Legal

Privacy Policy

A plain-English account of what we collect when you visit or buy from XO3D Shop, why we collect it, who else sees it, and how you exercise your rights.

Last reviewed: 22 July 2026

1. Who we are

For the purposes of the UK GDPR and the Data Protection Act 2018, the data controller is XO3D Ltd, a company registered in England and Wales, company number11876020, VAT 394 5800 68, based in Stevenage, UK. Contact us about anything on this page at[email protected].

2. What we collect

Two categories, depending on how you use the site:

  • Purchase data. When you buy a model: name, email, billing address, VAT number where supplied, the product bought, the amount paid and the timestamp. Card details go directly to Stripe and never touch our servers.
  • Site-usage data. When you browse: page URL, the page you came from, device and browser type, an approximate country derived from IP, and interactions with our forms and downloads. All of this only when you’ve given consent through the cookie banner.

3. Why we collect it

  • To fulfil your order (issue a receipt, deliver the download link, respond to support tickets). Lawful basis: contract performance.
  • To comply with tax and accounting law. Lawful basis: legal obligation.
  • To understand which products and pages are useful, and improve the site. Lawful basis: consent (cookies) or legitimate interest for aggregated, non-identifying analytics.
  • To respond to enquiries submitted through our contact form. Lawful basis: legitimate interest in running the business.

4. Who else sees it (third parties)

We rely on a small set of trusted processors. Each one is bound by contract to protect your data and use it only for the purpose we set.

  • Stripe — payment processing. Sees name, email, billing address and card details. Independent controller for anti-fraud purposes. Stripe Privacy Policy.
  • HubSpot — CRM and email delivery for order confirmations, support conversations and marketing emails you opted in to. HubSpot Privacy Policy.
  • Cloudflare — site hosting, CDN and DDoS protection. Sees your IP address and request metadata. Cloudflare Privacy Policy.
  • Google Analytics 4 (GA4) — aggregated site-usage analytics, only after cookie consent. IP anonymisation is enabled. Google Privacy Policy.
  • Microsoft Clarity — session replay and heatmaps to spot UX issues. Only after cookie consent. Microsoft Privacy Statement.
  • LinkedIn Insight Tag, Meta (Facebook) Pixel, Pinterest and Lemlist — advertising-audience attribution and website visitor tracking. Load only after you accept the “advertising” cookie category.
  • SharePoint (Microsoft 365) — storage of the downloadable model archives that customers receive after purchase. No personal data is stored on SharePoint; it holds the product files only.

5. Cookies

We use cookies in three categories:

  • Strictly necessary — make the site work (session, security, cart state). No consent needed.
  • Analytics — GA4 and Microsoft Clarity. Load only if you accept the “analytics” category in the consent banner.
  • Advertising — LinkedIn, Meta Pixel, Pinterest, Lemlist. Load only if you accept the “advertising” category.

You can change or withdraw consent at any time via the cookie banner (accessible from the footer). Withdrawing consent doesn’t affect the lawfulness of what we did before.

6. International transfers

Some of our processors (Stripe, HubSpot, Google, Microsoft, Meta) are based in the United States or transfer data to the US. Where they do, they rely on the UK addendum to the EU Standard Contractual Clauses (or the UK International Data Transfer Agreement) to safeguard your data. If you’d like copies of the specific transfer mechanisms in use, email us.

7. How long we keep data

  • Order records (invoices, tax records) — 6 years, as required by UK tax law.
  • Support conversations — 2 years, then reviewed and either archived or deleted.
  • Analytics data — 14 months in GA4, then aggregated.
  • Marketing lists — until you unsubscribe. Every email includes a one-click unsubscribe link.

8. Your rights

Under the UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct anything that’s wrong or incomplete.
  • Have your data erased where the law allows.
  • Restrict or object to how we use it.
  • Receive a portable copy of the data you gave us.
  • Withdraw consent at any time (via the cookie banner or by emailing us).

To exercise any of these rights, email[email protected]. We respond within one month. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk) if you think we’ve mishandled your data.

9. Security

Traffic to and from shop.xo3d.co.uk is served over HTTPS. Payment data is handled by Stripe under PCI-DSS Level 1. Our own systems are protected by role-based access, MFA on administrator accounts, and Cloudflare’s edge security. No system is invulnerable, but we take reasonable steps proportionate to the sensitivity of the data we hold.

10. Children

XO3D Shop is aimed at professional and studio users. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, contact us and we’ll delete it.

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to registered customers and posted here with a new “last reviewed” date.

This policy sits alongside our Terms of Serviceand Returns and refund policy.