Legal

Privacy Policy

Effective date: 31 July 2026 · Last updated: 31 July 2026

This policy explains how THEME CANVAS UK LIMITED handles personal data across our website and our mobile applications. It is written to be read, not skimmed past — if anything is unclear, email us.

1. Who we are

The data controller for the personal data described in this policy is THEME CANVAS UK LIMITED, a company registered in Northern Ireland under Company No. NI736836, with its registered office at 3a Main Street, Hillsborough, Northern Ireland, BT26 6AE, United Kingdom.

You can contact us about anything in this policy at team@themecanvas.uk. We are not currently required to appoint a Data Protection Officer; our privacy contact point is the same email address.

2. Scope

This policy covers:

  • our website at https://themecanvas.uk; and
  • the mobile applications published by THEME CANVAS UK LIMITED on the Apple App Store and Google Play ("our apps").

It does not cover third-party websites we link to, or the app stores themselves, which operate under their own privacy policies.

3. Information we collect on the website

3.1 Correspondence

Our website has no contact forms and no accounts. If you email us at team@themecanvas.uk, we receive whatever you choose to send — typically your email address, name and the content of your message — and we use it only to respond to you and manage the relationship that follows.

3.2 Technical and server logs

The website is served by our hosting provider, Cloudflare. As part of delivering and securing the site, Cloudflare processes technical request data such as your IP address, user agent (browser and device information) and request details in server and security logs. We use this data solely for security, abuse prevention and reliable delivery of the site.

3.3 No analytics or advertising cookies

The website itself sets no analytics or advertising cookies and runs no third-party trackers. See our Cookie Policy for the small number of strictly-necessary cookies Cloudflare's security layer may set.

4. Information we collect in our apps

The following describes the categories of data our apps may process. Individual apps may use only a subset of these; each app's store listing describes exactly what applies to it.

4.1 Account information

Only if an app offers accounts: your email address and a display name you choose. Accounts are always optional unless a feature genuinely cannot work without one (for example, syncing across devices).

4.2 User content created in the app

Content you create in an app (for example documents, designs, notes or settings) is stored on your device. If the app offers sync and you enable it, that content is also stored on our servers so it can follow you across devices. You remain the owner of your content at all times.

4.3 Device and technical data

Device model, operating-system version, app version, language setting, crash state and a non-advertising install identifier used to distinguish installations for support and diagnostics. We do not collect advertising identifiers.

4.4 Usage analytics (only if enabled)

Where an app includes usage analytics, we collect aggregated feature-usage events (for example, "export used") to understand which features matter. This never includes advertising identifiers and is not used to profile individuals.

4.5 Crash and diagnostics reports

If an app crashes, a diagnostic report (stack trace, device model, OS version, app version) may be collected so we can find and fix the fault.

4.6 App permissions

Our apps request only the system permissions they need, each for a stated purpose. Every permission is optional and can be revoked at any time in your device's system settings. Permissions an app may request include:

PermissionPurposeOptional?
NotificationsReminders and updates you have asked forYes — revocable in system settings
Photos / media (read or save)Importing images into your content or saving exports you requestYes — requested only at the moment of use
CameraCapturing an image directly into your content, where the app offers thisYes — requested only at the moment of use

4.7 What we do NOT do

  • We do not sell personal data.
  • We do not include advertising SDKs in our apps.
  • We do not track you across other companies' apps or websites.
  • We do not collect precise location data.

5. Purposes and lawful bases

Under the UK GDPR we must have a lawful basis for each use of personal data:

PurposeData categoriesLawful basis
Responding to your emails and enquiriesCorrespondence, contact detailsLegitimate interests (running our business and communicating with people who contact us)
Providing app features you use, including accounts and syncAccount information, user contentPerformance of a contract (our Terms of Use with you)
Securing the website and apps, preventing abuseServer/security logs, device and technical dataLegitimate interests (keeping our services secure and available)
Fixing crashes and faultsCrash and diagnostics reportsLegitimate interests (maintaining a working product)
Understanding aggregate feature usageUsage analytics events (if enabled)Consent, where required; otherwise legitimate interests (improving our products)
Sending optional emails such as early-access updatesEmail addressConsent — withdrawable at any time by replying "unsubscribe"
Keeping records we must keep (e.g. invoices)Transaction and correspondence recordsLegal obligation (tax and company law)

6. Who we share data with

We use a small number of service providers who process data under contract on our behalf:

  • Cloudflare, Inc. — website hosting, content delivery and security.
  • Apple Inc. and Google LLC — distribution of our apps and, where used, in-app purchase billing. For the purchase transaction itself, Apple and Google act under their own privacy policies; we never see your full payment details.
  • Crash-reporting or analytics tooling — only if enabled in a given app, limited to the diagnostic and aggregated data described in section 4. We commit to keeping this section current as tooling changes.

We do not sell or rent personal data to anyone. We may disclose data if required to do so by law, court order or a competent authority.

7. International transfers

Some of our providers process data outside the United Kingdom — for example, Cloudflare operates a global network. Where personal data leaves the UK, we rely on appropriate safeguards: UK adequacy regulations for the destination country where they exist, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or standard contractual clauses as applicable.

8. Retention

We keep personal data only as long as needed for the purpose it was collected for:

  • Email correspondence: up to 24 months after our last contact with you, then deleted unless a legal obligation requires longer retention.
  • Server and security logs: retained per Cloudflare's short rolling retention periods for security logs.
  • App account data: kept for as long as your account exists, and deleted within 30 days of account deletion.
  • Crash and diagnostics data: 90 days.
  • Backups: purged on a rolling 30-day cycle, so deleted data leaves backups within at most 30 further days.

9. Your rights

Under the UK GDPR you have the following rights over your personal data:

  • Access — ask for a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — ask us to delete your data ("right to be forgotten") where no legal basis requires us to keep it.
  • Restriction — ask us to limit how we use your data while a dispute or check is resolved.
  • Portability — receive data you provided to us in a structured, commonly used, machine-readable format.
  • Objection — object to processing based on legitimate interests, and to any direct marketing (we will stop marketing immediately on request).
  • Withdrawal of consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
  • Automated decision-making — rights in relation to solely automated decisions with legal or similarly significant effect. For clarity: we make no such automated decisions.

To exercise any right, email team@themecanvas.uk. We respond within one month. We may need to verify your identity before acting on a request — we will only ask for what is proportionate to do so.

10. Complaints

You have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO): https://ico.org.uk/, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113. We would appreciate the chance to resolve any concern first — please contact us before going to the ICO if you can.

11. Children

Our website and apps are not directed at children under 13, and we do not knowingly collect personal data from them. If you are a parent or guardian and believe a child has provided us with personal data, contact us at team@themecanvas.uk and we will delete it. The age ratings assigned in the Apple App Store and Google Play apply to our apps.

12. Account and data deletion

Where an app offers accounts, you can delete your account and associated data in two ways:

  • In the app: Settings → Account → Delete account (available in each app from the version in which accounts ship).
  • By email: send a message to team@themecanvas.uk with the subject "Account deletion request" from the email address linked to your account.

Deletion is completed within 30 days. After deletion, we may retain only the minimal records we are legally required to keep — for example, invoices and transaction records retained for up to 6 years under UK tax law — and data needed to establish, exercise or defend legal claims. Such retained records are kept isolated and are not used for any other purpose.

13. iOS App Tracking Transparency

Our apps do not track users across other companies' apps or websites, and do not share user data with data brokers. Accordingly, our apps do not show the iOS App Tracking Transparency (ATT) prompt, because no activity meeting Apple's definition of "tracking" occurs. If this ever changes, we will request your consent first through the ATT framework before any such tracking takes place.

14. Google Play Data Safety

We commit that the Data Safety declarations published on our Google Play store listings accurately mirror this policy, and that we will update both together whenever our data practices change.

15. Security

We protect personal data with measures appropriate to the risk, including: TLS encryption for data in transit; encryption at rest where applicable; least-privilege access controls so data is accessible only to those who need it; and reputable infrastructure providers. No system is perfectly secure, but if a personal-data breach occurs that risks your rights and freedoms, we will notify the ICO and, where required, affected individuals in accordance with UK GDPR Articles 33 and 34.

16. Changes to this policy

We may update this policy as our services and the law evolve. Material changes will be announced on this page (and, for app users, in the relevant app or its release notes) before they take effect. The "Last updated" date at the top of this page always reflects the current version, and we maintain that date with discipline — if the date hasn't changed, the policy hasn't changed.

17. Contact

Questions, concerns or requests about this policy or your personal data:

Email: team@themecanvas.uk
Post: THEME CANVAS UK LIMITED, 3a Main Street, Hillsborough, Northern Ireland, BT26 6AE, United Kingdom.