends the subject and body for extraction and adds draft orders to that workspace’s order book. There is no separate import confirmation step. An email sender address alone is not proof of identity. Imported orders are visible to the workspace according to the usual permissions and can be corrected or deleted there.
Opening a company’s private order workspace through the administrator support preview requires permission from its owner. The owner records a reason and grants access for one hour, and can revoke it sooner. The administrator records a separate reason, uses their own identity, and can only read through the preview. This includes orders, internal notes and files, catalog, settings, and team details. The owner can review the permission and visit history, including start and end times and pages viewed. Expiry or revocation blocks further preview requests; it cannot recall information already viewed, copied, or downloaded.
This support permission controls access through Pillar’s interface. Authorized personnel and service providers may still need operational access to infrastructure or data to maintain the service, investigate security issues, recover from failures, or comply with law. We do not promise that infrastructure access is impossible.
Client status links work without signing in. Anyone who has a link can view the information on that client page, including the client name, order and production details, tracking information, and shared photos. These links have no automatic expiry. A recipient can forward the link or copy what it shows. Studios should share links only with intended recipients. Internal notes, internal order files, full shipping addresses, and shipping fees are not shown on the client status page. Archiving the company disables its client pages; deleting an order removes its client page.
New client pages become available only after an owner or editor reviews and publishes them. Later order edits remain internal until publication. Existing client pages retain their previously visible content when this publishing feature is introduced. Studio branding and contact information continue to update directly from Settings. Publishing a client page does not send an email.
Owners and editors can explicitly email a work-order PDF and message to an assigned fabricator after reviewing the recipient and document. The PDF includes the client name, production specifications, and fabricator instructions. Pillar keeps the exact document and delivery record with the order. Internal notes, prices, shipping addresses, and client links are excluded from the generated PDF, but users should review any free-text instructions and messages before sending. Pillar cannot recall emailed copies.
Service providers and data location
We use service providers to run Pillar. Information may be processed in countries other than your own, whose privacy laws may differ.
- Render: hosts Pillar and its PostgreSQL database in Virginia, United States. It processes application data, locally stored uploads, and operational logs to provide hosting. This location does not mean all provider operations occur only in Virginia. See Render’s privacy information.
- Resend: delivers account sign-in emails and fabricator work-order emails, receiving recipient and reply-to addresses, message contents, attached work-order PDFs, and related delivery information. When email import is enabled, it also receives emails forwarded to Pillar, including their addresses, subject, body, headers, and any attachments sent with them. Pillar does not download or read those attachments for import. Sign-in links can be associated with a team invitation; team invitation links themselves are shared by the studio. Pillar can also use a configured SMTP email provider for sign-in delivery. See Resend’s privacy policy.
- OpenAI: catalog cleanup receives freshly imported public website descriptions, product names, and specification text; that feature excludes previously saved private catalog edits, manual studio descriptions, order records, client information, and uploaded files. Separately, Pillar automatically sends the subject and body of eligible forwarded emails to OpenAI to extract order information when they are received. The body can include client names, addresses, shipping details, quoted correspondence, and other information you forward. Pillar does not send email attachments or retrieve linked documents for this feature. For both features, Pillar requests that Responses API results not be stored using
store: false; this is not a promise of zero retention. OpenAI may retain content and technical information for abuse monitoring, security, and other purposes described in OpenAI’s API data controls.
Website imports contact the selected public website and its image hosts, which can receive Pillar’s server request details. An import review may also display images directly from the source website, exposing your browser’s IP address and browser information to that host. Saved client-page images are served through Pillar. External websites you visit through links have their own privacy practices.
We may also disclose information when necessary to comply with applicable law or protect the service and people from abuse. We do not authorize service providers to use Pillar customer information for our advertising.
Cookies and security
Pillar uses essential session cookies and security tokens to keep you signed in, remember the active session, and protect forms. It does not use optional advertising or marketing analytics cookies. Blocking essential cookies may prevent sign-in and other features from working.
Pillar does not track your browsing across other websites for advertising. Browser “Do Not Track” signals do not change the essential session and security processing described here.
Pillar uses encrypted connections, account and role checks, and restricted support previews. No service can guarantee absolute security. Keep sign-in emails and client links private, remove team access when it is no longer needed, and report suspected unauthorized access to the contact above.
Retention and your choices
Pillar retains active and archived workspace records to provide the service and allow restoration; it does not automatically purge old workspaces. Archiving is not deletion. Uploaded files use persistent storage that survives ordinary deployments and restarts, but retention is not a guarantee of recovery from deletion, corruption, or storage failure. Keep your own copies. Our data retention and deletion notice explains record retention, storage limits, and removal requests.
You can update your name in Account. Studio owners manage company details and team access; owners and editors can correct or delete orders. Depending on applicable law, you may also have rights to access, correct, delete, or obtain a copy of personal information, or to object to or restrict certain uses. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Send requests to support@pillar.nyc. We may need to verify your identity and authority before acting. If the information belongs to a studio’s order workspace, we may coordinate with that studio. You may also raise a concern with the privacy regulator responsible for your location.
Business use
Pillar is designed for studios and their authorized team members to manage business orders and share progress with clients. It does not ask for or verify users’ ages. If you believe information about a child has been submitted inappropriately, contact us so we can review the situation and any removal request.
Changes to this notice
We will update this page when Pillar’s practices change and show the revision date above. We will communicate material changes when required by applicable law.