Legal

Privacy Policy

This policy explains what Cadloom processes to provide its Shopify 3D product service and the choices available to merchants.

Last updated: August 12, 2026

1. Scope

This Privacy Policy applies to the Cadloom website, Shopify application, model-processing service, storefront viewer, and related support interactions. Cadloom is designed for merchants and does not request access to Shopify customer or order data.

2. Information we process

We process only the information needed to operate Cadloom:

  • Shopify shop domain, installation sessions, granted scopes, and technical identifiers.
  • Product identifiers, titles, model status, and publication references for products managed in Cadloom.
  • Uploaded STEP, GLB, glTF, ZIP, and related model files; generated 3D assets; conversion reports; filenames; sizes; and processing metrics.
  • Viewer settings such as camera, orientation, environments, materials, feature permissions, and generated thumbnails.
  • Daily product-level storefront viewer totals, such as viewer loads, visible sessions, interactions, feature usage, engagement duration, AR launches, and add-to-cart assists. These aggregates do not include customer names, emails, IP addresses, or persistent shopper profiles.
  • Plan, entitlement, managed-product usage, and subscription status supplied by Shopify.
  • Support messages and diagnostic information you choose to provide.
  • Security and operational logs, including shop, job, request, error, timing, IP-address, browser, and device identifiers.

3. How we use information

  • Authenticate the merchant and keep each shop's data isolated.
  • Receive, validate, convert, optimize, preview, and publish 3D models.
  • Save product-specific viewer settings and provide storefront functionality.
  • Provide merchants with aggregated information about 3D viewer adoption and engagement.
  • Apply plan limits, prevent abuse, troubleshoot failures, and improve reliability.
  • Respond to support, privacy, security, and legal requests.

Cadloom does not sell merchant data or use uploaded models to train shared artificial-intelligence models.

4. Website and cookies

The public Cadloom website does not currently use advertising cookies or sell visitor profiles. It records aggregate install, demo, and walkthrough link selections together with the page and campaign parameters supplied in the URL. This first-party measurement does not create a persistent visitor profile. The storefront viewer records product-level usage totals without setting Cadloom advertising cookies or creating persistent shopper profiles. Hosting providers may process standard request information needed to deliver and protect the service. If Cadloom introduces optional cookies or identity-based analytics, this policy and any required consent controls will be updated.

5. Service providers

Cadloom uses Shopify for installation, product integration, billing, hosted media, and theme delivery; Google Cloud for application hosting, processing, databases, object storage, queues, secrets, and operational monitoring; Cloudflare-hosted infrastructure for the public website; and YouTube's privacy-enhanced player for an optional onboarding walkthrough. The YouTube player is loaded only after the merchant chooses to watch it. These providers process information under their own contractual and security obligations.

6. Sharing and disclosure

We disclose information to service providers only as needed to operate Cadloom. We may also disclose information when required by law, to protect rights and security, or in connection with a business transaction subject to appropriate safeguards. We do not disclose private source CAD files to storefront visitors. Only a model the merchant explicitly publishes becomes Shopify product media.

7. Security

Cadloom uses encrypted transport, access controls, tenant-scoped storage paths, signed upload and download URLs, private processing services, secret management, authenticated webhooks, and operational monitoring. No system is completely secure, and merchants should avoid uploading information that is unnecessary for the product experience.

8. Retention and deletion

Data is retained while needed to provide the service and according to the Data Retention Policy. Deleting a Cadloom product setup removes its stored source and generated assets. After app uninstall, Shopify sends Cadloom a shop-redaction request; Cadloom then deletes the shop's application sessions, stored models, job records, billing entitlement records, and aggregated storefront analytics, unless limited retention is legally required.

9. Merchant choices and privacy requests

Merchants can replace, unpublish, or delete model setups from Cadloom. For access, correction, deletion, or other privacy requests, email support@cadloom.com from an address associated with the Shopify store. We may verify store ownership before acting.

10. International processing

Cadloom and its providers may process information in countries other than the merchant's country. Where required, appropriate contractual or legal transfer safeguards apply.

11. Changes

We may update this policy as Cadloom evolves. Material changes will be reflected by a new effective date and, when appropriate, notice through the application or Shopify listing.