Privacy Policy

Privacy Policy

Last updated: 15 August 2026

This Privacy Policy explains how 3D Ture ("3D Ture", "we", "us" or "our") collects, uses, shares and protects personal data when you use our 3D spatial-capture and virtual-tour platform at https://3dture.com and its associated web application (the "Service"). 3D Ture is operated by AMSTORM SIA (trading as "3D Ture"), registration No. 40203102670, established in Latvia, European Union. We act as the data controller for the personal data described here. Because we are established in the EU and serve EU data subjects, we process personal data in accordance with the EU General Data Protection Regulation (GDPR). This policy is written in plain language and describes only what our software actually does today.

Scope. This Privacy Policy covers the 3D Ture platform (web application). Privacy information for viewers of Matterport-based virtual tours is provided in the Virtual Tour Terms of Use and Privacy Notice (Latvian).

1.Who we are

3D Ture is a platform that turns spatial scans (for example point-cloud files such as E57, panoramas and images) into hosted, interactive 3D virtual tours. It also offers optional AI-assisted 3D asset generation and branded transactional email for business tenants.

Data controller: AMSTORM SIA (trading as "3D Ture"), registration No. 40203102670, established in Latvia, EU

Legal address: Nometņu iela 38 – 17, Salaspils, Salaspils novads, LV-2121, Latvia

Business address: Nometņu iela 26, Rīga, LV-1048, Latvia

Data-protection contact: We have not appointed a Data Protection Officer — this is not required for our size and processing activities under GDPR Article 37. For data-protection questions, our contact person is Atis Meiers, reachable at support@3dture.com.

General / business contact: info@3dture.lv

Privacy, support and data-rights requests: support@3dture.com

If you have any question about this policy or about how we handle your personal data, please contact us at support@3dture.com.

2.Scope & closed-pool access

3D Ture is currently a closed, invitation-only platform. It is not open to the general public and is used by a limited pool of allowlisted staff and pilot accounts.

  • There is no public sign-up form. Accounts are created for you by an administrator. The only identity information collected when your account is created is what the administrator enters — typically your email address, an optional internal role attribute, and your group/role assignment.
  • Sign-in is additionally restricted by an allowlist of authorised email addresses. Anyone who is not on the allowlist is refused access, even if they otherwise hold valid credentials.

Our public marketing website and its contact form are open to anyone; the closed-pool restriction does not apply to them. Those surfaces are covered by this policy as well.

This policy applies to the 3D Ture application and website. It does not cover third-party services that you separately choose to use (such as your own Meshy account), which are governed by their own privacy policies.

3.Personal data we collect

Account and authentication data

Access is by invitation only, so we do not collect a self-service profile. In connection with your account and each signed-in request we process:

  • your account email address, which is also your login identity (held in AWS Cognito);
  • a stable internal user identifier (your Cognito "sub");
  • your group memberships and role assignments, which determine what you are allowed to do;
  • whether your email address has been verified;
  • an optional internal "role" attribute that administrators may set for access-control and audit purposes.

We also maintain an allowlist of authorised email addresses that controls who may sign in. Self-registration is not possible — any direct sign-up attempt is refused, and the attempted email address may be recorded in our security logs. Sign-in by an address that is not on the allowlist is likewise refused.

Connected Google account email (Branded-Email feature only)

If an administrator uses the optional "Connect Google" step of our Branded-Email setup wizard, we receive the verified email address of the connected Google account. This is not a way to sign in to the product and is available only to authorised staff. See the dedicated section "Google user data & Limited Use" below.

Spatial scans and tour content

When you (or a staff operator on your behalf) create a project, we process:

  • the raw scan / point-cloud file you upload (e.g. E57, LAS or GLB);
  • the processed 3D assets we generate from it (3D meshes, level-of-detail models, point-cloud tiles, panorama/equirectangular images, thumbnails and related metadata);
  • project and tour metadata you provide or that is generated during processing — project name, description, tags, status, original file name and size, a content fingerprint, upload/processing settings, viewer preferences, a processing trace log, asset links and a view counter;
  • your consent choice for each project and its full change history (see "3D scans, tour content & your consent choices");
  • share-link settings you configure, which may include an access tier, a share token, a hashed share password, email addresses of viewers you choose to invite, an optional expiry, and a view count.

Uploaded scans and the tours built from them are your content.

Personal data in the content you upload, and data about other people

Spatial scans can depict real places and may incidentally capture people or personal information (for example, images of individuals, or of documents visible in a room). When you invite specific people to view a shared tour, you also provide us their email addresses. In these cases the personal data reaches us from you (or the account owner), not from the individuals themselves.

For the content of the scans you upload, you (or the organisation that enrolled you) decide why and how that content is captured and used through the Service; we process it on your instructions to provide the Service to you. You are responsible for having a lawful basis to capture, upload and process that content, and for informing any identifiable person in a scan — or anyone you invite to a shared tour — as the law requires. Please only upload scans you are entitled to upload (see our Terms).

Contact-form submissions

Our public contact form collects the name, email address and message you type. This information is not stored in a database. It is sent directly to our team by email, with your email address used as the reply-to address so we can respond.

Bring-your-own-key credentials (Meshy)

If you use the optional AI generation feature, you may connect your own Meshy API key. We store it encrypted and never display or return the full key — only its last four characters and validation metadata are shown. See "AI-assisted generation… Meshy (BYOK)" and "How we protect your data".

Technical and usage data

  • Authentication session cookies (see "Cookies & local storage").
  • IP address — derived from your request headers, used transiently to rate-limit the contact form and forwarded to Cloudflare for bot/CAPTCHA verification. It is held only in server memory (for up to one hour, for contact-form rate-limiting) and is not written to a database by us. (AWS, our hosting provider, may separately record request metadata in its own infrastructure logs, outside our application code.)
  • Bot-verification (CAPTCHA) tokens issued by Cloudflare Turnstile on the contact form and the login gate.
  • Short-lived processing-progress logs of the upload/processing pipeline (stage, message, timestamps and internal identifiers), which are automatically deleted about 30 minutes after they are written. Separately, our infrastructure keeps security and operational server logs (see "How long we keep your data").
  • AI generation prompts — see the AI section; we keep only a one-way hash of the prompt, not the prompt text.

What we do NOT collect

We do not use web analytics, product-analytics SDKs, advertising trackers, or cross-site tracking of any kind. There is no Google Analytics, no advertising pixel, and no behavioural ad-tech in the product. We do not sell or share personal data with advertising networks. The only usage measurement is a simple first-party per-project view counter.

4.How and why we use your data (legal bases)

Under the GDPR we must have a lawful basis for each use of your personal data. We identify a single primary basis for each purpose below.

What we doWhyLegal basis (GDPR Art. 6)
Create and operate your account; authenticate each requestTo let you access and use the ServicePerformance of a contract (Art. 6(1)(b)) where you contract with us directly; otherwise our legitimate interest in providing the platform to the organisation that enrolled you (Art. 6(1)(f))
Host your scans, build and serve your 3D tours, run the processing pipelineTo provide the core Service you requestedAs above — contract, or our legitimate interest in providing the Service
Send you service notifications (e.g. "your tour is ready" or a processing-failure notice) to your account emailTo keep you informed about your own projectsOur legitimate interest in keeping you informed about your projects
Enforce the closed-pool allowlist, force-log-out non-allowlisted sessions, rate-limit and CAPTCHA-verify forms, keep short-lived and security logsTo secure the platform and prevent abuseOur legitimate interest in the security and integrity of the Service
Use your uploaded scans to train or improve our AI models, or include them in commercial datasets/researchOnly if you actively opt inYour explicit consent (Art. 6(1)(a)) — the "Help improve the platform" or "Allow full commercial use" level you choose
Connect a Google account for the Branded-Email featureTo identify the forwarding inbox you choseYour consent, and our legitimate interest in providing the feature you requested
Generate 3D assets via Meshy using your own keyTo provide the feature you triggeredOur legitimate interest in providing the feature you initiated (performed under your own Meshy account)
Respond to contact-form enquiriesTo answer you and, where relevant, take steps toward a business relationshipSteps taken at your request prior to a contract (Art. 6(1)(b)) / our legitimate interest in responding to you
Meet legal, accounting or regulatory obligationsWhere the law requires itLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms, and you may object to that processing at any time (see "Your data-protection rights"); we can provide a summary of the relevant balancing assessment on request.

The default consent level for every uploaded scan is "Processing Only" — meaning no AI training and no commercial use. AI-training or commercial use never happens unless you deliberately select a higher consent level, and you can change your choice at any time. You may withdraw consent at any time; withdrawal does not affect processing carried out before withdrawal.

5.Google user data & Limited Use disclosure

3D Ture offers an optional "Connect Google" step inside our Branded-Email setup wizard. This feature is available only to authorised staff/administrators. It is not a way to sign in to the product.

When an administrator uses it, we ask Google only for the `openid email` scope (a non-sensitive scope). We use it solely to read the verified email address of the Google account being connected, so that address can be set as the inbound-mail forwarding target for a branded sending domain.

  • We do not request access to your Gmail, Google Drive, Calendar, contacts, profile, or any other Google data.
  • The tokens Google issues during this flow are used once, in server memory, to read the verified email address, and are then discarded. We never store, log, or return any Google-issued access, refresh or ID token, and we never send them to the browser.
  • Only the resulting email address string is stored — as the forwarding target on the relevant branded-domain record.

Limited Use. 3D Ture's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, the Google account email obtained through this feature is used solely to identify and configure the forwarding inbox for the Branded-Email feature. It is not sold, not used for advertising, not used to train generalized AI/ML models, and not transferred to any third party except as necessary to provide this feature to you, to comply with applicable law, or in connection with a merger or acquisition as permitted by that policy.

7.AI-assisted generation, remote processing & Meshy (BYOK)

Processing your uploads. When you upload a scan, we process it on AWS in the EU to generate your interactive 3D tour. Larger scans may be routed through an automated AWS processing pipeline (Step Functions with Fargate or Batch compute) in the same EU region. Some processing runs are instead performed on secured operator workstations in the EU (for example, when an operator processes a very large scan locally); the same confidentiality and deletion commitments apply, and the finished tour is delivered through the same EU storage. Short-lived progress logs are generated during processing and auto-deleted about 30 minutes later. Uploaded files may be automatically scanned by AWS Macie for sensitive data as a security measure; this scanning does not block your upload.

Optional AI 3D generation with Meshy (Bring-Your-Own-Key). 3D Ture can generate 3D assets from a text prompt using Meshy (`api.meshy.ai`), a third-party "text-to-3D" service. This feature uses a Bring-Your-Own-Key (BYOK) model:

  • You connect your own Meshy API key, and generation runs entirely under your own Meshy account, credits and terms. We do not proxy or pay for end-user generation.
  • Your key is first validated against Meshy, then stored encrypted (see "How we protect your data"). We never display or return the full key — only its last four characters and validation metadata.
  • When you generate an asset, the text prompt you type is sent to Meshy over HTTPS to fulfil your request. We do not store the plaintext prompt; we keep only a one-way SHA-256 hash of it for provenance.
  • Before any prompt is sent, it passes through an in-region AWS content-moderation step (AWS Bedrock); the moderation result is not stored.
  • The 3D model and thumbnail Meshy returns are copied into our EU storage for durability and served to you through short-lived signed links.

At present, only the text prompt is transmitted to Meshy for this feature — your raw scan and panorama files are not sent to Meshy. Please do not include personal data about other people in your prompts, as the prompt text leaves our platform and is sent to Meshy. (On the separate, staff-only marketplace generation path, prompts are sent to Meshy under the platform's own Meshy key rather than a personal key.) Meshy is an external provider whose servers may be located outside the EU; please review Meshy's own privacy terms, as your use of your Meshy account is governed by your agreement with Meshy.

8.Service providers & sub-processors

We rely on the following processors to run the Service. Where a provider is outside the EU, transfers are made under appropriate safeguards (see "International data transfers & EU hosting").

ProviderPurposeRegion
Amazon Web Services — CognitoAuthentication, session tokens, closed-pool allowlist enforcementEU — Stockholm (eu-north-1)
AWS — AppSync + DynamoDBApplication database: project metadata, consent records & history, share settings, encrypted BYOK keysEU — Stockholm (eu-north-1)
AWS — S3Storage of uploaded scans, generated 3D assets, panoramas and thumbnailsEU — Stockholm (eu-north-1)
AWS — CloudFrontContent-delivery network for processed/published tour assets, panoramas and thumbnails (origin in EU Stockholm)Global edge network (EU origin)
AWS — SESSending transactional and notification emailEU — Frankfurt (eu-central-1)
AWS — CloudWatch / X-Ray, SSM Parameter Store, Macie, KMS, BedrockOperational logging & tracing, allowlist parameter storage, sensitive-data scanning, encryption-key management, AI prompt moderationEU — Stockholm (eu-north-1)
Google LLC"Connect Google" email verification for the Branded-Email feature only (scope `openid email`)Google global infrastructure
Cloudflare, Inc.Bot/CAPTCHA verification (Turnstile) on the contact form and login gate; DNS/CDN for 3dture.com; tenant inbound-mail routing setupCloudflare global edge network
MeshyOptional AI text-to-3D generation, under your own key (BYOK)External — outside the EU (vendor region not specified)

The Cloudflare Turnstile widget loads in your browser to perform bot detection and may set its own cookies or local state as part of Cloudflare's product, outside our control. We use `next/font` to self-host our typeface (Inter), so no runtime request is made to Google Fonts. We do not use any advertising or analytics sub-processors.

9.Cookies & local storage

We use only the cookies necessary to operate the Service. We set no advertising, analytics or tracking cookies — only the strictly necessary cookies listed below, which are exempt from consent because they are required for security and for services you explicitly request.

Your choice. A notice appears on your first visit and records your decision. You can change it at any time via "Cookie settings" in the site footer — withdrawing is exactly as easy as giving. Two optional categories exist and both are off until you switch them on: *Preferences* (the browser local storage listed below except entries marked strictly necessary, remembering display and performance settings between visits) and *Embedded 3D tours* (the third-party tour player described under "Service providers"). Nothing in either category is stored before you say yes, and a decision stands for six months before we ask again.

What the "Embedded 3D tours" switch does, precisely. It records your preference; it does not by itself block the player. No tour loads until you press play on it — that is true whichever way the switch is set, and pressing play is itself the explicit request that permits the connection. Turning the switch off does not disable tours; it records that you would rather they did not load, and the notice beside every play button tells you the connection goes to Matterport in the United States before you press it.

One exception, by design. When one of our tour pages is embedded inside a customer's own website, our notice does not appear on it — that visit is governed by the host site's cookie policy and its own consent tool. Opening the same tour page directly on 3dture.com always shows our notice.

Cookies

  • `CognitoIdentityServiceProvider*` — one or more strictly necessary, httpOnly cookies that hold your authenticated session (managed by AWS Amplify). They are cleared/expired immediately if a signed-in account is found not to be on the allowlist. Lifetime follows standard AWS Cognito token lifetimes.
  • `google_oauth_state` — a short-lived, httpOnly security (anti-CSRF) cookie used only during the "Connect Google" flow. It is scoped to that flow, expires after 10 minutes, and is single-use.
  • `3dture-consent` — a strictly necessary record of the cookie decision you made above. It contains only which categories you allowed and when; it stores no identifier and is never sent to a third party. It exists so that a refusal is remembered as durably as an acceptance. Lifetime 6 months.
  • `site-lang` — a strictly necessary functional cookie holding the site language you picked with the language switcher. It is written only by your own explicit click and contains nothing but `en` or `lv`. Lifetime 1 year.

Browser local storage (stored on your device, not sent to us unless noted):

  • `3dture.upload.resume.*` — strictly necessary, exempt from consent: it exists solely so an upload you started can resume if interrupted (upload identifiers and settings only; kept up to 7 days, max 10 entries).
  • `nextonline.nestedObjects.<assetKey>` — your in-tour object/decoration placements.
  • `3dture-a11y-autoswitch-dismissed` and `cx-consent-upgrade-prompted:<projectId>` — one-time UI-dismissal flags (no personal data).
  • `userPerfPref` — your device/performance preference; for signed-in users this may also be synced to our own EU database (not to any third party).

The Cloudflare Turnstile widget may independently store its own state for bot detection, as described under "Service providers & sub-processors".

10.How long we keep your data

DataRetention
Account data (email, roles, verification status)For the life of your account; account deletion is a manual administrator action
Allowlist of authorised emailsUntil an operator edits or removes it
Raw uploaded scan filesKept for as long as the project exists (moved to cold "Glacier" storage after ~30 days). Deleting the project permanently deletes the stored files, including all prior file versions — see the deletion note below
Processed 3D assets, panoramas, thumbnailsKept for as long as the project exists. Deleting the project permanently deletes them (including prior file versions); already-published copies may persist temporarily in CDN caches — see the deletion note below
Project metadata, consent level & consent historyKept until the project record is deleted; consent history is append-only
Share-link settingsKept until you change/clear sharing or delete the project
Activity records of account and sharing actions (the account that acted, what it did, which project or item it concerned, the result, the time, and — for sharing changes — the access level before and after, a one-way fingerprint of the share link, and its expiry. These records also include one-way codes that let us tell separate sign-in sessions apart. They do not contain your IP address, your browser details, the share link itself, its password, or any of your content)Kept even after the project is deleted, and kept if you ask us to erase your data, because these records exist so that we can establish, exercise and defend legal claims (Art. 6(1)(f), and the exception to erasure in Art. 17(3)(e)). We keep them while your relationship with us is active and for as long afterwards as a claim could still be brought, and then we delete them. Deleting a project does not start that period — the end of your relationship with us does. You can object to this processing, and ask us why we keep a particular record, at any time (see "Your data-protection rights")
Branded-email domain settings (display name, reply-to and forwarding-target email addresses, incl. any connected Google account email, DNS/verification status)Kept in our server-side configuration store until the domain is removed by an administrator; the associated email-sending identity at AWS SES is removed separately by an operator
Live upload/processing progress logsAutomatically deleted ~30 minutes after creation
Security and operational server logs (AWS CloudWatch / CloudTrail, EU) — including denied sign-up attemptsRetained per our infrastructure log-retention settings (provider default periods)
Contact-form submissionsNot stored by us; delivered by email only
IP address — contact formHeld in server memory for up to 1 hour for rate-limiting; also sent once to Cloudflare for bot verification; not stored to disk by us
IP address — login gateProcessed transiently and sent once to Cloudflare for bot verification; not retained by the app
Derived scanner-calibration profiles (panorama face-orientation corrections keyed by a scanner-hardware fingerprint — no image content, no personal data)Retained as operational calibration knowledge; the link to the source project is removed when that project is deleted
Meshy BYOK credentialEncrypted, kept until you delete it
AI prompt textNot stored (only a one-way hash is kept for provenance)
Google-issued OAuth tokensNot stored — discarded immediately after the email is read
`google_oauth_state` cookie10 minutes

Important note on deleting a project. When you delete a project, we remove its database records and permanently delete its stored files from our encrypted EU storage — including all prior file versions. One category of record deliberately survives this: the activity record of account and sharing actions relating to that project — who changed its sharing, consent or publication, when, and what that change made reachable. Your content is deleted as described here; what we keep is the record that those actions happened, for the period and for the reason set out in the table above. The same applies if you ask us to erase your data: we delete your content, and we keep those activity records. Deletion is immediate and there is currently no recovery period, so please be certain, and keep your own copies (see our Terms). Copies can outlive the deletion for a limited time: CDN caches may retain already-published assets until their cache lifetime expires (up to about one year in the worst case); operator working copies created when a scan is processed on a secured operator workstation are removed by our operator erasure procedure rather than instantly; and copies may also persist for a limited period in system backups (see our Terms). If you ask us to erase your data (email support@3dture.com), we permanently delete every associated file — every stored version, any incomplete upload fragments, and any operator working copies — verify the deletion against our storage system's version index, and complete the verified erasure within 30 days of your request (see "Your data-protection rights").

11.How we protect your data

We take technical and organisational measures appropriate to the risk, including:

  • Encryption in transit — all traffic to the application and to our providers uses HTTPS/TLS.
  • Encryption at rest — files in S3 are server-side encrypted; a dedicated sensitive-data store and operational logs are encrypted with AWS KMS.
  • Your Meshy API key is encrypted with AES-256-GCM using a 32-byte, server-only master key and a fresh random initialisation vector per encryption; it is authenticated (tampered ciphertext is rejected rather than silently decrypted), never logged, and never returned to your browser.
  • Share-link passwords are never stored in plaintext — they are hashed with PBKDF2-HMAC-SHA256 (210,000 iterations) with a per-link salt.
  • Access controls — a closed, invitation-only user pool; an allowlist enforced at three independent layers that all fail closed (deny by default) if unset in production; role-based authorisation on every owner-scoped action; and automatic force-logout of any authenticated session that is not on the allowlist.
  • Session cookies are httpOnly and managed server-side.
  • Abuse protection — Cloudflare Turnstile bot verification and rate-limiting on public forms; AWS Macie scanning of uploads for sensitive data.

No system can be guaranteed 100% secure, but we work to protect your data and to notify you and the competent authority of any personal-data breach where legally required.

12.International data transfers & EU hosting

Your application data and files are stored and processed within the European Union — AWS Stockholm (eu-north-1) for application data and file storage, and AWS Frankfurt (eu-central-1) for outbound email. Both are EU regions.

However, published/processed tour content (3D assets, panoramas, thumbnails) is delivered through Amazon CloudFront and may be cached at CloudFront edge locations worldwide for up to about one year to speed up delivery. This edge delivery is covered by the AWS Data Processing Addendum.

Some of our sub-processors also operate outside the EU/EEA:

  • Google (for the Branded-Email "Connect Google" email verification) processes data on Google's global infrastructure;
  • Cloudflare (Turnstile bot verification, DNS/CDN) operates a global edge network;
  • Meshy (optional AI generation, under your own key) is hosted outside the EU.

Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and/or an applicable adequacy decision. You can contact us for more information about these safeguards.

13.Your data-protection rights

Subject to the conditions and exceptions in the GDPR, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten");
  • Restrict our processing in certain circumstances;
  • Object to processing based on our legitimate interests;
  • Data portability — receive certain data in a structured, machine-readable format;
  • Withdraw consent at any time where processing is based on consent (for example, your AI-training/commercial consent level), without affecting processing already carried out.

Automated decision-making. We do not make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. Automated bot-detection (Cloudflare Turnstile) and AI content-moderation checks are used only to secure the Service and prevent abuse.

To exercise any of these rights, contact support@3dture.com. We will respond within the timeframes required by law (generally within one month). We may need to verify your identity before acting on a request.

You also have the right to lodge a complaint with a supervisory authority. In Latvia this is the Data State Inspectorate (Datu valsts inspekcija) — https://www.dvi.gov.lv. You may also complain to the supervisory authority in your country of residence or work.

14.Children's data

3D Ture is a business tool intended for authorised staff and pilot organisations. It is not directed at children and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact support@3dture.com and we will take appropriate steps to delete it.

15.Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in the Service, our practices, or legal requirements. When we make material changes, we will update the "Last updated" date at the top and notify affected users (for example, by email or an in-app notice) before the changes take effect. We encourage you to review this policy periodically.

16.How to contact us

For any privacy question, or to exercise your rights:

  • Privacy & data-rights requests / support: support@3dture.com
  • General / business enquiries: info@3dture.lv
  • Legal address: Nometņu iela 38 – 17, Salaspils, Salaspils novads, LV-2121, Latvia
  • Business address: Nometņu iela 26, Rīga, LV-1048, Latvia
  • Data controller: AMSTORM SIA (trading as "3D Ture"), registration No. 40203102670
  • Data-protection contact: No Data Protection Officer is appointed (not required under GDPR Art. 37); for data-protection questions, contact person Atis Meiers via support@3dture.com

We aim to respond to all privacy enquiries promptly.