Effective date: June 15, 2026
Last updated: July 10, 2026
This Privacy Policy explains what personal information TurboSync Pro collects, how
we use it, and the choices you have. It applies to the TurboSync Pro web
application at turbosyncpro.com, the TurboSync Pro Media Station companion
desktop application, and any related services we provide (together, the
“Service”).
1. Who we are
The Service is operated by Larimax, a Maryland limited liability company
(“Larimax”, “TurboSync Pro”, “we”, “us”, or “our”). You can reach us at
support@larimax.ai for any privacy question or request described in this
policy.
TurboSync Pro is a business-to-business software service for worship, media, and
production teams. It connects your team’s Canva account to your ProPresenter
presentation system so that designs created in Canva can be prepared and
delivered to your ProPresenter computers automatically, on the schedule your team
chooses.
2. Scope
This policy covers personal information we collect when you create an account,
use the TurboSync Pro web app, connect your Canva account, install or use the
TurboSync Pro Media Station, or contact us for support. It does not apply to
third-party services you choose to connect (for example, Canva or ProPresenter),
which are governed by their own privacy notices.
3. Information we collect
We collect only the information we need to provide the Service. We do not
collect special-category personal data, government identifiers, precise
geolocation, or biometric data.
3.1 Account and identity data (collected through Clerk)
We use Clerk as our identity provider. When you sign up or sign in, Clerk
collects on our behalf:
- Your name and primary email address.
- A hashed password if you choose email/password sign-in, or the provider
identifier if you sign in with a third-party account (such as Google). - Your team or organization membership and role within TurboSync Pro
(administrator, member, invitee). - Sign-in metadata such as timestamps, IP address, browser, and device used for
security and abuse prevention. - An optional profile image, if you provide one.
Clerk stores authentication credentials and session tokens on its infrastructure.
TurboSync Pro receives identifiers, your email, and team membership through the
Clerk API.
3.2 Canva connection data
After you click “Connect Canva” in TurboSync Pro and authorize our app, we
receive an OAuth access token and refresh token through the Canva Connect
API. These tokens are stored, encrypted, and automatically refreshed by Clerk
as part of the External Accounts feature. The tokens are held server-side only
and are never exposed to your browser.
We request read-only Canva permissions (design:meta:read and
design:content:read). We never create, modify, delete, share, or publish
anything in your Canva account.
Using those tokens, we read:
- Design metadata: design ID, title, thumbnail URL, page count, owner, and
last-modified timestamp for designs in the connected Canva account. - Per-page image exports of a design, generated on demand through Canva’s
Exports API only when you or your team’s auto-sync schedule asks us to deliver
that design to a Media Station.
Those per-page image exports are streamed to the TurboSync Pro Media Station
running on your own computer and are written to local storage on that computer.
Larimax does not retain the rasterized image assets on our servers. Only the
metadata necessary to track sync activity (such as the design ID and the time of
delivery) is stored in our database.
3.3 Team, configuration, and operational data
To run the Service we also store, in our application database:
- Records of the Media Stations your team has linked, including a
customer-supplied label (for example, “Main Hall” or “Multi-use Room”) and a
unique identifier for each Media Station. - Your team’s auto-sync schedule and related preferences.
- Sync activity records — which design was sent to which Media Station, the
outcome (success, failure, retry), and timestamps — used to power the activity
feed in your dashboard and to troubleshoot problems. - App preferences such as theme.
- Application logs and error reports that contain identifiers for the
user/organization, the operation attempted, and any error returned by Canva,
Supabase, Ably (real-time messaging), or the Media Station.
3.4 Billing data
If your team subscribes to a paid plan, payments are processed by Stripe, Inc.
You provide your payment details directly to Stripe, and Stripe shares with us
limited information needed to manage the subscription: a customer identifier,
the plan and seat count, subscription status, billing email, country, and the
last four digits and brand of your card. TurboSync Pro never sees or stores
full payment card numbers, CVV codes, or bank account credentials.
Payment card data is stored and processed exclusively by Stripe, a PCI
DSS–compliant payment processor. TurboSync Pro does not store payment card data
on its servers; we retain only billing and transaction records (such as amount,
date, customer identifier, and card last four digits) for accounting and
tax-record purposes, as described in Section 8.
3.5 Support communications
When you contact us for support, we receive whatever information you choose to
send (such as your email address, message contents, and any screenshots or
diagnostic information you attach), and we retain that correspondence to follow
up and improve the Service.
3.6 Cookies and similar technologies
TurboSync Pro uses a small number of strictly necessary cookies and similar
browser-storage mechanisms:
- A session cookie set by Clerk to keep you signed in.
- A preference cookie that remembers your selected color theme.
- Short-lived tokens issued by Ably for real-time messaging.
We do not use advertising cookies or third-party analytics that profile
individual visitors across other websites.
4. How we use your information
We use the information described above to:
- Create and secure your account and verify your team membership.
- Display your Canva designs in the TurboSync Pro dashboard.
- Detect new and updated Canva designs and deliver the rasterized images to the
Media Stations your team has linked, on the schedule you choose. - Operate, maintain, debug, and improve the Service.
- Provide customer support and respond to your requests.
- Send service-related communications (account, security, billing, and material
changes to the Service or this policy). We do not send marketing emails
without your separate opt-in. - Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with our legal obligations and enforce our Terms of Service.
We do not sell your personal information, share it with advertising networks,
or use your Canva designs or metadata to train machine-learning models.
5. Legal bases (EEA, UK, and Swiss users)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we
process your personal data on the following legal bases:
- Performance of a contract — to provide the Service to you and your team.
- Legitimate interests — to keep the Service secure, prevent abuse, debug
issues, and improve the product, where those interests are not overridden by
your rights. - Consent — for any processing that requires consent (such as connecting
your Canva account, which you authorize through the Canva OAuth screen). You
can withdraw consent at any time by disconnecting Canva or deleting your
account. - Legal obligation — to meet record-keeping, tax, and similar legal
requirements.
6. Service providers and sub-processors
We share personal information only with service providers that help us run the
Service, under contracts that require them to protect that information. As of
the effective date above, our sub-processors are:
| Provider | Role | What they process |
|---|---|---|
| Clerk, Inc. | Authentication and OAuth token storage | Account credentials, profile data, Canva access/refresh tokens, session data |
| Supabase, Inc. | Application database and storage (PostgreSQL) | Team records, Media Station registrations, sync activity, app preferences |
| Ably (real-time messaging) | Real-time messaging between the web app and your Media Station | Short-lived auth tokens, channel messages (design IDs, status updates) |
| Stripe, Inc. | Subscription billing and payment processing | Billing contact, plan/seat data, card brand and last four digits |
| Canva Pty Ltd. | Source of your designs, accessed under the permissions you grant | Design metadata and on-demand rasterized exports |
| Hostinger International Ltd. | Web hosting for the turbosyncpro.com app | Web requests and server logs |
We will update this list when our sub-processors change. We may also share
information when required by law, to protect our rights, or in connection with a
merger, acquisition, or asset sale, in which case we will notify you of the
change in controller.
7. International data transfers
We are based in the United States. Some of our service providers process data
in the United States, the European Economic Area, the United Kingdom, Canada,
and Australia. When personal data is transferred out of your country, we rely
on appropriate safeguards such as the European Commission’s Standard
Contractual Clauses, the UK International Data Transfer Addendum, and the
equivalent commitments offered by each sub-processor.
8. Data retention
We keep personal information only as long as we need it for the purposes
described in this policy.
- Account and team data — retained for as long as your account or your team
account is active. We delete it within 30 days of account deletion, subject to
short backup-retention windows at our sub-processors. - Canva OAuth tokens — revoked at Canva and deleted from Clerk immediately
when you disconnect Canva or delete your account. - Rasterized image assets — never stored on our servers; they live on your
Media Station computer and are managed by you. - Cached Canva design metadata (design ID, title, thumbnail URL, page count,
timestamps, and cached design listings) — while your Canva account is connected,
individual entries are removed during reconciliation when the corresponding design
is deleted or is no longer accessible in Canva. When you disconnect Canva, delete
your account, or ask us to delete your data, we delete your cached Canva design
metadata within 30 days, using the deletion process described in Section 10. - Sync activity records — retained for up to 12 months for troubleshooting
and security review, then deleted or aggregated. - Billing records — retained for as long as required by applicable tax and
accounting law (typically 7 years in the United States). - Support correspondence — retained for up to 24 months after the issue is
resolved.
9. Security
We design the Service so that the most sensitive credentials — your Canva OAuth
tokens — are stored only by Clerk, on Clerk’s secure infrastructure, and are
fetched server-side immediately before each Canva API call. They are never
delivered to your browser. All data in transit between you, our servers, and
our sub-processors is encrypted with HTTPS/TLS. Database access in Supabase is
enforced with row-level security, so each user can read only their own
organization’s data. We require multi-factor authentication for administrative
access to our infrastructure and follow industry-standard practices for
operating a SaaS application.
No service can promise perfect security. If we ever experience a personal-data
breach that affects you, we will notify you and the relevant authorities as
required by law.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your personal information.
- Receive a portable copy of information you provided to us.
- Restrict or object to certain processing.
- Withdraw a consent you previously gave.
- Lodge a complaint with your local data protection authority.
If you are a California resident, you have the rights described in the
California Consumer Privacy Act, including the rights to know, delete, correct,
and to opt out of “sales” or “sharing” of personal information. TurboSync Pro
does not sell or share personal information for cross-context behavioral
advertising.
You can exercise most of these rights directly in the app — for example, by
disconnecting Canva from the Settings page or by deleting your account — or by
emailing us at support@larimax.ai. To request deletion of the Canva
data we hold about you, disconnect Canva in the app or email
support@larimax.ai; we will revoke the associated Canva token and
delete your cached Canva design metadata within 30 days. We will respond to other
requests within the time required by applicable law (typically 30 days). We will not
discriminate against you for exercising these rights.
11. Children
TurboSync Pro is a business tool for media teams and is not directed to
children under 16. We do not knowingly collect personal information from
children. If you believe a child has provided us with personal information,
please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. If we make a material change, we
will update the “Last updated” date at the top, notify account administrators
by email, and post a notice in the app before the change takes effect. The
current version is always available at
https://turbosyncpro.com/privacy.
13. Contact us
For any privacy question, to exercise a right described above, or to report a
concern, contact us at:
Larimax, LLC
Attn: Privacy
Email: support@larimax.ai
TurboSync Pro is an independent product. It is not endorsed by, affiliated
with, or sponsored by Canva Pty Ltd. or Renewed Vision, LLC.
