CanvassLite Back to Home

Privacy Policy

Effective date: February 1, 2026

CanvassLite ("we", "us", "our") operates the canvasslite.com website and platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Name and email address (campaign organizers)
  • Name only (volunteers joining via invite link)

1.2 Campaign Data

Campaign organizers upload or enter data including:

  • Household addresses, city, state, and ZIP code
  • Resident names and phone numbers (optional)
  • Visit records: status, notes, timestamps
  • Geographic coordinates (derived from address geocoding)

1.3 Usage Data

We automatically collect limited technical information including IP address, browser type, and access timestamps for security and service operation purposes.

1.4 Location Data

The volunteer map interface may request access to your device's GPS location to center the map on your position. This data is not stored on our servers — it is used only in your browser to display the map.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the CanvassLite platform
  • Authenticate users and secure access to campaigns
  • Send transactional emails (login PINs, account verification, trial/billing notifications)
  • Geocode addresses using the U.S. Census Bureau Geocoder (a public government API)
  • Process payments through Stripe (we do not store credit card information)
  • Send data retention warnings before scheduled account deletion

3. Data Storage and Security

  • Hosting: All data is stored in Amazon Web Services (AWS) in the us-east-1 (N. Virginia) region, within the United States.
  • Encryption at rest: Campaign data is stored in Amazon S3 with server-side encryption (SSE-KMS) using AWS-managed keys.
  • Encryption in transit: All connections use HTTPS/TLS encryption.
  • Tenant isolation: Each campaign's data is stored in a separate, isolated namespace. No campaign can access another campaign's data.
  • Authentication: User sessions are secured with JSON Web Tokens (JWT) with 7-day expiration.

4. Data Sharing and Third Parties

We do not sell, rent, or trade your personal information or campaign data. We share data only with the following service providers, solely to operate the platform:

  • Amazon Web Services (AWS) — infrastructure hosting, data storage, email receiving (us-east-1 region)
  • Brevo (formerly Sendinblue) — transactional email delivery (login PINs, notifications)
  • Stripe — payment processing (we never see or store your card details)
  • U.S. Census Bureau Geocoder — address-to-coordinate lookup (publicly available government API; addresses are sent for geocoding and not stored by the Census Bureau beyond processing)

We may also disclose information if required by law or to protect the rights, safety, or property of our users or the public.

5. Data Retention

  • Active accounts: Your data is retained as long as your account or subscription is active.
  • After trial or subscription ends: Data is retained for 60 days. A warning email is sent after 30 days. After 60 days, all campaign data is permanently deleted.
  • Deleted campaigns: When you delete a campaign, it enters a 30-day grace period, then is permanently deleted.
  • Data export: You may export your campaign data as CSV at any time before deletion.

6. Your Rights

You have the right to:

  • Access your data by logging into the dashboard or exporting CSV
  • Correct your data by editing household records or account information
  • Delete your campaign data by using the delete campaign feature, or by contacting us
  • Export your data in CSV format at any time

To exercise any of these rights, email us at support@canvasslite.com.

7. Cookies

CanvassLite uses only essential browser storage (localStorage) to maintain your login session and offline visit queue. We do not use tracking cookies, analytics scripts, or third-party advertising trackers.

8. Children's Privacy

CanvassLite is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. U.S. State Privacy Laws

If you are a resident of California (CCPA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), or another state with consumer privacy legislation:

  • We do not sell your personal information.
  • We do not use your data for targeted advertising.
  • We do not share your data with third parties for their own marketing purposes.
  • You may request deletion of your data at any time by contacting us.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. The "Effective date" at the top of this page indicates when the policy was last revised.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, contact us at:

Email: support@canvasslite.com

CanvassLite

© 2026 CanvassLite. Built for campaigns that knock doors.