Legal
Privacy Policy
Last updated: 18 August 2026 · Version 2.0
3Dash is quoting software for 3D print shops. This policy explains what we do with your data as a shop that subscribes to us, and — separately, because the rules are different — what we do with the data your customers submit through the quote widget on your site. Read alongside our Terms of Service.
The short version
- ✓ 3D model files are deleted automatically, 7 days after upload. A model is needed long enough to quote it and print it, and no longer. Keeping customer geometry past the job is a liability, not a feature.
- ✓ We never hold your customers' money and never see their card details. Payments run on your own payment account. We are not in the flow of funds.
- ✓ On the Quote plan we collect no contact details from your customers at all — no name, no email, no phone, no address. The widget shows a price and stops.
- — We do not sell personal data, and we do not use your customers' data to market anything to them.
1. Who we are, and our two roles
"3Dash", "we", "us" and "our" mean the 3Dash service operated from Bengaluru, Karnataka, India. 3Dash sells software: an embeddable quote widget and a quoting API. We do not print anything, we do not sell printed parts, and we do not operate a marketplace.
Under the Digital Personal Data Protection Act, 2023 ("DPDP Act") we wear two hats, and which one applies depends entirely on whose data it is:
| Whose data | Our role | What that means |
|---|---|---|
| The Shop — you, the owner or staff of a subscribing print shop | Data Fiduciary | We decide why and how your account data is processed, and we answer to you directly for it. Sections 2, 3 and 8 apply. |
| The End Customer — a visitor who uses the quote widget on the Shop's own website | Data Processor acting on the Shop's instructions | The Shop is the Data Fiduciary. We process this data only to deliver the quote, and the order if there is one, and for nothing else. Section 4 applies. |
If you are an end customer who used a quote widget on a print shop's website and you want your data corrected or erased, contact that shop first — they control it. We will act on their instruction, and we will also help you directly if they do not respond; see Section 9(b).
2. What we collect from a Shop
a. Account and identity
- Name and email address, and where you sign in through a third-party identity provider, the basic profile details it returns to us.
- A phone number, where you provide one for order notifications or verification.
- An account identifier we generate, and timestamps for account creation, sign-in, and your acceptance of these policies.
b. Shop configuration — the settings the product runs on
- Shop name, logo, public contact number and pickup address. These are deliberately public: the widget shows them to your customers, and the pickup point is what a courier is routed to.
- Printers, materials, rates, minimum order values and colours you configure.
- Files you upload to set up a printer. These describe machine configuration rather than a person, but they are your commercial information and we treat them as confidential: they are never shown to another shop, and never used to build any cross-shop dataset or benchmark.
c. Billing
- Your plan, billing cycle, subscription status, trial dates, invoice history and the amounts charged.
- Reference identifiers issued by our payment provider for your subscription and its payments.
- We do not receive or store your card number, CVV, UPI PIN or net-banking credentials. Those are collected directly by the payment provider under its own policies and PCI-DSS obligations.
d. Your payment account connection (Quote & Checkout plan only)
When you connect your own payment account so the widget can take payments, you authorise us through your payment provider, which issues us credentials limited to your account. We hold them securely and use them for one purpose: creating and managing payment orders on your account when your customer checks out. You can revoke them at any time by emailing support@3dash.in, or from your payment provider's own dashboard. Revoking also deletes them on our side.
e. API access
If you use the API, we store the label, creation and revocation timestamps of each key you issue, and the list of website addresses you have allowed to use it. Keys themselves are stored in a form we cannot reverse — which is why we can only show you a key once.
f. Technical and usage data
- IP address, browser and device type, and referring page, in ordinary server logs.
- Counts of quotes, models and orders, for fair-use limits and support.
- Product usage measurement — which pages you visit on our site, which setup steps you complete. See Section 6.
3. How we use a Shop's data
| Purpose | Ground under the DPDP Act |
|---|---|
| Creating and running your account; producing quotes from your settings; serving your widget and API | Consent, given when you register, and performance of our contract with you |
| Billing you, collecting subscription fees, passing on courier costs, issuing invoices | Consent and legitimate use; statutory record-keeping |
| Sending service email — trial expiry, payment failures, security notices, breaking changes to the API | Legitimate use; these are transactional, not marketing, and cannot be opted out of while your account is live |
| Support, debugging, fraud and abuse prevention, enforcing fair-use limits | Legitimate use |
| Aggregate, non-identifying product measurement | Legitimate use — the output identifies no shop and no person |
| Responding to lawful requests, and exercising or defending legal claims | Legal obligation |
We do not sell personal data. We do not share your data with advertisers, and we do not use your prices, your settings or your order volumes to advantage another shop.
4. What flows through the widget — your customers' data
This section is about the people who use the quote widget on a shop's website. For this data the shop is the Data Fiduciary and we are its processor. Your customers do not create a 3Dash account: the widget issues an anonymous session so the browser can read back its own quote, and that session carries no name and no contact detail.
a. On the Quote plan — nothing personal is collected, unless the shop turns it on
By default the Quote plan shows a price and stops. There is no form and no payment step, and the only thing that reaches us is the model file and the print options chosen, described below. This is how the plan behaves unless the shop has changed it.
If the shop has switched on lead capture, the widget asks for an email address before it shows a price, and tells the visitor on that same screen that the address and the file go to the shop. In that case we collect and pass to the shop:
- The email address entered.
- The uploaded file, its filename, and the print options chosen — material, infill, scale, quantity, colour.
- The price quoted, and when.
Nothing else: no name, no phone number, no address, and no payment details, because this plan takes no payment. The email address is never verified, is not used by us to contact anyone, and is subject to the same retention and rights as everything else here. The file itself is still deleted 7 days after upload under Section 8, whether or not it arrived with an email attached.
b. On the Quote & Checkout plan
When a customer places an order we collect and pass to you:
- Name, email address and phone number.
- If they choose delivery: the delivery address and pincode. If they choose pickup, no address is collected.
- The order contents — files, materials, quantities, options — and the amounts.
- Payment status and reference identifiers. We never see card, UPI or bank credentials; the payment is taken on your own account.
c. 3D model files and print specifications
Uploaded models are used to work out weight, print time and price against the shop's own settings. We also derive basic geometry facts such as size and volume.
A model file is never shown to any shop other than the one whose widget it was uploaded through, is never used to train any model, and is never published. Retention is covered in Section 8 and is short by design.
d. Technical data
IP address and browser information in server logs, and the measurement and abuse-prevention data described in Section 6.
e. Our instructions from the Shop
We process end-customer data only to: produce quotes; create, verify and hand you orders; arrange a courier when the customer chooses delivery; send order email; and prevent abuse. We do not use it for our own purposes, do not market to your customers, and do not disclose it to any other shop. If you instruct us to delete an end customer's data, we will.
5. Who we share data with
We do not sell data and we share as little as possible. Where we use a service provider, it receives only what it needs to do its job, is bound by contract to process that data only on our instructions, and may not use it for its own purposes. The categories are:
| Category | What they receive | Why |
|---|---|---|
| Cloud infrastructure | Hosting, storage and processing of the data described in this policy | Running the service. This is where the product and its data live. |
| Payment providers | Your billing details; and, on the Checkout plan, your customer's name, email, phone and the amount | Two separate things: collecting our subscription fee from you, and taking your customer's payment on your own account. |
| Courier partners | Pickup and drop addresses, and the contact numbers of the shop and the recipient | Arranging delivery. Only on the Checkout plan, and only when the customer chooses delivery. |
| Email delivery | Recipient address and message content | Sending transactional email — trial and billing notices, order notifications. |
| Product measurement and error monitoring | Pseudonymous usage events; and, when something breaks, the failing page and technical details of the failure | Understanding how the product is used and finding faults before you have to report them. |
| Security and anti-abuse | Device and interaction signals | Telling a real browser from a script abusing the service. |
We also disclose data where we are legally required to — a court order, or a valid demand from a law-enforcement or regulatory authority — and in a merger or acquisition, in which case the acquirer is bound by this policy or a materially equivalent one, and you will be told before your data moves.
If you need the current list of our service providers by name — for your own compliance records, or to satisfy a customer's request — write to legal@3dash.in and we will provide it.
6. Cookies and similar technologies
We use browser storage and cookies for three things, and no more:
- Strictly necessary. Keeping you signed in, holding the anonymous widget session, remembering preferences, and carrying anti-abuse tokens. The service does not work without these.
- Measurement. A pseudonymous identifier used to count visits and see which steps people complete. This runs inside the quote widget as well as on our own site, so a visitor to your website will have it set when the widget loads. It measures product usage only. We run no advertising or retargeting anywhere.
- Security. Signals used to distinguish a real browser from an abusive script.
You can block or delete cookies in your browser. Blocking the strictly necessary ones will break sign-in and the widget.
7. Security
A fuller account, written for the security or procurement team of a shop's customer — where files are stored, who can reach them and what we do not offer — is on our security and data handling page. This section is the binding summary.
- Encryption of data in transit and at rest.
- Credentials are stored so they cannot be read back — including your API keys, which is why a lost key is revoked and replaced rather than recovered.
- Access controls that resolve every request to one shop, so a shop can reach only its own records, quotes and orders.
- Internal access is limited to the people who need it to operate and support the service.
- Least data. The strongest control we have is that we throw model files away quickly — see Section 8.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and every affected Data Principal as required by the DPDP Act and its rules. Where the breach concerns end-customer data, we will notify the affected Shop without undue delay so it can meet its own obligations.
Found a vulnerability? Please report it to support@3dash.in. We will not pursue action against good-faith research that does not degrade the service or access data beyond what is needed to demonstrate the issue.
8. How long we keep things
| Data | Retention |
|---|---|
| Uploaded 3D model and drawing files | Deleted automatically 7 days after upload, by a storage rule rather than by anyone remembering to run one. A model is needed long enough to quote it and for the shop to print it; keeping customer geometry past the job is a liability, not a feature. |
| Quote records (measurements and amounts, no file) | Kept while your subscription is active, so you can look up what you quoted. Deleted with the account. |
| Leads, where a shop has switched on lead capture (an email address and the quote it belongs to) | Kept while your subscription is active, so you can follow them up. Deleted with the account, or on request — see Section 9. The file attached to a lead is not covered by this row: it follows the 7-day rule above, so a lead older than a week keeps its email and its price but no longer its model. |
| Order records, including customer contact and delivery details | Kept for as long as you need them and in any case for the period Indian tax and commercial law requires records of a transaction to be kept, currently up to eight years. Deleted or anonymised after that. |
| Shop account and configuration | While your account exists, and for 30 days after you close it so it can be restored. Then deleted. |
| Billing and invoice records | Retained for the statutory period under Indian tax law even after you close the account. This is a legal obligation and cannot be waived by a deletion request. |
| Payment account connection credentials | Deleted immediately when you disconnect, or when the account is closed. |
| Server and security logs | Typically 30–90 days. |
| Revoked API keys | Their record is retained so a revoked key can never be used again. |
9. Your rights
a. If you are a Shop
As a Data Principal under the DPDP Act you have the right to:
- Access a summary of the personal data we process about you and the processing activities involved.
- Correct, complete, update or erase your data. Most of it you can edit yourself in your account and shop settings.
- Withdraw consent at any time. Withdrawal is not retrospective, and because your account cannot run without the data it is built on, withdrawing consent means closing your account.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity — write to us with their details.
- Grievance redressal through the officer named in Section 12, before approaching the Board.
- Complain to the Data Protection Board of India if you are not satisfied with how we handled your grievance.
To exercise any of these, write to legal@3dash.in from your registered email address. We respond within 15 days. Erasure is subject to the statutory retention in Section 8.
b. If you are an end customer of a shop
Your rights are the same, but the shop is the Data Fiduciary — so the fastest route is to contact the shop whose website you used; its name and number are shown in the widget and on your order confirmation. If you cannot reach them, or they do not act, write to legal@3dash.in with the order reference or the email address you used, and we will act on it as processor and escalate to the shop. Note that your uploaded model file is deleted 7 days after upload under Section 8, so it has very likely gone already.
10. Children
3Dash is a business tool and is not directed at children. You must be 18 or over to hold an account, and a shop must not knowingly configure the widget to solicit personal data from a child. We do not knowingly process the personal data of anyone under 18; if we learn that we have, we delete it. Consistent with the DPDP Act, we do no behavioural tracking or targeted advertising directed at children — we do no behavioural advertising at all.
11. Where data is processed
Your data is processed primarily in India. Some service providers operate globally and may process limited data outside India. Any such transfer is made under the DPDP Act and its rules, to countries not restricted by the Central Government, and under contractual terms requiring protection equivalent to this policy.
12. Grievance Officer
In accordance with the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, you may direct any grievance, data-rights request or complaint about the Platform to:
Grievance Officer & Data Protection Officer
3Dash
Soladevanahalli, Bengaluru, Karnataka — 560107, India
We acknowledge every grievance within 48 hours and resolve it within 15 days of receipt.
13. Changes to this policy
We may update this policy. The "Last updated" date at the top reflects the most recent revision. If a change materially affects your rights or how we handle your data, we will email account holders and ask you to accept the updated policy the next time you sign in. Continued use after a change means you accept it.
14. Contact
For anything in this policy — a data-rights request, a grievance, or a question about how we handle information — write to legal@3dash.in. For everyday product help, support@3dash.in is faster. Our Terms of Service govern your use of the product, and the attributions page lists the open-source software we build on.