Privacy Policy

Key3D Fabrication, LLC · key3-d.com
Effective August 22, 2026 · Version 2026-08-22

This Privacy Policy explains how Key3D Fabrication, LLC ("Key3D," "we," "us") collects, uses, discloses, and protects personal information through key3-d.com, client.key3-d.com, our quote and client-portal workflows, and related services (together, the "Services").

1. Information We Collect

2. Quote Verification and Portal Account Creation

There is no open public portal signup. A public quote request is first staged in a server-only Firestore collection outside every customer organization, and we confirm it by email. When our team prices the request, the quote email brings the quote document and a one-time portal password issued to the submitted email address; on first sign-in you set your own password and affirmatively accept the Website Terms and this Privacy Policy. Only the recipient of that email can create the account. A staged quote request that is not released is scheduled for deletion after seven days. After release, the staging record keeps a non-secret receipt, its active token verifier is erased, and the record is scheduled for deletion within 30 days. The one-time portal password is delivered once by email, is not stored in plain text after issuance, and must be replaced by your own password at first sign-in. Portal-access invitations expire after seven days.

The public quote form does not upload CAD file bytes. It may collect a reference filename or an HTTPS sharing link. Actual CAD files are uploaded only through the authenticated portal to private, organization-scoped Cloud Storage.

3. How and Why We Use Information

We use information to respond to inquiries; verify ownership of quote requests; create and secure portal accounts; prepare and manage quotes; evaluate manufacturability; provide proofs; fabricate, fulfill, ship, and support orders; process authorizations, payments, refunds, and returns; communicate service and security notices; enforce our terms; prevent fraud and abuse; maintain records; comply with legal, accounting, and tax duties; and improve the Services.

Where applicable, we rely on steps requested before entering a contract, performance of a contract, compliance with law, our legitimate interests in operating and securing the Services, and consent for optional analytics or other uses for which consent is required.

4. Service Providers and Other Disclosures

We disclose information only as reasonably necessary for the purposes above, including to service providers operating under their own terms and data-protection obligations:

Provider / category
Purpose and information involved
Google Cloud and Firebase
Firebase Hosting; Firebase Authentication with Identity Platform; Firestore database; Cloud Storage for private customer files; and, depending on the approved deployment, Firebase App Hosting or Google Cloud Run. These services process account identifiers, quote and portal records, uploaded files, service logs, and related request metadata.
Firebase Trigger Email and configured email infrastructure
Deliver quote-verification, account-access, transactional, and support email. When the approved production delivery infrastructure is enabled, messages are queued in a server-only Firestore outbox for Firebase's Trigger Email extension and delivered through the separately configured SMTP or Google Workspace email service. After outbox reconciliation observes confirmed delivery, the secret-bearing message body is scrubbed from the outbox.
Stripe
Provide payment fields; create and confirm card authorizations and payments; prevent fraud; send receipts; and process captures, cancellations, and refunds. Payment credentials go directly to Stripe.
Web3Forms
Process submissions from certain separately configured or legacy general-contact forms. The current quote-verification and portal-account workflow does not use Web3Forms and instead submits to Key3D's own application backend.
Have I Been Pwned (HIBP)
Screen passwords set through Key3D invitation and first-login change workflows against the Pwned Passwords corpus using its k-anonymous range service. Only the first five characters of a password's SHA-1 hash are sent; HIBP does not receive the password or its complete hash.
Google Analytics (optional)
Measure site usage only after analytics consent and only when a valid property is configured. We request IP anonymization and disable Google advertising, personalization, and cross-device signals.
Google Fonts
Deliver typefaces and related resources; Google receives ordinary network-request information such as IP address and browser headers.
Shipping carriers and professional advisers
Deliver and track orders, resolve claims, and support legal, tax, accounting, insurance, and security obligations.

We may also disclose information when required by law; to investigate fraud or protect customers, Key3D, or others; to enforce agreements; or as part of a merger, financing, reorganization, or sale of the business. We do not sell personal information, share it for cross-context behavioral advertising, or use proprietary Customer Content to make parts for another customer.

5. Payments and Password Security

Stripe-hosted payment fields keep full card data off Key3D systems. Key3D stores only the limited transaction and masked display information described above. Firebase Authentication manages credentials and authentication tokens. In addition to Firebase password controls, passwords set through Key3D invitation and first-login change workflows are screened through HIBP's k-anonymous range API. Key3D receives the proposed password over an encrypted connection long enough to hash and compare it, but does not retain it or transmit it to HIBP.

6. Retention and Security

We keep each class of record only as long as it is needed for the purpose it was collected for, then delete or de-identify it. The schedule below states what we hold and for how long.

Backups roll off within 35 days. Legal holds suspend deletion. Where a record must be kept, we de-identify personal data that is not needed for the retained purpose.

Safeguards include encryption in transit, access controls, verified identities, organization-scoped authorization, private file storage, limited staff access, security logging, one-time credentials, and service-provider controls. No transmission, system, or storage method can be guaranteed completely secure. Do not send classified, export-controlled, or unusually sensitive regulated information unless Key3D has first agreed in writing to an appropriate handling process.

7. Cookies, Local Storage, and Analytics Choices

We use first-party cookies and browser storage that are necessary to remember privacy choices, retain a quote cart, prevent accidental duplicate submissions, preserve local notification preferences, maintain Firebase authentication, secure sessions, and support Stripe fraud prevention and payment functionality. A consent choice remains stored until you change it, clear browser data, or a material policy or consent-version change requires a new choice.

Google Analytics remains off unless you select Accept analytics and a valid analytics property is configured. Selecting Reject is stored just like acceptance and does not affect access to the Services. We treat an enabled Global Privacy Control signal as a refusal. You can revisit the dialog through the site's Privacy choices control or clear browser storage. Blocking necessary storage may prevent the portal, checkout, or preference controls from working correctly. We do not use advertising, marketing, or cross-site tracking cookies.

8. International Processing

Key3D is based in Colorado, United States, and the Services and providers above may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we and our providers rely on recognized transfer mechanisms such as Standard Contractual Clauses and apply supplementary safeguards appropriate to the information and service.

9. Your Privacy Rights and Choices

Depending on your location and applicable law, you may request access to, correction of, deletion of, or a portable copy of personal information; withdraw consent; object to or restrict certain processing; opt out of targeted advertising, sale, or sharing; or appeal our response. We do not sell personal information or use it for targeted advertising, and we will not discriminate against you for exercising a privacy right. Authorized agents may submit requests where permitted by law.

Email contact@key3-d.com with the subject Privacy Request. Describe the request and the email or account involved. We will verify identity and authority before disclosing or deleting information and respond within the period required by applicable law. Some records may be retained where needed to complete a transaction, protect security, exercise legal rights, or meet legal obligations. You may appeal a denied request by replying with the subject Privacy Appeal. Residents outside the United States may also complain to their local data-protection authority.

10. Children, Changes, and Contact

The Services are intended for business users and are not directed to children under 16. We do not knowingly collect personal information from children under 16. We may update this Policy and will post the revised version and effective date; material changes may also be presented in the Services or by email. Questions or privacy requests: contact@key3-d.com, Key3D Fabrication, LLC, Front Range, Colorado, United States.