OrbitStudio ← Back to site

Privacy Policy

Last updated: 22 July 2026

This policy explains what personal data OrbitStudio collects, why we collect it, how long we keep it, and what rights you have under the GDPR. We keep this short and specific, because vague privacy policies help nobody.

01 Who is responsible for your data

The controller of your personal data is SimplySolid3D, a sole proprietorship (eenmanszaak) registered in the Netherlands, trading as OrbitStudio.

  • Chamber of Commerce (KvK): 42111792
  • VAT number: NL005501927B66
  • Registered address: De Meulencamp 15, Meijel, Netherlands
  • Contact: SimplySolid3D@gmail.com

We are not required to appoint a Data Protection Officer, so you can reach us directly at the address above for any privacy question.

02 What we collect and why

DataWhyLegal basis
Email address, password (stored only as a salted hash — we never see your password), validation code, account tier and credit balance To create and secure your account, let you sign in, and give you the access you bought Performance of our contract with you
Your generations: selected coordinates, model settings, any text you engrave, and the resulting model files To produce your models, let you download them, and support you if something fails Performance of our contract with you
Technical data: IP address, browser type, timestamps, request and error logs To keep the service secure and available — rate limiting, abuse and fraud prevention, and debugging Our legitimate interest in a secure, working service
Purchase and invoice data (amount, date, VAT details). Card details are handled by our payment provider and never reach our servers To process your purchase and meet our bookkeeping obligations Contract, and our legal obligation under Dutch tax law
Emails you send us To answer your question Our legitimate interest in helping our users

We do not sell your data, we do not share it for advertising, and we do not use it to build profiles or make automated decisions with legal effects for you.

03 Cookies and local storage

OrbitStudio runs no analytics, no advertising pixels and no third-party tracking. That is why you do not see a cookie banner — there is nothing to consent to.

We use only strictly functional browser storage:

  • a login token stored in your browser's local storage, so you stay signed in;
  • a few interface preferences (such as your last map position and settings), stored locally so the app opens where you left off.

These never leave your browser except to authenticate you with our own server, and you can clear them at any time through your browser settings. Signing out removes the login token.

04 Who processes data on our behalf

We are a small operation and rely on a few well-established providers. They act as our processors, may only use the data to deliver their service to us, and are bound by data processing agreements.

ProviderRoleWhere
Google Cloud (Cloud Run, managed database) Runs our application and stores account and job data Region europe-west1 (Belgium, EU)
Cloudflare (Pages, R2 storage, CDN) Serves the website and stores generated model files Global network; may process outside the EEA
Resend, Inc. Sends account emails such as password resets United States (EU-US Data Privacy Framework certified)
Stripe Payments Europe, Ltd. Processes payments and holds card details (we never receive them) Dublin, Ireland (EU); Stripe may also process in the US
Google (Gmail) Hosts our support mailbox, so any email you send us is stored there EU and global Google infrastructure

We may also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend a legal claim.

05 Transfers outside the EEA

Our application and database run in the EU (Google Cloud, region europe-west1 in Belgium), and payments are handled by Stripe's Irish entity. Some providers process data outside the European Economic Area:

  • Resend is based in the United States. Even where email is dispatched from an EU region, Resend's account data and delivery logs are stored in the US. Resend is certified under the EU-US Data Privacy Framework, which provides the legal basis for this transfer.
  • Cloudflare and Google operate global networks and may process data outside the EEA. These transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

Only the data needed for each service is shared: Resend receives your email address and the contents of the account email being sent, and Stripe receives what it needs to take a payment.

06 How long we keep it

  • Account data — for as long as your account exists. If you delete your account, we remove it within 30 days, except where we must keep records by law.
  • Generated models and job data — model files are held in our object storage and the job record is kept while your account exists. Download links are temporary and expire 24 hours after they are issued. We do not offer a library of your past generations, so download and keep your own copies.
  • Invoices and payment records — 7 years, as required by Dutch tax law.
  • Security and error logs — normally up to 12 months, then deleted or aggregated.
  • Support emails — up to 24 months after your question is resolved.

07 How we protect it

  • All traffic runs over HTTPS.
  • Passwords are stored only as salted hashes (PBKDF2) — they cannot be read back, not even by us.
  • Access to production systems is restricted and authenticated.
  • Rate limiting and abuse protection guard against automated attacks.
  • Download links are time-limited and tied to your account.

No system is perfectly secure. If a data breach ever occurs that is likely to present a risk to you, we will notify the Dutch Data Protection Authority and, where required, you — without undue delay.

08 Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • rectify data that is incorrect or incomplete;
  • erase your data ("right to be forgotten");
  • restrict or object to our processing, including processing based on legitimate interest;
  • data portability — receive your data in a structured, machine-readable format;
  • withdraw consent at any time, where processing is based on consent.

Email us at SimplySolid3D@gmail.com and we will respond within one month. We may need to verify your identity first, so that nobody else can request your data.

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or with the supervisory authority in your own country. We would appreciate the chance to fix it first.

09 Children

OrbitStudio is not directed at children under 16. If you believe a child has given us personal data without the consent of a parent or guardian, contact us and we will delete it.

10 Changes to this policy

If we change how we handle personal data, we will update this page and the date at the top. If a change is significant, we will tell you by email or in the app.

11 Contact

Any privacy question, request or concern: SimplySolid3D@gmail.com. See also our Terms of Service.