3D SCAN GARAGE

Legal

Privacy Policy.

Last updated: draft, not yet published — see note below.

This is a working draft, not a reviewed legal document. It hasn’t been checked by a lawyer. The legal entity name, address, and contact details below are placeholders — fill them in and get this reviewed (especially the data-transfer and rights sections, for GDPR compliance) before real users rely on it.

1. What we collect

Account data — your email, the username (handle) you chose, your display name (which is private — never shown publicly, only your handle is), optional bio and country.

Content you provide — scan files and metadata you upload as a seller, bounty descriptions and reference photos, profile fields, and any support messages.

Transaction data — what you bought, for how much, and its status. We do not receive or store your card details at all; those go directly to our payment processor.

Usage data — basic technical data needed to operate the Service securely (e.g. IP address and user agent recorded against a file download, for abuse prevention).

2. How we use it

To operate the marketplace (show you the catalog, let you buy and sell, run the bounty board), review and verify listings, process payments, prevent fraud and abuse, respond to support requests, and improve the Service. We don’t sell your personal data, and we don’t use it for third-party advertising.

3. Who we share it with

Supabase — our database, authentication, and file storage infrastructure. Effectively all account and content data passes through it, protected by row-level security policies scoped to exactly who’s allowed to see each piece of data.

Our payment processor — handles checkout and acts as merchant of record for purchases, including any tax obligations on the sale. It receives your payment details and the email/ amount needed to complete an order; we only receive confirmation that an order was placed and paid.

We don’t share your data with anyone else except where required by law, or with your explicit consent.

4. Cookies

We use a session cookie to keep you signed in. That’s it — no third-party advertising or analytics cookies at this time.

5. How long we keep it

We keep your account data while your account is active, and for a reasonable period after deletion where needed for legal, tax, or fraud-prevention reasons (e.g. order records).

6. Your rights

You can access and correct most of your own data directly from your account settings, including deleting your account yourself — a “Danger zone” on that page removes your profile information immediately. Order and listing records aren’t deleted along with it: we keep them for the legal, tax, and fraud-prevention reasons described in Section 5, but they no longer show who you were. For anything that isn’t self-service — a copy of your data, or restricting/objecting to certain processing — contact us (Section 10).

7. Security

Data in transit is encrypted (HTTPS). Access to your data is enforced at the database level with row-level security — a policy on each table, not just a check in application code — meaning even a bug in our own frontend can’t normally expose data you shouldn’t see. No system is perfectly secure, but this is a real, structural control, not just a claim.

8. International transfers

Our infrastructure and payment providers may process data outside your own country. Where that involves transferring data out of the EU/EEA, we rely on the safeguards those providers offer (e.g. standard contractual clauses).

9. Children

The Service isn’t intended for anyone under 18, and we don’t knowingly collect data from minors.

10. Changes & contact

We may update this policy as the Service changes; material changes will update the date at the top of this page. [Placeholder — add a real privacy/support contact address before launch.]