Privacy Policy
What CanvasCircle collects, why, and your rights.
Effective date: June 15, 2026 · Version 2.15
Summary
CanvasCircle is a free art listing platform. We collect the minimum information needed to run the Service: a single email address (used both to sign you in and as the public contact email on your listings), a password, a display name, a unique @handle, a Facebook profile URL (required to post listings), an optional location, the listings you create, the listings you save, and basic technical data needed to keep the site secure. When you message another user through the "Email Seller" button on a listing, we store and deliver that first message; replies after that go directly between the two parties' email accounts and never pass through CanvasCircle (see Section 5). Sellers may also choose to submit a short Ownership Verification video for a listing, these videos are stored privately, used only for admin review, and then automatically deleted within about 24 hours (see Section 5). Sellers see basic analytics on their own listings, daily counts of views, saves, and inquiries, plus a record of price changes, to help them understand engagement; analytics never reveal who individual viewers are. We don't sell your data. We don't run ads. We don't track you across other sites.
1. Who we are
"CanvasCircle," "we," "us," and "our" refer to the operator of canvascircle.art. You can reach us at admin@canvascircle.art.
2. Information we collect
Information you give us
- Account information (required at signup): email address, password (stored only as a hash), display name, and a unique @handle. The email serves two purposes: it's how you sign in, and it's the contact email other users see on your listings (via the "Email Seller" / "Email Buyer" button). There's only one email per account.
- Required to post each sale listing (until you're Established): a short ownership-verification video (≤30 seconds) showing the artwork in your hands with a handwritten card displaying your @handle + today's date. The admin reviews each video and either approves the listing (which publishes with an Ownership Verified badge) or rejects. Non-Established sellers must submit a video with every sale listing, there's no carve-out for additional listings. Every verified listing also counts toward the 4-verified-listing criterion for Established Member status. "In Search Of" requests are exempt, they're buyer requests, not sale listings. Established Members (collectors who've met the auto-promotion criteria or received admin-granted status) bypass this gate; their sale listings publish without per-listing video. Video bytes are deleted within ~24 hours of review; we keep only a cryptographic fingerprint plus audit metadata (see Ownership Verification section below).
- Optional Facebook profile URL: if you add it to your profile, your listings will show a "Message on Facebook" button so buyers can reach you on Messenger. You can also set "Facebook Messenger" as your preferred contact method. Leaving this field blank is totally fine, buyers can still contact you via the "Email Seller" button on every listing.
- Optional profile information: location (city/state/ZIP, shown only to signed-in viewers on your listings).
- Optional "About" blurb: a short free-form text (up to 1,000 characters) you can write on your Profile to describe yourself as a collector. About text is reviewed by the admin before it goes live. Once approved, it is publicly visible on your seller page and on the seller block of your listings. Do not include personal information you don't want to be public (home address, phone number, real legal documents, etc.), once approved, this text is visible to anyone, signed in or not.
- Optional reference relationships: if you request another user to be a sales reference for you (or accept being one for someone else), CanvasCircle stores the relationship, which two accounts are linked, who initiated, the status (pending / accepted / rejected), and the timestamps. Accepted reference relationships are publicly visible on the seller's profile (showing the referrer's display name + @handle).
- Listings: for items you offer for sale, artist, title, description, dimensions, photos, price, condition, and other fields you fill in. For "In Search Of" (ISO) buyer requests, artist or title you're seeking, optional reference image, budget range, and any other details you provide.
- Optional Ownership Verification submissions: if you choose to apply for the Ownership Verified badge on one of your listings, you upload a short video (up to 30 seconds, 25 MB) showing the artwork together with a handwritten card displaying your @handle and the date filmed. The video is stored in a private bucket, only the reviewing admin can access it via a short-lived signed URL. After review (typically within a day or two), the video bytes are automatically deleted within about 24 hours. We retain only a non-reversible audit record of the submission: the decision (approved or rejected), the SHA-256 fingerprint of the video, submission and review timestamps, the reviewing admin's identifier, video size and duration, and any rejection note. The fingerprint cannot be used to reconstruct the video, it's kept indefinitely to detect a video being reused across submissions, which is a fraud signal. See Section 5 for what other users see, and Section 7 for retention details.
- Inquiry messages sent through the "Email Seller" button. When you send a buyer-to-seller inquiry through the in-listing contact form, CanvasCircle stores the message, sender, recipient, listing referenced, subject, full message body, the buyer's reply-to email captured at send time, an OPTIONAL phone number the buyer chose to include (see below), and the timestamp, and delivers it to the seller's contact email via our email provider (Resend). The seller's reply, and every subsequent exchange between the two parties, is sent directly from the seller's own email client to the buyer's address using the Reply-To header on the original message. Those follow-up replies never pass through CanvasCircle and are not stored by us. Only the first inquiry, the one sent through the form on the site, lives in our database. See Section 5 for visibility and Section 7 for retention.
- Optional phone number on an inquiry. The inquiry form has an optional field where the buyer (the sender) can include a phone number if they'd like the seller to call or text instead of replying by email. Phone numbers are never stored on profiles and are never displayed publicly. They appear only on the specific inquiry the buyer included them with, and only the recipient (the seller of that listing) and the admin can see them. If the buyer leaves the field blank, no phone number is stored. The seller does NOT have a stored phone field of their own, if the seller wants to share their number back, they do so off-platform (via the email reply, text reply, or call back). This keeps phone-number disclosure one-way and per-inquiry: the buyer opts in for one conversation, the seller never has a number to scrape, and CanvasCircle never displays phone numbers in any public or signed-in browsing surface.
- Offers ("Make an Offer" feature). Signed-in buyers can propose a price on any active sale listing via the "Offer" button. Each offer creates a database row containing the listing referenced, the proposer (buyer for the initial offer; seller for any counter-offer), the responder (the other party), the dollar amount, an optional short text note (capped at 500 characters, links blocked), the status, timestamps, and any decision note the responder attached. Counter-offers create new rows that point back to the offer they counter via parent_offer_id so the full negotiation chain stays reconstructable. Offers are NOT contracts. They are non-binding negotiation messages; nothing happens automatically when an offer is accepted, the two parties still complete the transaction off-platform, and either party can decline at any point. Visibility: only the two parties to an offer (proposer + responder) and the admin can see it; other users on the same listing never see anyone else's offers, amounts, or notes. Sellers may optionally configure a private per-listing auto-reject floor (a dollar threshold below which incoming offers are automatically declined and not delivered to the seller); the floor is stored on the listing row, never shown to buyers, and is solely to filter low-ball offers. The seller is not notified of below-floor attempts. The buyer, at submit time, sees an inline error message stating that their offer was automatically declined because it is below the seller's minimum for the listing, that the seller was not notified, and that they may submit a higher amount to try again — the floor amount itself is not disclosed. The below-floor attempt is not persisted to the offers table.
- Offer push notifications and saver nudges. When a buyer submits an offer that passes the seller's auto-reject floor, CanvasCircle sends the seller a push notification (if enabled) and writes an audit row recording who was notified about which offer. CanvasCircle may also (using the same push-notification infrastructure) send a "someone made an offer on a piece you saved" nudge to other users who have saved the same listing, to alert them that interest is building. Saver nudges are throttled to at most one per saver per listing per 24 hours, are opt-in (you must have enabled push notifications and saved the listing), and never reveal the offer amount or any identifying information about the buyer.
- Collections (personal catalog of owned pieces). Signed-in users can add pieces they own to a personal Collection that lives separately from sale listings. Each Collection item stores: artist, artwork title, medium, category (Unique/Original or Limited Edition), an image you upload, optional dimensions, optional frame size, optional "COA included" flag, an optional public "Story" field (capped at 500 characters and scrubbed for prices, links, phone numbers, and sale solicitations), an item-level public/private toggle, optional private fields (your personal "notes," your "appraised value," and "what you paid"), an optional pointer to the listing it originated from if you bought the piece on CanvasCircle, and create/update timestamps. Profile-level fields control the surface as a whole: a "Collection is public" boolean (off by default) and an optional public "About my Collection" blurb (capped at 1,000 characters, scrubbed by the same rules). Going public with your Collection requires Established Member status, see the Terms of Use for details. The private fields (private notes, appraised value, paid value) are never displayed publicly anywhere on the platform, are not exposed via any public API, and are not used by any matching or recommendation algorithm. They live in your row solely for your record-keeping and are visible only to you and to the admin. Images uploaded for Collection items are stored in a separate
collection-imagesbucket; image URLs include an unguessable per-item identifier so they aren't trivially scrapeable, but the bucket itself is public for performance reasons and we recommend you do not upload images you would consider sensitive. The per-item public/private toggle and the profile-level "Collection is public" boolean control visibility to other users — they do not exclude the CanvasCircle administrator from viewing Collection items for moderation and Terms-of-Use enforcement purposes. The administrator can view every public-facing field on every Collection item (including items you've marked private and items inside a Collection that is set to private overall) using internal admin tooling. The private fields described above (private notes, appraised value, paid value) remain administratively unviewable in routine moderation tooling and would only be accessed via direct database queries in genuine forensic or legal situations. If the administrator removes a Collection item as part of moderation, the owner sees a dismissable banner on the Collection tab of their portal the next time they sign in, showing the piece (artist and title), the administrator's reason, and the date of removal. CanvasCircle stores a "tombstone" record of the removal (containing the original item ID, owner ID, snapshot of artist + title, reason, removing administrator's ID, and timestamps) for an indefinite period as an internal audit trail; the tombstone does NOT contain the image itself, the description, the public story, or any of the private fields. A backup copy of the removed image is separately retained in our R2 backup mirror for forensic purposes (see Section 7) and is not displayed anywhere on the platform. - In-Search-Of (ISO) match notifications. When another user posts an "In Search Of" listing and the artist (and, if provided, the title) on that listing matches a piece in your Collection, CanvasCircle may send you a push notification telling you a buyer is looking, with a link to the ISO post. The same matching algorithm produces an aggregate public count on each ISO listing ("N collectors in the community own a matching piece"); that count is anonymous and never reveals which specific users own a match. Items you have marked private at the item level are still counted in the aggregate and still trigger your own push notifications, the privacy boundary is "your identity is never disclosed to the ISO poster," not "your match is excluded from the algorithm." Sale listings you have flipped into Collection state ("in_collection" status) are also included in matching on the same terms. You may suppress these notifications by removing the matching piece from your Collection, by disabling push permission in your browser, or by closing your account.
- Listing ↔ Collection round-trip and "Sell this piece" conversion. Sale listings can be flipped between "Available" and "in Collection" state at any time from your portal. When in-Collection, the listing is hidden from the public catalog and the seller page's "For Sale" tab but is shown on the public Collection tab if you've opted in. Verification badges, prices, images, and dimensions are preserved across flips on the same listing row. When you convert a native Collection item into a brand-new sale listing using the "Sell this piece" button, CanvasCircle deletes the source Collection item, copies the image into the listing-images bucket, and creates a fresh listing row; the new listing does NOT inherit any verification from the Collection item (Collection items never have verification) and is subject to the standard per-listing verification rules. Your private Collection fields (notes / appraised value / paid value) are not copied into the new listing and are lost when the source item is deleted; export them first if you want to retain them outside CanvasCircle.
- Preferred contact method. Sellers can OPTIONALLY set a preferred-contact-method on their profile, Email / Phone / Facebook Messenger / Either (default Either). This is a soft signal shown to signed-in viewers on the seller's listings and public seller page as a small label (e.g. "Prefers phone, include your phone number in the Email Seller form"). It does not contain a phone number or any other identifying data, just a preference. Sellers can change or remove it from their portal at any time.
- Follows and saved searches. Signed-in users can subscribe to alerts about new listings in three ways: (a) tap "+ Follow artist" on any listing to follow an artist by name; (b) tap "+ Follow this seller" on a seller's public page to follow a seller; (c) apply filters on the catalog (category / price range / Established / Verified / seller / text search) and tap "🔔 Save this search" to save the entire filter combination as a named search. CanvasCircle stores one row per follow / saved search, for follows: the user, the kind (artist or seller), the artist name OR the seller's user_id, and the timestamp; for saved searches: additionally a JSON snapshot of the filter criteria and a user-chosen name for the search. Follows and saved searches are private: artists, sellers, and other users cannot see who follows them or what filters anyone has saved. Only you (and the admin, for moderation / debugging) can see your own from the "Following" section in your portal. You can remove any of them at any time from that section, removal deletes the row.
- Follow-alert delivery log. When a new listing matching one of your follows becomes publicly visible, CanvasCircle sends you a push notification (if you've opted into notifications) and writes an audit row recording which user was notified about which listing at what time. Follow alerts are push-only, we do not send email for these events, by design (per-event emails for follow alerts get noisy fast). The audit row exists for two purposes: (a) preventing duplicate notifications if the same listing matches both an artist follow and a seller follow you have, and (b) enforcing a per-user daily cap (currently 20 follow-alerts per day) so a busy day of new listings doesn't overwhelm anyone. Only you and the admin can see this log; sellers and artists cannot. The push payload itself follows the same encrypted-in-transit model described in Section 4.
- Price-drop alerts on saved listings. When you save a listing (the heart icon) and the seller subsequently drops the asking price by a significant amount (currently ≥ 5% AND ≥ $25), CanvasCircle sends you a push notification with the new and previous prices. Price-drop alerts are push-only, no email, same design choice as follow alerts. To prevent spam if a seller toggles the price up and down, we record a "last notified about this saved listing" timestamp on your saved-listings row; subsequent drops on the same listing within 30 days are silently skipped. This means CanvasCircle uses your existing saved-listings rows for two purposes: the heart bookmark you already see (which other users' save counts contribute to publicly), and the per-listing notify-window timestamp (which only you and the admin can see). Unsaving a listing removes both the bookmark and the notification eligibility.
- Communications: messages you send us through the "Contact Admin" feature or by email.
- Push-notification subscriptions (optional): if you tap "Enable" on the notifications banner in your portal, we store the device's push endpoint URL, two encryption keys (the standard P-256 public key and an authentication secret from your browser), the user-agent string of your device at subscribe time, and timestamps for created/last-used. We use these only to deliver push notifications to that device, currently when a buyer sends you an inquiry. You can revoke at any time from the same banner ("Disable") or by clearing site data in your browser settings. We store one row per device per browser, so revoking on one device doesn't affect others.
- User blocks (optional self-service tool). If you choose to block another user from a seller page on CanvasCircle, we store a row containing your account identifier (the blocker), the other account's identifier (the blocked party), and a timestamp. Blocks are symmetric: when you block someone, their listings + seller page disappear from your view of CanvasCircle, AND your listings + page disappear from theirs. The block list is private: the user you blocked is not notified and the platform never tells either party who has blocked whom. Blocking on CanvasCircle does NOT block off-platform communication. If you've previously exchanged email, Facebook Messenger, phone numbers, or other contact info with that person, through a prior inquiry or anywhere else, they can still reach you through those channels; only CanvasCircle blocks what CanvasCircle controls. Admin accounts cannot be blocked (the admin is the platform's moderation channel; blocking them would make moderation unreachable). You can unblock anyone you've blocked at any time from My Account → Profile → Blocked users; unblocking restores visibility immediately in both directions.
Information we collect automatically
- Usage data: which listings you view and save, search and filter activity, device and browser type, IP address, approximate location derived from IP, and timestamps.
- Per-listing view events (used to power the listing's public view counter and the seller's analytics chart). Each view records the listing, a timestamp, and, if you were signed in at the time, your account identifier. We use the identifier internally to filter the seller's own visits out of their analytics and to detect view manipulation; we never expose individual viewer identities to sellers. The chart shows daily totals only.
- Listing price-change history: when a seller edits the asking price on one of their listings, the platform records a row containing the old price, the new price, the listing identifier, and a timestamp. This history powers the price-drop markers on the seller's own analytics chart and helps the admin investigate disputes about what a listing was priced at on a given date.
- Technical logs: errors, security events, request metadata. We use these to keep the site running and secure.
- Cookies and local storage: we use a small number of cookies and browser storage entries to keep you signed in, remember filter preferences on the catalog, and measure basic aggregate usage. We do not use third-party advertising or cross-site tracking cookies.
3. How we use your information
- To provide the Service: show you the catalog, sign you in, save your listings and saves, send transactional emails (welcome, password reset, admin replies, broadcast announcements you've opted into).
- To moderate listings and prevent abuse, fraud, and security issues.
- To respond to your inquiries and support requests.
- To deliver buyer-to-seller inquiry messages: when you submit an inquiry through the "Email Seller" form, we use the recipient's stored contact email to deliver your message and we attach your contact email as the Reply-To so the seller can respond directly to you without our involvement.
- To rate-limit and audit inquiry messages for abuse prevention. We cap how many inquiry messages a single account can send per hour (currently 5), and we use the stored audit log to investigate spam reports or harassment complaints.
- To deliver push notifications to subscribers. When you opt in, we send a push to your device for these events: (a) a buyer messages you about one of your listings, (b) a new listing matches an artist or seller you follow, and (c) a seller drops the price on a listing you saved. All event-driven notifications are push-only (no email) by design. We do not use push notifications for marketing, announcements, or any other purpose without separate disclosure, only the events you've opted in to.
- To improve the Service based on aggregate usage patterns.
- To comply with legal obligations and enforce our Terms of Use.
4. Service providers we share data with
We use a small set of third-party services to operate CanvasCircle. We share only what's needed for them to do their job. Each one is bound by its own privacy and security commitments.
- Supabase, database, authentication, file storage, and serverless functions. Stores your account, profile, listings, images, and saved-listing records. supabase.com/privacy.
- Cloudflare, hosting, content delivery, and basic security/DDoS protection for the website. Sees IP addresses and request metadata. We also use Cloudflare's R2 object storage for a nightly off-site backup mirror of our listing and Collection image buckets (see Section 7 for the retention details); R2 sees only the image bytes themselves, not database rows or any of your personal information. cloudflare.com/privacypolicy.
- Resend, sends transactional and broadcast emails (welcome, password reset, admin replies, announcements). Sees recipient email and message contents. resend.com/legal/privacy-policy.
- Sightengine, automated image content moderation. When you upload an image to your Collection, the image bytes are sent to Sightengine's API for scanning across categories (nudity, weapons, violence, drugs, hate symbols, etc.). The scan returns probability scores which CanvasCircle uses to allow, hold for admin review, or refuse the upload. Sightengine receives the raw image bytes for the duration of the scan; we do not control their retention beyond their own published policy. No CanvasCircle account identifiers (your user ID, email, display name, etc.) are sent to Sightengine — only the image. sightengine.com/legal/privacy-policy.
- Apple Push Notification service (APNs), delivers push notifications to iPhones, iPads, and Macs that have installed the CanvasCircle PWA and opted in to notifications. APNs sees the encrypted push payload (the body and title are encrypted with keys only your browser can decrypt) along with delivery metadata: when a push is sent, the recipient's anonymous push endpoint, and basic delivery telemetry. APNs is operated by Apple and is the only path through which iOS can receive notifications from web apps. apple.com/legal/privacy.
- Firebase Cloud Messaging (FCM), same role as APNs, but for Android devices and Chrome browsers. Sees the same shape of metadata. FCM is operated by Google. firebase.google.com/support/privacy.
- Mozilla autopush, push delivery for Firefox browsers. Same role as APNs/FCM, operated by Mozilla. mozilla.org/privacy/firefox.
About push notification delivery: when you opt in to notifications, your browser registers with the push service for your platform (Apple, Google, or Mozilla) and gives us back an opaque endpoint URL. We send pushes by POSTing an encrypted payload to that URL. The push service routes the notification to your device. Neither we nor the push service can read the encrypted payload contents in transit, only your browser (which holds the decryption keys) can read them on receipt. The push services do see the timing of each push and the destination endpoint, which is enough to infer that "this user got a notification at this time" but not what the notification said.
We do not sell your personal information to anyone, and we do not share it with advertisers.
5. What other users see
Visibility on CanvasCircle depends on where the viewer is and whether they're signed in. There are three distinct surfaces, with different rules on each.
The main catalog (canvascircle.art) and individual listing pages (canvascircle.art/listing.html?id=…)
Anonymous (signed-out) viewers see artwork details only, the image, artist, title, price, category, description. They do not see any seller identification: no display name, no @handle, no location, no Facebook URL, no contact email, no References, no About text. Where the seller block would appear, signed-out viewers see a "Sign in to see seller info" prompt instead. The "Seller" filter dropdown on the catalog is also hidden from anonymous viewers.
Signed-in viewers see everything anonymous viewers see, plus the seller block on each listing: your display name, @handle, location (if set), Facebook profile URL, contact email, Established Member status (if applicable), About text (expandable), and your accepted References list.
Your public seller page (canvascircle.art/seller?handle=<yourhandle>)
This is a page you can share directly with potential buyers, a "here's everything I'm selling" link. Because you control who you share the link with, this page is treated as opt-in public: anyone you give the link to, signed in or not, can see your display name, @handle, joined date, listing counts, Established Member status, your About text (once admin-approved), and your accepted reference relationships (display name + @handle of each vouching collector). They can also browse your full grid of approved-active listings.
On the same page, contact info, location, Facebook profile URL, contact email, is still gated to signed-in viewers. Signed-out visitors see a "Sign in to see contact info" prompt in place of the contact buttons.
Other places your info shows up
- "In Search Of" (ISO) buyer requests follow the same rules, anonymous viewers don't see who posted them, signed-in viewers do.
- When you save another user's listing, the seller of that listing can see your display name, your @handle, the date you saved it, your contact email, and your Facebook profile URL, so they can reach out to interested buyers directly. This save-time visibility is shown only to the seller of the listing you saved, not to anyone else.
- When you appear as someone's sales reference (after you've accepted their request), your display name and @handle appear on their seller page and on the seller block of their listings. Buyers seeing those references may reach out to you via your own listings' contact methods to ask about your experience.
- Ownership Verified badge. If the admin approves your Ownership Verification submission for a listing, an "Ownership Verified" badge is shown on that listing and counted on your public seller page. The badge itself is visible only to signed-in viewers (consistent with the seller-info gating above) and includes the date the listing was verified. The verification video itself is never publicly visible. Only the reviewing admin sees it during the moderation window, after which the bytes are deleted. Pending submissions, rejection notes, and the cryptographic fingerprint of submitted videos are visible only to you and the admin.
- Buyer-to-seller inquiry messages. When you send a message to a seller through the "Email Seller" button on a listing, the recipient (that seller) sees the full message, sender display name, @handle, message body, and the date, in their "Inquiries" tab on their portal dashboard and as a delivered email in their inbox. You, as the sender, can see your own sent inquiries via the stored record (no UI surfaces this today, but you may request a copy under Section 8). The CanvasCircle admin can see all inquiry messages indefinitely as part of the platform's spam-prevention and abuse-investigation audit log. No other user, not other sellers, not anonymous viewers, not other buyers, can see your inquiries. If the seller chooses to "Dismiss" an inquiry from their own tab, it disappears from their view but remains in the admin audit log. Replies sent by the seller after the initial inquiry go directly from their email account to yours (via the Reply-To header) and never pass through or get stored by CanvasCircle.
Seller analytics on your own listings
When you're signed in as a seller and you tap the "📊 Stats" button on one of your listings, you see a chart showing daily counts of three engagement signals over a 7-, 30-, or 90-day window, plus vertical markers for any price changes you made in that window. Specifically:
- Views per day: aggregated counts only. You see "3 people viewed this on Tuesday", you do not see who they were, what other listings they looked at, where they were, or anything else about them. Your own visits to your own listing are filtered out of the chart so you're seeing real outside traffic, not your own refreshes.
- Saves per day: aggregated counts of how many users hearted the listing on each day. The identities of users who saved your listing are visible in a separate "Saved by" view (already covered above under "Other places your info shows up"), the chart itself only shows daily totals.
- Inquiries per day: aggregated counts of how many "Email Seller" messages you received on each day. The full content and senders of those messages are visible in your Inquiries tab (covered above), the chart only shows daily totals.
- Price-change markers: the chart draws a vertical dashed line at any date when you edited the price of the listing, labeled with the old → new price. This is your own data about your own listing.
Sellers cannot see analytics for listings they don't own. The admin can see analytics for any listing as part of platform moderation and abuse investigation. No analytics are shown to buyers or anonymous viewers beyond the all-time view counter and save counter that appear on the public listing page.
Visible only to you (and the admin)
- Pending and rejected reference requests
- Your pending About-text submission (if any)
- Your pending display-name change request (if any)
- Pending and rejected Ownership Verification submissions, including any rejection note the admin left for you
- Your sign-in email, until you choose to post a listing or make a save (at which point it becomes your public contact email under the rules above)
- The seller analytics described in the previous subsection, only the listing's owner (and the admin) can see them.
Never shown publicly
- Your password (stored only as a salted hash; even we can't read it)
- Your IP address, device, and other technical metadata
- The raw list of every listing you've viewed (we log these for the seller's per-listing view counter, but we don't expose the viewer's identity to the seller or to anyone else)
Bottom line: don't put anything in your display name, @handle, About text, or contact fields that you wouldn't want visible under the rules above. If you're not sure, leave it blank.
6. How we protect your information
We use HTTPS for all traffic, store passwords only as hashes, restrict database access using row-level security policies, and limit administrative access to authorized personnel. No system is perfectly secure, but we apply commercially reasonable safeguards. If we ever learn of a breach affecting your data, we'll notify you as required by law.
7. How long we keep your information
We keep your account information and listings for as long as your account is active. If you delete a listing, we remove it from public view; backup copies may persist for a short time before being purged. If you close your account, we delete or anonymize your personal information within a reasonable time, except where retention is needed to resolve disputes, prevent fraud, or comply with legal obligations.
Ownership Verification videos follow a stricter, automated schedule. The raw video bytes are automatically deleted from storage within approximately 24 hours after the admin completes their review (approval or rejection). We retain, indefinitely, only the non-reversible audit record described in Section 2: the decision, SHA-256 fingerprint of the original file, timestamps, reviewing admin, video size, duration, and any rejection note. The fingerprint cannot be used to reconstruct or view the original video. We retain it to detect a video being reused across multiple submissions, which is a strong fraud signal.
Buyer-to-seller inquiry messages are retained indefinitely as part of the platform's spam-prevention and abuse-investigation audit log. The retention is not subject to the seller's "Dismiss" action: when a seller dismisses an inquiry from their portal Inquiries tab, the row is hidden from their view only, the underlying record (including the full message body, sender, recipient, listing referenced, and timestamps) remains available to the CanvasCircle admin. If you close your account, your inquiry messages are anonymized or deleted along with the rest of your personal information per the general rule above, except where retention is needed to resolve an active dispute, complete an open spam or harassment investigation, or comply with legal obligations. Only the first inquiry message sent through the in-listing form is stored by us; all subsequent replies between buyer and seller travel directly between the parties' email accounts and are not in our possession.
Per-listing view events and listing price-change history are retained for the lifetime of the listing so the seller's analytics chart can show historical trends. When a listing is deleted, both records are deleted with it via cascade. If you close your account, view events that record you as the (signed-in) viewer are anonymized, the viewer identifier is dropped, but the aggregate event timestamp remains so other sellers' analytics aren't retroactively distorted. Price-change history rows are deleted with the underlying listing.
Push-notification subscriptions are retained only as long as they're valid. When a push delivery to your device fails because the endpoint has been revoked by your browser (you cleared site data, uninstalled the PWA, or denied permission after the fact), we automatically delete the corresponding row. If you tap "Disable" in the portal, the row is deleted immediately. If you close your account, all of your push subscriptions are deleted via cascade along with the rest of your account data.
Off-site image backup mirror. To protect the platform against catastrophic loss of our primary storage provider (Supabase), CanvasCircle maintains a separate nightly mirror of the listing-images and collection-images buckets to a Cloudflare R2 bucket scoped to CanvasCircle. The mirror is a strict copy: it does not contain database rows, profile data, private notes, or messages, only the image bytes already present in the primary buckets. The R2 mirror is not exposed publicly and is accessible only to the administrator. When you delete a listing image, a Collection image, or your account, the row and image are removed from the primary Supabase Storage immediately; the R2 mirror copy is purged on the next nightly reconciliation pass or sooner. The administrator may retain individual image copies removed by administrative action (Terms-of-Use enforcement) for forensic and audit purposes for an indefinite period; those copies are not displayed anywhere on the platform. The Ownership Verification video bucket is NOT backed up to R2 (see the stricter video retention rule above).
8. Your rights
Depending on where you live, you may have rights regarding your personal information, including the right to:
- Access the information we hold about you.
- Correct inaccurate information.
- Delete your information.
- Object to or restrict certain processing.
- Portability, receive a copy of your data in a portable format.
- Withdraw consent for processing where we rely on consent.
You can exercise most of these rights yourself from My Account (edit your profile, delete listings, close your account by emailing us). For anything else, email admin@canvascircle.art and we'll respond within a reasonable time.
California residents: the California Consumer Privacy Act (CCPA) gives you rights to know, delete, correct, and limit the use of your information, and to not be discriminated against for exercising them. We do not "sell" or "share" personal information for cross-context behavioral advertising as defined by the CCPA.
EU/UK residents: the GDPR/UK GDPR gives you the rights listed above, plus the right to lodge a complaint with your local data protection authority. Our legal basis for processing is typically (a) performance of our contract with you (running the Service), (b) legitimate interests (security, abuse prevention, improving the Service), or (c) consent (where we ask for it).
9. Children
CanvasCircle is not directed to children under 18 and we don't knowingly collect personal information from anyone under 18. If you believe a child has used the Service, contact us and we'll remove the account.
10. International users
The Service is operated from the United States. If you use the Service from outside the U.S., you understand that your information may be transferred to and processed in the U.S. and other countries where our service providers operate, which may have different data protection rules than your country.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we'll update the "Effective date" at the top and, for material changes, give reasonable notice through the Service or email.
12. Contact us
Privacy questions or requests: admin@canvascircle.art.