Privacy Policy
Last updated: [date]
TODO: This is a structural placeholder, not final legal text. Generate the
full Datenschutzerklärung with a generator (e.g. e-recht24.de or
activemind.de) and merge it into these sections. The section list below
matches what this app actually does — keep it in sync when features change. 1. Controller
[Full name and address — same as the Imprint.]
For any privacy request, contact [contact email].
2. What data we process, and why
- Account data — name, email address, password (stored as a
hash). Legal basis: performance of contract (Art. 6(1)(b) GDPR).
- Workspace content — the data you enter to run your print
farm: printers, printer credentials, filament spools, print jobs, products,
inventory, and (if you connect Shopify) order data. Legal basis: performance
of contract (Art. 6(1)(b) GDPR). Printer access codes and Shopify tokens are
encrypted at rest.
- Session data — session cookies (strictly necessary; no
consent banner required), IP address and browser user-agent on sessions.
Legal basis: performance of contract and legitimate interest in securing the
service (Art. 6(1)(f) GDPR).
- Usage analysis to improve the service — we analyse how the
service is used (e.g. which features are used, error rates) to improve it.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Aggregated, anonymised statistics — we create aggregated,
anonymised statistics from usage and workspace content (for example,
industry-level printing and product trends). These statistics do not contain
personal data and cannot be traced back to you or your workspace; once
anonymised, they are outside the scope of the GDPR. We may use such
statistics commercially, including sharing industry insights with third
parties.
3. Support access
Our operators can access workspace data, including via an account
impersonation mechanism, strictly for support, debugging and operating the
service. Legal basis: performance of contract and legitimate interest
(Art. 6(1)(b) and (f) GDPR).
4. Processors and recipients
- Cloudflare, Inc. — hosting, application runtime and
database (Cloudflare Workers / D1). [TODO: link Cloudflare DPA; note EU–US
Data Privacy Framework / standard contractual clauses.]
- Resend — transactional email delivery (verification and
password-reset emails). [TODO: link Resend DPA; note transfer mechanism.]
- Shopify — only if you connect your own Shopify store; we
retrieve order data from your store on your behalf.
We do not sell personal data.
5. Storage and retention
Your data is stored for as long as your account exists. When your account is
deleted, your account data and all workspace content are permanently deleted.
[TODO: state any backup retention window once defined.]
6. Your rights
You have the right to access, rectify, erase and export your personal data,
to restrict or object to its processing, and to lodge a complaint with a
supervisory authority (Art. 15–21, 77 GDPR). To exercise these rights,
contact [contact email].
7. Cookies
We only set cookies that are strictly necessary to operate the service
(session authentication). We do not use tracking or advertising cookies.