Trust
Security and data handling
Last updated: 13 September 2026 · Version 1.0
If a 3D print shop you buy from quotes through 3Dash, the file you upload passes through our software. This page tells your security, IT or procurement team what happens to it — where it goes, who can see it, how it is protected and when it is deleted — in enough detail to complete a vendor review. It describes the service as it runs today. Your contract is with the shop; our Privacy Policy is the binding statement of how we handle data, and this page explains it for a reviewer and adds the technical facts the policy leaves out (see Section 14).
The short version
- ✓ Your file is used to quote and print your part, and is then deleted — automatically, 7 days after upload, by a rule on the storage itself rather than by anyone remembering to.
- ✓ Only the shop you uploaded it to can see it. Never another shop; our own access is limited to operating the service. We claim no rights in it, and it is not used to train anything, benchmark anything or build a dataset.
- ✓ It is stored and sliced in India, in Google Cloud's Mumbai region (asia-south1), encrypted in transit and at rest.
- ✓ Payment is taken on the shop's own Razorpay account. Card and UPI details never touch 3Dash, and 3Dash never holds the money.
- — 3Dash holds no security certification of its own. Our providers' certifications are listed below, and we do not present them as ours.
1. Who is who
3Dash is quoting software sold to 3D print shops by subscription. A shop embeds our quote widget on its own website. The widget slices the model a visitor uploads against that shop's own printer profile and shows a price; on the shop's higher plan it also takes the order, with payment made to the shop's own account. 3Dash does not print anything, sells nothing to a shop's customers, and never asks them to create an account.
Your file is your confidential information and, where it embodies a design, your intellectual property. We claim no rights in it, and we process it only to produce the quote and, if there is one, the order — which is what our Terms of Service commit to the shop. Where your submission includes personal data — a name, an email address, a phone number, a delivery address — the roles under the Digital Personal Data Protection Act, 2023 are these:
| Party | Role | What that means |
|---|---|---|
| You — the shop's customer | The person or company whose file it is | Your contract, your invoice and any confidentiality terms are with the shop. |
| The shop | Your supplier, and the Data Fiduciary for the personal data you submit | Decides why your data is collected and answers to you for it. Can see your file for the job, through its own signed-in account. |
| 3Dash | The shop's software supplier. Data Processor, acting on the shop's instructions | Processes your file to produce the quote and, if there is one, the order — and for nothing else. Does not contact you, market to you, or share your data with any other shop. |
If your company needs its supplier's subcontractors covered by contract, that is normal. On request we enter into a data-processing agreement with a subscribing shop and will consider a reasonable non-disclosure agreement, and a shop may pass its customer's requirements on to us. See Section 12.
2. What the widget collects
It depends on the plan the shop is on, and the widget says which on the screen where anything is asked for.
| Plan | Collected | Not collected |
|---|---|---|
| Quote (the default) | The model file and its filename. The print options chosen: material, infill, layer height, quantity, colour, scale. If the shop has switched on lead capture, the email address you type — asked for on the same screen that tells you it goes to the shop. | No name, no phone, no address, no payment, and no account to create. |
| Quote & Checkout | Everything above, plus: your name, email address and phone number; a delivery address and pincode only if you choose delivery rather than pickup; and the payment status and reference identifiers the order needs. | Card, UPI or bank credentials. They are entered on the payment provider's hosted checkout (Section 7) and never reach 3Dash or the shop's website. |
| Both | IP address and browser details in server logs, kept typically 30–90 days. Pseudonymous product-usage events such as "a file was uploaded" or "a checkout was opened". | Anything from the website the widget sits on — see Section 6. |
3. The life of an uploaded file
- Upload. Your browser sends the file over HTTPS directly to a private storage bucket in Google Cloud's Mumbai region. It goes there directly: not through the shop's web server, and not to any third party.
- Slice. Our slicing service, in the same region, fetches the file and slices it with the shop's own slicer profile. The output is a set of measurements — material weight, print time, dimensions — and from those, a price. The container it runs in has no persistent disk: working copies are held in memory for a short time after the job and then discarded automatically, so nothing accumulates.
- Quote. The price is shown. On the Quote plan without lead capture, the file is linked to no person: there is no name, email or account attached to it.
- The job. If you place an order, or the shop has collected your email as a lead, the shop can retrieve the file through its own signed-in account to print it, by a link specific to that one order or lead. The link stops working when the order is cancelled or the file is deleted.
- Deletion. Seven days after upload, the file is deleted by the storage bucket's own lifecycle rule — not a scheduled job that could be skipped, not a manual step. A shop that follows its link after that is told the file was deleted under this rule.
- What remains. The quote or order record: the measurements, the options, the amounts, and on the Checkout plan the contact and delivery details the order needed. No geometry. Order records are kept for the period Indian tax law requires of a transaction — see the Privacy Policy, Section 8.
Need it gone sooner than 7 days? Ask the shop — its name and number are shown in the widget, and it instructs us. If you write to us directly, at legal@3dash.in with the shop's name and the filename or order reference, we take it up with the shop — it may still need the file to finish a job you have paid for — and act on it as processor.
4. Where data lives
- Region. Your file, the database that holds quote and order records, the slicing service, and the services that produce quotes and take orders run in Google Cloud's asia-south1 region, Mumbai, India. The static pages of this site and of the widget are served from Google's global edge network; those pages contain no customer data.
- What may sit outside India. Some ancillary data is handled by providers that may store it outside India: sign-in records (a shop's login email or phone number, and the opaque identifier behind a customer's anonymous checkout session), server logs, product-usage measurement, and transactional email. Your model file, your order details and the database that holds them are not among it.
- In transit. Every connection to our services is over TLS, the upload included; plain-HTTP requests are redirected.
- At rest. Everything stored is encrypted at rest by the platform's default encryption.
- The provider's certifications. Google publishes its certifications and audit reports for Google Cloud — ISO/IEC 27001, 27017 and 27018, and SOC 1, 2 and 3 — at cloud.google.com/security/compliance. They cover the infrastructure we run on. They are not an audit of 3Dash.
5. Who can see your file
| Who | Access |
|---|---|
| The shop you uploaded it to | Yes, for the 7 days it exists, through its own signed-in account, and only for files that came in through its own widget or its own API key. |
| Any other shop | Never. Every request is resolved to exactly one shop, and the service is built so that a shop reaches only its own quotes, orders and files. There is no shared pool, no marketplace and no directory. |
| 3Dash staff | A small number of people hold production access for operating and supporting the service. There is no routine human access to uploaded files; it happens to fix a fault, at the shop's request, or where the law compels it (Privacy Policy, Section 5). |
| Automated systems | The slicing service reads it to price it. Nothing else does. The file is not used to train a model, build a benchmark or a dataset, or improve the product. |
| The public | Never. The storage is private and there are no public links to it. |
6. The widget on the shop's website
- It is isolated from the page it sits on. The widget is a frame served from 3dash.in. Under the browser's same-origin rules the widget cannot read the shop's page, its cookies, its forms or anything typed on it — and the shop's page cannot read what you type into the widget. The only things the two exchange are the widget's height and a scroll request, so that it fits the page.
- No account, no password. On the Checkout plan the widget creates an anonymous session so your upload and your order belong to your browser and nobody else's. Nothing asks you to sign up to 3Dash.
- Measurement, not tracking. A pseudonymous identifier inside the widget counts which steps people complete. It measures product usage only. We run no advertising or retargeting anywhere, and nothing of ours follows you around the shop's site.
- The key on the page is safe to be there. The shop's widget carries a publishable key: it identifies the shop and can do nothing except ask for a quote, and only from website domains the shop has registered. Keys that can do more are never accepted from a browser.
7. Payments and invoices
- Where the card details go. On the Checkout plan, payment is taken through Razorpay's hosted checkout, on the shop's own Razorpay account — an account the shop connected and can disconnect. Card and UPI credentials are entered into Razorpay's environment, which Razorpay states is PCI DSS Level 1 certified, and never reach 3Dash or the shop's website. 3Dash receives the payment status and reference identifiers, nothing more.
- Where the money goes. From you to the shop. 3Dash is not in the flow of funds, never holds them, and takes no commission from them. A refund, if there is one, comes from the shop's account.
- Who invoices you. The shop. It is the seller, so the tax invoice and any GST on it are the shop's to issue. 3Dash issues no invoice, receipt or tax document to a shop's customer.
- Purchase orders and credit terms. The widget takes payment when the order is placed. If your company buys against a purchase order and pays on invoice, use the widget for the price and place the order with the shop directly. Whether the shop accepts a purchase order, and on what terms, is the shop's decision.
8. What stays with the shop
A vendor review should draw the boundary honestly. These are the shop's, not ours:
- The shop's own website and its security. The widget is isolated from it (Section 6), but the page around the widget is the shop's.
- What happens to your file once the shop has downloaded it to print — its printers, its computers, its staff, and how long it keeps its own copy.
- The credentials of the shop's own 3Dash account. Your file is reachable through that sign-in for 7 days, so the shop should protect it as it would any supplier portal.
- Your invoice, GST, payment terms, refunds and delivery promises.
- The shop's own privacy notice to you, as the Data Fiduciary.
9. Service providers
Each receives only what it needs to do its job. Providers we engage are bound to process it only on our instructions. Razorpay is the exception in kind: it is the shop's payment provider, acting for the shop under the shop's own merchant agreement.
| Provider | What it receives | When |
|---|---|---|
| Google Cloud (primary region asia-south1, Mumbai — see Section 4) | Hosting, storage, database and compute for everything described on this page | Always |
| Razorpay | Your name, email, phone and the amount, on the shop's own account, and your payment details, which 3Dash never receives | Checkout plan, at payment |
| Courier partner | Pickup and drop addresses, and the contact numbers of the shop and the recipient | Checkout plan, only if you choose delivery and the shop uses a courier |
| Address lookup | The address text you type, to find its coordinates for the courier quote | Checkout plan, only if you choose delivery |
| Transactional email | Recipient address and message content | Notices to the shop about its account and its orders |
| Product measurement and error monitoring | Pseudonymous usage events; when something breaks, the failing page and technical details of the failure | Always |
The full list by name, for a shop's compliance records or for a customer's review passed on by the shop, is available from legal@3dash.in.
10. Application security
These are the controls we run. No system is perfectly secure, and this page describes what we do rather than guaranteeing that nothing can ever go wrong; Section 12 says what happens if it does.
- One shop per request. Every request — from the widget, the API or a shop's dashboard — is resolved to exactly one shop before anything is read, and the service is built so that a shop can reach only its own records.
- Credentials cannot be read back. API keys and other secrets are stored in a form that cannot be reversed. A lost key is revoked and replaced, never recovered.
- Publishable and secret keys are different things. The key visible on a shop's public page can only request quotes, from the shop's registered domains. Keys with wider powers are refused the moment they arrive from a browser, with an error that says so plainly, because that is a leaked credential and not a configuration mistake.
- Rate limits and quotas apply per shop, and signals that distinguish a real browser from a script protect the quoting service from abuse.
- Files are treated as geometry. Only STL files are accepted, they are capped in size, and a file that does not parse as one is refused. STL is not an executable format — it is a list of triangles — and a file is parsed, never run.
- The slicers are the ones print shops use. The engines that slice your file are the same open-source slicers print shops run on their own benches — see the attributions page — configured with that shop's own profile.
- Least data. The strongest control on this page is that the file is thrown away in 7 days. Everything above narrows who can reach it in the meantime.
11. What we do not offer
Said plainly, so that a questionnaire gets a straight answer:
- No certification of our own. 3Dash is not ISO 27001 or SOC 2 certified. We are a small company, we will say so on your form, and we will not borrow our providers' badges.
- No uptime service-level agreement.
- No on-premise or private deployment, and no region other than Mumbai.
- No end-to-end encryption that keeps the file unreadable to us. The slicer has to read the geometry to price it. What we offer instead is short retention and narrow access.
- No malware scanning of uploads — an STL is validated as geometry and refused if it is not, and it is parsed, never run.
12. Incidents, disclosure and vendor reviews
- If there is a personal data breach: where we are the Data Fiduciary, we notify the Data Protection Board of India and every affected individual (the Act's "Data Principal") as it requires; where the shop is, we notify the shop without undue delay so it can meet its own obligations to you.
- Found a vulnerability? Report it to support@3dash.in. We will not pursue action against good-faith research that does not degrade the service or reach data beyond what is needed to demonstrate the issue.
- Vendor security questionnaires, NDAs and data-processing agreements. Write to legal@3dash.in. We acknowledge within 48 hours and complete vendor security questionnaires. On request we enter into a data-processing agreement with a subscribing shop, and will consider a reasonable non-disclosure agreement. A shop may pass its customer's questionnaire to us directly.
- Grievances and data-rights requests go to the officer named in the Privacy Policy, Section 12.
13. Questions reviewers usually ask
Is our file used to train AI, or to improve your product?
No. It is sliced to price it, held for the shop to print it, and deleted 7 days after upload. It is not used for training, benchmarking, datasets or product development, and we claim no rights in it.
Can another print shop see our file?
No. A file is visible only to the shop whose widget or API key it came in through. There is no shared pool of files and no marketplace.
Where exactly is it stored?
In a private storage bucket in Google Cloud's asia-south1 region, Mumbai, India, encrypted at rest. It is sliced in the same region.
Can we have it deleted before 7 days?
Yes. Ask the shop, which instructs us. Or write to legal@3dash.in with the shop's name and the filename or order reference, and we will take it up with the shop, which may still need the file to finish a job you have paid for.
Does 3Dash see our card details?
No. They are entered on Razorpay's hosted checkout, on the shop's own account. 3Dash receives the payment status and reference identifiers only.
Who issues our invoice?
The shop. It is the seller; 3Dash issues no invoice, receipt or tax document to a shop's customer.
Do you keep a copy after the shop has printed the part?
No. Deletion runs 7 days from upload whatever the state of the job. If the shop needs the file again later, it will have to ask you for it.
Does the widget track us across the shop's website?
No. Measurement is confined to the steps inside the widget, there is no advertising or retargeting, and the widget cannot read the page around it.
Is 3Dash ISO 27001 or SOC 2 certified?
No. Our infrastructure provider is; we are not, and we will answer your questionnaire on that basis.
Will you sign an NDA?
Your NDA is with the shop. On request we enter into a data-processing agreement with a subscribing shop and will consider a reasonable NDA, which is how a shop covers its subcontractor.
14. Status of this page
This page is provided for information, to help a shop's customer complete a vendor review. It describes the service as it operates on the date shown at the top, and we update it when the service changes. It is not a contract between 3Dash and a shop's customer and creates no rights beyond those in our Privacy Policy and, for a subscribing shop, our Terms of Service; where this page and those documents differ, they prevail. Google Cloud and Razorpay are trademarks of their respective owners, named here to identify the services we use; no endorsement is implied.
15. Contact
For a vendor review, a questionnaire, an agreement or a deletion request: legal@3dash.in. For everyday product help, support@3dash.in.
Read with our Privacy Policy and our Terms of Service, which govern the shop's use of the product.