Privacy Policy
Last Updated: August 13, 2026
1. Who we are
Layerre is a sole proprietorship based in Ontario, Canada ("Layerre," "we," "our," or "us"). We provide a design automation API and web application at https://www.layerre.com (the "Services").
For privacy questions, data subject requests, and this policy, contact us at hello@layerre.com. We do not publish a postal address on this website.
Layerre is the data controller for personal information about our users (accounts, billing, support, and site analytics). When you use Layerre to generate designs that include other people's data (for example names on certificates), you are the controller of that content and Layerre is your processor. See our Data Processing Addendum (DPA / AVV).
2. Laws we follow (PIPEDA, Law 25, GDPR / DSGVO)
This Privacy Policy is intended to explain our practices under:
- PIPEDA: Canada's Personal Information Protection and Electronic Documents Act, which applies to our commercial activities in Canada
- Quebec Law 25: where we deal with personal information of individuals in Quebec
- GDPR / DSGVO: the EU General Data Protection Regulation (Datenschutz-Grundverordnung), and the UK GDPR, when we offer the Services to people in the EEA or UK (GDPR Art. 3)
- CASL: Canada's anti-spam law for commercial electronic messages
We do not block users in the European Union. If you are in the EEA or UK, you have the rights described in the GDPR / DSGVO section below.
3. Information we collect
3.1 Information you provide
- Account information: email address, password (stored as a hash by our auth provider), and profile details from Google or Microsoft if you sign in with those services
- User content: templates, variants, uploaded images, Canva design URLs, and other design data you submit so we can render outputs
- API data: API keys, request parameters, and usage metrics
- Communications: messages you send via email or in-app chat, and optional feedback if you delete your account
3.2 Information collected automatically
- Usage and device data: IP address, browser type, device information, pages visited, and referring URLs
- Cookies and similar technologies: strictly necessary cookies for login and security, and analytics cookies only if you accept them. See Cookies.
3.3 Payment information
Paid plans are billed by Stripe. We do not store full credit card numbers. Stripe collects payment details directly. We receive billing status, plan, and limited customer identifiers needed to provide the subscription.
4. How we use information and legal bases
Under the GDPR / DSGVO we only process personal data where we have a legal basis. Under PIPEDA we identify the purposes below and limit use to those purposes.
| Purpose | GDPR / DSGVO legal basis |
|---|---|
| Create and run your account, templates, API, and renders | Contract (Art. 6(1)(b) GDPR) |
| Process payments and manage subscriptions via Stripe | Contract (Art. 6(1)(b)); legal obligation for tax records |
| Transactional email (welcome, password reset, billing) | Contract (Art. 6(1)(b)) |
| In-app support chat (Crisp) for logged-in users | Contract / legitimate interests in supporting customers (Art. 6(1)(f)) |
| Security, fraud prevention, error monitoring | Legitimate interests (Art. 6(1)(f)); legal obligation |
| Google Analytics / Trust Views (site analytics) | Consent (Art. 6(1)(a)): not loaded until you accept cookies |
| Marketing email or newsletters (if we send them) | Consent and CASL; you can unsubscribe at any time |
We do not sell your personal information. We do not use your design files to train public AI models.
5. Service providers (subprocessors)
We share personal information with vendors who process it on our behalf to run the Services. They may only use it for those tasks.
| Provider | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database hosting, authentication, and file storage | United States |
| Stripe, Inc. | Payment processing and billing | United States |
| Google LLC | Analytics (Google Tag Manager / Google Analytics 4), fonts, and optional Google sign-in | United States |
| Cloudflare, Inc. | Website hosting, CDN, and security | United States |
| Crisp IM SAS | In-app customer support chat (logged-in users) | European Union (France) |
| Resend, Inc. | Transactional email delivery | United States |
| Canva Pty Ltd | Design import when you provide a Canva URL or connect a Canva design | Australia / global |
| TrustViews | Public testimonials / social-proof widget (analytics cookies) | United States |
| Slack Technologies, LLC | Internal operational alerts (errors, account-deletion notices) | United States |
| Microsoft Corporation | Optional Microsoft sign-in | United States |
We may also disclose information if required by law, to protect rights and security, or in connection with a merger or sale of the business.
6. International transfers
Layerre is based in Canada. Personal data may be processed in Canada, the United States, the European Union, and other countries where our providers operate.
The European Commission has issued an adequacy decision for Canada covering commercial organizations subject to PIPEDA. For transfers to the United States and other countries without an adequacy decision, we rely on our vendors' Standard Contractual Clauses (SCCs) and Data Processing Addenda.
7. Retention
- Account, template, variant, and API data: while your account is active
- After you delete your account: we delete that data from production systems. Backups and logs may remain for up to 90 days, then are overwritten
- Billing records held by Stripe: as required for tax and accounting (typically several years)
- Support chat: according to Crisp's retention for our workspace
- Analytics (if you consented): according to our Google Analytics retention settings
8. Your rights (including GDPR / DSGVO)
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your information (right to erasure / right to be forgotten)
- Restrict or object to certain processing
- Receive a copy of your data (portability)
- Withdraw consent where processing is based on consent
- Opt out of marketing emails
How to exercise these rights:
- Delete your account in Profile (self-serve). Feedback is optional.
- Email hello@layerre.com for access, correction, or other requests. We will respond within 30 days (or sooner where the GDPR / DSGVO requires it).
- Change analytics cookies with .
You may complain to the Office of the Privacy Commissioner of Canada or, if you are in the EEA or UK, to your local supervisory authority (in Germany, your Landesdatenschutzbehörde).
9. Cookies and tracking
We use cookies and similar technologies as follows. Analytics and Trust Views scripts are not loaded until you accept analytics cookies.
| Category | Examples | When it runs |
|---|---|---|
| Strictly necessary | Supabase authentication/session cookies; security | Always, to provide the Service |
| Payments | Stripe cookies on Stripe-hosted checkout | When you pay or manage billing |
| Support | Crisp chat (logged-in /app) | When you use the logged-in app |
| Analytics | Google Tag Manager, Google Analytics 4, Trust Views | Only after you click Accept |
We also load Google Fonts, which may cause your browser to request font files from Google. You can change your analytics choice anytime via or your browser settings. Rejecting analytics cookies does not block login or the API.
10. Data Processing Addendum
If you are a business in the EEA, UK, or elsewhere and need an Art. 28 GDPR / DSGVO agreement (AVV) because you process personal data of your customers or employees through Layerre, see our Data Processing Addendum. To request a signed copy, email hello@layerre.com.
11. Children
The Services are not intended for children under 13, or under 16 where that is the applicable age of digital consent under the GDPR / DSGVO. We do not knowingly collect information from children. If you believe we have, contact us and we will delete it.
12. Security
We use encryption in transit (TLS), encryption at rest with our hosting providers, access controls, and authentication. No method of transmission or storage is 100% secure. We cannot guarantee absolute security.
13. Changes
We may update this Privacy Policy. We will post the new version on this page and update the "Last Updated" date. For material changes we will also email registered users when practical. Continued use of the Services after the update means you accept the revised policy, except where applicable law requires additional consent.
14. Contact
Layerre (sole proprietorship), Ontario, Canada
Email: hello@layerre.com
Website: https://www.layerre.com
Related: Terms and Conditions · Data Processing Addendum


