Last updated: September 2026
This Privacy Policy sets out the rules for the processing and protection of personal data of users and customers of the SnapCanvas website and desktop software, accessible at https://snapcanvas.app (hereinafter referred to as the “Service” or “Website”).
We are committed to protecting your privacy and ensuring you feel secure when using our website, purchasing software licenses, and interacting with our desktop application.
The Data Controller of personal data collected through the Service within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation — GDPR) is:
RSCAD Sp. z o.o.
ul. Zielona 6A, 55-106 Czeszów (Zawonia), Poland
Entered into the National Court Register (KRS) kept by the District Court for Wrocław-Fabryczna in Wrocław, 9th Commercial Division of the National Court Register under KRS: 0001023072
Tax Identification Number (NIP / VAT EU): PL9151824896, REGON: 524650420
Represented by: Mateusz Szymański
Contact Form: Via Contact Form · Email: support@snapcanvas.app
Data Protection Officer: The Data Controller has not appointed a Data Protection Officer (DPO). For all inquiries, requests, or exercise of data rights, please contact the Data Controller directly via email or our contact form.
The Data Controller exercises due care to protect the rights and freedoms of data subjects and ensures that data collected is:
All communication between your device and our servers is secured using modern encryption protocols (SSL/TLS v1.2/v1.3).
We process personal data for the following specific purposes and on the following legal grounds:
Data scope: Name, email address, password hash, optional company name.
Legal basis: Article 6(1)(b) GDPR — necessity for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract (provision of electronic services).
Data scope: Google user identifier, email address, name/display name, profile avatar URL (if provided by Google).
Legal basis: Article 6(1)(b) GDPR — user authentication and account creation upon explicit user selection of Google sign-in.
Data scope: Email address, customer name, company name and VAT number (for business customers), billing country, payment transaction identifier, assigned software license keys.
Legal basis: Article 6(1)(b) GDPR (execution of sales contract for software licenses) and Article 6(1)(c) GDPR (compliance with legal tax, invoicing, and accounting obligations).
Data scope: License key, machine identifier / hardware hash (for device activation limits), application version, OS platform. When voluntarily submitting a crash report: anonymized stack trace, app version, and optional user contact.
Legal basis: Article 6(1)(b) GDPR (license validation and software delivery) and Article 6(1)(f) GDPR (legitimate interest in maintaining software reliability and preventing unauthorized license duplication).
Data scope: Name, email address, message contents, technical context, and the timestamp of privacy-notice acknowledgment.
Legal basis: Article 6(1)(f) GDPR — legitimate interest of the Data Controller in communicating with prospective and existing customers and answering technical/billing questions, or Article 6(1)(b) GDPR when inquiry relates to pre-contractual steps. The checkbox on the contact form is an informational acknowledgment, not a separate consent under Article 6(1)(a).
Data scope: IP address, browser type, request timestamp, URL visited, bot verification challenge tokens.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in ensuring network and IT infrastructure security, preventing abuse, spam, and DDoS attacks.
Data scope: Transaction history, license issuance records, correspondence.
Legal basis: Article 6(1)(f) GDPR — legitimate interest of the Controller in protecting its legal rights and defending against claims.
Our desktop software adheres strictly to Privacy by Design principles:
To provide our services, your personal data may be shared with trusted external service providers acting as data processors or independent controllers:
Where data processors are located outside the European Economic Area (EEA) (e.g. cloud or payment infrastructure), data transfers are conducted under recognized legal transfer mechanisms pursuant to Chapter V of the GDPR, including European Commission adequacy decisions (such as the EU-US Data Privacy Framework) or Standard Contractual Clauses (SCCs).
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
You have the following rights under European data protection legislation:
Request confirmation of whether we process your data and receive a copy of that data.
Request the immediate correction of inaccurate or incomplete personal data.
Request deletion of your data when it is no longer required or processing is unlawful.
Request limitation of processing while data accuracy or objection claims are verified.
Receive your personal data in a structured, machine-readable format or have it transferred.
Object at any time to processing based on legitimate interests (Article 6(1)(f)).
If processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
To exercise any of your rights, please submit a request via our contact form or by writing to support@snapcanvas.app.
You also have the right to lodge a complaint with a supervisory authority — in Poland: Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office), ul. Stawki 2, 00-193 Warsaw, or the relevant supervisory authority in your EU member state of residence.
Providing your personal data is voluntary. However, providing necessary details (such as email address and name during registration, or billing details during purchase) is a contractual requirement necessary to create an account, purchase licenses, generate activation keys, and receive customer support.
We do not subject your personal data to automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR.
The Service may contain links to external third-party websites (e.g. payment providers, developer documentation). We recommend reading the privacy policies published on those external sites.
We reserve the right to amend this Privacy Policy to reflect changes in legal requirements or our service features. Updated versions will be posted on this page with a revised effective date.