Privacy notice.
What we collect, why we collect it, and what you can ask us to do about it.
The short version: we collect what we need to build your site, bill you and email you about it. We run no analytics at all. The only tracking on this site measures our own ads, it only runs if you accept cookies, and it is never sent your name or email address. We do not sell your details, and we do not share them with anyone for their own marketing.
1. Who is responsible
Kane Foster, a sole trader trading as Kanvas One, of 3 Northside Cottages, NE61 3SN, is the data controller for the personal data described here. The service is called one.
Email privacy@kanvas.one with anything about this notice, or use the details on our contact page.
[If you are registered with the ICO as a data controller, add your registration number here. Most businesses that process personal data electronically must register and pay the annual data protection fee — check at ico.org.uk/registration.]
2. What we collect
If you fill in the enquiry form
Your name, your business name, your email address, which plan you are interested in, whether you want an app, and whatever you write in the box about what you need.
If you open an account
Your email address and a password, which is stored only as a hash — we cannot read it. Then, as you complete your business profile: business name, contact name, phone number, type of business, address, service area, opening hours, your services or menu, what you want the site to do, links to any site or social accounts you already have, and a logo or photo if you upload one.
While your plan runs
The change requests you send us and any files you attach to them, your plan, your points balance and when they last reset, your billing history, your web address, and your email preferences.
If you leave a review
Your name, your business name and what you wrote, so we can publish it.
Automatically
Our hosting provider keeps short-lived server logs, which include IP addresses, for security and to keep the service running.
We use no analytics software at all. If — and only if — you accept cookies, we load the Meta pixel, which tells Meta that a visit, an enquiry or a signup followed one of our ads. Choose “Essential only” and that code is never loaded. See the cookie policy for exactly what it sets and what we send with it.
3. Why, and our lawful basis
- To answer your enquiry
- Our legitimate interest in responding to someone who has asked us to get in touch, and in keeping a record of it. Basis: legitimate interests.
- To build and run your site and app
- We cannot do the work without your business details. Basis: performance of our contract with you.
- To take payment and keep billing records
- Basis: performance of our contract, and legal obligation for the accounting records we are required to keep.
- To email you about your account
- Confirmations, receipts, notices about your build, and replies to your requests. Basis: performance of our contract. These are not marketing and you cannot opt out of them while your account is open, though you can turn off the optional notifications.
- To email you about offers and new features
- Basis: your consent, which you give by ticking the box, and can withdraw at any time.
- To publish a review you have given us
- Basis: your consent, given when you submit it. Ask us and we will take it down.
- To measure our advertising
- Knowing which ads lead to an enquiry is what stops us paying for ads that do not work. Basis: your consent, given by choosing “Accept all” on the cookie pill, and withdrawable at any time from the footer of any page.
- To keep the service secure and prevent fraud
- Basis: our legitimate interest in protecting the service and our customers.
4. Emails we send
There are two kinds, and they are handled differently.
Service email is about your account: confirming your address, receipts, plan changes, progress on your build, replies to your requests. It comes with the service.
Marketing email is about offers, new features and things we think you would find useful. We only send it if you have opted in. Every marketing email carries an unsubscribe link and a one-click unsubscribe header that your email app can use, and unsubscribing takes effect immediately. You can also change your preferences from your account page at any time.
We use Resend to deliver email. They process the message and your address on our behalf and do not use it for anything else.
5. Who we share it with
We do not sell your personal data, and we do not share it with anyone for their own marketing. We use the following providers to run the service. The first four act only on our instructions; the last is there only if you accept cookies, and decides for itself what it does with what it receives:
- Vercel — hosting for this site and its server functions. Sees requests to the site, including IP addresses in short-term logs.
- Supabase — the database that holds your account, profile, requests and uploaded files, and the system that signs you in.
- Stripe — payments and subscriptions. Your card details go to Stripe directly from their own checkout page and never reach our servers. Stripe is a data controller in its own right for fraud prevention; see stripe.com/privacy.
- Resend — sending the emails described above.
- Meta (Facebook and Instagram) — only if you accept cookies. Receives that a page was viewed, an enquiry submitted, an account created or a plan started, along with your IP address and the identifier in the cookie it sets. We do not send your name or your email address, in any form. Meta decides for itself what it does with this, so it is a controller in its own right rather than a processor acting on our instructions. See facebook.com/privacy/policy.
When you use the web address finder, we send only the name you are checking to the relevant domain registry (Nominet for .uk addresses, the appropriate registry otherwise). No personal data is sent with it.
We will also disclose data where we are legally required to, or where it is necessary to establish or defend a legal claim. If the business is ever sold or transferred, customer records would transfer with it, and we would tell you first.
6. Where your data is held
Some of the providers above process data outside the United Kingdom. Where they do, the transfer is covered by the UK’s approved safeguards — an adequacy decision for the destination country, or the UK International Data Transfer Addendum to the standard contractual clauses. You can ask us for details of the safeguards in place for any particular provider.
[If you have set your Supabase project to a specific region, name it here — for example “Our database is hosted in London (eu-west-2).” It is a fair question and customers ask it.]
7. How long we keep it
- Enquiries that do not become accounts — 24 months from your last contact with us, then deleted.
- Account and profile data — for as long as your plan is active, then up to 12 months after it ends, so we can help if you come back or need your site exported. After that it is deleted.
- Change requests and uploaded files — the same period as your account.
- Billing and accounting records — six years from the end of the relevant financial year, because HMRC requires it. This applies even if you ask us to delete everything else.
- Reviews — until you ask us to remove them.
- Marketing preferences — we keep a record that you unsubscribed indefinitely, so that we do not email you again by mistake.
- Your cookie choice — kept in your own browser, not on our servers, until you clear it or change it.
8. How we protect it
The site is served over HTTPS. Passwords are hashed, never stored in a readable form. Database rows are locked to the account that owns them, so one customer cannot read another’s data even if something else goes wrong. Card details never touch our systems. Access to customer data is limited to the people who need it to do the work.
No system is perfectly secure. If a breach happens that is likely to put your rights at risk, we will tell the ICO within 72 hours and tell you without undue delay.
9. Your rights
Under UK data protection law you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong;
- delete it, where we do not have to keep it;
- restrict what we do with it while a dispute is sorted out;
- send it to you or another provider in a portable format;
- stop processing it where we rely on legitimate interests;
- stop sending you marketing, which you can do yourself at any time.
Where we rely on your consent, you can withdraw it at any time. That does not affect anything we did before you withdrew it.
Email privacy@kanvas.one and we will respond within one month. There is no charge. We may ask you to confirm who you are before we hand over data.
10. Data your own site collects
If the site we build for you collects personal data about your customers — a contact form, a booking, a mailing list — then you are the controller of that data and we act as your processor. You need your own privacy notice for it, and we will help you put one in place. This notice covers our relationship with you, not your relationship with your customers.
11. Children
This is a service for businesses. It is not directed at children and we do not knowingly collect data about anyone under 18. If you think we have, tell us and we will delete it.
12. Complaints
If you are unhappy with how we have handled your data, please tell us first at privacy@kanvas.one so we can put it right.
You also have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.