Privacy Policy

Privacy Policy

Version 1.2 — Effective August 11, 2026

1. Introduction

CloudStack Canvas, a service operated by Mid Michigan MFG, LLC, a Michigan limited liability company ("we," "us," "CSC"), is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. This policy applies to all users of cloudstackcanvas.com and related services.

2. Data We Collect

Account data: Name, email address, username, profile information (company, job title, location, website, bio), and hashed passwords.

OAuth profile data: When you sign in with Google, we receive and store your name, email address, and profile picture from your Google account. We use these solely to populate your CloudStack Canvas profile and to authenticate your identity. OAuth access tokens and ID tokens are stored in our Account table solely for authentication; they are never used for any other purpose and are not shared with third parties.

Usage data: Pages visited, features used, canvas sessions, project save/load events, and error logs. Collected to improve the product.

Project data: Your infrastructure diagrams, node configurations, and generated IaC templates stored server-side when you save projects.

Contact form submissions: When you submit the contact form on our website, we store your name, email address, message subject/category, and message content in our database. If you are signed in, we also link your submission to your account. We retain contact submissions indefinitely to maintain support history and respond to inquiries. Non-account holders' contact data is also retained.

GitHub integration data: If you connect your GitHub account for Git/PR export, we store a repository-scoped access token (encrypted using AES-256-GCM), your GitHub login, and the requested OAuth scopes. This token is used solely to push generated CloudFormation templates to your repository and open pull requests at your request. It is revocable at any time via Settings → GitHub, and is never used for any other purpose.

Newsletter subscriptions: If you subscribe to our newsletter (for example from the homepage), we store your email address, the page where you subscribed, and the subscription date — whether or not you have an account. We use this only to send you product updates and news. Every newsletter includes an unsubscribe link that works without an account; unsubscribing stops all newsletter email to that address, and we retain the address only as a suppression record so we don't email you again. You can also request full removal at privacy@cloudstackcanvas.com.

Technical data: IP address, browser type, device identifiers, and session tokens needed to operate the service securely.

Payment data: Billing information is processed by Stripe. We store only a Stripe customer ID and the last 4 digits of payment methods. We never store raw card numbers.

3. Data We Do NOT Collect

  • AWS credentials, access keys, or secret keys
  • Live AWS account data or resource inventories (unless a future feature explicitly requests it with your consent)
  • The contents of your live cloud infrastructure
  • Sensitive personal data (health, financial, biometric) — do not enter these in project descriptions

4. How We Use Your Data

  • Provide and operate the Service (storing projects, authenticating users)
  • Send transactional emails (account confirmation, billing receipts)
  • Send product update emails (if you opted in)
  • Analyze usage to improve features and fix bugs
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

We do not sell your personal data to third parties.

5. Data Sharing & Processors

We share data only with the following data processors and third parties:

  • AWS — cloud infrastructure hosting and database provider for CloudStack Canvas
  • Stripe — payment processing; card data never touches our servers (subject to Stripe's Privacy Policy)
  • Resend — transactional email delivery (receives your name and email address to send account confirmations, password resets, billing receipts, and contact responses)
  • Google — OAuth sign-in provider; only the access token needed to verify your identity, never shared or sold
  • GitHub — only when you connect GitHub for Git/PR export; we authenticate via OAuth and transmit only the CloudFormation templates you explicitly request to be pushed
  • Sentry — error tracking and monitoring (active only when configured; receives technical error context and stack traces to help us identify and fix bugs)
  • Legal authorities — when required by law, court order, or to protect safety

6. Data Retention & Deletion

We retain your account and project data for as long as your account is active. When you delete your account via Settings → Danger Zone, your account data — projects, diagrams, settings, sessions, subscription records, and team memberships — is immediately and permanently deleted in a cascading hard delete. There is no recovery window or grace period — deletion is irreversible. If you wish to preserve your projects, export them before requesting account deletion.

One exception: contact form submissions are retained after account deletion (unlinked from the deleted account) to maintain our support history. You may request deletion of your specific submission(s) by emailing privacy@cloudstackcanvas.com.

Anonymized usage analytics may be retained indefinitely.

7. Cookies and Tracking

We use strictly necessary cookies for authentication sessions. We do not use advertising trackers or third-party analytics cookies. You may disable cookies in your browser; however, the application requires session cookies to function.

8. Operator Access

Our site administrator(s) can access the following data for the purpose of operating the Service, responding to support requests, and investigating abuse:

  • User account email address, name, and subscription plan
  • Full contact form submissions (including sender name, email, subject, category, and message)
  • Error logs and usage analytics

Operator access is governed by strict confidentiality obligations and is logged for audit purposes.

9. Shared Links

When you create a public share link for a project, anyone with the unique URL can view your canvas in read-only mode without requiring an account or authentication. Shared canvases include the project name, full node/edge configuration, mode, and last updated timestamp. You are responsible for the content of shared projects and may revoke access at any time by deleting the share link. Treat share links as sensitive URLs — anyone with the link can view your architecture.

10. Your Rights (GDPR / CCPA)

Depending on your jurisdiction you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — correct inaccurate data via Settings → Profile
  • Erasure — request deletion of your account and associated data
  • Portability — export your project data in JSON format
  • Restriction — request we stop processing your data in certain circumstances
  • Opt-out of marketing — unsubscribe via Settings → Preferences or the email footer; newsletter subscribers without an account can use the unsubscribe link in any newsletter email

To exercise these rights email privacy@cloudstackcanvas.com. We will respond within 30 days.

11. Data Security

We use industry-standard security measures including TLS encryption in transit, encrypted storage at rest, hashed passwords (bcrypt), and periodic security reviews. No system is 100% secure; we will notify you of any confirmed breach affecting your data within 72 hours as required by GDPR.

12. Children

The Service is not directed to users under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it promptly.

13. International Transfers

Your data may be processed in the United States. If you are in the EU/EEA, we transfer data under Standard Contractual Clauses (SCCs) approved by the European Commission.

14. Changes to This Policy

We will notify you of material changes via email or in-app notice at least 30 days before they take effect. The current version is always available at this URL.

15. Contact

For privacy questions or requests: privacy@cloudstackcanvas.com

v1.2 changelog: Disclosed newsletter email collection (added 2026-08-09) and its account-free unsubscribe path.

v1.1 changelog: Updated for billing launch, Google sign-in, share links, contact-form storage, and GitHub App integration; corrected deletion timing (immediate, not 30 days).