Last updated: July 24, 2026
This Privacy Policy describes how Canvas ("the App", "we", "us", "our") handles data when you install and use the App on your Shopify store.
Canvas stores image layout data in your Shopify store's metafields. This includes:
Published canvas layouts are stored in your Shopify store's metafields. Imported files are stored in Shopify Files. Limited app-session, handoff, and operational records are also processed by our application hosting and database providers.
Canvas does not collect, store, or transmit:
Canvas accesses only the Shopify API scopes necessary to manage files, metafields, and products (for linking). No customer-scoped data is accessed.
Published layout data is stored as Shopify metafields. Images and rendered Canva assets are stored in your Shopify Files library and served from Shopify's CDN.
We retain app sessions, store-addressed handoff records, subscription state, and limited operational events in our application database for as long as needed to provide, secure, and troubleshoot Canvas. Temporary upload data may be processed while an asset is transferred into Shopify Files.
Canvas Desktop keeps its Shopify login cookies in a private, persistent profile on your computer. Local prompts, source media, and unaccepted generation results remain on that computer.
Canvas uses Shopify for authentication, billing, metafields, and file hosting, and Vercel for application hosting and aggregate web analytics. Canvas does not send generation requests to hosted AI model providers. Canva source metadata is processed when you import a Canva design. We do not sell personal information.
Uninstalling Canvas removes the App's access to your store. Store-addressed handoff and operational records are deleted when Shopify sends the required shop-redaction webhook. Metafield data and uploaded images remain in your Shopify store unless you delete them.
To fully remove Canvas data, delete the Canvas metafields from your store's admin (Settings → Custom data → Metafields) and remove any uploaded images from Files.
Canvas does not request access to customer or order data. We support Shopify's mandatory customer-data-request, customer-redact, and shop-redact webhooks. Shop redaction removes external records associated with the store. You may also contact us to request access, correction, or deletion where applicable.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date.
Questions about this policy? Email howdy@buildwithcanvas.com or write to TARXAN INC, 2121 Lohmans Crossing Lane, Suite 504-450, Lakeway, Texas 78734, United States.
See also: Terms of Service · Documentation