Privacy Policy

Privacy Policy

Version 1.3 — Effective September 2, 2026

1. Introduction

CloudStack Canvas, a service operated by Mid Michigan MFG, LLC, a Michigan limited liability company ("we," "us," "CSC"), is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. This policy applies to all users of cloudstackcanvas.com and related services.

2. Data We Collect

Account data: Name, email address, username, profile information (company, job title, location, website, bio, and an optional profile picture you upload, stored in our database), and hashed passwords.

OAuth profile data: When you sign in with Google, we receive and store your name, email address, and profile picture from your Google account. We use these solely to populate your CloudStack Canvas profile and to authenticate your identity. OAuth access tokens and ID tokens are stored in our Account table solely for authentication; they are never used for any other purpose and are not shared with third parties.

Usage data: Project save history, monthly export counts, the time of your last sign-in and an approximate last-activity time, error logs, and the site analytics described next. Collected to operate the Service and improve the product.

Site analytics: We run our own first-party page-view analytics; no third-party analytics service receives your data. Each page view records the page viewed (from a fixed list of page names), the campaign tag from the link you followed (if any), the domain of the referring site (if any), and a one-way visitor hash derived from your IP address and browser type with a salt that rotates daily — the raw IP address and browser string are never stored in analytics records, and the daily salt rotation means views cannot be linked across days. Raw page-view records are not linked to your account and are kept only for short-term operational review — we delete them on a rolling basis, targeting a 90-day maximum; aggregate daily counts, which contain no per-visitor data, are retained indefinitely.

Signup attribution: If you first arrived via a campaign link (a URL containing ?ref=), we record that campaign tag — and, where present, the domain of the external site that referred you — on your account when you sign up, so we know which channels bring users. This attribution is stored with your account and deleted with it.

Project data: Your infrastructure diagrams, node configurations, and generated IaC templates stored server-side when you save projects.

Contact form submissions: When you submit the contact form on our website, we store your name, email address, message subject/category, and message content in our database. If you are signed in, we also link your submission to your account. We retain contact submissions indefinitely to maintain support history and respond to inquiries. Non-account holders' contact data is also retained.

GitHub integration data: If you connect your GitHub account for Git/PR export, we store a repository-scoped access token (encrypted using AES-256-GCM), your GitHub login, and the requested OAuth scopes. This token is used solely to push generated CloudFormation templates to your repository and open pull requests at your request. It is revocable at any time via Settings → GitHub, and is never used for any other purpose.

Newsletter subscriptions: If you subscribe to our newsletter (for example from the homepage), we store your email address, the page where you subscribed, and the subscription date — whether or not you have an account. We use this only to send you product updates and news. Every newsletter includes an unsubscribe link that works without an account; unsubscribing stops all newsletter email to that address, and we retain the address only as a suppression record so we don't email you again. You can also request full removal at privacy@cloudstackcanvas.com.

Organization invitations: When an Organization member invites someone by email, we store the invited email address, the assigned role, who sent the invitation, and its expiry date in order to deliver and process the invitation — including for invitees who do not yet have an account.

Technical data: IP address, browser type, and session tokens needed to operate the service securely.

Payment data: Billing information is processed by Stripe. We store only Stripe customer and subscription identifiers and your plan status. We never store card numbers or card details — billing information lives with Stripe.

3. Data We Do NOT Collect

  • AWS credentials, access keys, or secret keys
  • Live AWS account data or resource inventories
  • The contents of your live cloud infrastructure
  • Sensitive personal data (health, financial, biometric) — do not enter these in project descriptions

4. How We Use Your Data

  • Provide and operate the Service (storing projects, authenticating users)
  • Send transactional emails (account confirmation, billing receipts)
  • Send product update emails (if you opted in)
  • Analyze usage to improve features and fix bugs
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

We do not sell your personal data to third parties.

5. Data Sharing & Processors

We share data only with the following data processors and third parties:

  • AWS — cloud infrastructure hosting and database provider for CloudStack Canvas
  • Stripe — payment processing; card data never touches our servers (subject to Stripe's Privacy Policy)
  • Resend — transactional email delivery (receives your name and email address to send account confirmations, password resets, billing receipts, organization invitations, and contact responses — and, for contact-form notifications, the content of your message)
  • Google — OAuth sign-in provider; only the access token needed to verify your identity, never shared or sold
  • GitHub — only when you connect GitHub for Git/PR export; we authenticate via OAuth and transmit only the CloudFormation templates you explicitly request to be pushed
  • Legal authorities — when required by law, court order, or to protect safety

6. Data Retention & Deletion

We retain your account and project data for as long as your account is active. When you delete your account via Settings → Danger Zone, your account data — projects, diagrams, settings, sessions, subscription records, and team memberships — is immediately deleted from our live database in a cascading hard delete, and any active subscription is canceled. There is no recovery window or grace period — we cannot restore a deleted account. Residual copies of deleted data may persist in encrypted database backups for a limited period (currently up to 7 days) before those backups expire; backups are used only for disaster recovery, never to restore deleted accounts. If you wish to preserve your projects, export them before deleting your account.

Exceptions: (1) contact form submissions are retained after account deletion (unlinked from the deleted account) to maintain our support history — you may request deletion of your specific submission(s) by emailing privacy@cloudstackcanvas.com; (2) if an administrative action was ever taken on your account (for example a suspension), the administrative record of that action retains your email address so the history of administrative actions stays accurate; (3) if you unsubscribed from our newsletter, we keep that email address as a suppression record so we never email it again; (4) records held by our payment processor, Stripe, are retained by Stripe under its own terms and legal obligations.

Raw site-analytics records are not linked to your account and are deleted on a rolling basis (90-day target); aggregate daily page-view counts, which contain no per-visitor data, are retained indefinitely (see Section 2).

7. Cookies and Tracking

We use strictly necessary cookies for authentication sessions. If you arrive via a campaign link (a URL containing ?ref=), we also set one first-party cookie, csc_ref, which holds the campaign tag and a timestamp for up to 30 days; it is used only to attribute your visits and any eventual signup to the campaign that brought you, contains no identifier, and is never shared with anyone. We do not use advertising trackers or third-party analytics cookies. You may disable cookies in your browser; however, the application requires session cookies to function.

8. Operator Access

Our site administrator(s) can access the following data for the purpose of operating the Service, responding to support requests, and investigating abuse:

  • Account details: email address, name, subscription plan and billing status (including whether a Stripe billing account is linked — never card details), suspension and email-verification state, feature-access flags, sign-in and last-activity timestamps, and signup attribution (Section 2)
  • Organization memberships and the number of projects on an account (the admin panel does not display project contents)
  • Full contact form submissions (including sender name, email, subject, category, and message)
  • Aggregate site analytics (page-view counts by page, day, campaign tag, and referring domain — no per-visitor data) and error logs
  • The record of administrative actions previously taken on accounts

Administrative changes to accounts — suspension, verification, plan changes, password resets, deletions — are logged for audit purposes. Operator access is governed by strict confidentiality obligations.

9. Shared Links

When you create a public share link for a project, anyone with the unique URL can view your canvas in read-only mode without requiring an account or authentication. Shared canvases include the project name, full node/edge configuration, mode, and last updated timestamp. You are responsible for the content of shared projects and may revoke access at any time by deleting the share link. Treat share links as sensitive URLs — anyone with the link can view your architecture.

10. Your Rights (GDPR / CCPA)

Depending on your jurisdiction you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate data via Settings → Profile
  • Erasure — request deletion of your account and associated data
  • Portability — export your project data in JSON format
  • Restriction — request we stop processing your data in certain circumstances
  • Opt-out of marketing — unsubscribe via Settings → Preferences or the email footer; newsletter subscribers without an account can use the unsubscribe link in any newsletter email

To exercise these rights email privacy@cloudstackcanvas.com. We will respond within 30 days.

11. Data Security

We use industry-standard security measures including TLS encryption in transit, encrypted storage at rest, hashed passwords (bcrypt), and periodic security reviews. No system is 100% secure; if we confirm a breach affecting your personal data, we will notify affected users without undue delay and notify supervisory authorities within 72 hours where GDPR requires.

12. Children

The Service is not directed to users under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it promptly.

13. International Transfers

Your data is processed in the United States. Where our processors transfer EU/EEA personal data, those transfers are covered by the Standard Contractual Clauses incorporated in our agreements with those processors.

14. Changes to This Policy

We will notify you of material changes via email or in-app notice, and no change takes effect before it is published at this URL with an updated version number and effective date.

15. Contact

For privacy questions or requests: privacy@cloudstackcanvas.com

v1.3 changelog: Disclosed first-party site analytics (daily-rotating salted visitor hash, 90-day raw retention, permanent aggregate counts), the csc_ref campaign cookie, and signup attribution; corrected the usage-, technical-, and payment-data descriptions to what is actually collected; added uploaded profile pictures, organization invitations, and sign-in/activity timestamps; expanded post-deletion retention exceptions (administrative records, newsletter suppression, Stripe records, encrypted backups) and noted subscription cancellation on deletion; rewrote operator access to match the admin panel; corrected the breach-notification and international-transfer statements; removed Sentry (not currently active) and a future-feature reference; replaced the fixed 30-day notice promise with publish-first change notice.

v1.2 changelog: Disclosed newsletter email collection (added 2026-08-09) and its account-free unsubscribe path.

v1.1 changelog: Updated for billing launch, Google sign-in, share links, contact-form storage, and GitHub App integration; corrected deletion timing (immediate, not 30 days).