Privacy Policy

Effective date: __ EFFECTIVE_DATE __

Template notice: Have a privacy attorney or auto-generated service (Termly, iubenda) verify this matches your actual data handling before going live.

1. Who we are

Cloud Forge is operated by __ COMPANY LEGAL NAME __ ("we"), __ ADDRESS __. For privacy questions email privacy@cloudforge3d.com.

2. What we collect

You give us directly

Collected automatically

From our partners

3. How we use it

4. Who we share it with

We share the minimum data necessary with:

We do not sell your personal information. We do not share it for third-party marketing.

5. Where we store it

Data is stored on servers operated by our hosting partners (currently Netlify and Google, primarily in the United States). If you are in the EU/UK, your data may be transferred to and stored in the United States under Standard Contractual Clauses or other lawful transfer mechanisms.

6. Cookies & similar technologies

We use a small number of cookies:

7. Your rights

Depending on your jurisdiction, you have the right to:

To exercise any right, email privacy@cloudforge3d.com. We respond within 30 days.

8. Retention

We keep order records for 7 years to comply with tax and accounting laws. Account data is kept while your account is active and for 90 days after deletion. Designs you delete are removed within 30 days.

9. Children's privacy

Cloud Forge is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe we have collected data from a child under 13, contact us and we will delete it.

10. California (CCPA/CPRA)

California residents have additional rights including the right to know what we collect, the right to delete, and the right to opt out of "sale" or "sharing" (we don't sell or share for cross-context advertising). Submit requests to privacy@cloudforge3d.com.

11. EU/UK residents (GDPR)

The legal bases we rely on are (a) contract (to process your orders), (b) legitimate interests (to improve the Service, prevent fraud), (c) consent (analytics cookies, marketing emails), and (d) legal obligation (tax records). Our EU representative for GDPR purposes is __ REP NAME & ADDRESS __.

12. Security

We use TLS in transit and at rest where supported by our processors. Payment card data never touches our servers (Stripe handles it directly). No internet service is 100% secure; we make commercially reasonable efforts.

13. Changes

If we materially change this Policy we will notify you via email or in-product banner at least 7 days before the change takes effect.