Draft: bracketed fields in this document are pending completion and legal review.
CanvasForge Privacy Policy
Effective date: [EFFECTIVE DATE]
Placeholders in [BRACKETS] must be completed before publication, and this document should be reviewed by qualified legal counsel for the jurisdictions you operate in. It is written to accurately describe what the CanvasForge software actually does as of the effective date.
CanvasForge ("CanvasForge", "we", "us") provides a product-customization platform: a cloud service (the "Cloud Service") and extensions for WooCommerce, Shopify, PrestaShop, and Magento / Adobe Commerce (the "Extensions", together the "Service"). The Service lets merchants offer customizable products, and lets their customers ("shoppers") design those products in the merchant's storefront.
This policy explains what personal data we process, why, and what rights you have. It is written for both merchants (who install the Extensions and hold CanvasForge accounts) and shoppers (who use the designer on a merchant's site).
1. Our role: controller and processor
- For merchant account data (your login, store registration, billing, support requests), CanvasForge is the data controller.
- For shopper data processed through a merchant's store (designs, order metadata), the merchant is the controller and CanvasForge is a processor acting on the merchant's instructions. Shoppers should consult the merchant's own privacy policy for how the merchant uses their data.
2. What we collect
From merchants
- Account data: name, email address, and a bcrypt-hashed password when you create a CanvasForge account. We never store plaintext passwords.
- Store registration data: when an Extension registers a store, it sends the platform type, the site name, the site URL, and a store identifier derived from the site. The WooCommerce, PrestaShop, and Magento extensions send no email address at registration. The Shopify app receives the shop domain through Shopify's OAuth flow.
- Billing data: subscription plan and billing status. Payment is collected by our payment processors — Shopify (for Shopify-managed billing) or Stripe (for direct billing). We never receive or store card numbers.
- Support data: support requests and, if you choose to send one, a diagnostic bundle. Diagnostic bundles are redacted server-side before storage: API keys and secrets are stripped.
From shoppers (on behalf of the merchant)
- Design documents: the layout, text, and image references a shopper places in the designer. If a shopper types personal information into a design (for example a name on a mug), that content is part of the design document.
- Order design metadata: when a design is attached to an order, we store the order and line-item identifiers and, where the platform provides it, the order's customer email address, so the merchant can locate and reproduce the design for that order.
- Uploaded images: images a shopper uploads for use in a design.
What we do NOT collect
- No usage telemetry from the Extensions. Current Extension releases send no telemetry at all — the telemetry code paths are disabled in the shipped code. If a future release adds telemetry, it will be disabled by default, require the merchant's explicit opt-in, and strip personal data before sending.
- No payment card data. Handled entirely by Shopify or Stripe.
- No shopper browsing or tracking data. The Extensions add no analytics or advertising trackers to storefronts. All Cloud Service calls are made server-side from the merchant's site; the shopper's browser never talks to the Cloud Service directly and never sees the merchant's API key.
3. Why we process it (legal bases)
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Providing the Service (rendering, storage, order lookup) | Account, store, design, and order data | Contract performance (Art. 6(1)(b)) |
| Billing and account administration | Account and billing data | Contract performance; legal obligation |
| Security, abuse prevention, audit | Audit and security event logs | Legitimate interest (Art. 6(1)(f)) |
| Support | Support and diagnostic data | Contract performance |
| Optional AI design assistance | Design content you submit to it | Contract performance; used only when invoked |
4. AI features
The design assistant offers AI-assisted suggestions. External AI providers are disabled by default; unless we enable an external provider for the Service (a service-level setting — we will update this policy and the sub-processor list before doing so), suggestions come from a deterministic local engine. Suggestions are never applied automatically — a human must accept them. We do not use merchant or shopper data to train AI models.
5. Sharing and sub-processors
We do not sell personal data. We share it only with:
- Payment processors: Shopify Inc. (Shopify-managed billing) and Stripe, Inc. (direct billing).
- Hosting and infrastructure providers that run the Cloud Service: [HOSTING PROVIDER(S)].
- External AI providers, only if one is enabled for the Service (they are off by default and would be added to the sub-processor list first), and only for content submitted to the design assistant.
- Authorities, where required by law.
A current sub-processor list is available at https://cforge.design/legal/subprocessors.
6. Retention
- Design and order data: kept while the merchant's account is active, so orders remain reproducible. Merchants can archive designs at any time; archived designs are excluded from normal use. Full removal happens at account closure (below).
- Audit logs: deleted after 365 days by default.
- Security event logs: deleted after 180 days by default.
- Backups: snapshots are kept on a fixed rotation and pruned automatically.
- After account closure: we delete or anonymize the account's data within [DELETION WINDOW, e.g. 90 days], except where law requires longer retention.
7. Security
- API keys and session tokens are stored only as SHA-256 hashes; stored platform credentials are encrypted at rest.
- Every request is scoped to the authenticated tenant; cross-tenant access is denied by design and covered by automated tests.
- Outbound webhook and provider URLs are validated against private-network targets (SSRF protection); inbound webhooks are signature-verified against raw request bytes.
- Diagnostic bundles are redacted before storage; privacy exports contain only an explicit whitelist of fields.
No system is perfectly secure; we notify affected controllers of personal-data breaches without undue delay, consistent with applicable law.
8. International transfers
The Cloud Service is hosted in [HOSTING REGION(S)]. Where personal data is transferred across borders, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
9. Your rights
Merchants can access and update account data in the merchant dashboard, and can request export or deletion by contacting us.
Shoppers should direct requests to the merchant (the controller). We provide merchants with tooling to honor them: tenant-scoped export of a data subject's records, and anonymization that removes the stored personal-data linkage (the customer email) from them. CanvasForge implements Shopify's mandatory privacy webhooks: a redaction request submitted through Shopify is carried out automatically (the customer's design records held by the app are deleted), a customer data request is recorded and surfaced for the merchant to fulfil, and uninstalling the app automatically erases the data the Shopify app holds for the shop after Shopify's 48-hour window. Data held in the Cloud Service is removed at account closure as described in Section 6.
Depending on your jurisdiction, you may have rights to access, rectify, erase, restrict, port, or object to processing, and to lodge a complaint with a supervisory authority.
10. Children
The Service is a business tool, not directed at children. We do not knowingly collect personal data from children; storefront age policies are the merchant's responsibility.
11. Changes
We will post changes to this policy at this URL and update the effective date. Material changes affecting merchants will be announced to account contacts in advance.
12. Contact
[COMPANY LEGAL NAME] [REGISTERED ADDRESS] Email: [PRIVACY CONTACT EMAIL]
EU/UK representative or Data Protection Officer, if appointed: [REPRESENTATIVE / DPO DETAILS]