Privacy Policy
Last updated: March 8, 2026
HeadshotCanvas is a Canadian company that provides AI-generated professional headshots. This Privacy Policy explains what information we collect, how we use it, how it is processed by our service providers, and the choices available to you.
Information We Collect
We collect account information such as your email address and authentication credentials. Password hashes and authentication flows are managed through Supabase Auth.
We collect the selfie you upload in JPEG, PNG, or WebP format and the headshots generated from that upload.
Payment information is processed by Stripe. We do not store your full card number or other complete payment card details on our own systems.
We may collect usage data such as page views and feature usage through PostHog, but PostHog analytics are planned and not yet active at this time.
We use Rewardful for cookie-based referral attribution when you arrive through an affiliate link.
How We Use Your Information
We use your uploaded photo to generate AI headshots and deliver those results to you.
We use account and order information to process payments and send service-related transactional emails such as order confirmations and delivery notifications.
When analytics are active, we may use aggregated product usage information to improve product quality, identify bugs, and understand how customers use the service.
We use referral attribution information to track affiliate referrals and support commission reporting through Rewardful.
HeadshotCanvas currently sends only service-related transactional emails such as order confirmations and "headshots ready" notices. We do not send marketing or promotional emails at this time. If we introduce marketing emails in the future, we will handle them in accordance with applicable consent requirements, including Canada's Anti-Spam Legislation (CASL).
How We Process Your Photos
Your uploaded selfie is stored in Cloudflare R2 and sent to Replicate, a third-party AI inference provider, so headshot outputs can be generated on our behalf using models such as PuLID and GFPGAN.
We do not use your photos to train AI models.
HeadshotCanvas automatically deletes uploaded photos and generated headshots from our own storage after 30 days.
Replicate's handling of data is governed by its own privacy policy, available at replicate.com/privacy.
If you want your data deleted earlier, you can request early deletion by contacting our privacy contact listed below.
Cross-Border Data Processing
HeadshotCanvas is a Canadian company. However, we use third-party service providers that operate outside Canada, primarily in the United States. As a result, your personal information, including uploaded photos, may be processed and stored in jurisdictions outside Canada and may be subject to the laws of those jurisdictions, including lawful access by foreign courts, law enforcement, or governmental authorities. We remain accountable for your personal information under PIPEDA regardless of where it is processed.
Biometric Data Notice
Face photos may be considered biometric data under certain laws, including BIPA in Illinois and the GDPR in the European Union.
By uploading your photo, you consent to its use for AI headshot generation as described in this policy.
We do not sell, lease, or trade biometric data.
Biometric data stored by HeadshotCanvas is deleted from our storage within 30 days.
Third-Party Services
- Supabase: Authentication and database. Privacy policy: https://supabase.com/privacy
- Cloudflare: File storage via R2. Privacy policy: https://www.cloudflare.com/privacypolicy/
- Replicate: AI photo processing. Privacy policy: https://replicate.com/privacy
- Stripe: Payment processing. Privacy policy: https://stripe.com/privacy
- Resend: Email delivery. Privacy policy: https://resend.com/legal/privacy-policy
- Rewardful: Affiliate tracking. Privacy policy: https://www.rewardful.com/privacy
- PostHog: Product analytics - planned, not yet active. Privacy policy: https://posthog.com/privacy
Security and Breach Response
We use commercially reasonable technical and organizational safeguards to protect your personal information, including HTTPS, access controls, and secure third-party infrastructure.
If a data breach affects your personal information, we will notify affected individuals and report to applicable regulatory authorities as required by law, including the Office of the Privacy Commissioner of Canada where applicable.
Data Retention
Photos and generated headshots are automatically deleted from our storage after 30 days.
Account data is retained until you request deletion of your account.
Payment records are retained as required by tax, accounting, and legal obligations.
Your Rights
You may request access to your personal information.
You may request correction or deletion of your data.
You may withdraw consent for processing, subject to legal or contractual limits.
For Canadian residents, PIPEDA provides rights that include access to personal information, the ability to challenge its accuracy, and the ability to file a complaint with the Office of the Privacy Commissioner of Canada.
To exercise any of these rights, contact our privacy contact below.
Children's Privacy
Our service is not intended for users under 16.
We do not knowingly collect personal information from children.
Changes to This Policy
We may update this policy from time to time. We will post the updated version on this page and update the revision date. If we make material changes to how we handle your personal information, we will provide notice and obtain any consent required by applicable law.
Privacy Contact
For questions about this policy, to exercise your privacy rights, to request data access or deletion, or to file a privacy-related complaint, contact us at: privacy@headshotcanvas.com.