CanvasPrivacy Notice · v1.0
Back to Home
Data Governance

Privacy Policy

Version 1.0 · Effective September 19, 2026

Canvas Marketplace Inc. (“Canvas”, “we”, “us”) runs the Canvas UGC Marketplace, which connects app brands with content creators. This Privacy Policy explains how we handle personal information collected through canvasugcmp.com, the Canvas application, our emails and our support channels (together, the “Service”).

In short
  • We collect what the marketplace needs to run: account details, profile, the handles and links you register, view reports and screenshots, and payout identifiers. Card and bank details go straight to Stripe and never reach us.
  • We do not sell personal information, do not share it for targeted advertising, and run no analytics or advertising trackers. The only cookies are the ones that keep you signed in and keep bots out.
  • Brands and creators on the same campaign see each other’s marketplace activity, because that is how the marketplace works.
  • You can access, correct, export or delete your information by emailing hello@canvasugcmp.com.

01 / Who we are and what this covers

Canvas Marketplace Inc. is the controller of personal information collected through the Service. This Policy applies to everyone who visits the site or holds an account, whether as a brand, a creator or an administrator. It does not cover the practices of TikTok, Instagram, Stripe or any other third party, even where we link to them.

02 / Personal information we collect

2.1Information you give us.

  • Account data: email address, password (stored only as a salted hash), display name, role (brand or creator), and the time you accepted our terms.
  • Profile data: country; for creators, portfolio URL, niches, languages and whether you are willing to run dedicated campaign accounts; for brands, company name and app URL.
  • Campaign data: the TikTok and Instagram handles you register for a campaign, warm-up check-ins, concept hooks and captions, the URLs of the posts you publish, and reviews and notes exchanged with the other side of the campaign.
  • View reports and screenshots: the view counts you report and the screenshots you upload to support them.
  • Rights files: video files a creator delivers when a brand buys usage rights.
  • Payout identifiers: your chosen payout method and the PayPal or Wise handle you give us, or the identifier of your Stripe Connect account. We never receive card numbers, bank account numbers or government identifiers; Stripe collects those directly under its own privacy policy.
  • Two-factor data: for accounts that enable it, an encrypted authenticator secret and hashed backup codes.
  • Communications: what you send us by email or through the Service.

2.2Information collected automatically.

  • Session and device data: IP address and browser user agent, stored with each sign-in session and, for money-moving or metric-changing actions, in an append-only audit log.
  • Rate-limit counters: short-lived counts keyed by IP address or account, used to stop abuse.
  • Ledger and audit records: every wallet, campaign-fund and payout movement, and every administrative action, with the acting account and timestamp.
  • Cookies: only the strictly necessary cookies described in our Cookie Notice. We run no analytics, advertising or session-replay tools.

2.3Information from other sources.

  • Stripe: whether your Stripe customer or Connect account exists, whether it has completed onboarding and whether payouts are enabled, plus payment and transfer identifiers and statuses sent to our webhook.
  • Cloudflare: the connecting IP address and the result of the Turnstile human-verification check at sign-up.
  • Other users: reviews, notes, view reports and rights requests that the brand or creator on the other side of your campaign submits about your activity.

03 / Where it comes from

Directly from you when you register, complete your profile, apply to or run a campaign, report views or set up payouts; automatically from your browser and our infrastructure when you use the Service; from Stripe and Cloudflare as described above; and from other users of the marketplace.

04 / How we use it

  • To run the marketplace: create and secure your account, match creators to campaigns, run warm-ups, concept approvals and post reviews, compute earnings from verified views, hold and allocate campaign funds, and send payouts.
  • To verify and prevent fraud: check view reports and screenshots, detect inflated metrics, duplicate accounts and abuse, and keep an audit trail of every money-moving action.
  • To communicate with you: email verification, password resets, campaign events (offers, approvals, rejections, funding alerts, payout notices) and support. These are service messages, not marketing. If we ever send marketing email, it will carry an unsubscribe link.
  • To secure the Service: rate limiting, session management, two-factor authentication and incident investigation.
  • To comply with law and enforce our terms: respond to lawful requests, meet tax and accounting obligations, resolve disputes, and enforce the Terms of Service and Creator Agreement.
  • To improve the Service: using aggregated or de-identified statistics such as applications per campaign or average views per post. We do not use your personal information to train artificial-intelligence models.

We do not use personal information for targeted advertising, and we do not make automated decisions about you that have legal or similarly significant effects without human review; view reports above our automatic threshold are always checked by a person.

05 / How we share it

  • Other users on your campaign. A brand sees the display name, registered handles, post links, view reports and screenshots of the creators contracted to its campaigns, and the rights files it has purchased. A creator sees the brand’s company name, app and brief. Neither side sees the other’s email address, payout details or IP address.
  • Service providers that process data on our behalf under contract: Cloudflare (hosting, database, file storage, cache, bot protection and email routing), Stripe (payments, identity verification and payouts) and Resend (transactional email delivery). Each may access only what it needs to provide its service.
  • Payment providers you choose. If you are paid by PayPal or Wise, we send them your handle and the amount.
  • Professional advisers such as lawyers, accountants and insurers, under confidentiality.
  • Authorities and others when we believe in good faith that disclosure is required by law or necessary to protect the rights, safety or property of Canvas, our users or the public, including reporting suspected fraud to platforms and payment providers.
  • Business transfers. In a merger, acquisition, financing, reorganisation or sale of assets, personal information may be disclosed to the counterparty and its advisers and transferred to a successor, who will be bound by this Policy.

We do not sell personal information, and we do not share it with advertisers or data brokers.

06 / Cookies and tracking

The Service sets only strictly necessary cookies: a session cookie that keeps you signed in, a short-lived cookie used during two-factor sign-in, and security cookies set by Cloudflare. Stripe’s own pages set Stripe’s cookies when you pay or onboard there. We use no analytics, advertising, social-media or session-replay technologies and no tracking pixels in our emails. Details and controls are in the Cookie Notice.

07 / How long we keep it

DataRetention
Account and profile dataWhile your account is open. On deletion, the profile is anonymised and sign-in records are removed.
SessionsExpire after 7 days of inactivity and are deleted on sign-out or password reset.
Rate-limit countersMinutes to hours.
Campaign data, concepts, post links, reviewsWhile the campaign and your account exist, then anonymised.
View-report screenshotsDeleted automatically 120 days after upload.
Rights filesRetained for the brand that purchased them; the creator may request our copy be deleted after delivery is confirmed.
Ledger, payout items, batches and audit logKept for seven years after the transaction for accounting, tax and fraud-investigation purposes. These records are append-only and are retained after account deletion, linked to an anonymised account identifier.
Support emailUp to three years after the matter closes.

Where the law requires a longer period, or a dispute or investigation is open, we keep the relevant data until it ends.

08 / Your choices

  • Access, correction and portability. You can view and update your profile and payout details in the Service. To get a copy of your data in a machine-readable format, email hello@canvasugcmp.com from the address on your account.
  • Deletion. Email hello@canvasugcmp.com to close your account. We delete or anonymise what Section 7 allows and keep only the financial and audit records it describes.
  • Email. Service messages are part of running your account and cannot be switched off while it is open. Any marketing email will carry an unsubscribe link.
  • Cookies. You can block or delete cookies in your browser, but you will not be able to sign in without the session cookie.
  • Do Not Track and Global Privacy Control. Because we do not sell or share personal information for advertising, there is nothing for these signals to switch off. We treat a Global Privacy Control signal as a valid opt-out request where the law gives it that effect.
  • Stripe. Information you gave Stripe is controlled by Stripe; use the Stripe dashboard link in the Service or contact Stripe directly.

09 / Security

We use technical and organisational safeguards designed for a platform that moves money: TLS everywhere, salted password hashing, two-factor authentication required for administrators, per-request content-security policies, rate limiting, append-only financial and audit records enforced at the database level, private file storage with short-lived signed links, and least-privilege payment keys. No system is perfectly secure, and we cannot guarantee the security of your information. If we learn of a breach affecting you we will notify you as the law requires.

10 / International transfers

We are based in the United States and use Cloudflare’s global network, so your information may be processed in the United States and in other countries where our providers operate. Those countries may not offer the same protections as yours. Where we transfer personal information from the United Kingdom, the European Economic Area or Switzerland, we rely on our providers’ standard contractual clauses or equivalent safeguards.

11 / Children

The Service is for adults. We do not knowingly collect personal information from anyone under 18, and creators must not feature minors in content without lawful consent. If you believe a minor has given us personal information, contact us and we will delete it.

12 / Changes

We may update this Policy. Material changes will be announced by email or a prominent notice on the Service before they take effect. The version and effective date appear at the top of this page. Using the Service after the effective date means the updated Policy applies.

13 / US state privacy rights

Residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Utah and other states with comprehensive privacy laws (“State Privacy Laws”) may have the rights below, to the extent the relevant law applies to us. We honour these requests for all users regardless of state.

  • Know and access: the categories and specific pieces of personal information we hold, its sources, purposes and recipients.
  • Correct inaccurate personal information.
  • Delete personal information, subject to the exceptions in Section 7.
  • Portability: receive a copy in a portable format.
  • Opt out of sale, sharing for targeted advertising, and profiling with legal or similarly significant effects. We do none of these.
  • Limit use of sensitive personal information. We collect none within the meaning of these laws; payout and identity data go to Stripe.
  • Non-discrimination for exercising any right.
  • Appeal a decision we make on your request by replying to our response; we will answer within 45 days.

13.1How to exercise these rights. Email hello@canvasugcmp.com from the address on your account, or sign in and use the account controls. We verify requests by matching the sending address to the account and, where needed, by a confirmation link sent to that address. An authorised agent may submit a request with your signed permission; we may still confirm the request with you directly. We respond within 45 days and may extend once by a further 45 days with notice.

13.2Categories under the CCPA. The table lists the categories of personal information (as defined in Cal. Civ. Code § 1798.140) that we have collected in the past 12 months, the purposes, and the categories of third parties to which we disclose them for a business purpose. We have not sold or shared any category.

CategoryExamplesPurposesDisclosed to
IdentifiersEmail, display name, IP address, account and Stripe identifiersService operation, security, payouts, legalCloudflare, Stripe, Resend, campaign counterparties (display name only)
Customer recordsCountry, company, payout method and handleService operation, payouts, taxStripe, PayPal or Wise (if chosen)
Commercial informationWallet, campaign funds, payout and rights-purchase historyService operation, accounting, fraud preventionStripe, professional advisers
Internet activitySession timestamps, user agent, audit log, rate-limit countersSecurity, fraud preventionCloudflare
Audio-visual contentScreenshots, rights video files, post linksVerification, rights deliveryCloudflare (storage), campaign counterparties
Professional informationPortfolio URL, niches, languagesMatching creators to campaignsCampaign counterparties
InferencesNone drawn
Sensitive personal informationNone collected by us; Stripe collects identity and financial data directly

13.3California Shine the Light. We do not disclose personal information to third parties for their own direct-marketing purposes. California residents may confirm this by emailing hello@canvasugcmp.com with “Shine the Light Request” in the subject line.

13.4Nevada. We do not sell covered information as defined in NRS Chapter 603A. Nevada residents may record an opt-out request anyway by emailing hello@canvasugcmp.com.

14 / Contact

Privacy questions, rights requests and complaints go to: