"Print3D" is owned and operated by RyLex Industries LLC ("RyLex Industries," "we," "us," or "our"). We operate an engineering-grade 3D print farm and this ordering platform. This Privacy Policy explains what personal information we collect, how we use and share it, how long we keep it, and the rights you have regarding your data.

This policy applies to all users of our website, ordering platform, and related services, regardless of where you are located, and complies with:

  • The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), as amended
  • The New York SHIELD Act and NY Privacy Act obligations applicable to us
  • The EU/UK General Data Protection Regulation (GDPR / UK GDPR) for individuals accessing our service from the European Economic Area or United Kingdom
  • Applicable US federal privacy obligations

1. Information We Collect

1.1 Information You Provide
  • Account information: full name, email address, and a hashed password when you register.
  • Order and shipping information: delivery address, phone number, order specifications, quantity, material preferences, and any special instructions.
  • Uploaded files: 3D model files (STL, STEP, or similar) you submit for quoting or manufacturing.
  • Payment information: billing address. All card processing is handled by Stripe, Inc., a PCI-DSS Level 1 certified processor. We do not receive, store, or transmit raw card numbers, CVV codes, or full card details on our infrastructure.
  • Communications: emails, support tickets, or other messages you send us, including any personal information contained therein.
  • NDA and legal records: if you request a mutual NDA, we record your name, email, IP address, and the date and time of electronic acceptance.
1.2 Information Collected Automatically
  • Log data: IP address, browser type and version, operating system, pages visited, time and date, referring URL, and session duration, collected by our servers and NGINX.
  • Device identifiers: HTTP headers and similar technical identifiers transmitted automatically by your browser.
  • Session data: encrypted session cookies required for authentication and security. We do not use third-party advertising or tracking cookies.
1.3 Sensitive Personal Information

We do not intentionally collect sensitive categories of personal information (health data, biometric data, racial or ethnic origin, etc.). 3D model files may reveal information about intended use; we treat all uploaded files as confidential under our Mutual NDA terms.

2. How We Use Your Information

We use personal information for the following purposes:

Purpose Legal basis (GDPR) California category
Creating and managing your account Contract performance Identifiers
Processing and fulfilling print orders Contract performance Commercial information
Payment processing via Stripe Contract performance Financial information
Shipping and delivery Contract performance Identifiers, commercial information
Customer support and communications Legitimate interest / contract Identifiers, communications
Security monitoring and fraud prevention Legitimate interest Internet activity information
Legal compliance and record-keeping Legal obligation All categories as required
Service improvements and analytics (aggregated, non-identifying) Legitimate interest Internet activity information
Sending order status, shipping, and transactional emails Contract performance Identifiers

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We do not use personal information for automated decision-making that produces legal or similarly significant effects without human review.

3. How We Share Your Information

We share personal information only as described below:

  • Service providers (sub-processors): Stripe (payment processing), shipping carriers (FedEx, UPS, USPS, or similar) for label and tracking data, transactional email providers, cloud hosting providers. All sub-processors are bound by data processing agreements that prohibit use of your data for their own purposes.
  • Compliance and legal process: we disclose information when required by law, court order, or governmental authority, and when necessary to protect our rights, property, or the safety of users or the public.
  • Business transfers: in the event of a merger, acquisition, or sale of assets, personal information may be transferred to the successor entity, who will be bound by this policy or one offering equivalent protection.
  • With your consent: for any other purpose with your explicit consent.

We do not share uploaded model files or NDA-protected design data with any third party except sub-processors necessary to manufacture your order, all of whom are bound by confidentiality obligations.

4. Data Retention

  • Account data: retained while your account is active and for 7 years after closure for tax, legal, and warranty purposes, unless a shorter period is required by law.
  • Order records: retained for 7 years to satisfy US tax and commercial record-keeping requirements.
  • Uploaded model files: retained for 90 days after order completion. You may request earlier deletion by contacting us in writing. Files may be retained longer if needed to resolve disputes or as required by law.
  • Server logs: retained for 90 days, then purged.
  • NDA records: retained for 3 years from acceptance plus any additional period required by applicable law.
  • Communications and support records: retained for 3 years after resolution.

5. Data Security

We implement technical and organizational security measures appropriate to the risk, including:

  • TLS 1.2+ encryption for all data in transit
  • Encryption at rest for databases and file storage
  • Argon2id password hashing — we never store plaintext passwords
  • Time-based one-time password (TOTP) multi-factor authentication, available to all account holders
  • Role-based access controls limiting staff access to data required for their function
  • ClamAV antivirus scanning of all uploaded files
  • Audit logging of all data access and modifications
  • Regular security reviews and vulnerability assessments

No method of transmission or storage is 100% secure. In the event of a data breach affecting your personal information, we will notify you and applicable regulators as required by federal and state law, including within the timeframes required by the NY SHIELD Act (most expedient time possible, not to exceed 30 days for New York residents) and applicable state breach notification laws.

6. Cookies and Tracking Technologies

We use the following cookies:

  • Session cookie (strictly necessary): an encrypted server-side session identifier required for login, CSRF protection, and cart functionality. Without this cookie the platform cannot function. This cookie expires when you close your browser or after 12 hours of inactivity.
  • CSRF token: a single-use security token that prevents cross-site request forgery attacks. Strictly necessary.

We do not use advertising cookies, cross-site tracking pixels, Google Analytics, Facebook Pixel, or any third-party tracking technology. Our products are ad-free and we do not share browsing data with advertisers.

7. Your Privacy Rights

7.1 Rights Available to All US Residents
  • Request access to the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal information (subject to legal retention obligations)
  • Opt out of any future sale or sharing of your personal information (note: we do not currently sell or share personal information for cross-context behavioral advertising)
7.2 California Residents (CCPA/CPRA)

In addition to the rights above, California residents have the right to:

  • Know the categories and specific pieces of personal information we have collected about you in the past 12 months
  • Know the categories of sources, business purposes, and third parties to whom personal information was disclosed
  • Delete personal information we have collected, subject to exceptions
  • Correct inaccurate personal information
  • Opt out of the sale or sharing of personal information. Print3D does not sell or share personal information as defined under the CCPA/CPRA.
  • Limit use of sensitive personal information (we do not collect sensitive personal information as defined under CPRA beyond what is necessary to provide the service)
  • Non-discrimination: we will not discriminate against you for exercising your CCPA/CPRA rights

California residents may submit requests via the contact information in Section 9. We will respond within 45 days (extendable by an additional 45 days with notice).

7.3 New York Residents (NY SHIELD Act)

New York residents are protected by the Stop Hacks and Improve Electronic Data Security (SHIELD) Act. We maintain a data security program that includes reasonable administrative, technical, and physical safeguards appropriate to the size and complexity of our business and the sensitivity of the personal information we handle. In the event of a breach of private information of a New York resident, we will notify affected individuals in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement and the measures necessary to determine the scope of the breach.

7.4 EU/EEA and UK Residents (GDPR / UK GDPR)

Individuals in the EU, EEA, or UK have the following rights under the GDPR (and equivalent UK GDPR):

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure ("right to be forgotten," Article 17) — subject to legal retention obligations
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20) — for data processed by automated means on the basis of your consent or a contract
  • Right to object (Article 21) — to processing based on legitimate interests
  • Right to withdraw consent at any time, without affecting the lawfulness of prior processing
  • Right to lodge a complaint with your local supervisory authority

International transfers: our servers and sub-processors are located in the United States. If you access our service from the EU/EEA/UK, your personal information is transferred to the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other approved transfer mechanisms, for transfers from the EEA/UK to the US where required. You may obtain a copy of the applicable transfer mechanism by contacting us.

Data Protection Officer: given the scale of our operations, we are not required to designate a formal DPO under GDPR. Privacy inquiries from EU/UK residents are handled directly by our management team. Contact information is in Section 9.

8. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected personal information from a child under 18, please contact us immediately using the information in Section 9 and we will delete it promptly.

9. Contact Us & Exercising Your Rights

To exercise any privacy right, submit a data request, or ask questions about this policy, contact us by:

  • Email: [email protected]
  • Mail: RyLex Industries LLC (Print3D), Attn: Privacy, Morton Grove, IL 60053, United States

We will verify your identity before fulfilling a data access or deletion request. California residents may designate an authorized agent to make requests on their behalf; we will require written proof of authorization and may verify your identity directly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by posting the updated policy with a revised effective date and, where required by law, by direct notification to affected users via email. Continued use of our services after the effective date constitutes acceptance of the updated policy. We encourage you to review this page periodically.

This Privacy Policy was prepared for RyLex Industries LLC (operating as Print3D) and reflects our current practices as of the effective date above. It does not constitute legal advice. If you operate a print farm and wish to adapt this policy for your own use, consult a qualified attorney familiar with the privacy laws applicable to your jurisdiction and business.