Privacy policy
Privacy Notice
CANIS ARES LLC
Effective / Last Updated: August 16, 2026
Attorney-review draft - Shopify / North America revision. Internal version: 2026-08-16-v4-Shopify-NA. This version integrates the Shopify-generated privacy language supplied on August 16, 2026 with Canis Ares LLC's business-specific U.S./Canadian, consumer-health-data, biometric/likeness, medical-imaging, AI-processing, retention, and sensitive-file provisions. It is intended for the Shopify-powered storefront and should replace Privacy Notice v3 only when the Shopify storefront is used in production.
1. Scope, Who We Are, and Policy Priority
Canis Ares LLC ("Canis Ares," the "Company," "we," "us," or "our") operates this store and website and provides design, 3D modeling, 3D scanning, photogrammetry, additive-manufacturing, prototyping, digital-file, medical-imaging sculpture, likeness-based, AI-assisted, in-person, mobile, and related products and services (collectively, the "Services"). Our online store is powered by Shopify, which provides technology that enables us to offer the storefront, cart, checkout, customer-account, order, payment, security, and related commerce functions.
This Privacy Notice describes how we collect, use, disclose, retain, and protect personal information when you visit, use, purchase from, or otherwise interact with the Services; communicate with us; submit project information; upload authorized files through an approved method; participate in a face/body/property scan; or visit a location where we perform a requested scan.
If there is a conflict between our Terms of Service and this Privacy Notice regarding the collection, use, processing, disclosure, or retention of personal information, this Privacy Notice controls for that privacy issue. If Exhibit A (Consumer Health Data Privacy Policy) or Exhibit B (Biometric & Likeness Data Privacy / Retention Policy) provides greater protection for covered data, the applicable Exhibit controls for that data.
The Services are intended for the United States and, initially, Canada outside Quebec as described below. This Notice may also apply to a person who merely visits the public website from another location.
2. Relationship with Shopify
Shopify hosts and powers important parts of the Services and collects and processes personal information about access to and use of the storefront in order to provide, secure, support, personalize, and improve Shopify-powered services. Information submitted through Shopify-powered parts of the Services is transmitted to Shopify and may also be processed by Shopify subprocessors or other third parties in countries other than the country where you live.
We may use Shopify features that incorporate information from interactions with our store together with information Shopify has from interactions with other merchants or Shopify services. When Shopify processes information for its own Shopify consumer services or Enhanced Services, Shopify may be independently responsible for that processing and for responding to certain privacy requests relating to that processing. Shopify explains its consumer processing at https://www.shopify.com/legal/privacy/consumers and provides privacy choices at https://privacy.shopify.com/en.
Canis Ares remains responsible for our own collection and use of personal information and for configuring our Shopify store and other vendors consistently with applicable law and this Notice.
3. Personal Information We Collect or Process
"Personal information" means information that identifies, relates to, describes, or can reasonably be linked to an identifiable person, subject to the definition under applicable law. It generally does not include information that has been lawfully anonymized or de-identified so that it cannot reasonably be linked to a person.
3.1 Contact, Account, Transaction, and Communication Information
-
contact details, including name, email address, telephone number, billing address, and shipping address;
-
account information, including customer-account identifiers, authentication or verification information, preferences, settings, and account status;
-
transaction and shopping information, including products or services viewed, placed in a cart or wishlist, purchased, returned, exchanged, canceled, or reordered, along with order history, discounts, shipping selections, and related status information;
-
project and order information, including project descriptions, product selections, material choices, dimensions, tolerances, reference objects, approval decisions, quotes, proofs, and support requests;
-
communications with us, including email, forms, messages, feedback, dispute notices, privacy requests, and records of customer-service interactions; and
-
identity or authorization information when reasonably needed to verify a privacy request, rights in submitted content, age/guardian authority, or authority to act for another person.
3.2 Payment and Financial Information
When you pay through Shopify or another approved payment method, Shopify, Shopify Payments, payment processors, banks, or other financial-service providers may collect payment-card, financial-account, transaction, billing, fraud-prevention, and payment-confirmation information. Canis Ares generally does not receive or store the full payment-card number or card security code. We may receive payment status, transaction identifiers, limited or tokenized payment information, billing contact information, fraud or risk signals, refunds, chargebacks, and accounting records needed to administer the transaction.
3.3 Project Files and Customer-Provided Content
For ordinary projects, we may collect CAD files, STL/3MF/OBJ or similar model files, meshes, point clouds, photographs, drawings, logos, reference images, measurements, texture captures, written instructions, and other content needed to evaluate or complete a requested project.
Until Canis Ares provides an approved sensitive-file upload method, do not send MRI/CT/DICOM/NIfTI files, clinical records, face/body scan files, raw biometric geometry, Social Security numbers, full financial-account information, or similarly sensitive data through ordinary Shopify contact fields, order notes, chat, ordinary email, or other general-purpose communication channels. You may describe the general type of project without transmitting the sensitive source data.
3.4 Medical Imaging and Consumer Health Data
If you request an anatomy-sculpture project through an approved workflow, we may receive Medical Imaging Data such as MRI, CT, DICOM, NIfTI, ultrasound exports, radiology images, or other files that depict or reveal information about a person's body or health. We may also create segmentation files, meshes, derived 3D models, screenshots, or project notes based on those files. We treat this information as highly sensitive "Health Data" for purposes of this Notice, whether or not a particular law classifies it that way.
We ask you not to submit unrelated clinical records, insurance information, Social Security numbers, financial-account information, or other data that is unnecessary for the requested artistic project. Transaction information associated with a health-related creative project may itself reveal or infer health-related information in some jurisdictions and is treated under Exhibit A where applicable.
3.5 Face/Body Scans, Likeness Data, and Biometric Information
If you request a likeness-based or in-person scanning project, we may collect photographs, video frames, facial or body geometry, contours, measurements, depth information, point clouds, textures, meshes, scan metadata, and derived artistic models that depict or can reasonably be associated with you or another authorized person ("Likeness Data"). Depending on the technology and applicable law, some Likeness Data may be biometric information or a biometric identifier, including a scan of face or hand geometry.
We collect Likeness Data for customer-requested creative modeling and manufacturing, not for authentication, surveillance, law-enforcement identification, eligibility decisions, credit, employment, insurance, housing, or behavioral profiling. We do not intentionally use creative-project scans to infer health conditions, emotions, race, religion, sexual orientation, or other sensitive characteristics.
For property or premises scanning, incidental images may capture interiors, objects, documents, screens, photographs, bystanders, or other information. Customers should clear the target area of anything they do not want captured and obtain permission from people or property owners whose authorization is required.
3.6 Device, Usage, Cookie, and Storefront Information
When you access the Shopify-powered storefront or related Services, we and Shopify may automatically receive device, browser, network, IP-address, approximate-location, requested-page, referrer, timestamp, shopping-session, cart, checkout, fraud-prevention, security, and usage information. Depending on our Shopify configuration and applicable consent choices, Shopify may also process analytics, attribution, personalization, or marketing information about how you interact with the store.
Shopify uses cookies and similar technologies on merchant storefronts for necessary store functions and may use additional cookies or similar technologies for reporting, analytics, marketing, personalization, privacy preferences, fraud prevention, Shop Pay, customer login, cart, checkout, and related functions. The exact technologies can change over time and may depend on Shopify settings, installed apps, region, and visitor choices. Shopify describes its cookies at https://www.shopify.com/legal/privacy/cookies.
4. Personal Information Sources
We may collect personal information:
-
directly from you, including when you create an account, purchase or inquire about Services, communicate with us, submit authorized project information, or exercise privacy rights;
-
automatically through Shopify, our storefront, your browser or device, cookies, similar technologies, security systems, or approved website technologies;
-
from Shopify, payment processors, shipping carriers, fraud-prevention providers, email providers, file-transfer/storage providers, service providers, contractors, and other vendors used to provide the Services;
-
from business, marketing, or advertising partners when such relationships are used and lawfully configured; and
-
from another person or organization that lawfully submits information on your behalf, including a parent, guardian, authorized agent, or project customer with authority concerning a subject.
For source Health Data and raw biometric/Likeness Data, the expected source is you or a person you have authorized to act for you, through a separately approved workflow.
5. How We Use Personal Information
Depending on how you interact with us and which features are enabled, we may use personal information to:
-
provide, administer, tailor, and improve the Services, including maintaining the storefront, cart, checkout, customer account, order history, preferences, and customer support;
-
respond to inquiries, evaluate project feasibility, prepare quotes, proofs, models, previews, and order documents;
-
perform design, modeling, fabrication, finishing, quality control, packaging, shipping, delivery, and related customer-service activities;
-
process payments, refunds, returns, taxes, accounting, chargebacks, fraud screening, and transaction records;
-
authenticate users and privacy requests, secure accounts and systems, detect and investigate fraudulent, illegal, unsafe, abusive, or malicious activity, and protect people and property;
-
communicate with you about accounts, inquiries, projects, purchases, shipping, policy changes, security, product safety, or support;
-
maintain records, resolve disputes, participate in legal proceedings or civil discovery, enforce agreements, protect legal rights, and comply with valid legal process or regulatory obligations;
-
operate, troubleshoot, measure, personalize, and improve ordinary storefront and business functions using Shopify or other approved technologies; and
-
conduct marketing or advertising activities using ordinary personal information where enabled, lawfully permitted, and subject to applicable consent and opt-out rights. Health Data and raw biometric information are subject to the stricter limitations below.
6. How We Use Health Data
We use Health Data only for purposes reasonably necessary to provide and administer the anatomy-sculpture service you requested, including receiving and validating files through an approved workflow, creating segmentations or meshes, preparing previews, communicating with you, creating a digital or printed sculptural model, resolving technical problems, delivering the project, protecting the security and integrity of the service, complying with law, and handling a dispute or legal claim.
WE DO NOT USE HEALTH DATA TO DIAGNOSE, TREAT, PROFILE YOUR HEALTH FOR ADVERTISING, SET PRICES BASED ON YOUR HEALTH, MAKE ELIGIBILITY OR EMPLOYMENT DECISIONS, OR TRAIN GENERAL-PURPOSE ARTIFICIAL-INTELLIGENCE OR MACHINE-LEARNING MODELS. We do not sell Health Data. We do not intentionally use Health Data for targeted advertising or submit source medical files into ordinary Shopify advertising, analytics, or Network Intelligence fields.
Where applicable law requires separate consent for collection or sharing of Consumer Health Data, we will obtain the required affirmative consent before the activity unless applicable law permits processing because it is necessary to provide the product or service you requested.
7. How We Use Likeness and Biometric Data
We use Likeness Data to schedule and conduct requested scans; generate, reconstruct, sculpt, retopologize, texture, stylize, edit, or prepare 3D models; produce lithophanes, reliefs, miniatures, busts, figurines, chess pieces, tabletop figures, and similar products; create proofs; fulfill reorders where lawful archival storage was requested; prevent fraud or misuse; secure the Services; respond to privacy requests; and comply with law.
We do not use a customer's Likeness Data for unrelated targeted advertising, a public portfolio, social-media promotion, or generalized model training unless the relevant person separately and affirmatively authorizes the specific use where lawful. A marketing/publicity release is not required to purchase ordinary Services. Raw face/body geometry is not intended to be submitted through ordinary Shopify storefront, checkout, analytics, advertising, or marketing fields.
8. How We Disclose Personal Information
We may disclose personal information for legitimate business purposes described in this Notice, including to:
-
Shopify and Shopify subprocessors that host, secure, process, personalize, support, or improve the Shopify-powered storefront, checkout, customer account, payment, fraud, analytics, privacy, and related commerce services;
-
technology, cloud-storage, secure file-transfer, email, customer-support, security, backup, and other service providers;
-
payment processors, fraud-prevention providers, banks, accountants, tax professionals, and bookkeeping providers;
-
shipping carriers, fulfillment providers, material suppliers, and vendors used to complete or deliver an order;
-
specialized contractors, scanning/modeling providers, manufacturing providers, and AI or machine-learning service providers when needed for the requested project and subject to the sensitive-data restrictions and consents described in this Notice;
-
business or marketing partners where a marketing or personalization function is enabled and permitted by applicable law;
-
lawyers, insurers, auditors, investigators, and other professional advisers;
-
government authorities, courts, law enforcement, regulators, or other parties when disclosure is required by law or reasonably necessary to protect rights, safety, security, or the integrity of the Services; and
-
a buyer, successor, lender, or transaction adviser in connection with a merger, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and protections appropriate to sensitive information.
For Health Data and identifiable Likeness Data, we seek to limit disclosures to the recipients and purposes permitted by Exhibits A and B. We do not intentionally disclose source Health Data or raw biometric geometry to data brokers, unrelated advertising networks, or social-media advertising platforms.
9. Shopify Network Intelligence, Sale/Sharing, Targeted Advertising, and Opt-Outs
Shopify offers Enhanced Services through Shopify Network Intelligence. When this feature is enabled, Shopify may use ordinary customer and storefront interaction information from our store together with information from interactions with other merchants or Shopify services to provide personalization, performance improvements, fraud/security functions, advertising-related services, and other Enhanced Services. Under some U.S. state privacy laws, portions of this activity may be considered "sharing" or processing for "targeted advertising," even when Canis Ares does not sell personal information for cash.
Where applicable, you may opt out of qualifying sale, sharing, or targeted-advertising uses through our Shopify data-sharing opt-out page at https://www.canisares.com/pages/data-sharing-opt-out. Shopify may also honor Global Privacy Control (GPC) signals as required and as supported by our Customer Privacy settings. Shopify provides additional privacy choices at https://privacy.shopify.com/en.
Canis Ares does not sell Consumer Health Data. We do not sell, lease, trade, or otherwise monetize raw biometric identifiers or raw face/body geometry in a manner prohibited by law, and we do not intentionally use source medical images, raw face/body geometry, or similarly sensitive project files for targeted advertising. General Terms acceptance or ordinary privacy acknowledgment is not authorization for a sale of Consumer Health Data or a materially different commercialization of biometric information.
If we materially change our ordinary-data advertising, sale, or sharing practices, we will update applicable disclosures and implement any additional consent, opt-out, notice-at-collection, browser preference-signal, or other mechanism required before the changed practice begins.
10. Cookies and Similar Technologies
The Shopify-powered Services use cookies and similar technologies for functions such as storefront operation, cart and checkout, customer authentication, security and anti-tampering, localization, payment features, privacy preferences, reporting, analytics, and, depending on enabled features and consent choices, marketing or personalization. Shopify maintains a current description of Shopify cookies at https://www.shopify.com/legal/privacy/cookies.
Where applicable law or our agreements with Shopify require consent or an opt-out for nonessential technologies, we use Shopify Customer Privacy settings or compatible tools to present a cookie banner, honor visitor choices, recognize applicable preference signals, and limit nonessential processing. The availability and behavior of these controls may vary by region and Shopify configuration.
We do not intentionally place Health Data, source medical filenames or file contents, raw face/body geometry, or sensitive project details into advertising pixels or ordinary marketing/analytics event parameters.
11. Third-Party Websites and Links
The Services may link to websites, applications, social-media platforms, or other online services operated by third parties. Their privacy and security practices are governed by their own notices and terms. We do not control or guarantee the privacy, security, accuracy, or practices of independent third-party sites merely because we provide a link to them. Information you intentionally post in public or semi-public spaces may be visible and used by other people or platforms according to their own practices.
12. Medical Data, HIPAA, and Health-Care Organizations
Direct submission of Medical Imaging Data by a consumer does not, by itself, make Canis Ares a HIPAA covered entity or business associate. HIPAA applies based on the legal status and relationship of the parties. If Canis Ares receives, maintains, or transmits protected health information on behalf of a HIPAA covered entity or business associate to perform a regulated function or service, separate written review and, where required, a Business Associate Agreement must be completed before the data is transmitted.
Regardless of HIPAA status, other federal and state privacy, consumer-health-data, data-security, and breach-notification laws may apply. Our separate Consumer Health Data Privacy Policy appears as Exhibit A and should be implemented as a separately linked policy wherever required by law.
13. Retention and Deletion
We retain ordinary personal information for as long as reasonably necessary to provide the Services, maintain customer accounts and order history, process payments and returns, provide support, maintain accounting and tax records, enforce agreements, prevent fraud, resolve disputes, comply with law, and meet legitimate business needs. Shopify and other service providers may maintain data according to their own retention obligations and contractual roles.
For Health Data, our default data-minimization target is: (a) source medical-imaging files and working segmentation files are scheduled for deletion within 90 days after final project delivery or cancellation; (b) identifiable derived anatomical models are scheduled for deletion within 180 days after final delivery unless you affirmatively request longer lawful archival storage for reorders; and (c) encrypted or disaster-recovery backups may persist until overwritten in the ordinary backup cycle, targeted to occur within 180 additional days. Legal holds, security investigations, payment disputes, or applicable law may require longer retention of limited data.
For Likeness Data and biometric information, our default target is to delete raw face/body scan captures, point clouds, depth maps, texture captures, and working geometry within 90 days after final project delivery or cancellation, unless a shorter period is required by law or you affirmatively request and the law permits archival storage for reorders. Identifiable derived models are targeted for deletion within 180 days after final delivery unless archival storage is requested and lawful. Where a biometric-retention law applies, the shorter legally required period controls. Backup copies may persist until overwritten in the ordinary backup cycle, subject to legal requirements and technical feasibility.
Operational systems should enforce stated sensitive-data retention periods rather than relying solely on manual deletion. If actual business needs require materially different sensitive-data retention, this Notice must be updated before the practice changes.
14. Security
We use administrative, technical, and physical safeguards designed for the nature and sensitivity of the information we handle, and we rely on Shopify and other service providers for security controls within their respective services. For Health Data, Likeness Data, and biometric information, expected safeguards include encrypted transmission where supported, restricted access, strong authentication, limited storage locations, security logging where appropriate, software updates, vendor restrictions appropriate to the data, and deletion controls.
No security system is perfect or impenetrable, and we cannot guarantee absolute security. Information sent through insecure channels may be exposed while in transit. Do not send sensitive or confidential information through ordinary email, general Shopify contact/order fields, or another unapproved channel. Protect account access, verification codes, download links, passwords where applicable, and devices used to access the Services.
15. Data Breach and Incident Response
If we discover unauthorized access to or acquisition of information, we will investigate and provide notices to affected individuals, regulators, service providers, or others when required by applicable law. Different breach-notification laws may apply depending on the data, residence of affected individuals, vendors involved, and whether HIPAA applies to a particular relationship.
For Canadian personal information subject to PIPEDA, Canis Ares will assess a breach of security safeguards for a real risk of significant harm, maintain breach records, and provide required notice to affected individuals and the Office of the Privacy Commissioner of Canada where applicable. Provincial breach or incident requirements may also apply. U.S. federal and state breach-notification obligations remain separately applicable according to the affected data and individuals.
16. Your Privacy Rights and Choices
Depending on where you live and which law applies, you may have rights to access or know personal information we hold about you, request correction or deletion, receive a portable copy, learn about certain disclosures, withdraw consent prospectively, restrict certain sensitive-data processing, opt out of qualifying sale/sharing or targeted advertising, or appeal a denied privacy request. These rights are not absolute and may be subject to verification, statutory thresholds, exceptions, or retention obligations.
To make a request directly to Canis Ares, email CanisAres@CanisAres.com with the subject line "PRIVACY REQUEST" and describe the right you wish to exercise. We may request information reasonably necessary to verify your identity or authority. We will not unlawfully discriminate against you for exercising a privacy right. An authorized agent may submit a request where applicable law permits, subject to proof of authority and any permitted identity verification.
Certain information processed independently by Shopify may be subject to Shopify's own privacy-request process. Shopify provides privacy choices and request information at https://privacy.shopify.com/en.
16.1 U.S. State Privacy Rights
Depending on the state, our size, the type of data, Shopify settings, the practices actually conducted, and applicable statutory thresholds or exemptions, U.S. residents may have rights such as access, correction, deletion, portability, information about disclosures, limits on sensitive-data processing, and opt-out rights relating to qualifying sales, sharing, targeted advertising, or profiling. Where required for practices we conduct, Shopify's data-sharing opt-out page or another lawful mechanism will be made available. Where applicable law requires recognition of browser-based opt-out preference signals such as Global Privacy Control, we will process those signals as required and as supported by our configured privacy tools.
The Shopify data-sharing opt-out page for the store is expected at https://www.canisares.com/pages/data-sharing-opt-out when enabled. The availability or legal effect of an opt-out depends on the visitor's jurisdiction, applicable law, and the practices active at that time.
16.2 Canadian Privacy Rights
Where Canadian private-sector privacy law applies, you may have rights to know why personal information is collected, access personal information we hold about you, challenge its accuracy and request correction, withdraw consent prospectively subject to legal or contractual restrictions and reasonable notice, and challenge our compliance. The form of consent depends on context; Canis Ares seeks express consent for highly sensitive information such as Health Data, raw biometric information, and expanded/public AI disclosure where required or appropriate.
Canadian privacy requests may be sent to the Privacy Officer listed in Section 23. If applicable law gives you a right to complain to the Office of the Privacy Commissioner of Canada or a provincial privacy regulator, nothing in this Notice limits that right.
17. Children and Minors
The Services are not directed to children under 13, and we do not knowingly collect personal information online directly from a child under 13 without legally sufficient parental consent. As of the Effective Date, we do not have actual knowledge that we sell or share, as those terms are defined by applicable law, personal information of individuals under 16.
Orders involving a minor's Medical Imaging Data, photographs, face/body scan, or other identifiable likeness must be submitted by, or with verifiable written authorization from, a parent or legal guardian. For in-person scanning of a minor, a parent or legal guardian must ordinarily be present unless a documented lawful arrangement is approved in advance. Additional state/provincial protections for minors apply where required.
18. Marketing and Communication Preferences
We may send promotional email, text, postal mail, or other marketing communications where enabled and permitted by applicable law. You may unsubscribe from promotional email using the unsubscribe mechanism in the message or by contacting us. Opting out of marketing does not prevent transactional, security, legal, product-safety, account, order, or active-project communications.
We do not intentionally use Health Data or raw biometric geometry to select or personalize marketing. For recipients in Canada, commercial electronic messages will be sent only where Canis Ares has consent or another lawful basis required by Canada's Anti-Spam Legislation (CASL) or other applicable law, and messages will include required sender identification and an unsubscribe mechanism.
19. Third-Party Service Providers and AI Processing
Our business may use or link to third-party providers, including Shopify, payment processors, email providers, shipping carriers, cloud/storage and secure file-transfer services, customer-support tools, scanning/modeling software, image-processing tools, contractors, and AI/machine-learning providers. Their independent practices are governed by their contracts and privacy notices. We evaluate sensitive processing separately from ordinary storefront processing.
For identifiable Health Data and Likeness Data, we prefer private, business, enterprise, local, or no-generalized-training configurations where reasonably available. If a project would use a public/general-purpose AI service or another expanded processing configuration that may permit provider retention, human review, service improvement, or generalized model training beyond performing the project, we seek separate affirmative consent before disclosing identifiable Likeness Data and do not use Health Data for generalized model training.
20. International and Cross-Border Transfers
Canis Ares is based in the United States. Shopify and other providers may transfer, store, or process personal information in the United States, Canada, or other countries. Those jurisdictions may have privacy or government-access laws different from those where you live. For Canadian personal information transferred to service providers for processing, Canis Ares remains accountable to the extent required by applicable Canadian privacy law and uses contractual or other safeguards appropriate to the sensitivity and circumstances.
Where a transfer of personal information from the European Economic Area or United Kingdom requires a recognized transfer mechanism, the relevant provider or party may rely on mechanisms such as applicable Standard Contractual Clauses, an adequacy determination, or another lawful transfer mechanism as appropriate to the processing.
For Canadian commercial activities, PIPEDA may apply to cross-border personal information and to private-sector activities where provincial law does not displace it; Alberta, British Columbia, and Quebec have private-sector privacy statutes that may apply in their respective circumstances. This Notice does not reduce any mandatory federal or provincial privacy right.
Canis Ares currently intends to accept Canadian consumer orders and projects outside Quebec only. Quebec visitors may browse the public store and send a non-sensitive general inquiry, but Canis Ares does not currently accept Quebec consumer orders, sensitive-data uploads, or paid projects until the required Quebec-specific French-language and consumer/privacy implementation has been reviewed and enabled. This restriction does not reduce any privacy right a Quebec visitor may have regarding information actually received.
21. Complaints
If you have a complaint about how Canis Ares processes personal information, contact us using Section 23. Depending on where you live and applicable law, you may have a right to appeal a privacy decision or lodge a complaint with a government privacy or data-protection authority. Nothing in this Notice limits a legally available complaint right.
22. Changes to This Privacy Notice
We may update this Notice to reflect changes in law, Shopify or other vendor settings, technology, products, or business practices. We will post the revised version and update the "Last Updated" date. If a change materially expands our use of sensitive information or Health Data, we will provide additional notice or obtain consent where required before applying the new practice. Shopify may separately update its own privacy policies and platform technologies.
23. Contact
Privacy Officer / Person Responsible for Privacy: Canis Ares LLC
Email: CanisAres@CanisAres.com
Phone: +1 716-352-5529
Privacy questions, access/correction/deletion requests, consent withdrawals, consumer-health-data requests, biometric/likeness requests, and other privacy requests may be sent using the contact information above. Use the subject line "PRIVACY REQUEST" unless a specialized policy asks for a different subject line. We may take reasonable steps to verify identity or authority before disclosing or deleting personal information.
Exhibit A
CONSUMER HEALTH DATA PRIVACY POLICY
Implement as a separate, distinct website link where required (including Washington).
A1. What This Health Data Policy Covers
This Consumer Health Data Privacy Policy describes how Canis Ares LLC collects, uses, shares, and protects "Consumer Health Data" when laws such as the Washington My Health My Data Act apply. It supplements the Canis Ares Privacy Notice. If this policy provides greater protection for Consumer Health Data than the general Privacy Notice, this policy controls for that data.
Consumer Health Data generally means personal information that is linked or reasonably linkable to a consumer and identifies or reveals past, present, or future physical or mental health status. For our Services, this can include Medical Imaging Data, MRI/CT/DICOM/NIfTI files, anatomical images, segmentation files, derived anatomy models, information identifying a person as seeking an anatomy-model service, and other health-related information that applicable law treats as Consumer Health Data.
A2. Categories of Consumer Health Data We Collect
Depending on your project, we may collect:
-
medical imaging and diagnostic-image files you submit, including MRI, CT, DICOM, NIfTI, ultrasound exports, or similar data;
-
anatomical images, body measurements, segmentation masks, meshes, derived 3D anatomy models, and project previews created from those files;
-
project information that identifies the type of anatomy or body structure you asked us to model;
-
contact, account, transaction, and communication information when it is linked to the health-related project; and
-
limited technical or security information associated with an upload or project when that information is reasonably linkable to the consumer and treated as Consumer Health Data by applicable law.
A3. Why We Collect and How We Use Consumer Health Data
We collect and use Consumer Health Data only as needed to provide the anatomy-sculpture service you request or as otherwise permitted with legally valid consent. Purposes include: receiving and validating approved sensitive-file uploads; creating a segmentation, mesh, model, preview, or physical print; communicating about the project; troubleshooting; delivering files or goods; processing related transactions; preventing fraud and security incidents; complying with law; and resolving disputes. Ordinary Shopify order/payment metadata may be processed for commerce administration, but source medical files are not intended to be submitted through general Shopify storefront, checkout, analytics, marketing, or Network Intelligence fields.
We do not use Consumer Health Data for diagnosis, treatment, clinical decision-making, targeted advertising, behavioral advertising, health-based pricing, eligibility decisions, employment decisions, or general-purpose AI/model training. We do not sell Consumer Health Data.
A4. Sources of Consumer Health Data
We collect Consumer Health Data primarily from you. We may also receive it from a parent, guardian, authorized agent, or organization that you have lawfully authorized to act for you. We create derived segmentation files, meshes, or models from the data you or your authorized representative provides.
A5. Categories of Consumer Health Data We Share
We may share the minimum Consumer Health Data reasonably necessary to provide the service, including uploaded medical-image files, derived models, project identifiers, and related communications, only when needed for the requested product or service, security, legal compliance, or another purpose permitted by law.
A6. Categories of Recipients
Consumer Health Data may be disclosed to the following categories of recipients when necessary and permitted:
-
secure file-transfer, cloud hosting/storage, backup, email, and technology providers that process covered data on our behalf;
-
specialized modeling, fabrication, or finishing contractors needed to complete the requested project, if any;
-
Shopify, payment processors, and fraud/security providers only to the extent ordinary transaction or order metadata associated with the health-related project is processed for checkout, payment, fraud prevention, accounting, or order administration;
-
security, incident-response, legal, insurance, and professional advisers; and
-
government authorities or other recipients when disclosure is required or permitted by applicable law.
We do not intentionally share source Consumer Health Data with data brokers, advertising networks, social-media advertising platforms, or unrelated analytics companies. We do not use Consumer Health Data for targeted advertising. To the extent ordinary Shopify order or transaction metadata associated with a health-related service is treated as Consumer Health Data under applicable law, this policy governs that metadata and we use available data-minimization, consent, and privacy controls as required. We do not have affiliates with which we share Consumer Health Data unless specifically identified in an updated version of this policy.
A7. Consent; Collection; Sharing; Withdrawal
Where applicable law requires consent, we will request a clear affirmative opt-in before collecting Consumer Health Data for a specified purpose, unless the collection is necessary to provide a product or service you requested and the law permits that collection without separate consent. If separate consent is required for sharing, we will request it separately from collection consent.
A request for consent will describe the categories of Consumer Health Data, the purpose, the categories of recipients, and how to withdraw consent. You may withdraw consent for future collection or sharing by emailing CanisAres@CanisAres.com with the subject line "HEALTH DATA REQUEST." Withdrawal does not require us to undo processing that was lawful before withdrawal, but we will stop future consent-based processing as required by law.
A8. Consumer Health Data Rights
Subject to applicable law and verification, you may have the right to:
-
confirm whether we collect, share, or sell Consumer Health Data about you;
-
access Consumer Health Data about you;
-
receive a list of third parties or affiliates with whom covered Consumer Health Data was shared or sold, when required;
-
withdraw consent for future collection or sharing;
-
request deletion of Consumer Health Data, including deletion requests that must be forwarded to processors or other covered recipients; and
-
appeal a refusal to act on a request.
Submit a request to CanisAres@CanisAres.com with the subject line "HEALTH DATA REQUEST." We may request information reasonably necessary to authenticate you or your authorized agent. We will respond within the period required by applicable law and will not unlawfully discriminate against you for exercising a right.
A9. Deletion
When a verified deletion request applies, we will delete covered Consumer Health Data from active systems and notify covered processors, contractors, or other recipients as required by law. Data in archived or backup systems may be deleted on the schedule permitted by applicable law. We may retain limited information when a statutory exception applies, such as security, fraud prevention, legal claims, or other legally permitted purposes.
A10. Security
We restrict access to Consumer Health Data to personnel, processors, and contractors that need access for the purpose for which the data was collected or to provide the requested product or service. We maintain administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and accessibility of Consumer Health Data appropriate to its volume and sensitivity.
A11. Sale of Consumer Health Data
Canis Ares does not sell Consumer Health Data and does not condition the Services on authorizing such a sale. Our current business policy is not to treat Medical Imaging Data, derived health-related project data, or other Consumer Health Data as advertising or data-broker inventory. If a future business model ever contemplated a transaction that applicable law defines as a sale of Consumer Health Data, Canis Ares would first conduct a separate legal review, update this policy, and obtain the separate, valid authorization required by applicable law before any such sale. General Terms acceptance or ordinary privacy acknowledgment is not authorization for a health-data sale.
A12. Geofencing
Canis Ares does not use geofencing around health-care facilities to identify or track people seeking health services, collect Consumer Health Data, or send health-related messages or advertising based on presence at a health-care facility.
A13. Changes and Contact
We will not collect, use, or share additional categories of Consumer Health Data, or use Consumer Health Data for materially different purposes, without updating this policy and obtaining consent where required. Questions and rights requests may be sent to CanisAres@CanisAres.com.
Exhibit B
BIOMETRIC & LIKENESS DATA PRIVACY / RETENTION POLICY
This Exhibit should be separately linkable and its key collection, purpose, consent, disclosure, and retention disclosures should be presented immediately before any face/body scan or approved upload flow that may collect biometric information.
B1. Scope and Definitions
This policy applies when Canis Ares collects or possesses Likeness Data that may constitute biometric information or a biometric identifier under applicable law. Examples include scans of face or hand geometry, facial/body depth data, automatically measured biological characteristics, point clouds, or derived data capable of being associated with an identifiable person. A photograph alone may be treated differently under particular statutes, but photographs and image-derived data remain personal information under this Privacy Notice.
Canis Ares collects this data for customer-requested creative modeling and manufacturing. We do not use it for identity authentication, surveillance, law-enforcement identification, employment decisions, credit, insurance, housing, or eligibility decisions.
B2. Notice and Written Consent
Before a collection subject to a biometric-consent law, Canis Ares will provide notice that biometric information is being collected or stored, describe the specific purpose and expected length of collection/use, and obtain a written or electronic release/consent from the subject or legally authorized representative as required by law. Consent for an in-person scan may be captured on a signed physical or electronic release. Consent for a website upload may be captured using a separate unchecked acceptance control with a stored timestamp and policy version.
Because biometric and uniquely identifying facial/body geometry may be highly sensitive personal information, Canis Ares also seeks meaningful express consent where applicable Canadian privacy law or the circumstances require it. The consent request is intended to identify the nature of the data, the purpose of the creative project, relevant recipients or processing categories, and any materially non-obvious AI processing.
B3. Purposes of Collection and Use
Authorized purposes include conducting the requested scan; producing measurements and geometry needed for the project; generating, sculpting, reconstructing, retopologizing, texturing, editing, and rendering a digital model; producing a physical or digital deliverable; creating proofs; processing a reorder where archival storage was requested; customer support; security; dispute handling; and legal compliance. We do not materially expand these purposes without additional consent when required.
B4. Disclosure and AI Processing
We may disclose biometric or Likeness Data to contractors and service providers that need the data to perform the requested service, subject to applicable consent and restrictions. Source raw face/body geometry is not intended to be submitted through ordinary Shopify storefront, checkout, analytics, advertising, or marketing fields. Shopify may process ordinary account, payment, or transaction metadata associated with an order. For public/general-purpose AI or other expanded processing that may permit provider retention, human review, service improvement, or generalized model training, we seek separate affirmative consent before disclosure of identifiable Likeness Data. We do not disclose biometric data for unrelated advertising, data brokerage, or surveillance.
B5. No Sale or Monetization of Raw Biometric Data
Canis Ares does not sell, lease, trade, or otherwise monetize a person's raw biometric identifier or biometric information where prohibited by law, and our current business policy is not to use raw face/body geometry or comparable biometric data as advertising, data-broker, or unrelated commercial inventory. Fees charged for scanning, modeling, artistic labor, digital deliverables, fabrication, finishing, and physical products compensate Canis Ares for the requested service and work product; they are not intended as a sale of the subject's raw biometric identifier. Any future materially different commercialization proposal would require separate legal review and any new consent or authorization required by law.
B6. Retention and Permanent Destruction
Canis Ares maintains a retention schedule designed to permanently destroy biometric information when the initial purpose for collection has been satisfied or when an applicable statutory deadline requires earlier destruction. As an operational default, raw face/body scan captures and working geometry are targeted for deletion within 90 days after final delivery or cancellation, and identifiable derived models within 180 days unless the subject affirmatively requests lawful archival storage for reorders. Where Illinois BIPA applies, destruction will occur when the initial purpose has been satisfied or within three years of the individual’s last interaction with Canis Ares, whichever occurs first, subject to lawful exceptions. Other state laws may require a shorter period.
B7. Security
Canis Ares will use reasonable care to store, transmit, and protect biometric information and intends to protect it in a manner at least as protective as the manner used for other confidential and sensitive information. Access is limited to people and providers with a business need for the authorized project or a lawful compliance purpose.
B8. Rights; Withdrawal; Deletion Requests
A subject may contact CanisAres@CanisAres.com with the subject line "BIOMETRIC / LIKENESS REQUEST" to request information, withdrawal of consent, or deletion as available under applicable law. Withdrawal is prospective and does not invalidate prior lawful processing. If the subject previously authorized disclosure to a third-party public/general-purpose AI service, Canis Ares will make legally required or reasonably available deletion requests but cannot promise technical retrieval or deletion from every provider system or model after an authorized disclosure.
B9. Changes and Contact
If Canis Ares materially changes the purpose for collecting or using biometric information, it will provide updated notice and obtain additional consent where required. Questions may be sent to CanisAres@CanisAres.com.