DRAFT v0.1 — FOR ATTORNEY REVIEW ONLY. NOT LEGAL ADVICE. NOT YET EFFECTIVE.
Last updated: [EFFECTIVE DATE] · Version: 0.1-DRAFT
*Drafting note for reviewing counsel (delete before publication): This first draft reflects U.S. state comprehensive privacy laws in effect as of 2026, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, "CCPA/CPRA") and CPPA regulations effective January 1, 2026; the Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana comprehensive laws; the Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, and Maryland laws; and the three comprehensive laws that took effect January 1, 2026 in Indiana, Kentucky, and Rhode Island. Verify entity name, thresholds/applicability, retention periods, subprocessor list, and the loyalty "financial incentive" analysis against final product and business facts before adoption.*
1. Introduction and Scope
2. Our Roles: Business/Controller vs. Service Provider/Processor
3. Personal Information We Collect
4. Sources of Personal Information
5. How and Why We Use Personal Information
6. How We Disclose Personal Information
7. Cookies, Analytics, and Opt-Out Preference Signals
8. How Long We Keep Personal Information
9. How We Protect Personal Information
10. Your Privacy Rights and How to Exercise Them
11. California Privacy Disclosures (CCPA/CPRA)
12. Other U.S. State Privacy Disclosures
13. Children and Minors (21+ Service)
14. U.S.-Only Service
15. Changes to This Policy
16. How to Contact Us
This Privacy Policy explains how Cannvas, LLC, doing business as "Cannvas" ("Cannvas," "we," "us," or "our"), collects, uses, discloses, and otherwise processes personal information, and describes the privacy rights available to individuals in the United States.
Cannvas is an ancillary cannabis-technology company. We provide software only; we do not grow, process, distribute, sell, possess, or otherwise handle cannabis or cannabis products. Our services (collectively, the "Service") consist of:
This Privacy Policy applies to personal information we process as a business/controller, namely personal information about:
What this Policy does *not* govern. This Policy does not govern our processing of an Organization's business data submitted to, generated in, or processed through the Dashboard ("Org Data"). For Org Data, the Organization is the controller and Cannvas acts as its service provider/processor. Our handling of Org Data is governed by our Data Processing Addendum ("DPA") with the relevant Organization and by that Organization's own privacy notices — not by this Policy. See Section 2.
Capitalized terms have the meanings given where they are defined. This Policy should be read together with our Cookie Policy (Section 7) and, for Organizations and their personnel, our DPA.
Cannvas plays different privacy roles depending on the data:
(a) Cannvas as a business/controller. We act as a business (under CCPA/CPRA) and a controller (under other U.S. state privacy laws) — meaning we determine the purposes and means of processing — with respect to:
This Privacy Policy describes those activities.
(b) Cannvas as a service provider/processor. We act as a service provider (under CCPA/CPRA) and a processor (under other U.S. state privacy laws) — meaning we process personal information on behalf of and under the documented instructions of an Organization — with respect to Org Data. In that role:
Where the same individual is both an Authorized User and a subject of Org Data (for example, an operator's employee whose name appears in the operator's records), the account information we control is addressed by this Policy, while the operator's records about that person are Org Data addressed by the DPA.
"Personal information" (also called "personal data") means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. It does not include lawfully de-identified, aggregated, or publicly available information.
The categories of personal information we collect are summarized below. The examples are illustrative, not exhaustive. Not every individual will have every category collected about them; what we collect depends on how you interact with the Service.
| # | Category | Examples of data in this category | Do we collect it? |
|---|---|---|---|
| A | Identifiers and account information | Name; username; email address; account, user, or Organization identifier; hashed authentication credentials; optional phone number | Yes |
| B | Organization / professional contact information (Authorized Users) | Business/employer name; job title or role; work email and phone; the Org to which an account belongs | Yes |
| C | Commercial and usage information | Consumer Apps interactions; "Where to Buy" searches and product look-ups; loyalty-program participation, points, tiers, and rewards (when the loyalty program launches); feature usage within the Service | Yes |
| D | Ratings and reviews content (user-generated content) | Star ratings, written reviews, product feedback, and other content a Consumer chooses to submit | Yes |
| E | Internet, network, and device activity / analytics | IP address; device type, browser, and operating system; pages/screens viewed; referring/exit pages; clicks and interactions; session identifiers; timestamps; first-party analytics event data collected via our own tracker script | Yes |
| F | Approximate (coarse) location | General, city- or region-level location inferred from IP address | Yes, if applicable — coarse only |
| G | Precise geolocation | Device GPS location | Not collected or stored by us. The optional map "locate me" feature, if you choose to use it, accesses your device location in your browser only to display your position on the map; that precise location is not transmitted to, or stored by, Cannvas. |
| H | Age-verification signals | Age-gate confirmation and 21-and-over attestation; date of birth or age only if you provide it for eligibility | Yes |
| I | Communications and preferences | Messages you send to support; email/communication preferences; feedback and survey responses | Yes |
| J | Sensitive personal information (SPI) | Account log-in credentials (a username or email in combination with a password or access credential permitting access to the account) | Yes — limited (see Section 11.4) |
| K | Biometric, genetic, health, precise-geolocation, government-ID, financial-account, racial/ethnic-origin, religious, sex-life/sexual-orientation, and similar SPI | — | No — we do not intentionally collect these categories |
| L | Inferences | Limited preferences derived from your ratings or Consumer Apps activity (e.g., product interests) | Yes — limited |
We do not intentionally collect Social Security numbers, driver's license or passport numbers, financial account or payment-card numbers, biometric or genetic data, health information, precise geolocation, contents of your private communications where we are not the recipient, or information revealing racial or ethnic origin, religious or philosophical beliefs, union membership, citizenship or immigration status, or sex life or sexual orientation. Please do not submit such information to us (for example, in a review or support message).
We collect personal information from the following categories of sources:
We use personal information for the following business and commercial purposes:
1. To provide, operate, and maintain the Service — create and manage accounts, authenticate Authorized Users and Consumers, deliver the Dashboard and Consumer Apps features (including the "Where to Buy" locator and ratings), and store and display ratings and reviews you submit.
2. To verify eligibility — apply the 21-and-over age gate and confirm that Consumers meet the minimum-age requirement for the Consumer Apps.
3. To operate the loyalty program (once launched) — enroll participants, track points and rewards, and deliver program benefits. If the loyalty program constitutes a "financial incentive" under applicable law, we will provide a separate notice of financial incentive at the point of enrollment (see Section 11.7).
4. For security, integrity, and fraud prevention — protect the Service, detect and prevent fraudulent, malicious, unauthorized, or illegal activity, debug and repair errors, and enforce our terms.
5. For analytics and improvement — understand how the Service is used, measure and improve performance and features, and develop new functionality, using our first-party analytics. This includes analyzing interactions with our AI features (including questions the AI was unable to answer) in de-identified and aggregated form to prioritize and build AI capabilities. When we analyze AI interactions across customers for this purpose, we do not use identifiable Org content, customer or user identity, or any single customer's proprietary information; proprietary details (such as cultivar or dispensary names and specific values) are removed before such analysis, and results are reported only as aggregate patterns.
6. To communicate with you — respond to inquiries and support requests, send administrative, transactional, security, and Service-related messages, and (where permitted) send marketing or program communications you may opt out of.
7. To comply with law and legal process — meet legal, regulatory, tax, and recordkeeping obligations, respond to lawful requests from authorities, and establish, exercise, or defend legal claims.
8. For corporate transactions — evaluate, negotiate, or complete a merger, acquisition, financing, reorganization, or sale of assets, subject to Section 6.
We will not use your personal information for a materially different, unrelated, or incompatible purpose without providing you notice and, where required, obtaining your consent. We use sensitive personal information only for the limited purposes described in Section 11.4 and do not use it to infer characteristics about you.
We do NOT sell your personal information, and we do NOT share your personal information for cross-context behavioral advertising. We have not sold or shared personal information for these purposes in the preceding 12 months, and we do not engage in "targeted advertising" or in "profiling" that produces legal or similarly significant effects about you, as those terms are defined under applicable U.S. state privacy laws. We also do not sell or share the personal information of individuals we know to be under the applicable age thresholds.
We disclose personal information only as described below:
A current list of subprocessors and their functions is available on request and, for Organizations, in or alongside the DPA.
We may also disclose de-identified or aggregated information that cannot reasonably be used to identify you. When we do, we maintain and use such information in de-identified form and do not attempt to re-identify it, except as permitted by law to test that it cannot be re-identified.
Cookies and similar technologies. We and our service providers use cookies, local storage, pixels, and similar technologies, together with our first-party analytics tracker script, to operate the Service, remember preferences, maintain sessions and security, and understand and improve usage. For details about the specific technologies we use, their purposes and durations, and your choices, please see our Cookie Policy.
We use first-party analytics. Our analytics are first-party and used to measure and improve our own Service. We do not use cookies or tracking technologies to sell your personal information or to share it for cross-context behavioral advertising, and we do not permit third-party advertising networks to track you across unaffiliated sites through the Service.
Opt-out preference signals / Global Privacy Control. Some browsers and extensions let you broadcast a universal opt-out preference signal, such as the Global Privacy Control ("GPC"), that communicates your choice to opt out of the "sale" or "sharing" of personal information and, in some states, targeted advertising. Where required by applicable state law (including California, Colorado, Connecticut, Texas, Montana, Oregon, and other states that recognize universal opt-out mechanisms), we honor these signals as a valid opt-out request for the browser or device from which they are sent. Because we do not sell or share personal information or engage in targeted advertising, there is no such activity to opt out of; nevertheless, we recognize and respect these signals. Where our systems detect and process a valid opt-out preference signal, we will treat it as a request to opt out and, where applicable law requires, reflect that the signal has been honored.
We retain each category of personal information for as long as reasonably necessary to fulfill the purposes described in this Policy, unless a longer period is required or permitted by law. To determine the appropriate retention period, we consider:
General retention periods (subject to the criteria above and to be confirmed by counsel and operations):
| Category | General retention |
|---|---|
| Account and Organization/professional contact information (A, B) | For the life of the account, then up to [X months/years] after account closure |
| Ratings and reviews content (D) | Until you delete the content or your account, or up to [X] thereafter |
| Loyalty-program data (C) | For the duration of enrollment, then up to [X] after you leave the program |
| Analytics, log, device, and usage data (E, F) | Up to [X months] (e.g., 12–24 months), then deleted or aggregated/de-identified |
| Support and other communications (I) | Up to [X] after the matter is resolved |
| Age-verification signals (H) | For the period necessary to evidence eligibility, up to [X] |
When personal information is no longer needed, we will delete, destroy, or de-identify it in accordance with our retention schedule. Residual copies may persist for a limited time in secure backups and are purged on a rolling basis.
We maintain reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, loss, or destruction. These measures include, as appropriate to the risk: encryption of data in transit (and, where appropriate, at rest); access controls and authentication; the principle of least privilege; use of reputable infrastructure providers (including Cloudflare and Supabase); logging and monitoring; and periodic review of our practices.
No method of transmission or storage is completely secure. While we work to protect your personal information, we cannot and do not guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly of any suspected unauthorized use of your account.
Depending on your state of residence, you may have some or all of the following rights with respect to personal information we process about you as a business/controller. State-specific details appear in Sections 11 and 12. (For rights in Org Data, contact the relevant Organization; see Section 2.)
You (or an authorized agent) may submit a privacy-rights request by:
To protect your information, we will take reasonable steps to verify your identity before responding, generally by matching information you provide with information in our records. We may request additional information where necessary to verify you or the scope of your request. We will not use information collected for verification for any other purpose.
You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written permission and may require you to verify your own identity directly with us and/or confirm that you authorized the agent.
We will acknowledge and respond to verifiable requests within the timeframes required by applicable law — generally within 45 days. Where reasonably necessary, we may extend the response period as permitted by law (for example, by an additional 45 days under California law, with notice to you). Where an extension is available under the applicable state's appeal rules, it may differ (see Section 12).
We will process requests free of charge, except that we may charge a reasonable fee, or decline to act, if a request is manifestly unfounded, excessive, or repetitive, as permitted by law, and we will tell you why.
If we decline to act on your request, we will notify you of the decision, our reasons, and how to appeal. To appeal, follow the instructions in our response or contact us at [email protected] with the subject line "Privacy Appeal." We will respond to your appeal within the period required by applicable law (generally within 45–60 days). If your appeal is denied, you may contact your state Attorney General or applicable regulator; contact details are in Sections 11 and 12.
This section applies to California residents and supplements the rest of this Policy. It also serves, together with Sections 3–8, as our Notice at Collection under the CCPA/CPRA. Terms used in this section have the meanings given in the CCPA/CPRA.
At or before the point of collection, we inform you of: the categories of personal information and sensitive personal information we collect (Section 3); the purposes for which each category is used (Section 5); whether that information is sold or shared (it is not — Section 6); and the length of time we intend to retain each category, or the criteria used to determine that period (Section 8).
We do not sell personal information and do not share personal information for cross-context behavioral advertising, and have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16 years of age. (Our Consumer Apps are 21+; see Section 13.)
The only sensitive personal information we collect is account log-in credentials (username/email in combination with a password or access credential). We use this information solely to authenticate you and secure your account — a use that does not trigger the right to limit under Cal. Civ. Code § 1798.121, because we do not use or disclose sensitive personal information to infer characteristics or for purposes beyond those permitted. We do not use or disclose sensitive personal information for any purpose to which the right to limit would apply. Should this change, we will update this Policy and provide a "Limit the Use of My Sensitive Personal Information" mechanism.
California residents have the rights to: know/access the categories and specific pieces of personal information we have collected; delete personal information we collected, subject to exceptions; correct inaccurate personal information; opt out of the sale or sharing of personal information (not applicable, as we do neither); limit the use and disclosure of sensitive personal information (see Section 11.4); and to non-discrimination for exercising these rights. To exercise your rights, see Section 10 ("How to submit a request").
California residents may request information about our disclosure of personal information to third parties for those third parties' direct marketing purposes. We do not disclose personal information to third parties for their own direct-marketing purposes. You may confirm this by contacting [email protected].
Our loyalty program is planned and not yet live. If and when it launches, and if it offers a price or service difference or other benefit in exchange for personal information such that it constitutes a "financial incentive" under the CCPA/CPRA, we will provide a separate notice of financial incentive describing the material terms, how to opt in and withdraw, and a good-faith estimate of the value of your personal information and the method used to calculate it. Participation will be voluntary and require your opt-in consent.
We honor the Global Privacy Control and other recognized opt-out preference signals as described in Section 7. Consistent with California regulations effective January 1, 2026, where our systems process such a signal we will treat it as a valid opt-out request and, where applicable, reflect that the signal has been honored.
We aim to provide this Policy in a format that is reasonably accessible to people with disabilities and, where we ordinarily provide information to California consumers in another language, in that language. Contact [email protected] for assistance or an alternative format.
If you have unresolved concerns, you may contact the California Privacy Protection Agency or the California Attorney General's Office.
This section supplements the rest of this Policy for residents of U.S. states with comprehensive consumer privacy laws. As of the date above, this includes Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana; Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, and Maryland; and, effective January 1, 2026, Indiana, Kentucky, and Rhode Island. This list is expanding, and additional state laws take effect over time; we will honor the rights the law of your state provides even if your state is not individually named here.
Depending on your state, you may have the right to:
As explained in Section 6, we do not sell personal data, engage in targeted advertising, or conduct profiling that produces legal or similarly significant effects, so those opt-out rights have nothing to act upon; we nonetheless honor any such request and any recognized universal opt-out signal. Processing of sensitive data (as your state defines it) is conducted only with consent where required; as noted, we do not intentionally collect the sensitive categories other than account credentials.
State variations. Rights and their exceptions vary by state. For example, Utah and certain other states do not provide a right to correct or an appeal mechanism, and the scope of opt-out and profiling rights differs among states. We apply the rights available under the law applicable to you.
Submit requests as described in Section 10 (webform or [email protected]). We will verify and respond generally within 45 days, with an extension where permitted by your state's law. If we decline your request, we will explain why and how to appeal; we will respond to an appeal within the period your state requires (commonly within 45 days, extendable by up to 60 days where reasonably necessary). If your appeal is denied, you may contact your state Attorney General to submit a complaint.
For residents of states that require it (including Colorado, Connecticut, Texas, Montana, Oregon, and others recognizing universal opt-out mechanisms), we recognize opt-out preference signals such as the Global Privacy Control as valid opt-out requests, as described in Section 7 — noting again that we do not sell personal data, conduct targeted advertising, or engage in covered profiling.
Nevada residents may direct certain requests regarding the sale of covered information to us at [email protected]. We do not sell covered information as defined under Nevada law.
The Service is intended for a general adult audience, and the Consumer Apps are for individuals who are 21 years of age or older. We employ an age gate and require age attestation for the Consumer Apps.
We do not knowingly collect personal information from anyone under 21, and we do not knowingly collect personal information from children under 13 (or the applicable minimum age under the Children's Online Privacy Protection Act) or otherwise direct the Service to minors. If we learn that we have collected personal information from an individual under the applicable minimum age, we will delete that information promptly. If you believe a person under 21 has provided us personal information, please contact [email protected] so we can take appropriate action.
We do not knowingly sell or share the personal information of minors, and, as stated above, we do not sell or share personal information at all.
The Service is intended for users located in the United States, and our data-processing activities take place in or are directed from the United States. We do not offer the Service to, or knowingly process the personal information of, individuals outside the United States. If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with local law.
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and post the updated Policy. If we make material changes, we will provide additional notice as required by law and appropriate under the circumstances — for example, by prominent notice on our websites or the Consumer Apps, or by email to your account address — before or when the changes take effect. Where required by law, we will obtain your consent to material changes. Your continued use of the Service after an update becomes effective constitutes acceptance of the revised Policy, except where consent is required.
If you have questions, requests, or complaints about this Privacy Policy or our privacy practices, contact our privacy team:
Cannvas, LLC (d/b/a "Cannvas")
Attn: Privacy Team
[NOTICE ADDRESS]
Email: [email protected]
Privacy-rights requests: https://cannvas.app/legal/privacy-request.html
For privacy rights relating to Org Data, please contact the relevant Organization, and see our Data Processing Addendum. For information about cookies and similar technologies, see our Cookie Policy.
*This document is a draft prepared for review by the client's counsel. It is not legal advice, is not yet effective, and must be reviewed, completed, and approved before publication or reliance.*