> ## Documentation Index
> Fetch the complete documentation index at: https://docs.accountcanvas.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How Account Canvas collects, uses, shares, protects, and retains personal information.

**Effective date: September 3, 2026**\
**Last updated: September 3, 2026**

This Privacy Policy describes how Brandle & Co LLC, doing business as Account
Canvas ("Account Canvas," "we," "us," or "our"), collects, uses, discloses,
and protects personal information when merchants install or use the Account Canvas
Shopify application, when their customers interact with Account Canvas features in
Shopify customer accounts, and when anyone visits our website, documentation, or
contacts support (collectively, the "Services").

This policy should be read together with our [Terms of Use](/terms) and
[Subprocessors list](/subprocessors).

## 1. Our privacy roles

The role we have depends on the information and why it is processed:

* **Merchant and buyer data processed for the Service.** The Shopify merchant
  generally determines why and how its buyer personal information is processed. For
  that information, the merchant is generally the controller or business, and Account
  Canvas acts as its processor or service provider. We process this information on the
  merchant's documented instructions, including the merchant's configuration of pages,
  blocks, conditions, variables, forms, and workflows.
* **Our business operations.** Account Canvas is a controller or business for
  information used to administer merchant accounts, billing, security, support,
  product operations, and our websites and documentation.
* **Shopify.** Shopify separately processes information under its own agreements and
  privacy notices. Merchants and buyers should also review the policies that apply to
  their Shopify relationship.

The legal labels above can vary by jurisdiction, but the practical allocation remains
the same: merchants control their customer relationships and Account Canvas operates
the configured Service on their behalf.

## 2. Information we process

We limit collection to information reasonably needed to provide, secure, support, and
maintain the Services.

### Information received from Shopify

Depending on the features a merchant enables and the permissions Shopify approves, we
may receive or access:

* Shopify shop domain, store identity, locale, plan and subscription status, installed
  app status, and relevant account configuration;
* merchant-user session information, including Shopify user identifiers, name, email,
  locale, account-owner status, and granted access scopes;
* products, product images or files, and related commerce content selected by the
  merchant for display;
* customer account information used for merchant-configured personalization, such as
  customer identifier, first and last name, display name, email address, order count,
  order identifiers and ownership information, market currency, and store-credit
  account information or balance;
* customer and order metafields that the merchant configures Account Canvas to read or
  write; and
* privacy, installation, scope, and billing webhook information needed to keep the app
  synchronized with Shopify and respond to legal requests.

Some customer information is read at display time through Shopify's Customer Account
API and used only to render the merchant-configured experience. Account Canvas does
not intentionally create a separate long-term profile from that display-time data.

### Information merchants provide

Merchants may provide:

* pages, blocks, sections, templates, images, links, labels, variables, conditions,
  visibility rules, form fields, and other content or configuration;
* workflow settings, notification preferences, and authorized Shopify metafield or
  order-note destinations;
* support messages, screenshots, diagnostic details, and contact information; and
* billing choices and other administrative settings. Shopify processes app charges;
  we receive plan, charge, trial, and subscription-status information, not full payment
  card details.

### Information merchant customers submit

When a merchant enables a form, order action, or other workflow, a signed-in customer
may submit the fields selected by the merchant. A submission can include text, contact
preferences, order instructions, gift messages, purchase-order references, customer
or order identifiers, and other information requested by that merchant.

Account Canvas is not designed to collect, and the Service attempts to reject, payment
card numbers or security codes, government identifiers, health or medical information,
passwords, access tokens, private keys, or other authentication secrets. Merchants and
customers must not submit those categories through Account Canvas.

### Technical, security, and usage information

We may process IP address and request metadata, browser and device information,
timestamps, Shopify and app route information, authentication and webhook status,
rate-limit records, sanitized error details, pseudonymous tenant references, and
first-party usage events such as page views, block views, condition evaluations, and
workflow submissions.

We configure our application monitoring to disable default personal-information
collection, Session Replay, and SDK log forwarding. We also sanitize error, trace, and
analytics data to reduce the chance that customer identifiers, message bodies, secrets,
or URL query data are sent to monitoring systems. No safeguard can guarantee that
technical data will never be personal information.

### Website, documentation, and support information

When someone visits our website or documentation, our hosting providers may process
IP address, browser and device details, request logs, security data, and cookie or
similar technology data. When someone contacts us, we process the sender's contact
details, message, attachments, and any follow-up correspondence.

## 3. How we use information

We use personal information to:

* authenticate merchants and customers through Shopify;
* provide and render merchant-configured customer-account content;
* evaluate conditions and personalization variables;
* receive, validate, store, display, export, and delete workflow submissions;
* write information to Shopify customer metafields, order metafields, or order notes
  only when the merchant configures and authorizes that destination;
* send a merchant a transactional notification that a workflow was submitted. The
  notification contains a workflow title and submission reference, but is designed not
  to contain the customer's answers or customer and order identifiers;
* administer subscriptions, trials, entitlements, and billing status through Shopify;
* provide support and respond to privacy, security, and legal requests;
* detect abuse, enforce limits, secure the Service, investigate incidents, and maintain
  reliable operations;
* understand product usage through minimized first-party analytics and improve the
  Service; and
* comply with law and enforce our agreements.

We do not sell personal information. We do not share personal information for
cross-context behavioral advertising, and we do not use merchant or buyer data to
build advertising profiles across merchants.

## 4. When we disclose information

We may disclose information in the following circumstances:

* **To the merchant.** Workflow submissions and related records are available to the
  Shopify merchant that configured the workflow. A merchant may direct Account Canvas
  to copy selected information into its Shopify records.
* **To service providers and subprocessors.** We use providers for Shopify platform
  services, application and database hosting, transactional email, error monitoring,
  website and documentation hosting, and business email. They may process information
  only for the relevant service and subject to applicable contractual restrictions.
  Our current providers are described on the [Subprocessors page](/subprocessors).
* **For legal and safety reasons.** We may disclose information when reasonably
  necessary to comply with law or valid legal process; protect the rights, safety, and
  security of Account Canvas, Shopify, merchants, customers, or others; investigate
  fraud or abuse; or establish, exercise, or defend legal claims.
* **Business transactions.** Information may be disclosed as part of a merger,
  financing, acquisition, reorganization, bankruptcy, or sale of all or part of our
  business, subject to appropriate confidentiality and legal requirements.
* **With consent or direction.** We may disclose information when the relevant person
  or merchant asks or authorizes us to do so.

We may use and disclose aggregated or de-identified information that cannot reasonably
be linked to a person, subject to applicable law.

## 5. Cookies and local storage

The embedded application relies on Shopify authentication and related security
technologies. Account Canvas uses a short-lived, signed cookie to protect the return
from a Shopify billing approval flow. The merchant admin interface also uses browser
local storage to remember whether certain setup notices have been dismissed. These
items are used for security and product functionality, not cross-site advertising.

Our website and documentation providers may use essential cookies or similar
technologies for security, routing, preferences, and service operation. Optional
analytics will be used only as configured by us and subject to consent where required.
Browser settings can restrict cookies, but doing so may prevent parts of the Services
from working.

## 6. Retention and deletion

We retain personal information only for as long as reasonably necessary for the
purposes described above, subject to these normal periods:

* **Workflow submissions and linked analytics:** normally 45 days from submission.
* **Case-specific workflow holds:** an authorized hold for active support,
  security, merchant-request, or legal work can delay normal deletion, but the hold
  cannot extend beyond 90 days from the first hold. A Shopify customer or shop
  redaction request overrides a hold.
* **Other first-party usage analytics:** normally 45 days.
* **Local operational issue records and completed retention-run records:** normally
  30 days.
* **Expired online authentication sessions:** removed by the recurring retention process. Offline credentials are retained while needed for background access and token refresh; verified uninstall removes active credentials; ambiguous installation state requires reconciliation before destructive cleanup.
* **Privacy export scope:** encrypted and available for no more than 30 days; associated
  request records are removed after their operational period.
* **Merchant content and configuration:** retained while the merchant uses the Service,
  until the merchant deletes it, or until final shop redaction after uninstall.
* **Lifecycle replay protection:** minimal shop-domain, installation-state, event-ID, topic, and timestamp records are retained separately from deleted merchant content to prevent delayed or replayed events from affecting a later installation. These records do not contain access tokens or webhook bodies.
* **Support, billing, legal, and security records:** retained for the period reasonably
  needed to resolve the matter, meet financial or legal obligations, prevent abuse, or
  establish or defend claims.

When a workflow copies information to a Shopify metafield or order note, Shopify and
the merchant also hold that copy. Account Canvas tracks app-created copies so that it
can delete or reconcile them where technically and legally appropriate. Merchant
changes can affect whether an exact app-created copy can be safely removed. New order-note requests use separate Account Canvas order metafields rather than modifying the merchant’s shared order note. Legacy shared-note entries require reconciliation or coordinated removal when automatic removal could overwrite a merchant’s changes.

Uninstalling Account Canvas deactivates the local plan and removes active app sessions.
Shopify later sends the mandatory shop-redaction request, after which Account Canvas
deletes shop-owned records from its database. Some information may remain temporarily
in provider backups or security records and will be isolated and deleted according to
provider schedules and applicable law.

## 7. Security

We use administrative, technical, and organizational safeguards designed to protect
personal information. These include Shopify authentication and signed session tokens,
shop and customer ownership checks, tenant-scoped access controls, TLS in transit,
application-level authenticated encryption for access tokens and protected workflow
data, request-size and rate controls, restricted production access, data minimization,
sanitized monitoring, bounded retention, and tested privacy-webhook handling.

No system is completely secure. Merchants are responsible for protecting their Shopify
accounts, limiting staff access, configuring workflows appropriately, and avoiding
sensitive information that the Service is not designed to collect.

## 8. International processing

Account Canvas is operated by an Indiana, United States company. We and our providers
may process information in the United States and other countries where privacy laws may
differ from those in the person's location.

Where applicable law requires a transfer mechanism, we and our providers use measures
such as adequacy decisions, the EU Standard Contractual Clauses, the UK International
Data Transfer Addendum or Agreement, the EU-U.S. Data Privacy Framework and its UK or
Swiss extensions where valid and applicable, or another lawful safeguard. A merchant
that requires a specific transfer document should contact us before enabling the
Service for affected individuals.

## 9. Legal bases for EEA and UK processing

When Account Canvas acts as a controller and the GDPR or UK GDPR applies, we generally
rely on:

* performance of a contract or steps requested before entering a contract;
* our legitimate interests in providing, securing, supporting, and improving the
  Services, balanced against the individual's rights;
* compliance with legal obligations; and
* consent, when required and requested.

When we act as a processor, the merchant determines the legal basis for processing its
customers' information. The merchant is responsible for providing required notices and
obtaining any required consent.

## 10. Privacy rights and choices

Depending on applicable law, an individual may have rights to request access,
correction, deletion, portability, restriction, or an explanation of personal
information; to object to certain processing; to withdraw consent; and to appeal a
denied request. Some rights are subject to exceptions.

If the request concerns a Shopify merchant's customer-account content, order, or
workflow, the customer should contact that merchant first. The merchant controls the
customer relationship and can submit the appropriate Shopify privacy request. Account
Canvas supports Shopify's mandatory customer-data-request, customer-redaction, and
shop-redaction webhooks and will assist merchants with applicable requests.

Merchants, website visitors, and support contacts may submit a request by emailing
[support@accountcanvas.app](mailto:support@accountcanvas.app) with the subject
"Privacy request." We may verify identity and authority before acting. Authorized
agents must provide evidence of their authority. We will not discriminate against a
person for exercising an applicable privacy right.

Account Canvas does not sell personal information or use it for targeted advertising,
so we do not offer a sale or targeted-advertising opt-out for the Service. We also do
not use personal information to make decisions that produce legal or similarly
significant effects through automated profiling.

An EEA or UK individual may also complain to the data-protection authority in the
country where they live or work. Canadian individuals may contact the Office of the
Privacy Commissioner of Canada or an applicable provincial authority. U.S. residents
may contact their state attorney general or privacy authority where applicable.

## 11. Children

The Services are designed for Shopify merchants and authenticated customer-account
users, not for children to use independently. We do not knowingly collect personal
information directly from children in violation of applicable law. Merchants are
responsible for determining whether their use of the Service involves minors and for
providing notices, obtaining consent, and applying age-appropriate protections where
required.

## 12. Changes to this policy

We may update this policy to reflect changes in the Services, providers, or law. We
will change the "Last updated" date and provide additional notice when required. The
version published when information was collected will govern to the extent required by
law.

## 13. Contact

The privacy contact for Account Canvas is:

**Brandle & Co LLC, doing business as Account Canvas**\
3211 Boulevard Place\
Indianapolis, Indiana 46208\
United States\
[support@accountcanvas.app](mailto:support@accountcanvas.app)

Do not send passwords, access tokens, payment card information, or unredacted customer
records by email. We will arrange a safer transfer method if records are needed to
resolve a verified request.


## Related topics

- [Privacy and data](/privacy-and-data.md)
- [Welcome to Account Canvas](/index.md)
- [Terms of Use](/terms.md)
- [Workflows and forms](/workflows-and-forms.md)
- [Install, reinstall, and uninstall](/install-and-uninstall.md)
