Privacy Policy
Last updated: August 2, 2026
1. Introduction
This Privacy Policy describes how 3D Print Quote Calculator ("we", "our", or "the App") collects, uses, discloses, retains, and deletes information when a merchant installs or uses our Shopify application.
2. Information We Process
The App processes the following information:
- Shop and account information: The Shopify store domain and the merchant account details made available during app authentication, plus contact details the merchant enters for support, branding, or quote notifications.
- Configuration data: Pricing, material, printer, branding, currency, delivery, retention, and other preferences configured by the merchant.
- 3D model and quote data: Customer-uploaded STL, OBJ, or 3MF files; file names; dimensions; volume; selected print options; calculated prices; and quote timestamps. A customer email address is stored only when that customer explicitly asks to receive a quote by email.
- Order verification and purchase analytics data: For an order line created by the App, we process the Shopify order identifier and display name, order creation time, the relevant line identifier, title, price, quantity, and App-created line properties needed to locate and verify the originating quote. After a valid purchase, we retain only the order identifier, display name, purchase timestamp, verified amount in EUR, and an analytics provenance marker on the matching quote. We ignore unrelated order lines and do not request Shopify's protected customer name, email, phone, or address fields.
- Service usage data: Quote counts, storage usage, feature usage, plan status, and operational error records required to run and secure the service.
The optional email a customer types into the quote form is collected directly by the App. It does not require or use Shopify's protected customer email field.
3. How We Use Information
- Provide, secure, and support the 3D quote and file-download service.
- Calculate prices, delivery estimates, and available print options.
- Deliver quote emails only when requested and merchant notifications when enabled.
- Link verified purchases to their quotes so merchants can see quote-to-order conversion and verified revenue analytics.
- Compare the signed quote total with the actual line total to exclude invalid or tampered purchases from analytics. Where granted Shopify permissions allow it, a mismatch can be tagged for merchant review.
- Enforce plan limits, diagnose errors, prevent abuse, and improve the service.
- Respond to privacy requests and comply with applicable legal obligations.
The App does not automatically cancel orders and does not use customer data for decisions that produce legal or similarly significant effects.
4. Storage, Security, and Retention
- Transport security: Public app, webhook, and object-storage traffic uses HTTPS/TLS. Shopify webhook signatures are verified before payloads are processed.
- Database: Configuration and quote records are stored in an access-controlled PostgreSQL database on dedicated application infrastructure.
- File storage: Customer files are stored in Cloudflare R2, which encrypts objects at rest. Upload and private download operations use time-limited, signed URLs.
- Uploaded files: Files are retained for the merchant-selected period of 1 to 90 days (30 days by default), then deletion is queued and retried until it succeeds.
- Shareable quotes: Quote-link records, bearer tokens, and any stored customer email are deleted after the merchant-selected validity period of 1 to 90 days (7 days by default). The underlying model follows the separate uploaded-file retention period above so an order file is not removed prematurely.
- Purchase analytics: Order-linked identifiers and verified purchase analytics are retained for no more than 24 months, or until a valid customer deletion request or app uninstall, whichever happens first.
- Access: Production access is limited to authorized personnel who need it for service operation, security, or requested support.
5. Service Providers and Disclosure
We do not sell, rent, or use personal information for advertising. We use the following providers only to deliver and secure the App:
- Hetzner Cloud: Hosts the application, PostgreSQL database, and operational logs.
- Cloudflare R2: Stores 3D model files and related file objects.
- Resend: Receives a customer email address and quote message only when the customer explicitly requests email delivery, or sends merchant notifications when configured. Resend also delivers a minimized customer-data-request report to the Shopify shop owner (with the public shop contact as a fallback) when Shopify sends the App a valid privacy request. The minimized pending request and stable report are held in a retry queue only until delivery, for no more than 30 days. The App then deletes that queued content and retains only a non-personal delivery receipt.
- Frankfurter API: Supplies exchange rates; no personal, quote, order, or shop data is sent to it.
- Legal disclosure: Information may be disclosed when required by law or necessary to protect rights, safety, and service integrity.
Protected order metadata is processed by the application and database hosting infrastructure only. It is not intentionally sent to Resend, Frankfurter, or Cloudflare R2 by the order webhook.
6. Customer Choices and Rights
Depending on applicable law, customers may have rights to access, correct, export, restrict, object to, or delete their information. Requests can be made through the merchant or by contacting us. We support Shopify's mandatory privacy webhooks and apply valid customer consent and deletion instructions to the data the App controls.
For a valid Shopify customer-data request, the App durably queues the minimum customer reference and requested order IDs, creates a minimized report, and uses Resend to deliver it directly to the shop owner's Shopify email, with the public shop contact as a fallback. The queued request and report are deleted after successful delivery or at the end of a 30-day retry window. The App then retains only a non-PII delivery outcome receipt to prevent duplicate delivery when Shopify retries the request.
Because we do not sell customer data, there is no data-sale opt-out process. Quote email delivery is opt-in and occurs only after the customer provides an email address and asks for the message.
7. Uninstall and Deletion
When the final installation for a shop is removed, the App deletes its relational shop data, including settings, sessions, quote history, purchase analytics, billing records, and custom materials. Associated object-storage deletion is placed in a durable queue and retried until completed. Customer-redaction requests remove matching quote-email records and clear stored order identifiers and purchase analytics for the supplied orders.
8. Merchant and Processor Roles
The merchant acts as controller for customer data processed through the App, and Novogroup Systems SRL acts as processor on the merchant's behalf. We process that data only to provide the functions described in this policy and follow documented merchant instructions delivered through Shopify or the App. Merchants are responsible for their own customer notices, lawful basis, and consent obligations.
9. Cookies and Browser Storage
The storefront widget uses limited local browser storage for currency safeguards and quote-session state. We do not use third-party advertising trackers.
10. Policy Changes
We may update this policy as the service or legal requirements change. The current version is published on this page with its effective date.
For privacy questions or data-rights requests, contact Novogroup Systems SRL at contact@novo.ro.