3DRenderingAgency

Legal

Privacy Policy

This policy explains what personal data 3DRenderingAgency collects when you visit our website, request a quote, use your client account or buy our services, and the rights you have over it. It applies to visitors and clients worldwide.

Last updated

1. Who we are and how to contact us

This Privacy Policy explains how 3DRenderingAgency (also "3DRA", "we", "us" or "our") collects, uses, shares and protects personal data when you visit 3drenderingagency.com (the "Website"), request a quote, use your client account at account.3drenderingagency.com (the "Client Account"), or buy our 3D rendering, visualization and related services (the "Services").

3DRenderingAgency is registered in the United States and is the data controller for the personal data described in this policy. That means we decide why and how that data is processed and we are responsible for it under applicable data protection law.

  • Company: 3DRenderingAgency (3DRA)
  • Mailing address: 132 Christiana Mall, Newark, DE 19702, United States. This is a mailing address only; our team works remotely.
  • Email: sales@3drenderingagency.com. For anything relating to your personal data, please use the subject line "Privacy request" so that your message reaches the right person promptly.

You can also reach us through our contact page. This policy should be read together with our Terms of Service, our Refund & Revisions Policy and our Cookie & Tracking Policy.

1.1 Definitions

  • "Personal data" means any information that identifies, or can reasonably be linked to, an individual person.
  • "Processing" means anything done with personal data, such as collecting, storing, using, sharing or deleting it.
  • "Processor" means a service provider that processes personal data on our behalf and under our instructions.
  • "GDPR" means the EU General Data Protection Regulation, and "UK GDPR" means the version of it that applies in the United Kingdom together with the UK Data Protection Act 2018.
  • "EEA" means the European Economic Area.

2. What we collect, by source

We collect only the personal data we need to answer quote requests, deliver the Services, run the Client Account, take payment and keep basic statistics about the Website. We group it below by where it comes from.

2.1 Quote form on /quote/

When you use our quote form, we collect:

  • the service you are interested in;
  • your project description and any details you choose to include in it;
  • your deadline;
  • the page you came from to reach the form, the first page of your visit, and the referrer (the site that sent you to us, if your browser reports one);
  • campaign tags attached to the link you followed, namely UTM parameters and the Google Ads click identifier (gclid).

If you start a quote and do not claim it by creating or signing in to a Client Account, the unclaimed draft is deleted after 7 days.

2.2 Client Account

When you create or use a Client Account at account.3drenderingagency.com, we collect:

  • your name and email address;
  • your phone number, if you choose to give it (this is optional);
  • your company name;
  • files you upload, such as drawings, 3D models, photographs and reference material;
  • messages exchanged with our team through the account;
  • your order history, including quotes, orders, deliverables and revision requests.

Uploaded files are stored on Cloudflare R2 in a private storage bucket. Files you upload may themselves contain personal data, for example photographs of people or property, or names on drawings. You are responsible for having the right to share that material with us, as set out in our Terms of Service.

2.3 Payments

Card payments are processed by Stripe. You enter your card details directly with Stripe, and we never see or store your full card number. From Stripe we receive the payment status, the last 4 digits of the card and the card brand, which we keep with your order record.

2.4 Email

We send transactional email, such as quote notifications, account messages and order updates, through our email provider Resend. In doing so we process your email address, the content of the message and delivery information (for example whether a message was delivered). We do not send marketing email without your consent.

2.5 Website visits

We use a cookieless visit counter to understand how the Website is used. For each page view it records:

  • the page path and page title;
  • the referrer;
  • campaign tags (UTM parameters and gclid);
  • your country and region, derived from your IP address at the time of the visit;
  • your device type and browser.

Your IP address is not stored. To tell visits apart for one day only, the counter creates a salted hash from your IP address, your browser string and the date. The salt changes daily, and the hash cannot be reversed to reveal your IP address or identify you, and cannot be used to link your visits across different days. Visit records are kept for up to 24 months.

2.6 Browser storage

The Website stores a small amount of information in your own browser:

  • in sessionStorage: the first page of your visit, the referrer and any UTM tags, so that if you request a quote we can see how your visit began. sessionStorage is cleared when you close the tab;
  • in localStorage: your consent choice, kept for 12 months;
  • in the Client Account area only: a strictly necessary session cookie that keeps you signed in.

Our Website does not set cookies for tracking or advertising. Full details, including how consent works in different regions, are in our Cookie & Tracking Policy.

3. How we use personal data and our lawful bases

We use personal data only for the purposes below. Where the GDPR or UK GDPR applies, each use relies on one of the following lawful bases.

Purposes and lawful bases
PurposeData usedLawful basis
Preparing and sending quotesQuote form data, contact detailsContract (steps taken at your request before entering into a contract)
Creating and running your Client AccountAccount details, messages, uploaded filesContract
Carrying out orders, delivering files and handling revisionsAccount details, uploaded files, order history, messagesContract
Taking paymentPayment status, last 4 digits, card brandContract
Sending transactional emailEmail address, message contentContract
Keeping the Website, Client Account and files secure, and preventing fraudTechnical and account dataLegitimate interests
Basic visit statistics for visitors outside the EEA, the UK and SwitzerlandVisit counter data, browser storageLegitimate interests
Visit counting and browser storage for visitors in the EEA, the UK and SwitzerlandVisit counter data, browser storageConsent
Marketing email, if anyEmail addressConsent
Keeping tax and accounting recordsOrder and payment recordsLegal obligation (kept 7 years)

Where we rely on legitimate interests, our interests are keeping our systems and clients' files safe, preventing fraud, and understanding in general terms how visitors find and use the Website so that we can improve it. We have balanced these interests against your rights and consider that the limited, non-identifying data involved does not override them. You may object to this processing as described in section 7.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before you withdrew it.

We do not use personal data for automated decision-making that produces legal or similarly significant effects on you, and we do not build advertising profiles.

3.1 Client files and AI

We use the files you upload only to carry out your project. Client files are not used to train AI models. Our approach to AI is described in our Terms of Service.

4. Sharing and processors

We share personal data only with the processors listed below, who help us run the Website, the Client Account and the Services. Each processes data on our instructions and under a written agreement that requires it to protect the data.

Our processors
ProcessorRoleWhere
CloudflareHosting, content delivery network (CDN), security, file storage (R2) and visit counter infrastructureUnited States and Cloudflare's global network
SupabaseDatabase, hosted in its US regionUnited States
StripeCard payment processingAs described in Stripe's own privacy policy
ResendTransactional email deliveryUnited States

Stripe processes card details as an independent provider of payment services under its own terms and privacy policy, which apply when you enter your card details on its checkout.

We may also disclose personal data where we are required to do so by law, to respond to valid legal process, or to establish, exercise or defend legal claims, and to a successor in the event of a merger, acquisition or sale of all or part of our business, subject to this policy.

We do not sell personal data, and we do not share it for cross-context behavioral advertising.

5. International transfers

We are a United States business, and personal data is processed in the United States. Some processors may also process data elsewhere within their networks.

Where personal data of people in the EEA, the UK or Switzerland is transferred to the United States or another country that has not been recognized as providing adequate protection, we rely on:

  • the EU Standard Contractual Clauses approved by the European Commission;
  • the UK International Data Transfer Addendum to those clauses, for data from the UK;
  • the safeguards that our processors themselves put in place; and
  • the EU-US Data Privacy Framework, where a processor is certified under it.

You may ask us for more information about these safeguards by writing to us as described in section 8.

6. Retention

We keep personal data only for as long as we need it for the purposes in section 3, and then delete it or make it anonymous.

How long we keep data
DataKept for
Unclaimed quote drafts7 days
Client Accounts and ordersWhile the account is active, then 7 years for tax and accounting purposes
Uploaded project files12 months after final delivery, unless you ask us to delete them sooner or to keep them longer
Visit recordsUp to 24 months
Email logsAs kept by Resend
Consent choice (in your browser)12 months
Visit start data in sessionStorage (in your browser)Until you close the tab

Where a legal claim or investigation is pending, we may keep relevant data for longer until it is resolved.

7. Your rights

7.1 Under the GDPR and UK GDPR

If you are in the EEA, the UK or Switzerland, or the GDPR or UK GDPR otherwise applies to our processing of your data, you have the right to:

  • access: obtain confirmation of whether we process your personal data and a copy of it;
  • rectification: have inaccurate data corrected and incomplete data completed;
  • erasure: have your data deleted in the circumstances set out in the law;
  • restriction: ask us to limit how we use your data while a concern is resolved;
  • portability: receive data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller;
  • objection: object to processing based on legitimate interests, and to any direct marketing at any time;
  • withdraw consent: withdraw any consent you have given, at any time;
  • complain: lodge a complaint with a supervisory authority, in particular in the country where you live or work or where an alleged breach occurred. We would welcome the chance to address your concern first.

7.2 Under US state privacy laws

If you are a resident of California or of another US state with a comprehensive privacy law, and that law applies to us, you have the right to:

  • know: request the categories and specific pieces of personal data we have collected about you, the sources, the purposes and the categories of recipients;
  • delete: request deletion of personal data we hold about you, subject to legal exceptions;
  • correct: request correction of inaccurate personal data;
  • opt out of sale or sharing: we do not sell personal data or share it for cross-context behavioral advertising, so there is nothing to opt out of, but you may still contact us about it;
  • non-discrimination: we will not deny you services, charge you a different price or provide a different quality of service because you exercised any of these rights.

Under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the categories of personal data we collect are identifiers (such as name, email and phone), commercial information (such as order history), internet or other electronic activity information (such as pages viewed, referrer and campaign tags), approximate geolocation (country and region) and the content of files and messages you send us. The sources, purposes, recipients and retention periods are set out in sections 2 to 6. We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit.

8. How to exercise your rights

  1. Email sales@3drenderingagency.com with the subject line "Privacy request".
  2. Tell us which right you wish to exercise and give enough detail for us to find the relevant data, such as the email address on your Client Account.
  3. We may need to verify your identity before acting on the request, for example by asking you to confirm the request from the email address we hold or to provide further information. We use any information given for verification only for that purpose.
  4. We will answer within one month where the GDPR or UK GDPR applies, or within 45 days under the CCPA. Where the law allows, we may extend this period if a request is complex or we receive many requests, and we will tell you if we do.

You may use an authorized agent to make a request on your behalf where your local law allows it. We may ask the agent for proof of authorization and may ask you to confirm your identity directly.

Requests are free of charge. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline it, as the law allows, and will explain why.

You can change your consent choice for visit counting and browser storage at any time with the "Privacy choices" link in the Website footer. See our Cookie & Tracking Policy.

9. Security

We use technical and organizational measures appropriate to the data we hold, including:

  • encryption in transit: the Website and Client Account are served only over HTTPS;
  • limited access: access to personal data and client files is restricted to our team members who need it to do their work;
  • private storage: uploaded files are kept in a private storage bucket that is not publicly accessible;
  • payment security: card details are handled by Stripe, and we never see or store full card numbers.

No method of transmission or storage is completely secure. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities where the law requires us to.

10. Children

The Website and Services are intended for businesses and adults and are not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has given us personal data, please contact us and we will delete it.

11. Changes to this policy

We may update this policy from time to time. When we do, we will post the new version on this page with a new "updated" date. If we make a material change, we will also email account holders at the address on their Client Account before or when the change takes effect.

Questions about this policy can be sent to sales@3drenderingagency.com with the subject line "Privacy request", or through our contact page.