SCOPE & NOTICE

01.1

This Privacy Policy applies to the public-facing Aiurion 3D printing service, including quoting, checkout, account access, order tracking, pickup or delivery coordination, and related customer communications.

01.2

It covers personal information collected directly from you, automatically from your browser or device when you use the site, and from service providers involved in payment, hosting, authentication, security, bot detection, email delivery, and fulfillment, including Cloudflare where used for those purposes.

01.3

This Policy does not govern third-party sites or services that you visit separately, such as Stripe-hosted checkout pages or carrier tracking pages. Those services have their own policies and practices.

PRIVACY_NOTE // AIU-REF-PP01
Material changes will be posted on this page with an updated revision date. Where California law requires additional notice, we will provide it in the manner then required.

INFORMATION WE COLLECT

02.1

Depending on how you use the service, we may collect the following categories of personal information. The examples below are illustrative, not exhaustive.

PAYMENT_NOTE // AIU-REF-PP02
Stripe processes checkout and payment information. We may receive contact, shipping, and payment-status information from Stripe, but we do not store your full payment card number.
CATEGORYEXAMPLESCOLLECTED_LAST_12_MONTHS
IDENTIFIERSName, email address, phone number, shipping address, billing details we receive from checkout, order number, quote ID, IP address, public tracking tokenYES
CALIFORNIA_CUSTOMER_RECORDSContact and fulfillment details associated with an order, including address and telephone informationYES
COMMERCIAL_INFORMATIONUploaded 3D model files, quote details, material selections, quantity, order history, payment status, fulfillment recordsYES
INTERNET_ACTIVITYBrowser type, device information, request metadata, session state, authentication cookies, anonymous first-party analytics events, site interaction data needed to operate the service, and security or bot-detection signals processed when Cloudflare Turnstile is usedYES
SENSITIVE_PERSONAL_INFORMATIONAccount log-in credentials for registered users; we do not store full payment card numbers because payment card data is handled by StripeYES_FOR_REGISTERED_USERS

SOURCES & USES

03.1

We collect personal information directly from you when you upload a file, request a quote, create an account, complete checkout, communicate with us, or receive an order.

03.2

We also collect some information automatically from your browser, device, and request headers to run the site, maintain sessions, prevent abuse, protect the service, and understand whether anonymous business actions such as quote starts, upload completion, material selection, checkout starts, contact clicks, and order completion are working. When you use a quote or upload flow protected by Cloudflare Turnstile, Cloudflare processes technical signals such as IP address, browser and device characteristics, user agent, sitekey and associated origin, and challenge response data needed to distinguish human users from bots and validate the submission. We may also route quote-processing requests, including uploaded model files, through Cloudflare services used to secure internal service-to-service communications. We may receive additional information from Stripe after checkout and from carriers or couriers when fulfillment or tracking updates are available.

03.3

We use personal information to provide quotes, process payments, manufacture and fulfill orders, coordinate pickup or delivery, send receipts and order updates, respond to support requests, maintain account access, prevent fraud and misuse, troubleshoot issues, keep records, and comply with legal, tax, accounting, and regulatory obligations.

03.4

We may also internally analyze uploaded files and related order data, and create or use de-identified, aggregated, transformed, or derived technical data from them, to improve our quoting, manufacturability review, workflow, quality-control, and related internal service systems. We do not sell uploaded customer files or use them for third-party advertising or marketing.

SHARING & DISCLOSURE

04.1

In the preceding 12 months, we have disclosed personal information for business purposes only to service providers, fulfillment providers, and other recipients reasonably necessary to operate the service.

04.2

This includes Cloudflare for Turnstile bot detection and, where used, to secure quote-processing requests between our services.

SECURITY_NOTE // AIU-REF-PP03
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not disclose personal information to third parties for their own direct marketing.
CATEGORYDISCLOSED BUSINESS PURPOSEDATA SOLD OR SHARED?
IDENTIFIERSStripe, Supabase, Cloudflare, Resend, carriers or couriers, and advisors or authorities where legally requiredNO
CALIFORNIA_CUSTOMER_RECORDSStripe, Supabase, carriers or couriers, and advisors or authorities where legally requiredNO
COMMERCIAL_INFORMATIONStripe, Supabase, Cloudflare where used to secure quote-processing requests, Resend, carriers or couriers, and advisors or authorities where legally requiredNO
INTERNET_ACTIVITYCloudflare, Supabase, and technical providers that help us host, authenticate, secure, detect abuse, or maintain the serviceNO
SENSITIVE_PERSONAL_INFORMATIONSupabase authentication and related technical providers only as needed to provide and secure accountsNO

COOKIES, TRACKING & CALOPPA

05.1

We use cookies and similar technologies mainly for site functionality, authentication, session management, security, fraud prevention, anti-bot verification, and limited first-party business action analytics. We do not use third-party ad-tech, third-party analytics trackers, or cross-site behavioral advertising tools on the public 3D printing service. Cloudflare Turnstile, where enabled, is used for security and bot detection rather than advertising or cross-site behavioral profiling.

05.2

When Cloudflare Turnstile is loaded or executed, Cloudflare may process technical signals from your browser or device, such as IP address, TLS fingerprint, user-agent data, sitekey and associated origin, and related challenge data, to run the challenge and help distinguish humans from bots. See the Cloudflare Turnstile Privacy Addendum and Cloudflare Privacy Policy for more information about Cloudflare's processing.

05.3

Our first-party business action analytics use a random anonymous session ID stored in sessionStorage, not a tracking cookie. Analytics events do not intentionally include uploaded file names, customer notes, email addresses, phone numbers, shipping addresses, Stripe session IDs, quote IDs, order IDs, IP addresses, or free-text form content.

05.4

Because we do not track consumers' online activities over time and across third-party websites for advertising purposes, we do not currently change our public-site behavior in response to browser Do Not Track signals.

05.5

We do not knowingly allow other parties to collect personal information about your online activities over time and across different websites through the public 3D printing service for advertising purposes. If you leave our site for Stripe-hosted checkout or a carrier tracking page, that separate service's own privacy policy applies.

TRACKING_NOTE // AIU-REF-PP05
If we send you a public order-tracking link, anyone with that link may be able to view limited order information associated with that token, including status, file name, price, and fulfillment details. Treat the link like confidential order information.

CALIFORNIA PRIVACY RIGHTS

06.1

California's Online Privacy Protection Act (CalOPPA) requires us to post a conspicuous privacy policy describing the categories of information we collect, the categories of third parties with whom we share it, how we handle changes to this policy, the policy's effective date, and our treatment of Do Not Track signals. This Policy is intended to satisfy those requirements.

06.2

Aiurion does not currently qualify as a "business" subject to the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA) because Aiurion does not meet the statutory applicability thresholds. If our legal obligations change, we will update this Policy and our privacy practices accordingly.

06.3

Even though CCPA/CPRA does not currently apply to Aiurion, we still do not sell personal information, we do not share personal information for cross-context behavioral advertising, and we do not use or disclose sensitive personal information in a way that would require a separate California limitation right for this public 3D printing service.

  • A) You may still contact us to request access to, correction of, or deletion of personal information we hold about you, subject to legal exceptions and operational limitations;
  • B) We may take reasonable steps to verify your identity before acting on a request;
  • C) We will review requests in good faith and respond within a commercially reasonable time; and
  • D) If Aiurion later becomes subject to CCPA/CPRA, we will update this Policy to describe any additional California rights that then apply.
  • ACCESS_NOTE // AIU-REF-PP06
    To submit a privacy request, email privacy@aiurion.com. Please include enough information for us to identify your order or account and describe your request.

    RETENTION, SECURITY & CONTACT

    07.1

    We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including quoting, fulfillment, customer support, recordkeeping, fraud prevention, dispute resolution, and compliance with legal, tax, accounting, and regulatory obligations. Different categories of data may be retained for different periods depending on those needs.

    07.2

    We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

    07.3

    Our service is intended for adults. We do not knowingly collect personal information from children under 13, and if we learn that we have done so, we will take reasonable steps to delete it.

    CONTACT_NOTE // AIU-REF-PP07
    Questions about this Policy can be sent to privacy@aiurion.com. General business contact information is also available on our Contact page.