Privacy
Last updated 29 August 2026
3dfoundry.io is a back-office tool for print shops that sell through Shopify. This page says what we collect, why, where it lives, and how to make us delete it — in plain English, because a privacy policy you can't read isn't one.
Two hats are worn here, and the distinction matters. For your account data — your login, your settings, your billing — we are the controller. For your customers' data — the orders, messages and files that flow through your shop — you are the controller and we process it on your instructions. Most of this page covers the first hat; the section on your customers covers the second.
What we collect about you
- Your email address, to sign you in. Login is a one-time code — we never hold a password for you. Codes are stored hashed and expire quickly.
- Your shop's settings: pricing ladders, support profiles, folder mappings, brand colours — the configuration that makes the tool yours.
- Billing details via Stripe or Shopify. We never see your card number; we hold the subscription state and invoices those platforms report back.
- An audit log of admin actions in your workspace — who changed what, when. That log protects you; it is how "who deleted this order?" gets an answer.
What flows through on your behalf
When you connect your accounts, the tool handles data so you don't retype it:
- Shopify — we keep a working copy of your products, variants, collections and orders so the queue stays fast and works when Shopify is down.
- Gmail, Messenger and Instagram — support messages are ingested into your ticket queue, and replies are sent through the connected account.
- Google Drive — we read your STL library to match orders to files, and write finished support projects back. We don't move your library and we don't keep a copy of it.
- Customer uploads — if you turn on Custom Print, your customers' uploaded models are stored so they can be quoted, paid for and printed. They are deleted automatically when the job expires, and on any erasure request.
Connection tokens for all of the above are encrypted at rest (AES-256-GCM). Email addresses used for lookups are stored as keyed hashes, not plaintext indexes.
The honest section: message content and Claude
Support tickets are sorted, summarised and given a draft reply. That work is done by Claude, Anthropic's language model, which means the content of a support conversation is sent to Anthropic's API to be classified. Three things keep that narrow:
- Only conversations active in the last 48 hours are ever processed automatically.
- Anthropic does not train its models on API data.
- Nothing sends automatically. The drafts are drafts; a person presses send, every time.
If you don't want this, don't connect an inbox — the rest of the tool works without it.
What we deliberately don't do
- No tracking on the website. The marketing pages carry no analytics scripts, no ad pixels, no fingerprinting. The only cookie anywhere is the session cookie that keeps you signed in to the app.
- No selling data. To anyone, in any form, aggregated or not.
- No raw IP addresses in the database. Where rate limiting needs to recognise repeat traffic (customer uploads), the IP is stored as a keyed hash.
Where it lives
The application and its database run on Fly.io in London. Files are stored on Tigris (S3-compatible object storage), keyed per shop so one shop's files can never be listed from another's. Every shop's data is fenced to that shop in every query.
Subprocessors
| Who | What for | What they see |
|---|---|---|
| Fly.io | Hosting and database | Everything, encrypted at rest |
| Tigris Data | File storage | Uploaded models and generated assets |
| Upstash | Job queue | Job identifiers, not content |
| Anthropic | Ticket sorting and drafts | Support conversation content |
| Stripe | Billing | Your billing identity |
| Shopify, Google, Meta | The accounts you connect | What you authorise, per provider |
| Resend | Email delivery, where configured | Recipient addresses and message content |
Your customers' rights, handled for you
When one of your customers exercises their GDPR rights through Shopify, the mandatory webhooks fire and we act on them automatically: a data request is compiled, an erasure request deletes their conversations, jobs and uploaded files, and a shop-level erasure removes everything the shop ever stored — files included, in one sweep. You don't have to remember we exist for your compliance to work.
How long we keep things
- Customer-uploaded models: until the job expires, then swept automatically.
- Your account and workspace data: for as long as you have an account.
- After you leave: ask and we delete the workspace. Your Drive and your Shopify were always yours, so there is nothing to hand back — disconnecting revokes our access.
Your rights
Access, correction, deletion, portability, objection — the UK GDPR set. Email us and we do it; none of it requires a form. If you think we've handled your data badly you can complain to the ICO (ico.org.uk), though we'd appreciate the chance to fix it first.
Changes and contact
If this policy changes in a way that matters, account holders get an email before it takes effect — not a quiet edit and an updated date.
Questions, requests, complaints: hello@3dfoundry.io.