Privacy Policy
This Privacy Policy explains how Key3D Fabrication, LLC ("Key3D," "we," "us") collects, uses, discloses, and protects personal information through key3-d.com, client.key3-d.com, our quote and client-portal workflows, and related services (together, the "Services").
1. Information We Collect
- Contact and account information: name, company, email address, phone number, portal role, account status, and authentication-related identifiers. Firebase Authentication manages sign-in credentials. Key3D does not retain plaintext passwords; our server receives a proposed password transiently when it validates invite acceptance, first-login changes, or breach screening.
- Quote and project information: requested service, product and material selections, quantity, timeline, part description, customization notes, reference filenames, secure file-sharing links, quote status, and communications about the project.
- Customer Content: CAD, mesh, model, drawing, image, specification, and related files that an authenticated customer uploads, plus technical metadata such as filename, type, size, storage path, upload time, uploader identifier, object generation, and integrity hash.
- Order, billing, and shipping information: items, engraving instructions, prices, invoices, returns, shipping addresses, carrier and tracking details, and order history.
- Payment information: Stripe collects payment credentials directly through Stripe-hosted fields. We receive and retain limited transaction information such as a PaymentIntent identifier, amount, currency, status, timestamps, receipt email, fraud or verification outcome, and masked card details when available. We do not receive or store full payment-card numbers or card security codes.
- Communications: quote-verification and account emails, support messages, portal messages, proof decisions, return requests, and other communications you send to us.
- Device, network, and security information: IP address, request time, browser and device information, authentication events, service logs, and anti-abuse signals. If you consent and a valid Google Analytics property is configured, we also collect analytics information described in Section 7.
2. Quote Verification and Portal Account Creation
There is no open public portal signup. A public quote request is first staged in a server-only Firestore collection outside every customer organization, and we confirm it by email. When our team prices the request, the quote email brings the quote document and a one-time portal password issued to the submitted email address; on first sign-in you set your own password and affirmatively accept the Website Terms and this Privacy Policy. Only the recipient of that email can create the account. A staged quote request that is not released is scheduled for deletion after seven days. After release, the staging record keeps a non-secret receipt, its active token verifier is erased, and the record is scheduled for deletion within 30 days. The one-time portal password is delivered once by email, is not stored in plain text after issuance, and must be replaced by your own password at first sign-in. Portal-access invitations expire after seven days.
The public quote form does not upload CAD file bytes. It may collect a reference filename or an HTTPS sharing link. Actual CAD files are uploaded only through the authenticated portal to private, organization-scoped Cloud Storage.
3. How and Why We Use Information
We use information to respond to inquiries; verify ownership of quote requests; create and secure portal accounts; prepare and manage quotes; evaluate manufacturability; provide proofs; fabricate, fulfill, ship, and support orders; process authorizations, payments, refunds, and returns; communicate service and security notices; enforce our terms; prevent fraud and abuse; maintain records; comply with legal, accounting, and tax duties; and improve the Services.
Where applicable, we rely on steps requested before entering a contract, performance of a contract, compliance with law, our legitimate interests in operating and securing the Services, and consent for optional analytics or other uses for which consent is required.
4. Service Providers and Other Disclosures
We disclose information only as reasonably necessary for the purposes above, including to service providers operating under their own terms and data-protection obligations:
We may also disclose information when required by law; to investigate fraud or protect customers, Key3D, or others; to enforce agreements; or as part of a merger, financing, reorganization, or sale of the business. We do not sell personal information, share it for cross-context behavioral advertising, or use proprietary Customer Content to make parts for another customer.
5. Payments and Password Security
Stripe-hosted payment fields keep full card data off Key3D systems. Key3D stores only the limited transaction and masked display information described above. Firebase Authentication manages credentials and authentication tokens. In addition to Firebase password controls, passwords set through Key3D invitation and first-login change workflows are screened through HIBP's k-anonymous range API. Key3D receives the proposed password over an encrypted connection long enough to hash and compare it, but does not retain it or transmit it to HIBP.
6. Retention and Security
We keep each class of record only as long as it is needed for the purpose it was collected for, then delete or de-identify it. The schedule below states what we hold and for how long.
- Staged quote requests, not released: deleted after 7 days.
- Staged quote requests, released: a non-secret receipt is kept 30 days to reconcile the release, then deleted.
- Transactional email records: message bodies are scrubbed after confirmed delivery and the rows are deleted within 8 days.
- Saved quotes: 14-day commercial validity. The record is kept as a business record with the order it produced, or 24 months after expiry if it is never accepted, to support reorders and disputes.
- Orders, invoices, ledger, and payment metadata: 7 years after the transaction, to meet tax and accounting minimums. We never hold full card numbers or card security codes.
- CAD source files and previews: kept while the part is a saved part in your portal; otherwise deleted 90 days after delivery, or on request. This supports reorders and the 60-day guarantee.
- Support messages: kept with the order they concern; standalone threads 24 months.
- Portal accounts: for the life of the organization's account. On closure, personal identifiers are de-identified within 30 days, except where a record above must still be kept.
- Staff audit records: two-person money approvals 400 days; audit rows 3 years, for security and dispute defense.
- Rate-limit and security counters: 24 hours after the window closes.
Backups roll off within 35 days. Legal holds suspend deletion. Where a record must be kept, we de-identify personal data that is not needed for the retained purpose.
Safeguards include encryption in transit, access controls, verified identities, organization-scoped authorization, private file storage, limited staff access, security logging, one-time credentials, and service-provider controls. No transmission, system, or storage method can be guaranteed completely secure. Do not send classified, export-controlled, or unusually sensitive regulated information unless Key3D has first agreed in writing to an appropriate handling process.
7. Cookies, Local Storage, and Analytics Choices
We use first-party cookies and browser storage that are necessary to remember privacy choices, retain a quote cart, prevent accidental duplicate submissions, preserve local notification preferences, maintain Firebase authentication, secure sessions, and support Stripe fraud prevention and payment functionality. A consent choice remains stored until you change it, clear browser data, or a material policy or consent-version change requires a new choice.
Google Analytics remains off unless you select Accept analytics and a valid analytics property is configured. Selecting Reject is stored just like acceptance and does not affect access to the Services. We treat an enabled Global Privacy Control signal as a refusal. You can revisit the dialog through the site's Privacy choices control or clear browser storage. Blocking necessary storage may prevent the portal, checkout, or preference controls from working correctly. We do not use advertising, marketing, or cross-site tracking cookies.
8. International Processing
Key3D is based in Colorado, United States, and the Services and providers above may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we and our providers rely on recognized transfer mechanisms such as Standard Contractual Clauses and apply supplementary safeguards appropriate to the information and service.
9. Your Privacy Rights and Choices
Depending on your location and applicable law, you may request access to, correction of, deletion of, or a portable copy of personal information; withdraw consent; object to or restrict certain processing; opt out of targeted advertising, sale, or sharing; or appeal our response. We do not sell personal information or use it for targeted advertising, and we will not discriminate against you for exercising a privacy right. Authorized agents may submit requests where permitted by law.
Email contact@key3-d.com with the subject Privacy Request. Describe the request and the email or account involved. We will verify identity and authority before disclosing or deleting information and respond within the period required by applicable law. Some records may be retained where needed to complete a transaction, protect security, exercise legal rights, or meet legal obligations. You may appeal a denied request by replying with the subject Privacy Appeal. Residents outside the United States may also complain to their local data-protection authority.
10. Children, Changes, and Contact
The Services are intended for business users and are not directed to children under 16. We do not knowingly collect personal information from children under 16. We may update this Policy and will post the revised version and effective date; material changes may also be presented in the Services or by email. Questions or privacy requests: contact@key3-d.com, Key3D Fabrication, LLC, Front Range, Colorado, United States.