Makr3D.app

Privacy Policy

How Makr3D handles seller account data, buyer delivery data, uploaded files, platform logs, AI-assisted checks and international privacy requests.

Last updated

1. Scope

This Privacy Policy is written for a UK-based service used by sellers and buyers in multiple countries. It is intended to be read with the Data Processing Addendum and Subprocessor List.

2. Who is responsible for personal data

Yorkshire3D Limited, trading as Makr3D, is registered in England and Wales. Data protection contact: [email protected].

For seller account data, staff data, billing, payment references, fraud, security, audit, support, legal, tax, product safety, analytics and business records, Makr3D is normally the controller. For buyer names, addresses, order details and delivery contact information that a seller sends to us so we can fulfil that seller's order, the seller is normally the controller and Makr3D acts as processor. Some delivery, fraud, safety, legal and carrier-claim records may also be processed by Makr3D as controller where we have our own legal or operational responsibility.

3. Personal data we collect

  • Seller account data: name, email, business name, country, role, authentication identifiers, onboarding answers, plan, settings and support messages.
  • Buyer fulfilment data: recipient name, address, shipping service, marketplace order references, tracking information and limited contact details needed for delivery or dispute handling.
  • Order and production data: products, quantities, SKUs, files, variants, colours, print settings, notes, QA records, remake reasons, packaging choices, carrier events and support history.
  • Uploaded files: STL, 3MF, STEP, OBJ or related files, images, thumbnails, previews, Print Intelligence evidence, slicer outputs and production artefacts.
  • Billing data: invoices, charges, refunds, payment status, VAT details, payout records and payment-method references. Full card numbers are handled by Stripe, not stored by Makr3D.
  • Technical data: IP address, user agent, logs, device and session information, cookies, OAuth state, API-key metadata, webhook delivery logs, error reports and security events.
  • Communications: emails, support tickets, admin notes, takedown notices, compliance evidence and complaint records.

4. How we use personal data

We use personal data to:

  • create and secure seller accounts;
  • quote, review, print, pack, dispatch and support orders;
  • operate Print options, Print Intelligence, previews and production checks;
  • process payments, refunds, VAT, subscriptions and invoices;
  • sync orders from authorised channels such as Etsy or API integrations;
  • send service emails, order updates, support replies and security notices;
  • detect fraud, abuse, policy breaches, security incidents and payment issues;
  • handle IP notices, product safety issues, returns, remakes and carrier claims;
  • keep legal, accounting, audit, tax, safety and dispute records;
  • measure aggregate product usage and improve the service.

5. Lawful bases when Makr3D is controller

Our lawful bases under UK GDPR are usually contract, legitimate interests, legal obligation and, where required, consent. Legitimate interests include running a secure fulfilment platform, preventing fraud, improving production quality, supporting sellers, protecting rights holders, managing disputes and keeping evidence of transactions. Where local law requires consent, opt-out or other handling, we will apply it where applicable.

6. Buyer delivery data

Sellers must have a lawful basis to send buyer data to Makr3D. We process buyer delivery data primarily to fulfil the seller's order, generate labels, ship parcels, provide tracking, investigate loss or damage, handle remakes, meet carrier requirements and keep required records. We do not use buyer delivery data to market Makr3D or other sellers to the buyer.

7. Uploaded files and AI-assisted checks

Uploaded files are private. Makr3D uses them to quote, inspect, preview, slice, run Print Intelligence, manufacture, QA, pack, support and keep necessary records for your orders. We do not sell, publish, share or licence uploaded files to other sellers unless you separately opt into a hosted catalogue, creator catalogue, mini-store or revenue-share programme with written terms.

Makr3D does not use seller files to train our own AI models and does not opt in to API-provider training. Where OpenAI or another AI provider is used for Print Intelligence or assistant features, data may be processed by that provider to deliver the service, maintain security and monitor abuse according to its API data-control terms.

8. Cookies and analytics

We use cookies and similar technologies for authentication, session security, seller preferences, OAuth handshakes, payment flows, API protection and analytics or conversion measurement. The Cookie Policy lists the main categories. We may use tools such as Plausible, Google Analytics and Reddit conversion tracking to understand site usage, referrers and seller acquisition funnels.

9. Subprocessors and recipients

We use subprocessors and service providers for authentication, hosting, database, object storage, payments, email, error monitoring, AI-assisted checks, shipping labels, marketplace connections and support. The current launch list is in the Subprocessor List. We may also share data with carriers, professional advisers, insurers, banks, tax authorities, regulators, law enforcement, courts, rights holders or complainants where lawful and necessary.

10. International transfers

Makr3D is based in the UK, but some service providers, sellers, buyers, platforms and carriers may be outside the UK. Where UK GDPR transfer rules apply and data is sent to a country without an applicable adequacy regulation, we aim to use appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, provider data processing terms, or another lawful transfer mechanism.

11. Retention

We keep personal data while your account is active and for as long as it is reasonably needed for the purposes described above. Rather than fixed retention schedules, we decide how long to keep data using criteria such as:

  • whether your account is still open and the data is needed to run it;
  • whether order, invoice, payment and tax records are still required by accounting and tax obligations;
  • whether buyer delivery data is still needed for fulfilment, disputes, carrier claims and legal records;
  • whether uploaded files are still attached to your account, a product or an order, or you have asked us to delete them;
  • whether security, audit and API logs are still needed for investigation, abuse prevention and service integrity;
  • whether takedown, safety and compliance records are still needed to evidence our response.

You can ask us to delete your data at any time through support. We honour deletion requests unless we need to retain limited records for legal obligations, accounting, fraud prevention, disputes, safety, IP complaints, enforcement, audit trails or defence of claims.

12. Your rights

Where UK GDPR applies, you may have rights to access, rectify, erase, restrict, port or object to certain processing. You may also have a right to complain to the Information Commissioner's Office. If your request relates to buyer data controlled by a seller, we may refer the request to that seller unless Makr3D also has its own controller role for the data.

13. California and US privacy notes

To the extent the California Consumer Privacy Act or similar US state privacy laws apply, Makr3D does not sell personal information and does not share personal information for cross-context behavioural advertising at launch. We process personal information for business purposes such as fulfilment, payments, security, support, analytics and legal compliance. Eligible California residents may request access, deletion, correction, portability, information about categories of data and opt-out rights where applicable.

Makr3D is not directed to children under 13 and sellers must not submit children's personal data unless it is strictly necessary for a lawful fulfilment purpose and they have the required parental, guardian or legal authority. Products intended for children also require separate product-safety review.

14. Security

We use access controls, authentication, encryption in transit where supported, private file storage, staff-gated admin workflows, logging, audit records and provider security controls. No online service is risk-free, so sellers must also protect their accounts, staff access, API keys and connected stores.

15. Changes and contact

We may update this policy as the service, subprocessors, legal requirements or launch scope change. Contact [email protected] for privacy requests or questions.