Privacy Policy

Privacy Policy

Last updated: 23 July 2026

This Privacy Policy explains how 3D Ture ("3D Ture", "we", "us" or "our") collects, uses, shares and protects personal data when you use our 3D spatial-capture and virtual-tour platform at https://3dture.com and its associated web application (the "Service"). 3D Ture is operated by 3D Ture, established in Latvia, European Union. We act as the data controller for the personal data described here. Because we are established in the EU and serve EU data subjects, we process personal data in accordance with the EU General Data Protection Regulation (GDPR). This policy is written in plain language and describes only what our software actually does today.

1.Who we are

3D Ture is a platform that turns spatial scans (for example point-cloud files such as E57, panoramas and images) into hosted, interactive 3D virtual tours. It also offers optional AI-assisted 3D asset generation and branded transactional email for business tenants.

Data controller: 3D Ture (established in Latvia, EU)

Registered address: Nometnu street 26, Riga, LV-1002, Latvia

General / business contact: info@3dture.lv

Privacy, support and data-rights requests: support@3dture.com

If you have any question about this policy or about how we handle your personal data, please contact us at support@3dture.com.

2.Scope & closed-pool access

3D Ture is currently a closed, invitation-only platform. It is not open to the general public and is used by a limited pool of allowlisted staff and pilot accounts.

  • There is no public sign-up form. Accounts are created for you by an administrator. The only identity information collected when your account is created is what the administrator enters — typically your email address, an optional internal role attribute, and your group/role assignment.
  • Sign-in is additionally restricted by an allowlist of authorised email addresses. Anyone who is not on the allowlist is refused access, even if they otherwise hold valid credentials.

Our public marketing website and its contact form are open to anyone; the closed-pool restriction does not apply to them. Those surfaces are covered by this policy as well.

This policy applies to the 3D Ture application and website. It does not cover third-party services that you separately choose to use (such as your own Meshy account), which are governed by their own privacy policies.

3.Personal data we collect

Account and authentication data

Access is by invitation only, so we do not collect a self-service profile. In connection with your account and each signed-in request we process:

  • your account email address, which is also your login identity (held in AWS Cognito);
  • a stable internal user identifier (your Cognito "sub");
  • your group memberships and role assignments, which determine what you are allowed to do;
  • whether your email address has been verified;
  • an optional internal "role" attribute that administrators may set for access-control and audit purposes.

We also maintain an allowlist of authorised email addresses that controls who may sign in. Self-registration is not possible — any direct sign-up attempt is refused, and the attempted email address may be recorded in our security logs. Sign-in by an address that is not on the allowlist is likewise refused.

Connected Google account email (Branded-Email feature only)

If an administrator uses the optional "Connect Google" step of our Branded-Email setup wizard, we receive the verified email address of the connected Google account. This is not a way to sign in to the product and is available only to authorised staff. See the dedicated section "Google user data & Limited Use" below.

Spatial scans and tour content

When you (or a staff operator on your behalf) create a project, we process:

  • the raw scan / point-cloud file you upload (e.g. E57, LAS or GLB);
  • the processed 3D assets we generate from it (3D meshes, level-of-detail models, point-cloud tiles, panorama/equirectangular images, thumbnails and related metadata);
  • project and tour metadata you provide or that is generated during processing — project name, description, tags, status, original file name and size, a content fingerprint, upload/processing settings, viewer preferences, a processing trace log, asset links and a view counter;
  • your consent choice for each project and its full change history (see "3D scans, tour content & your consent choices");
  • share-link settings you configure, which may include an access tier, a share token, a hashed share password, email addresses of viewers you choose to invite, an optional expiry, and a view count.

Uploaded scans and the tours built from them are your content.

Personal data in the content you upload, and data about other people

Spatial scans can depict real places and may incidentally capture people or personal information (for example, images of individuals, or of documents visible in a room). When you invite specific people to view a shared tour, you also provide us their email addresses. In these cases the personal data reaches us from you (or the account owner), not from the individuals themselves.

For the content of the scans you upload, you (or the organisation that enrolled you) decide why and how that content is captured and used through the Service; we process it on your instructions to provide the Service to you. You are responsible for having a lawful basis to capture, upload and process that content, and for informing any identifiable person in a scan — or anyone you invite to a shared tour — as the law requires. Please only upload scans you are entitled to upload (see our Terms).

Contact-form submissions

Our public contact form collects the name, email address and message you type. This information is not stored in a database. It is sent directly to our team by email, with your email address used as the reply-to address so we can respond.

Bring-your-own-key credentials (Meshy)

If you use the optional AI generation feature, you may connect your own Meshy API key. We store it encrypted and never display or return the full key — only its last four characters and validation metadata are shown. See "AI-assisted generation… Meshy (BYOK)" and "How we protect your data".

Technical and usage data

  • Authentication session cookies (see "Cookies & local storage").
  • IP address — derived from your request headers, used transiently to rate-limit the contact form and forwarded to Cloudflare for bot/CAPTCHA verification. It is held only in server memory (for up to one hour, for contact-form rate-limiting) and is not written to a database by us. (AWS, our hosting provider, may separately record request metadata in its own infrastructure logs, outside our application code.)
  • Bot-verification (CAPTCHA) tokens issued by Cloudflare Turnstile on the contact form and the login gate.
  • Short-lived processing-progress logs of the upload/processing pipeline (stage, message, timestamps and internal identifiers), which are automatically deleted about 30 minutes after they are written. Separately, our infrastructure keeps security and operational server logs (see "How long we keep your data").
  • AI generation prompts — see the AI section; we keep only a one-way hash of the prompt, not the prompt text.

What we do NOT collect

We do not use web analytics, product-analytics SDKs, advertising trackers, or cross-site tracking of any kind. There is no Google Analytics, no advertising pixel, and no behavioural ad-tech in the product. We do not sell or share personal data with advertising networks. The only usage measurement is a simple first-party per-project view counter.

4.How and why we use your data (legal bases)

Under the GDPR we must have a lawful basis for each use of your personal data. We identify a single primary basis for each purpose below.

| What we do | Why | Legal basis (GDPR Art. 6) | |---|---|---| | Create and operate your account; authenticate each request | To let you access and use the Service | Performance of a contract (Art. 6(1)(b)) where you contract with us directly; otherwise our legitimate interest in providing the platform to the organisation that enrolled you (Art. 6(1)(f)) | | Host your scans, build and serve your 3D tours, run the processing pipeline | To provide the core Service you requested | As above — contract, or our legitimate interest in providing the Service | | Send you service notifications (e.g. "your tour is ready" or a processing-failure notice) to your account email | To keep you informed about your own projects | Our legitimate interest in keeping you informed about your projects | | Enforce the closed-pool allowlist, force-log-out non-allowlisted sessions, rate-limit and CAPTCHA-verify forms, keep short-lived and security logs | To secure the platform and prevent abuse | Our legitimate interest in the security and integrity of the Service | | Use your uploaded scans to train or improve our AI models, or include them in commercial datasets/research | Only if you actively opt in | Your explicit consent (Art. 6(1)(a)) — the "Help improve the platform" or "Allow full commercial use" level you choose | | Connect a Google account for the Branded-Email feature | To identify the forwarding inbox you chose | Your consent, and our legitimate interest in providing the feature you requested | | Generate 3D assets via Meshy using your own key | To provide the feature you triggered | Our legitimate interest in providing the feature you initiated (performed under your own Meshy account) | | Respond to contact-form enquiries | To answer you and, where relevant, take steps toward a business relationship | Steps taken at your request prior to a contract (Art. 6(1)(b)) / our legitimate interest in responding to you | | Meet legal, accounting or regulatory obligations | Where the law requires it | Legal obligation (Art. 6(1)(c)) |

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms, and you may object to that processing at any time (see "Your data-protection rights"); we can provide a summary of the relevant balancing assessment on request.

The default consent level for every uploaded scan is "Processing Only" — meaning no AI training and no commercial use. AI-training or commercial use never happens unless you deliberately select a higher consent level, and you can change your choice at any time. You may withdraw consent at any time; withdrawal does not affect processing carried out before withdrawal.

5.Google user data & Limited Use disclosure

3D Ture offers an optional "Connect Google" step inside our Branded-Email setup wizard. This feature is available only to authorised staff/administrators. It is not a way to sign in to the product.

When an administrator uses it, we ask Google only for the `openid email` scope (a non-sensitive scope). We use it solely to read the verified email address of the Google account being connected, so that address can be set as the inbound-mail forwarding target for a branded sending domain.

  • We do not request access to your Gmail, Google Drive, Calendar, contacts, profile, or any other Google data.
  • The tokens Google issues during this flow are used once, in server memory, to read the verified email address, and are then discarded. We never store, log, or return any Google-issued access, refresh or ID token, and we never send them to the browser.
  • Only the resulting email address string is stored — as the forwarding target on the relevant branded-domain record.

Limited Use. 3D Ture's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, the Google account email obtained through this feature is used solely to identify and configure the forwarding inbox for the Branded-Email feature. It is not sold, not used for advertising, not used to train generalized AI/ML models, and not transferred to any third party except as necessary to provide this feature to you, to comply with applicable law, or in connection with a merger or acquisition as permitted by that policy.

7.AI-assisted generation, remote processing & Meshy (BYOK)

Processing your uploads. When you upload a scan, we process it on AWS in the EU to generate your interactive 3D tour. Larger scans may be routed through an automated AWS processing pipeline (Step Functions with Fargate or Batch compute) in the same EU region. Short-lived progress logs are generated during processing and auto-deleted about 30 minutes later. Uploaded files may be automatically scanned by AWS Macie for sensitive data as a security measure; this scanning does not block your upload.

Optional AI 3D generation with Meshy (Bring-Your-Own-Key). 3D Ture can generate 3D assets from a text prompt using Meshy (`api.meshy.ai`), a third-party "text-to-3D" service. This feature uses a Bring-Your-Own-Key (BYOK) model:

  • You connect your own Meshy API key, and generation runs entirely under your own Meshy account, credits and terms. We do not proxy or pay for end-user generation.
  • Your key is first validated against Meshy, then stored encrypted (see "How we protect your data"). We never display or return the full key — only its last four characters and validation metadata.
  • When you generate an asset, the text prompt you type is sent to Meshy over HTTPS to fulfil your request. We do not store the plaintext prompt; we keep only a one-way SHA-256 hash of it for provenance.
  • Before any prompt is sent, it passes through an in-region AWS content-moderation step (AWS Bedrock); the moderation result is not stored.
  • The 3D model and thumbnail Meshy returns are copied into our EU storage for durability and served to you through short-lived signed links.

At present, only the text prompt is transmitted to Meshy for this feature — your raw scan and panorama files are not sent to Meshy. Please do not include personal data about other people in your prompts, as the prompt text leaves our platform and is sent to Meshy. (On the separate, staff-only marketplace generation path, prompts are sent to Meshy under the platform's own Meshy key rather than a personal key.) Meshy is an external provider whose servers may be located outside the EU; please review Meshy's own privacy terms, as your use of your Meshy account is governed by your agreement with Meshy.

8.Service providers & sub-processors

We rely on the following processors to run the Service. Where a provider is outside the EU, transfers are made under appropriate safeguards (see "International data transfers & EU hosting").

| Provider | Purpose | Region | |---|---|---| | Amazon Web Services — Cognito | Authentication, session tokens, closed-pool allowlist enforcement | EU — Stockholm (eu-north-1) | | AWS — AppSync + DynamoDB | Application database: project metadata, consent records & history, share settings, encrypted BYOK keys | EU — Stockholm (eu-north-1) | | AWS — S3 | Storage of uploaded scans, generated 3D assets, panoramas and thumbnails | EU — Stockholm (eu-north-1) | | AWS — CloudFront | Content-delivery network for processed/published tour assets, panoramas and thumbnails (origin in EU Stockholm) | Global edge network (EU origin) | | AWS — SES | Sending transactional and notification email | EU — Frankfurt (eu-central-1) | | AWS — CloudWatch / X-Ray, SSM Parameter Store, Macie, KMS, Bedrock | Operational logging & tracing, allowlist parameter storage, sensitive-data scanning, encryption-key management, AI prompt moderation | EU — Stockholm (eu-north-1) | | Google LLC | "Connect Google" email verification for the Branded-Email feature only (scope `openid email`) | Google global infrastructure | | Cloudflare, Inc. | Bot/CAPTCHA verification (Turnstile) on the contact form and login gate; DNS/CDN for 3dture.com; tenant inbound-mail routing setup | Cloudflare global edge network | | Meshy | Optional AI text-to-3D generation, under your own key (BYOK) | External — outside the EU (vendor region not specified) |

The Cloudflare Turnstile widget loads in your browser to perform bot detection and may set its own cookies or local state as part of Cloudflare's product, outside our control. We use `next/font` to self-host our typeface (Inter), so no runtime request is made to Google Fonts. We do not use any advertising or analytics sub-processors.

9.Cookies & local storage

We use only the cookies necessary to operate the Service. We set no advertising, analytics or tracking cookies — only the strictly necessary cookies listed below, which are exempt from consent because they are required for security and for services you explicitly request.

Cookies

  • `CognitoIdentityServiceProvider*` — one or more strictly necessary, httpOnly cookies that hold your authenticated session (managed by AWS Amplify). They are cleared/expired immediately if a signed-in account is found not to be on the allowlist. Lifetime follows standard AWS Cognito token lifetimes.
  • `google_oauth_state` — a short-lived, httpOnly security (anti-CSRF) cookie used only during the "Connect Google" flow. It is scoped to that flow, expires after 10 minutes, and is single-use.

Browser local storage (stored on your device, not sent to us unless noted):

  • `3dture.upload.resume.*` — lets an interrupted upload resume (upload identifiers and settings only; kept up to 7 days, max 10 entries).
  • `nextonline.nestedObjects.<assetKey>` — your in-tour object/decoration placements.
  • `3dture-a11y-autoswitch-dismissed` and `cx-consent-upgrade-prompted:<projectId>` — one-time UI-dismissal flags (no personal data).
  • `userPerfPref` — your device/performance preference; for signed-in users this may also be synced to our own EU database (not to any third party).

The Cloudflare Turnstile widget may independently store its own state for bot detection, as described under "Service providers & sub-processors".

10.How long we keep your data

| Data | Retention | |---|---| | Account data (email, roles, verification status) | For the life of your account; account deletion is a manual administrator action | | Allowlist of authorised emails | Until an operator edits or removes it | | Raw uploaded scan files | Retained until erased. Moved to cold "Glacier" storage after ~30 days; no automatic expiry is configured today. Deleting a project currently removes its database record only — the files remain in encrypted EU storage until purged by an operator or on your erasure request (see the deletion note below) | | Processed 3D assets, panoramas, thumbnails | Retained until erased; no automatic expiry is configured today. As above, deleting a project does not currently remove these files automatically | | Project metadata, consent level & consent history | Kept until the project record is deleted; consent history is append-only | | Share-link settings | Kept until you change/clear sharing or delete the project | | Branded-email domain settings (display name, reply-to and forwarding-target email addresses, incl. any connected Google account email, DNS/verification status) | Kept in our server-side configuration store until the domain is removed by an administrator; the associated email-sending identity at AWS SES is removed separately by an operator | | Live upload/processing progress logs | Automatically deleted ~30 minutes after creation | | Security and operational server logs (AWS CloudWatch / CloudTrail, EU) — including denied sign-up attempts | Retained per our infrastructure log-retention settings (provider default periods) | | Contact-form submissions | Not stored by us; delivered by email only | | IP address — contact form | Held in server memory for up to 1 hour for rate-limiting; also sent once to Cloudflare for bot verification; not stored to disk by us | | IP address — login gate | Processed transiently and sent once to Cloudflare for bot verification; not retained by the app | | Meshy BYOK credential | Encrypted, kept until you delete it | | AI prompt text | Not stored (only a one-way hash is kept for provenance) | | Google-issued OAuth tokens | Not stored — discarded immediately after the email is read | | `google_oauth_state` cookie | 10 minutes |

Important note on deleting a project. When you delete a project, we currently remove its database record only. Because of how our storage is configured today, the underlying uploaded scan file and generated assets remain in our encrypted EU storage until they are purged by an operator — they are not yet automatically deleted at the same time. Copies may also persist for a limited period in content-delivery-network (CDN) caches (up to about one year) and in versioned storage / backups. If you delete a project or ask us to erase your data, we will permanently delete the associated files — including prior file versions — and invalidate CDN caches within 30 days of your request. To have us fully erase all files associated with a project or your account, email support@3dture.com (see "Your data-protection rights"). We are also working to align our automated storage deletion with project deletion.

11.How we protect your data

We take technical and organisational measures appropriate to the risk, including:

  • Encryption in transit — all traffic to the application and to our providers uses HTTPS/TLS.
  • Encryption at rest — files in S3 are server-side encrypted; a dedicated sensitive-data store and operational logs are encrypted with AWS KMS.
  • Your Meshy API key is encrypted with AES-256-GCM using a 32-byte, server-only master key and a fresh random initialisation vector per encryption; it is authenticated (tampered ciphertext is rejected rather than silently decrypted), never logged, and never returned to your browser.
  • Share-link passwords are never stored in plaintext — they are hashed with PBKDF2-HMAC-SHA256 (210,000 iterations) with a per-link salt.
  • Access controls — a closed, invitation-only user pool; an allowlist enforced at three independent layers that all fail closed (deny by default) if unset in production; role-based authorisation on every owner-scoped action; and automatic force-logout of any authenticated session that is not on the allowlist.
  • Session cookies are httpOnly and managed server-side.
  • Abuse protection — Cloudflare Turnstile bot verification and rate-limiting on public forms; AWS Macie scanning of uploads for sensitive data.

No system can be guaranteed 100% secure, but we work to protect your data and to notify you and the competent authority of any personal-data breach where legally required.

12.International data transfers & EU hosting

Your application data and files are stored and processed within the European Union — AWS Stockholm (eu-north-1) for application data and file storage, and AWS Frankfurt (eu-central-1) for outbound email. Both are EU regions.

However, published/processed tour content (3D assets, panoramas, thumbnails) is delivered through Amazon CloudFront and may be cached at CloudFront edge locations worldwide for up to about one year to speed up delivery. This edge delivery is covered by the AWS Data Processing Addendum.

Some of our sub-processors also operate outside the EU/EEA:

  • Google (for the Branded-Email "Connect Google" email verification) processes data on Google's global infrastructure;
  • Cloudflare (Turnstile bot verification, DNS/CDN) operates a global edge network;
  • Meshy (optional AI generation, under your own key) is hosted outside the EU.

Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and/or an applicable adequacy decision. You can contact us for more information about these safeguards.

13.Your data-protection rights

Subject to the conditions and exceptions in the GDPR, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten");
  • Restrict our processing in certain circumstances;
  • Object to processing based on our legitimate interests;
  • Data portability — receive certain data in a structured, machine-readable format;
  • Withdraw consent at any time where processing is based on consent (for example, your AI-training/commercial consent level), without affecting processing already carried out.

Automated decision-making. We do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. Automated bot-detection (Cloudflare Turnstile) and AI content-moderation checks are used only to secure the Service and prevent abuse.

To exercise any of these rights, contact support@3dture.com. We will respond within the timeframes required by law (generally within one month). We may need to verify your identity before acting on a request.

You also have the right to lodge a complaint with a supervisory authority. In Latvia this is the Data State Inspectorate (Datu valsts inspekcija) — https://www.dvi.gov.lv. You may also complain to the supervisory authority in your country of residence or work.

14.Children's data

3D Ture is a business tool intended for authorised staff and pilot organisations. It is not directed at children and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact support@3dture.com and we will take appropriate steps to delete it.

15.Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our practices, or legal requirements. When we make material changes, we will update the "Last updated" date at the top and notify affected users (for example, by email or an in-app notice) before the changes take effect. We encourage you to review this policy periodically.

16.How to contact us

For any privacy question, or to exercise your rights:

  • Privacy & data-rights requests / support: support@3dture.com
  • General / business enquiries: info@3dture.lv
  • Postal address: Nometnu street 26, Riga, LV-1002, Latvia
  • Data controller: 3D Ture

We aim to respond to all privacy enquiries promptly.