Privacy Policy
Privacy Policy for Canvasses
Effective Date: July 10, 2025
1. Introduction
Welcome to Canvasses.org. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, process, and safeguard your information when you visit our website canvasses.org, purchase our products, or use our services.
This policy applies to all information collected through our website and any related services, sales, marketing, or events. By using our services, you agree to the collection and use of information in accordance with this policy.
2. What Information We Collect
We collect personal information that you voluntarily provide to us and information that is automatically collected from your device.
a) Information You Provide Directly:
-
Contact and Identity Information: Your first and last name, email address, postal address, and phone number when you create an account, place an order, or contact us.
-
Payment Information: Credit card details or other payment information when you make a purchase. This information is processed directly by our secure payment processor (Shopify Payments) and is not stored on our servers.
-
Communications: Any information you provide when you contact us via Shopify Inbox, email, or other means, including feedback and product reviews.
b) Information We Collect Automatically:
-
Usage and Device Information: When you access our website, we automatically collect information about your device and how you interact with our site. This may include your IP address, browser type, operating system, device identifiers, referring URLs, pages viewed, and the dates/times of your visits. This is collected using cookies and similar tracking technologies.
3. How and Why We Use Your Information (Legal Basis)
Under GDPR, we are required to have a "legal basis" for processing your data. Here is how we use your information and the legal grounds we rely on:
4. Who We Share Your Information With
We do not sell your personal information. We only share it with trusted third parties who help us operate our business. These include:
-
E-commerce Platform: Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you. Your data is stored through Shopify’s data storage, databases, and the general Shopify application.
-
Fulfillment and Dropshipping Partner: To get your products to you, we share your name and shipping address with our vendors to fulfill orders on your behalf.
-
Payment Processors: Shopify Payments and other payment gateways process your payment information securely.
-
Marketing and Advertising Partners: We share information with partners to help us with marketing and advertising. This data is often collected via cookies and pixels and is based on your consent. These partners include:
-
Google Analytics: For analytics and running targeted ads.
-
Social Media Apps: For running targeted ads and tracking campaign performance.
-
Email Marketing and SMS: To manage our email and SMS marketing campaigns.
-
-
Customer Service and Communication Tools:
-
Shopify: To manage our direct communications with you.
-
Shop App: To facilitate an accelerated checkout and provide order tracking through the Shopify ecosystem.
-
-
Analytics and Performance Apps:
-
SEO Apps: To analyze and improve our website's performance.
-
-
Loyalty and Affiliate Program Providers:
-
Loyalty Rewards & Affiliate Apps: To operate our customer loyalty and affiliate programs.
-
-
Embedded Content: When you interact with embedded content, like a YouTube video on our site, the provider (Google/YouTube) may collect data as if you had visited their site directly.
5. Cookies and Tracking Technologies
Our website uses cookies, pixels, and other tracking technologies to provide functionality, analyze performance, and for marketing purposes. When you first visit our site, you are presented with a cookie banner where you can provide or withdraw your consent for non-essential cookies. For more details, please see our Cookie Policy page.
6. International Data Transfers
As we use global service providers like Shopify, and Google, your personal information may be transferred to and processed in countries outside of the European Economic Area (EEA), such as the United States. We ensure that these transfers are lawful and that your data is protected through mechanisms like Standard Contractual Clauses (SCCs), which are legally binding agreements approved by the European Commission ensuring a similar standard of data protection.
7. Data Retention
We will only retain your personal information for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. For example, we are required to keep order information for [Specify number, e.g., 6-10] years for tax and legal reasons. Data used only for marketing will be kept until you withdraw your consent.
8. Your Rights Under GDPR
If you are a resident of the EEA, you have the following data protection rights:
-
The right to access: You can request copies of your personal data.
-
The right to rectification: You can request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
-
The right to erasure (right to be forgotten): You can request that we erase your personal data, under certain conditions.
-
The right to restrict processing: You can request that we restrict the processing of your personal data, under certain conditions.
-
The right to object to processing: You can object to our processing of your personal data, under certain conditions.
-
The right to data portability: You can request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
To exercise any of these rights, please contact us.
You also have the right to lodge a complaint with a supervisory authority, such as the Finnish Data Protection Ombudsman, if you believe our processing of your personal data infringes GDPR.
9. Children's Privacy
Our services are not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children under 16.
10. Changes to This Privacy Policy
We may update this policy from time to time. The updated version will be indicated by a revised "Effective Date" and will be effective as soon as it is accessible. We encourage you to review this privacy policy frequently to be informed of how we are protecting your information.
11. Contact Us
If you have any questions about this Privacy Policy or our practices, please contact us by clicking here.
By using Canvasses.org, you consent to the terms of this Privacy Policy.