Privacy policy
This policy explains what CallCanvas stores, why, and how to get it back or have it deleted. It describes what the software actually does.
Who is responsible
Stephan Keck, Berne, Switzerland, is the controller for the personal data described here. Questions go to callcanvas@pm.me.
Adults only
Accounts are for adults. People under 18 may not register, accept an invitation, or sign in. A coach may list players on a team roster so that diagrams can label them, and those roster entries have no login, no email address, and no account. Use a first name, jersey number, or short label rather than full identifying details.
What is stored
| Data | Why |
|---|---|
| Email address | Signing in. CallCanvas uses one-time codes and links, so there is no password to store. |
| Display name | So teammates can tell who is who. |
| Team name, short code, and membership | Deciding which playbooks you may open and what you may change. |
| Playbooks, plays, routes, and formations | The content you create. This is the product. |
| Roster entries | Labelling players in diagrams. No login or contact details. |
| Uploaded files, such as playbook PDFs and game film | Importing existing plays and producing replay clips. |
| Security and membership audit records | Showing who invited, removed, or changed the rights of a member. |
| Subscription status | Knowing whether a team's access is current. |
What is not stored
- No password, because sign-in uses one-time codes.
- No card number, expiry, or security code. Payment details are entered only in the payment provider's own system and never reach CallCanvas.
- No advertising identifiers, and no sale or sharing of personal data with advertisers.
- No route geometry, play names, email addresses, or tokens in diagnostic telemetry.
Why we are allowed to store it
- Performing our contract with you — running the account, the team, and the playbooks you asked us to store.
- Legitimate interests — keeping the service secure and preventing abuse, which is what the audit records are for.
- Legal obligation — retaining billing records for the period tax law requires.
Where it is stored
Application data and uploaded files are stored in the European Union (West EU). The site and application are delivered through a global content network, which serves the application shell only — team playbook content is never cached as a public asset.
Who else processes it
- Supabase — database, authentication, and private file storage.
- Cloudflare — domain services and delivery of the site and application.
- Resend — sending sign-in and account emails.
- Paddle — taking payment and holding payment details.
These providers act on our instructions. We do not sell personal data to anyone.
How long it is kept
- Playbooks and plays you delete are removed from the live service immediately and are not recoverable through the application.
- Uploaded import source files are removed after 30 days. The plays created from them remain until the team deletes them.
- Security and membership audit records are kept for 12 months.
- Account data is removed from the live service immediately when self-service deletion succeeds, subject to billing records the payment provider must retain by law.
- Encrypted backups are kept for 30 days and then expire automatically. Deleted data is not restored to the live service except as part of disaster recovery, when the deletion record is reapplied.
Team playbooks belong to the team
Plays you create inside a team stay with that team when you leave it, in the same way notes written on a team's whiteboard stay with the team. Deleting your own account removes you and your personal details. If you own a team with another active member, you must transfer ownership before deleting your account. If you are the team's only active member, deleting your account also permanently deletes that team and its plays.
Your rights
You can ask for a copy of your data, correct it, have it deleted, object to processing, or ask us to restrict it. Write to callcanvas@pm.me, or use the account deletion page. The in-app deletion is immediate; we respond to manual rights requests within 30 days.
If you are in the EU, the UK, or Switzerland and are not satisfied with our response, you may complain to your national data protection authority.
Changes
If this policy changes in a way that affects you, we will tell you by email before the change takes effect. The date at the bottom of this page always reflects the current version.