Privacy Policy
This policy explains how THEME CANVAS UK LIMITED handles personal data across our website and our mobile applications. It is written to be read, not skimmed past — if anything is unclear, email us.
1. Who we are
The data controller for the personal data described in this policy is THEME CANVAS UK LIMITED, a company registered in Northern Ireland under Company No. NI736836, with its registered office at 3a Main Street, Hillsborough, Northern Ireland, BT26 6AE, United Kingdom.
You can contact us about anything in this policy at team@themecanvas.uk. We are not currently required to appoint a Data Protection Officer; our privacy contact point is the same email address.
2. Scope
This policy covers:
- our website at https://themecanvas.uk; and
- the mobile applications published by THEME CANVAS UK LIMITED on the Apple App Store and Google Play ("our apps").
It does not cover third-party websites we link to, or the app stores themselves, which operate under their own privacy policies.
3. Information we collect on the website
3.1 Correspondence
Our website has no contact forms and no accounts. If you email us at team@themecanvas.uk, we receive whatever you choose to send — typically your email address, name and the content of your message — and we use it only to respond to you and manage the relationship that follows.
3.2 Technical and server logs
The website is served by our hosting provider, Cloudflare. As part of delivering and securing the site, Cloudflare processes technical request data such as your IP address, user agent (browser and device information) and request details in server and security logs. We use this data solely for security, abuse prevention and reliable delivery of the site.
3.3 No analytics or advertising cookies
The website itself sets no analytics or advertising cookies and runs no third-party trackers. See our Cookie Policy for the small number of strictly-necessary cookies Cloudflare's security layer may set.
4. Information we collect in our apps
The following describes the categories of data our apps may process. Individual apps may use only a subset of these; each app's store listing describes exactly what applies to it.
4.1 Account information
Only if an app offers accounts: your email address and a display name you choose. Accounts are always optional unless a feature genuinely cannot work without one (for example, syncing across devices).
4.2 User content created in the app
Content you create in an app (for example documents, designs, notes or settings) is stored on your device. If the app offers sync and you enable it, that content is also stored on our servers so it can follow you across devices. You remain the owner of your content at all times.
4.3 Device and technical data
Device model, operating-system version, app version, language setting, crash state and a non-advertising install identifier used to distinguish installations for support and diagnostics. We do not collect advertising identifiers.
4.4 Usage analytics (only if enabled)
Where an app includes usage analytics, we collect aggregated feature-usage events (for example, "export used") to understand which features matter. This never includes advertising identifiers and is not used to profile individuals.
4.5 Crash and diagnostics reports
If an app crashes, a diagnostic report (stack trace, device model, OS version, app version) may be collected so we can find and fix the fault.
4.6 App permissions
Our apps request only the system permissions they need, each for a stated purpose. Every permission is optional and can be revoked at any time in your device's system settings. Permissions an app may request include:
| Permission | Purpose | Optional? |
|---|---|---|
| Notifications | Reminders and updates you have asked for | Yes — revocable in system settings |
| Photos / media (read or save) | Importing images into your content or saving exports you request | Yes — requested only at the moment of use |
| Camera | Capturing an image directly into your content, where the app offers this | Yes — requested only at the moment of use |
4.7 What we do NOT do
- We do not sell personal data.
- We do not include advertising SDKs in our apps.
- We do not track you across other companies' apps or websites.
- We do not collect precise location data.
5. Purposes and lawful bases
Under the UK GDPR we must have a lawful basis for each use of personal data:
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Responding to your emails and enquiries | Correspondence, contact details | Legitimate interests (running our business and communicating with people who contact us) |
| Providing app features you use, including accounts and sync | Account information, user content | Performance of a contract (our Terms of Use with you) |
| Securing the website and apps, preventing abuse | Server/security logs, device and technical data | Legitimate interests (keeping our services secure and available) |
| Fixing crashes and faults | Crash and diagnostics reports | Legitimate interests (maintaining a working product) |
| Understanding aggregate feature usage | Usage analytics events (if enabled) | Consent, where required; otherwise legitimate interests (improving our products) |
| Sending optional emails such as early-access updates | Email address | Consent — withdrawable at any time by replying "unsubscribe" |
| Keeping records we must keep (e.g. invoices) | Transaction and correspondence records | Legal obligation (tax and company law) |
6. Who we share data with
We use a small number of service providers who process data under contract on our behalf:
- Cloudflare, Inc. — website hosting, content delivery and security.
- Apple Inc. and Google LLC — distribution of our apps and, where used, in-app purchase billing. For the purchase transaction itself, Apple and Google act under their own privacy policies; we never see your full payment details.
- Crash-reporting or analytics tooling — only if enabled in a given app, limited to the diagnostic and aggregated data described in section 4. We commit to keeping this section current as tooling changes.
We do not sell or rent personal data to anyone. We may disclose data if required to do so by law, court order or a competent authority.
7. International transfers
Some of our providers process data outside the United Kingdom — for example, Cloudflare operates a global network. Where personal data leaves the UK, we rely on appropriate safeguards: UK adequacy regulations for the destination country where they exist, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or standard contractual clauses as applicable.
8. Retention
We keep personal data only as long as needed for the purpose it was collected for:
- Email correspondence: up to 24 months after our last contact with you, then deleted unless a legal obligation requires longer retention.
- Server and security logs: retained per Cloudflare's short rolling retention periods for security logs.
- App account data: kept for as long as your account exists, and deleted within 30 days of account deletion.
- Crash and diagnostics data: 90 days.
- Backups: purged on a rolling 30-day cycle, so deleted data leaves backups within at most 30 further days.
9. Your rights
Under the UK GDPR you have the following rights over your personal data:
- Access — ask for a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — ask us to delete your data ("right to be forgotten") where no legal basis requires us to keep it.
- Restriction — ask us to limit how we use your data while a dispute or check is resolved.
- Portability — receive data you provided to us in a structured, commonly used, machine-readable format.
- Objection — object to processing based on legitimate interests, and to any direct marketing (we will stop marketing immediately on request).
- Withdrawal of consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
- Automated decision-making — rights in relation to solely automated decisions with legal or similarly significant effect. For clarity: we make no such automated decisions.
To exercise any right, email team@themecanvas.uk. We respond within one month. We may need to verify your identity before acting on a request — we will only ask for what is proportionate to do so.
10. Complaints
You have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO): https://ico.org.uk/, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113. We would appreciate the chance to resolve any concern first — please contact us before going to the ICO if you can.
11. Children
Our website and apps are not directed at children under 13, and we do not knowingly collect personal data from them. If you are a parent or guardian and believe a child has provided us with personal data, contact us at team@themecanvas.uk and we will delete it. The age ratings assigned in the Apple App Store and Google Play apply to our apps.
12. Account and data deletion
Where an app offers accounts, you can delete your account and associated data in two ways:
- In the app: Settings → Account → Delete account (available in each app from the version in which accounts ship).
- By email: send a message to team@themecanvas.uk with the subject "Account deletion request" from the email address linked to your account.
Deletion is completed within 30 days. After deletion, we may retain only the minimal records we are legally required to keep — for example, invoices and transaction records retained for up to 6 years under UK tax law — and data needed to establish, exercise or defend legal claims. Such retained records are kept isolated and are not used for any other purpose.
13. iOS App Tracking Transparency
Our apps do not track users across other companies' apps or websites, and do not share user data with data brokers. Accordingly, our apps do not show the iOS App Tracking Transparency (ATT) prompt, because no activity meeting Apple's definition of "tracking" occurs. If this ever changes, we will request your consent first through the ATT framework before any such tracking takes place.
14. Google Play Data Safety
We commit that the Data Safety declarations published on our Google Play store listings accurately mirror this policy, and that we will update both together whenever our data practices change.
15. Security
We protect personal data with measures appropriate to the risk, including: TLS encryption for data in transit; encryption at rest where applicable; least-privilege access controls so data is accessible only to those who need it; and reputable infrastructure providers. No system is perfectly secure, but if a personal-data breach occurs that risks your rights and freedoms, we will notify the ICO and, where required, affected individuals in accordance with UK GDPR Articles 33 and 34.
16. Changes to this policy
We may update this policy as our services and the law evolve. Material changes will be announced on this page (and, for app users, in the relevant app or its release notes) before they take effect. The "Last updated" date at the top of this page always reflects the current version, and we maintain that date with discipline — if the date hasn't changed, the policy hasn't changed.
17. Contact
Questions, concerns or requests about this policy or your personal data:
Email: team@themecanvas.uk
Post: THEME CANVAS UK LIMITED, 3a Main Street, Hillsborough, Northern Ireland, BT26 6AE, United Kingdom.