Version 1.2 — Effective August 11, 2026
CloudStack Canvas, a service operated by Mid Michigan MFG, LLC, a Michigan limited liability company ("we," "us," "CSC"), is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. This policy applies to all users of cloudstackcanvas.com and related services.
Account data: Name, email address, username, profile information (company, job title, location, website, bio), and hashed passwords.
OAuth profile data: When you sign in with Google, we receive and store your name, email address, and profile picture from your Google account. We use these solely to populate your CloudStack Canvas profile and to authenticate your identity. OAuth access tokens and ID tokens are stored in our Account table solely for authentication; they are never used for any other purpose and are not shared with third parties.
Usage data: Pages visited, features used, canvas sessions, project save/load events, and error logs. Collected to improve the product.
Project data: Your infrastructure diagrams, node configurations, and generated IaC templates stored server-side when you save projects.
Contact form submissions: When you submit the contact form on our website, we store your name, email address, message subject/category, and message content in our database. If you are signed in, we also link your submission to your account. We retain contact submissions indefinitely to maintain support history and respond to inquiries. Non-account holders' contact data is also retained.
GitHub integration data: If you connect your GitHub account for Git/PR export, we store a repository-scoped access token (encrypted using AES-256-GCM), your GitHub login, and the requested OAuth scopes. This token is used solely to push generated CloudFormation templates to your repository and open pull requests at your request. It is revocable at any time via Settings → GitHub, and is never used for any other purpose.
Newsletter subscriptions: If you subscribe to our newsletter (for example from the homepage), we store your email address, the page where you subscribed, and the subscription date — whether or not you have an account. We use this only to send you product updates and news. Every newsletter includes an unsubscribe link that works without an account; unsubscribing stops all newsletter email to that address, and we retain the address only as a suppression record so we don't email you again. You can also request full removal at privacy@cloudstackcanvas.com.
Technical data: IP address, browser type, device identifiers, and session tokens needed to operate the service securely.
Payment data: Billing information is processed by Stripe. We store only a Stripe customer ID and the last 4 digits of payment methods. We never store raw card numbers.
We do not sell your personal data to third parties.
We share data only with the following data processors and third parties:
We retain your account and project data for as long as your account is active. When you delete your account via Settings → Danger Zone, your account data — projects, diagrams, settings, sessions, subscription records, and team memberships — is immediately and permanently deleted in a cascading hard delete. There is no recovery window or grace period — deletion is irreversible. If you wish to preserve your projects, export them before requesting account deletion.
One exception: contact form submissions are retained after account deletion (unlinked from the deleted account) to maintain our support history. You may request deletion of your specific submission(s) by emailing privacy@cloudstackcanvas.com.
Anonymized usage analytics may be retained indefinitely.
We use strictly necessary cookies for authentication sessions. We do not use advertising trackers or third-party analytics cookies. You may disable cookies in your browser; however, the application requires session cookies to function.
Our site administrator(s) can access the following data for the purpose of operating the Service, responding to support requests, and investigating abuse:
Operator access is governed by strict confidentiality obligations and is logged for audit purposes.
When you create a public share link for a project, anyone with the unique URL can view your canvas in read-only mode without requiring an account or authentication. Shared canvases include the project name, full node/edge configuration, mode, and last updated timestamp. You are responsible for the content of shared projects and may revoke access at any time by deleting the share link. Treat share links as sensitive URLs — anyone with the link can view your architecture.
Depending on your jurisdiction you have the right to:
To exercise these rights email privacy@cloudstackcanvas.com. We will respond within 30 days.
We use industry-standard security measures including TLS encryption in transit, encrypted storage at rest, hashed passwords (bcrypt), and periodic security reviews. No system is 100% secure; we will notify you of any confirmed breach affecting your data within 72 hours as required by GDPR.
The Service is not directed to users under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it promptly.
Your data may be processed in the United States. If you are in the EU/EEA, we transfer data under Standard Contractual Clauses (SCCs) approved by the European Commission.
We will notify you of material changes via email or in-app notice at least 30 days before they take effect. The current version is always available at this URL.
For privacy questions or requests: privacy@cloudstackcanvas.com
v1.2 changelog: Disclosed newsletter email collection (added 2026-08-09) and its account-free unsubscribe path.
v1.1 changelog: Updated for billing launch, Google sign-in, share links, contact-form storage, and GitHub App integration; corrected deletion timing (immediate, not 30 days).