CanvasForge Privacy Policy

Effective date: [EFFECTIVE DATE]

Placeholders in [BRACKETS] must be completed before publication, and this document should be reviewed by qualified legal counsel for the jurisdictions you operate in. It is written to accurately describe what the CanvasForge software actually does as of the effective date.

CanvasForge ("CanvasForge", "we", "us") provides a product-customization platform: a cloud service (the "Cloud Service") and extensions for WooCommerce, Shopify, PrestaShop, and Magento / Adobe Commerce (the "Extensions", together the "Service"). The Service lets merchants offer customizable products, and lets their customers ("shoppers") design those products in the merchant's storefront.

This policy explains what personal data we process, why, and what rights you have. It is written for both merchants (who install the Extensions and hold CanvasForge accounts) and shoppers (who use the designer on a merchant's site).

1. Our role: controller and processor

2. What we collect

From merchants

From shoppers (on behalf of the merchant)

What we do NOT collect

3. Why we process it (legal bases)

Purpose Data Legal basis (GDPR)
Providing the Service (rendering, storage, order lookup) Account, store, design, and order data Contract performance (Art. 6(1)(b))
Billing and account administration Account and billing data Contract performance; legal obligation
Security, abuse prevention, audit Audit and security event logs Legitimate interest (Art. 6(1)(f))
Support Support and diagnostic data Contract performance
Optional AI design assistance Design content you submit to it Contract performance; used only when invoked

4. AI features

The design assistant offers AI-assisted suggestions. External AI providers are disabled by default; unless we enable an external provider for the Service (a service-level setting — we will update this policy and the sub-processor list before doing so), suggestions come from a deterministic local engine. Suggestions are never applied automatically — a human must accept them. We do not use merchant or shopper data to train AI models.

5. Sharing and sub-processors

We do not sell personal data. We share it only with:

A current sub-processor list is available at https://cforge.design/legal/subprocessors.

6. Retention

7. Security

No system is perfectly secure; we notify affected controllers of personal-data breaches without undue delay, consistent with applicable law.

8. International transfers

The Cloud Service is hosted in [HOSTING REGION(S)]. Where personal data is transferred across borders, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

9. Your rights

Merchants can access and update account data in the merchant dashboard, and can request export or deletion by contacting us.

Shoppers should direct requests to the merchant (the controller). We provide merchants with tooling to honor them: tenant-scoped export of a data subject's records, and anonymization that removes the stored personal-data linkage (the customer email) from them. CanvasForge implements Shopify's mandatory privacy webhooks: a redaction request submitted through Shopify is carried out automatically (the customer's design records held by the app are deleted), a customer data request is recorded and surfaced for the merchant to fulfil, and uninstalling the app automatically erases the data the Shopify app holds for the shop after Shopify's 48-hour window. Data held in the Cloud Service is removed at account closure as described in Section 6.

Depending on your jurisdiction, you may have rights to access, rectify, erase, restrict, port, or object to processing, and to lodge a complaint with a supervisory authority.

10. Children

The Service is a business tool, not directed at children. We do not knowingly collect personal data from children; storefront age policies are the merchant's responsibility.

11. Changes

We will post changes to this policy at this URL and update the effective date. Material changes affecting merchants will be announced to account contacts in advance.

12. Contact

[COMPANY LEGAL NAME] [REGISTERED ADDRESS] Email: [PRIVACY CONTACT EMAIL]

EU/UK representative or Data Protection Officer, if appointed: [REPRESENTATIVE / DPO DETAILS]