Privacy notice
Your information, clearly explained.
In short: Clayton Plymill uses account, security, project, preference, support, and limited cookieless audience information to provide, protect, and improve the MECH Canvas service. We do not sell personal information, share it for cross-context behavioral advertising, or use advertising or analytics cookies.
1. Who operates MECH Canvas
Operator and privacy contact: Clayton Plymill
Email: admin@mechcanvas.com
Mailing address: 5510 Old Hickory Blvd Ste B #1007, Hermitage, Tennessee 37076, United States
Clayton Plymill is responsible for personal information handled through mechcanvas.com, portal.mechcanvas.com, auth.mechcanvas.com, BMS Graphics Studio, and BMS Floorplan Studio (together, the "Service"). If your employer or another organization provides your account, that organization may separately control how it assigns access and uses work created by its users.
2. Information we collect
- Account and organization data: user ID, email address, display name or username, organization, role, entitlements, account status, and account creation and update times.
- Authentication and security data: password hashes, sign-in sessions, login-attempt records, email-verification state, multi-factor authentication settings, encrypted authenticator secrets, recovery-code hashes, IP addresses, user-agent information, and security/audit events. We do not store the contents of authenticator codes after verification.
- Content and project data: graphics, floorplans, names, descriptions, models, component definitions, textures, uploaded blueprint/background images, animation and point-control settings, sharing state, ownership, and save times. A project may contain personal information if you put it there.
- Preferences: editor layout, view, grid, snapping, control-step, component-scale, and other workspace choices.
- Contact data: name, email, optional company, message, delivery status, and cryptographic hashes used to prevent spam and duplicate submissions.
- Technical records: request time, requested host/path, IP address, response status, and operational and security logs. Sensitive authentication query values are redacted from edge logs.
- Cookieless audience measurements: page path, referring website domain (not the full referring URL), viewport and screen dimensions, device-pixel ratio, a coarse mobile/tablet/desktop class, consent version, and a daily pseudonymous visitor signature. The signature is generated on our server from limited request information using a secret cryptographic key; it changes each day. We do not put the raw IP address, full user-agent string, or a persistent visitor identifier in the audience-measurement table.
We receive this information from you, your organization administrator, your browser or device, and our identity and service systems. Please do not upload sensitive personal information unless it is necessary and your organization has authorized it.
3. Why we use information and our legal bases
| Purpose | Typical information | Legal basis where required |
|---|---|---|
| Provide accounts, studios, saved projects, exports, preferences, and support | Account, organization, content, preference, contact | Performance of a contract or steps you request before a contract |
| Authenticate users, enforce permissions, prevent abuse, maintain backups, diagnose failures, and protect the Service | Account, authentication, IP, logs, audit and project data | Our legitimate interests in security, availability, fraud prevention, and service administration; and legal obligations |
| Respond to inquiries and communicate about the Service | Contact and account data | Contract steps and our legitimate interests in customer support |
| Understand which public pages and screen-size ranges are used so we can improve the website and promote the Service effectively | Limited cookieless audience measurements | Your separate, optional consent, which you may withdraw at any time |
| Comply with law, enforce agreements, and establish or defend legal claims | Relevant records | Legal obligations and legitimate interests |
Your acknowledgement confirms that you received this notice; it is not consent to unrelated or optional processing. If we later introduce processing that legally requires consent, we will request a separate, specific opt-in that you can withdraw.
4. How we disclose information
We disclose information only as needed to: service providers acting for us (including infrastructure, backup, identity, and IONOS email delivery); authorized administrators and members of your organization; professional advisers; a successor in a merger, financing, reorganization, or sale; or public authorities and other parties when reasonably necessary to comply with law, protect rights and safety, or prevent abuse. Providers may use information only to perform contracted services and must protect it. We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or exchange it for money or other valuable consideration.
5. Cookies and browser storage
The Service uses only first-party cookies and similar storage that are strictly necessary for sign-in, session continuity, security, load handling, requested preferences, and remembering your audience-measurement choice. Keycloak and oauth2-proxy set authentication and session cookies. The editors may temporarily hold an unsaved draft or interface state in browser memory or storage. Public-site audience measurement is off by default and is controlled separately on the Analytics Preferences page. It uses no analytics cookie, advertising identifier, or persistent visitor ID. We do not use advertising or third-party analytics cookies. You can withdraw permission there at any time; we also honor enabled Global Privacy Control and Do Not Track browser signals. You can block or delete cookies in your browser, but the protected Service will not function without essential authentication cookies.
6. Retention
- Account, organization, and saved project data are kept while the account or organization service relationship is active and then deleted or de-identified when no longer reasonably needed, subject to legal, dispute, and backup requirements. Users with permission can delete individual projects in the Service.
- Authentication sessions and one-time codes expire under their configured security limits. Login-attempt and operational security records are kept only as long as reasonably necessary to detect abuse and investigate incidents.
- Hashed contact-delivery throttle records are deleted after 30 days. Inquiry messages delivered to our mailbox are kept only as long as needed to respond, maintain appropriate business records, or resolve disputes.
- Cookieless audience events and their daily pseudonymous visitor signatures are deleted after 90 days. Aggregated totals may be retained longer when they no longer identify or single out a visitor.
- Daily access-controlled service backups are retained for approximately 15 days. Deletion from backups occurs through normal backup rotation.
- Privacy acknowledgement receipts and related audit evidence are generally kept for the account relationship plus six years where needed to demonstrate compliance or resolve disputes.
We may retain a record longer when law requires it, litigation is reasonably anticipated, or deletion would impair security or another person's rights.
7. International processing
MECH Canvas and its providers may process information in countries other than the one where you live. Our current processing locations are: United States. Those countries may have different privacy laws. Where required, we use an approved transfer mechanism, contractual protections, and appropriate technical and organizational safeguards. Contact us for information about safeguards applicable to a particular transfer.
8. Security
We use measures designed to protect information, including TLS, access controls, per-service credentials, network isolation, password hashing, encryption for authenticator secrets, input limits, origin checks, security headers, audit events, restricted backups, and restoration tests. No system is completely secure. Protect your credentials and notify us if you suspect unauthorized access.
9. Your privacy rights
Depending on where you live, you may have rights to access, know, correct, delete, restrict or object to processing, receive a portable copy, withdraw consent without affecting prior processing, opt out of sale, sharing, targeted advertising, or qualifying profiling, and appeal a denied request. You may also complain to your local data-protection authority. California residents may use an authorized agent and will not receive discriminatory treatment for exercising applicable rights. Because we do not sell or share personal information for behavioral advertising, there is no sale/share opt-out required for our current practices. We honor a recognized Global Privacy Control signal by disabling public-site audience measurement, and the separate Analytics Preferences page lets you allow or withdraw that optional measurement on this device.
Send a request to admin@mechcanvas.com. Describe the right you wish to exercise and the account or email involved. We will verify requests proportionately, respond within the period required by applicable law, and explain any lawful exception. If an organization controls your account, we may direct an organization-specific request to its administrator.
10. Children
The Service is a professional design workspace and is not directed to children under 16. We do not knowingly collect personal information from a child under 16. Contact us if you believe a child provided information, and we will investigate and delete it where required.
11. Automated decisions and sensitive information
We do not use personal information for automated decisions that produce legal or similarly significant effects. We use security rules to authenticate requests, rate-limit contact submissions, and enforce assigned permissions. We do not use or disclose sensitive personal information to infer characteristics.
12. Changes to this notice
We may update this notice as the Service or law changes. The version and effective date appear below. We will require a new acknowledgement before protected use when a change is material. Earlier acknowledgements remain recorded with the exact policy hash that was shown.
13. Contact and complaints
Email admin@mechcanvas.com with privacy questions, complaints, or accessibility requests. We will investigate privacy complaints and provide information about escalation or appeal rights that apply in your location.