Skip to content

Legal

Privacy policy

This policy explains the personal data we process when merchants use PactCanvas to collect order approvals and agreements.

Effective July 20, 2026

1. Who we are and what this covers

TechImprovement Inc. (“PactCanvas,” “we,” “us,” or “our”) provides the PactCanvas Sign & Proof application to Shopify merchants. This policy covers our application, public signing pages, support interactions, and related operational services. Shopify separately processes data under its own privacy terms.

2. Data we process

Depending on how a merchant configures the app, we process:

  • Merchant data: shop domain, store identifiers, staff/session identifiers, contact email, app settings, and the Shopify access token required to provide the service.
  • Agreement and order data: agreement text and versions, product and company assignments, order identifiers and line-item details, approval status, and related merchant content.
  • Signer data: name, email, company, optional role or title, typed or drawn signature, required acknowledgements, and comments submitted during the signing process.
  • Evidence and device data: timestamps, IP-derived evidence, browser/user-agent details, locale, document hashes, event records, and completed evidence PDFs.
  • Support and operations data: messages sent to us, privacy requests, webhook/job status, security events, and limited diagnostic logs.

We receive this data from the merchant, Shopify, signers, and the devices used to access the service. We do not collect payment-card credentials through PactCanvas.

We do not use advertising cookies or customer data for cross-context behavioral advertising. The embedded app relies on Shopify session tokens, and Shopify or the browser may use essential cookies or storage needed for authentication, cart state, security, and the current signing flow. These technologies are used to provide and protect the service, not to build advertising profiles.

3. Why we process data

We process data only as needed to:

  • install, authenticate, secure, and operate the application;
  • determine which merchant-configured agreement applies;
  • display documents and collect attributable electronic acceptance;
  • validate required completion and associate evidence with an order;
  • generate, retain, export, and delete evidence at the merchant’s direction;
  • provide support, prevent abuse, investigate incidents, and meet legal obligations.

For merchant and customer data supplied through Shopify, the merchant generally determines the purpose of processing and we act as its service provider or processor. For account security, service administration, and legal compliance, we may act as an independent controller where applicable.

Where a legal basis is required for our controller activities, we rely on performance of our contract for merchant account and support operations, legitimate interests in securing and improving the service, compliance with legal obligations, and consent where the law requires it.

4. Sharing and sale of data

We do not sell personal data and do not use Shopify customer data for behavioral advertising. We disclose data only to the merchant that controls it, at a user’s direction, where legally required, or to service providers needed to run the application.

Provider categories can include Shopify, infrastructure and hosting, transactional email, domain and certificate services, backup storage, and monitoring or incident-response services. These providers may process data only for contracted services and are subject to appropriate confidentiality and data-protection terms. Current provider information is available by contacting us.

5. Retention and deletion

Merchants choose an evidence-retention period in the app. The default is seven years, intended for commercial agreement evidence, but the merchant must select a period appropriate for its contracts and law. We delete or de-identify eligible signing records, evidence, and operational data after the configured period, subject to active workflows, legal holds, disputes, and applicable law.

When the app is uninstalled, we stop ordinary processing and remove access sessions and saved custom email credentials. The Shopify store owner can choose immediate deletion of live PactCanvas data or a short rapid-reinstall grace period. Grace-period data is deleted when Shopify sends its mandatory shop-redaction request or when the 48-hour application fallback expires. Residual copies may remain temporarily in backups until normal rotation. We keep only limited records needed to document completed deletion, security, billing, or legal compliance.

6. Security

We use layered administrative, technical, and organizational controls, including tenant authorization, restricted production access, HTTPS, authenticated Shopify webhooks, private evidence storage, application-level encryption for uploaded proof files, drawn-signature representations and completed PDFs, tamper-evident event records, retention workflows, and incident procedures. No service can promise absolute security. More information is on our security page.

7. Your choices and privacy rights

Depending on location, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data. If your data belongs to a Shopify merchant, contact that merchant first; we assist it with verified requests. You may also contact us directly.

PactCanvas does not make decisions about people based on profiling that produce legal or similarly significant effects. Agreement validation applies rules configured by the merchant to the current cart or company context.

8. International processing

Data may be processed in countries other than the individual’s home country. Where required, we use recognized transfer mechanisms and contractual protections. Merchants should contact us for information relevant to their location and selected infrastructure.

9. Children

The service is for merchants and people authorized to enter commercial transactions. It is not directed to children, and merchants must not use it to collect a child’s signature without a lawful basis and all required parental or guardian authorization.

10. Changes and contact

We may update this policy as the service or law changes. We will post the revised effective date here and provide additional notice where required. Questions and privacy requests can be sent to info@techimprovement.net.