Desktop app 30-day trial · then 7.99 EUR + TAX / lifetime license Buy a license →
SnapCanvas SnapCanvas
Legal Documentation

Privacy Policy

Last updated: September 2026

§ 1. Introduction

This Privacy Policy sets out the rules for the processing and protection of personal data of users and customers of the SnapCanvas website and desktop software, accessible at https://snapcanvas.app (hereinafter referred to as the “Service” or “Website”).

We are committed to protecting your privacy and ensuring you feel secure when using our website, purchasing software licenses, and interacting with our desktop application.

§ 2. Data Controller

The Data Controller of personal data collected through the Service within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation — GDPR) is:

RSCAD Sp. z o.o.

ul. Zielona 6A, 55-106 Czeszów (Zawonia), Poland

Entered into the National Court Register (KRS) kept by the District Court for Wrocław-Fabryczna in Wrocław, 9th Commercial Division of the National Court Register under KRS: 0001023072

Tax Identification Number (NIP / VAT EU): PL9151824896, REGON: 524650420

Represented by: Mateusz Szymański

Contact Form: Via Contact Form · Email: support@snapcanvas.app

Data Protection Officer: The Data Controller has not appointed a Data Protection Officer (DPO). For all inquiries, requests, or exercise of data rights, please contact the Data Controller directly via email or our contact form.

§ 3. Principles of Data Processing

The Data Controller exercises due care to protect the rights and freedoms of data subjects and ensures that data collected is:

  • Processed lawfully, fairly, and in a transparent manner in relation to the data subject (lawfulness, fairness, and transparency);
  • Collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes (purpose limitation);
  • Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (data minimization);
  • Accurate and, where necessary, kept up to date (accuracy);
  • Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (storage limitation);
  • Processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical and organizational measures (integrity and confidentiality).

All communication between your device and our servers is secured using modern encryption protocols (SSL/TLS v1.2/v1.3).

§ 4. Purposes, Legal Grounds, and Scope of Data Processing

We process personal data for the following specific purposes and on the following legal grounds:

1. User Account Registration and Management

Data scope: Name, email address, password hash, optional company name.
Legal basis: Article 6(1)(b) GDPR — necessity for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract (provision of electronic services).

2. Single Sign-On via Google (Google OAuth)

Data scope: Google user identifier, email address, name/display name, profile avatar URL (if provided by Google).
Legal basis: Article 6(1)(b) GDPR — user authentication and account creation upon explicit user selection of Google sign-in.

3. Order Processing, License Key Generation, and Invoicing

Data scope: Email address, customer name, company name and VAT number (for business customers), billing country, payment transaction identifier, assigned software license keys.
Legal basis: Article 6(1)(b) GDPR (execution of sales contract for software licenses) and Article 6(1)(c) GDPR (compliance with legal tax, invoicing, and accounting obligations).

4. Desktop Software Activation, Update Feed, and Crash Reports

Data scope: License key, machine identifier / hardware hash (for device activation limits), application version, OS platform. When voluntarily submitting a crash report: anonymized stack trace, app version, and optional user contact.
Legal basis: Article 6(1)(b) GDPR (license validation and software delivery) and Article 6(1)(f) GDPR (legitimate interest in maintaining software reliability and preventing unauthorized license duplication).

5. Handling Inquiries via Contact Form and Support

Data scope: Name, email address, message contents, technical context, and the timestamp of privacy-notice acknowledgment.
Legal basis: Article 6(1)(f) GDPR — legitimate interest of the Data Controller in communicating with prospective and existing customers and answering technical/billing questions, or Article 6(1)(b) GDPR when inquiry relates to pre-contractual steps. The checkbox on the contact form is an informational acknowledgment, not a separate consent under Article 6(1)(a).

6. Security, Bot Prevention, and Server Logs

Data scope: IP address, browser type, request timestamp, URL visited, bot verification challenge tokens.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in ensuring network and IT infrastructure security, preventing abuse, spam, and DDoS attacks.

7. Establishment, Exercise, or Defense of Legal Claims

Data scope: Transaction history, license issuance records, correspondence.
Legal basis: Article 6(1)(f) GDPR — legitimate interest of the Controller in protecting its legal rights and defending against claims.

§ 5. Privacy by Design: Desktop Application & Local Processing

Our desktop software adheres strictly to Privacy by Design principles:

  • Local Screen Grabs & Annotations: All screenshots captured, annotations drawn, and edits made remain exclusively on your local computer. We do not upload or store your images on our servers.
  • Local Optical Character Recognition (OCR): Text recognition runs 100% locally on your device. Your image content is never transmitted to cloud OCR APIs or third parties.
  • Local Redaction & Blurring: Redaction tools obscure sensitive information directly on your machine before you choose to save or export files.

§ 6. Data Recipients and Subcontractors

To provide our services, your personal data may be shared with trusted external service providers acting as data processors or independent controllers:

  • Payment Processors: Stripe Payments Europe Ltd. / Stripe Inc. — processes credit card and electronic payments securely. Payment card numbers are handled directly by Stripe and are never stored on our servers.
  • Single Sign-On Authentication: Google Ireland Limited / Google LLC — enables Google OAuth login when selected by the user.
  • Security and Anti-Spam Providers: Cloudflare Inc. (including Cloudflare Turnstile for bot prevention).
  • Hosting and Cloud Infrastructure: Providers supplying server infrastructure, database hosting, and domain/DNS services.
  • Accounting and Tax Advisors: Certified accounting entities responsible for tax reporting, financial audit, and legal compliance.
  • Email and Notification Services: Infrastructure providers used for transactional emails (e.g., license delivery, password resets, verification notices).
  • Public Authorities: State bodies and law enforcement agencies only when required by mandatory provisions of applicable law.

§ 7. International Data Transfers

Where data processors are located outside the European Economic Area (EEA) (e.g. cloud or payment infrastructure), data transfers are conducted under recognized legal transfer mechanisms pursuant to Chapter V of the GDPR, including European Commission adequacy decisions (such as the EU-US Data Privacy Framework) or Standard Contractual Clauses (SCCs).

§ 8. Data Retention Period

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account and license data: For the duration of the account and active lifetime license support, or until you request account deletion (subject to statutory record-keeping requirements);
  • Billing and accounting records: For 5 years following the end of the tax year in which the transaction occurred, in compliance with statutory tax obligations;
  • Contact inquiries: For the time necessary to resolve the inquiry and up to 12 months thereafter for context;
  • Server access logs: For a rolling period of up to 90 days for diagnostic and security auditing purposes.

§ 9. Your Rights Under GDPR

You have the following rights under European data protection legislation:

1. Right of Access (Art. 15 GDPR)

Request confirmation of whether we process your data and receive a copy of that data.

2. Right to Rectification (Art. 16 GDPR)

Request the immediate correction of inaccurate or incomplete personal data.

3. Right to Erasure (Art. 17 GDPR)

Request deletion of your data when it is no longer required or processing is unlawful.

4. Right to Restriction (Art. 18 GDPR)

Request limitation of processing while data accuracy or objection claims are verified.

5. Right to Data Portability (Art. 20 GDPR)

Receive your personal data in a structured, machine-readable format or have it transferred.

6. Right to Object (Art. 21 GDPR)

Object at any time to processing based on legitimate interests (Article 6(1)(f)).

If processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.

To exercise any of your rights, please submit a request via our contact form or by writing to support@snapcanvas.app.

You also have the right to lodge a complaint with a supervisory authority — in Poland: Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office), ul. Stawki 2, 00-193 Warsaw, or the relevant supervisory authority in your EU member state of residence.

§ 10. Voluntary Provision of Data

Providing your personal data is voluntary. However, providing necessary details (such as email address and name during registration, or billing details during purchase) is a contractual requirement necessary to create an account, purchase licenses, generate activation keys, and receive customer support.

§ 11. Automated Decision-Making and Profiling

We do not subject your personal data to automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR.

§ 12. Final Provisions

The Service may contain links to external third-party websites (e.g. payment providers, developer documentation). We recommend reading the privacy policies published on those external sites.

We reserve the right to amend this Privacy Policy to reflect changes in legal requirements or our service features. Updated versions will be posted on this page with a revised effective date.