Skip to main content
Effective date: September 3, 2026
Last updated: September 3, 2026
This Privacy Policy describes how Brandle & Co LLC, doing business as Account Canvas (“Account Canvas,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal information when merchants install or use the Account Canvas Shopify application, when their customers interact with Account Canvas features in Shopify customer accounts, and when anyone visits our website, documentation, or contacts support (collectively, the “Services”). This policy should be read together with our Terms of Use and Subprocessors list.

1. Our privacy roles

The role we have depends on the information and why it is processed:
  • Merchant and buyer data processed for the Service. The Shopify merchant generally determines why and how its buyer personal information is processed. For that information, the merchant is generally the controller or business, and Account Canvas acts as its processor or service provider. We process this information on the merchant’s documented instructions, including the merchant’s configuration of pages, blocks, conditions, variables, forms, and workflows.
  • Our business operations. Account Canvas is a controller or business for information used to administer merchant accounts, billing, security, support, product operations, and our websites and documentation.
  • Shopify. Shopify separately processes information under its own agreements and privacy notices. Merchants and buyers should also review the policies that apply to their Shopify relationship.
The legal labels above can vary by jurisdiction, but the practical allocation remains the same: merchants control their customer relationships and Account Canvas operates the configured Service on their behalf.

2. Information we process

We limit collection to information reasonably needed to provide, secure, support, and maintain the Services.

Information received from Shopify

Depending on the features a merchant enables and the permissions Shopify approves, we may receive or access:
  • Shopify shop domain, store identity, locale, plan and subscription status, installed app status, and relevant account configuration;
  • merchant-user session information, including Shopify user identifiers, name, email, locale, account-owner status, and granted access scopes;
  • products, product images or files, and related commerce content selected by the merchant for display;
  • customer account information used for merchant-configured personalization, such as customer identifier, first and last name, display name, email address, order count, order identifiers and ownership information, market currency, and store-credit account information or balance;
  • customer and order metafields that the merchant configures Account Canvas to read or write; and
  • privacy, installation, scope, and billing webhook information needed to keep the app synchronized with Shopify and respond to legal requests.
Some customer information is read at display time through Shopify’s Customer Account API and used only to render the merchant-configured experience. Account Canvas does not intentionally create a separate long-term profile from that display-time data.

Information merchants provide

Merchants may provide:
  • pages, blocks, sections, templates, images, links, labels, variables, conditions, visibility rules, form fields, and other content or configuration;
  • workflow settings, notification preferences, and authorized Shopify metafield or order-note destinations;
  • support messages, screenshots, diagnostic details, and contact information; and
  • billing choices and other administrative settings. Shopify processes app charges; we receive plan, charge, trial, and subscription-status information, not full payment card details.

Information merchant customers submit

When a merchant enables a form, order action, or other workflow, a signed-in customer may submit the fields selected by the merchant. A submission can include text, contact preferences, order instructions, gift messages, purchase-order references, customer or order identifiers, and other information requested by that merchant. Account Canvas is not designed to collect, and the Service attempts to reject, payment card numbers or security codes, government identifiers, health or medical information, passwords, access tokens, private keys, or other authentication secrets. Merchants and customers must not submit those categories through Account Canvas.

Technical, security, and usage information

We may process IP address and request metadata, browser and device information, timestamps, Shopify and app route information, authentication and webhook status, rate-limit records, sanitized error details, pseudonymous tenant references, and first-party usage events such as page views, block views, condition evaluations, and workflow submissions. We configure our application monitoring to disable default personal-information collection, Session Replay, and SDK log forwarding. We also sanitize error, trace, and analytics data to reduce the chance that customer identifiers, message bodies, secrets, or URL query data are sent to monitoring systems. No safeguard can guarantee that technical data will never be personal information.

Website, documentation, and support information

When someone visits our website or documentation, our hosting providers may process IP address, browser and device details, request logs, security data, and cookie or similar technology data. When someone contacts us, we process the sender’s contact details, message, attachments, and any follow-up correspondence.

3. How we use information

We use personal information to:
  • authenticate merchants and customers through Shopify;
  • provide and render merchant-configured customer-account content;
  • evaluate conditions and personalization variables;
  • receive, validate, store, display, export, and delete workflow submissions;
  • write information to Shopify customer metafields, order metafields, or order notes only when the merchant configures and authorizes that destination;
  • send a merchant a transactional notification that a workflow was submitted. The notification contains a workflow title and submission reference, but is designed not to contain the customer’s answers or customer and order identifiers;
  • administer subscriptions, trials, entitlements, and billing status through Shopify;
  • provide support and respond to privacy, security, and legal requests;
  • detect abuse, enforce limits, secure the Service, investigate incidents, and maintain reliable operations;
  • understand product usage through minimized first-party analytics and improve the Service; and
  • comply with law and enforce our agreements.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use merchant or buyer data to build advertising profiles across merchants.

4. When we disclose information

We may disclose information in the following circumstances:
  • To the merchant. Workflow submissions and related records are available to the Shopify merchant that configured the workflow. A merchant may direct Account Canvas to copy selected information into its Shopify records.
  • To service providers and subprocessors. We use providers for Shopify platform services, application and database hosting, transactional email, error monitoring, website and documentation hosting, and business email. They may process information only for the relevant service and subject to applicable contractual restrictions. Our current providers are described on the Subprocessors page.
  • For legal and safety reasons. We may disclose information when reasonably necessary to comply with law or valid legal process; protect the rights, safety, and security of Account Canvas, Shopify, merchants, customers, or others; investigate fraud or abuse; or establish, exercise, or defend legal claims.
  • Business transactions. Information may be disclosed as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate confidentiality and legal requirements.
  • With consent or direction. We may disclose information when the relevant person or merchant asks or authorizes us to do so.
We may use and disclose aggregated or de-identified information that cannot reasonably be linked to a person, subject to applicable law.

5. Cookies and local storage

The embedded application relies on Shopify authentication and related security technologies. Account Canvas uses a short-lived, signed cookie to protect the return from a Shopify billing approval flow. The merchant admin interface also uses browser local storage to remember whether certain setup notices have been dismissed. These items are used for security and product functionality, not cross-site advertising. Our website and documentation providers may use essential cookies or similar technologies for security, routing, preferences, and service operation. Optional analytics will be used only as configured by us and subject to consent where required. Browser settings can restrict cookies, but doing so may prevent parts of the Services from working.

6. Retention and deletion

We retain personal information only for as long as reasonably necessary for the purposes described above, subject to these normal periods:
  • Workflow submissions and linked analytics: normally 45 days from submission.
  • Case-specific workflow holds: an authorized hold for active support, security, merchant-request, or legal work can delay normal deletion, but the hold cannot extend beyond 90 days from the first hold. A Shopify customer or shop redaction request overrides a hold.
  • Other first-party usage analytics: normally 45 days.
  • Local operational issue records and completed retention-run records: normally 30 days.
  • Expired online authentication sessions: removed by the recurring retention process. Offline credentials are retained while needed for background access and token refresh; verified uninstall removes active credentials; ambiguous installation state requires reconciliation before destructive cleanup.
  • Privacy export scope: encrypted and available for no more than 30 days; associated request records are removed after their operational period.
  • Merchant content and configuration: retained while the merchant uses the Service, until the merchant deletes it, or until final shop redaction after uninstall.
  • Lifecycle replay protection: minimal shop-domain, installation-state, event-ID, topic, and timestamp records are retained separately from deleted merchant content to prevent delayed or replayed events from affecting a later installation. These records do not contain access tokens or webhook bodies.
  • Support, billing, legal, and security records: retained for the period reasonably needed to resolve the matter, meet financial or legal obligations, prevent abuse, or establish or defend claims.
When a workflow copies information to a Shopify metafield or order note, Shopify and the merchant also hold that copy. Account Canvas tracks app-created copies so that it can delete or reconcile them where technically and legally appropriate. Merchant changes can affect whether an exact app-created copy can be safely removed. New order-note requests use separate Account Canvas order metafields rather than modifying the merchant’s shared order note. Legacy shared-note entries require reconciliation or coordinated removal when automatic removal could overwrite a merchant’s changes. Uninstalling Account Canvas deactivates the local plan and removes active app sessions. Shopify later sends the mandatory shop-redaction request, after which Account Canvas deletes shop-owned records from its database. Some information may remain temporarily in provider backups or security records and will be isolated and deleted according to provider schedules and applicable law.

7. Security

We use administrative, technical, and organizational safeguards designed to protect personal information. These include Shopify authentication and signed session tokens, shop and customer ownership checks, tenant-scoped access controls, TLS in transit, application-level authenticated encryption for access tokens and protected workflow data, request-size and rate controls, restricted production access, data minimization, sanitized monitoring, bounded retention, and tested privacy-webhook handling. No system is completely secure. Merchants are responsible for protecting their Shopify accounts, limiting staff access, configuring workflows appropriately, and avoiding sensitive information that the Service is not designed to collect.

8. International processing

Account Canvas is operated by an Indiana, United States company. We and our providers may process information in the United States and other countries where privacy laws may differ from those in the person’s location. Where applicable law requires a transfer mechanism, we and our providers use measures such as adequacy decisions, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, the EU-U.S. Data Privacy Framework and its UK or Swiss extensions where valid and applicable, or another lawful safeguard. A merchant that requires a specific transfer document should contact us before enabling the Service for affected individuals. When Account Canvas acts as a controller and the GDPR or UK GDPR applies, we generally rely on:
  • performance of a contract or steps requested before entering a contract;
  • our legitimate interests in providing, securing, supporting, and improving the Services, balanced against the individual’s rights;
  • compliance with legal obligations; and
  • consent, when required and requested.
When we act as a processor, the merchant determines the legal basis for processing its customers’ information. The merchant is responsible for providing required notices and obtaining any required consent.

10. Privacy rights and choices

Depending on applicable law, an individual may have rights to request access, correction, deletion, portability, restriction, or an explanation of personal information; to object to certain processing; to withdraw consent; and to appeal a denied request. Some rights are subject to exceptions. If the request concerns a Shopify merchant’s customer-account content, order, or workflow, the customer should contact that merchant first. The merchant controls the customer relationship and can submit the appropriate Shopify privacy request. Account Canvas supports Shopify’s mandatory customer-data-request, customer-redaction, and shop-redaction webhooks and will assist merchants with applicable requests. Merchants, website visitors, and support contacts may submit a request by emailing support@accountcanvas.app with the subject “Privacy request.” We may verify identity and authority before acting. Authorized agents must provide evidence of their authority. We will not discriminate against a person for exercising an applicable privacy right. Account Canvas does not sell personal information or use it for targeted advertising, so we do not offer a sale or targeted-advertising opt-out for the Service. We also do not use personal information to make decisions that produce legal or similarly significant effects through automated profiling. An EEA or UK individual may also complain to the data-protection authority in the country where they live or work. Canadian individuals may contact the Office of the Privacy Commissioner of Canada or an applicable provincial authority. U.S. residents may contact their state attorney general or privacy authority where applicable.

11. Children

The Services are designed for Shopify merchants and authenticated customer-account users, not for children to use independently. We do not knowingly collect personal information directly from children in violation of applicable law. Merchants are responsible for determining whether their use of the Service involves minors and for providing notices, obtaining consent, and applying age-appropriate protections where required.

12. Changes to this policy

We may update this policy to reflect changes in the Services, providers, or law. We will change the “Last updated” date and provide additional notice when required. The version published when information was collected will govern to the extent required by law.

13. Contact

The privacy contact for Account Canvas is: Brandle & Co LLC, doing business as Account Canvas
3211 Boulevard Place
Indianapolis, Indiana 46208
United States
support@accountcanvas.app
Do not send passwords, access tokens, payment card information, or unredacted customer records by email. We will arrange a safer transfer method if records are needed to resolve a verified request.