PRIVACY / LOCAL STORAGE / COOKIES

Your data.
Clear boundaries.

This notice explains which personal data the 3DForge OÜ online store processes, why it is needed, who receives it and which rights you have.

CONTENTS 01 Controller 02 Data & purposes 03 Retention 04 Recipients 05 Cookies & local storage 06 Your rights 07 Security
Last updated: 1 September 2026
01

Data controller

Legal name
3DForge OÜ
Registry code
14664850
Email
3dforge.ou@gmail.com
Orders and rights requests
3dforge.trade@gmail.com
Address
Harju maakond, Tallinn, Lasnamäe linnaosa, Pallasti tn 33-30, 11416

3DForge OÜ is the controller of personal data collected through this online store. For privacy questions or rights requests, write to the orders email address.

02

Data, purpose and legal basis

ActivityData and purposeLegal basis
Order and deliveryName, contact details, billing and delivery address or selected pickup point, cart, payment status and order reference — to conclude and perform the contract, support the customer and deliver the order.Performance of a contract and pre-contractual steps; legal obligation for accounting records.
PaymentStripe processes payment and fraud-prevention data. 3DForge OÜ does not store full card details.Performance of a contract; Stripe may process some data under its legitimate interests or legal obligations.
Contact formName, email, subject and message — to answer an enquiry, prepare a quote or take steps toward a possible contract.Pre-contractual steps or legitimate interest in managing customer communications.
Withdrawals and claimsName, email, order reference, statement or claim content, and submission date and time — to register, handle and evidence the request.Legal obligation and the establishment, exercise or defence of legal claims.
Custom commissionInstructions, measurements, images and references voluntarily supplied for a project — to design and produce a personalised figurine.Performance of a contract and pre-contractual steps.
Technical securityServer or hosting security logs may contain an IP address, request time, page, device or browser technical data and error information — to detect attacks and keep the service reliable.Legitimate interest in protecting the store and customer data.

Details marked as required for an order are necessary to conclude the contract. Without them, the order or request may not be completed. Data is not currently collected or used for marketing.

The personal tracking link in the order email contains a random access token. It is used only to show order status and delivery information and should not be shared with unauthorised people.

03

Retention periods

  • Orders, invoices and other accounting source documents: seven years from the end of the financial year in which the transaction was recorded.
  • Contact enquiries that do not lead to a contract: up to 12 months after closure, unless an unresolved dispute or request requires longer retention.
  • Withdrawal statements and claims: up to three years after final resolution; any part forming an accounting source document is retained for seven years.
  • Custom-project files and personal references: for the project and up to 90 days after delivery, unless longer storage is separately agreed or required for an unresolved claim.
  • Security logs: normally up to 30 days, unless investigation of a specific security incident requires longer retention.

After the retention period, data is deleted or anonymised unless the law requires further storage.

04

Recipients and transfers

Data is disclosed only as needed to fulfil an order or request: to the selected carrier (Omniva, Smartpost or DPD), payment processor Stripe, web-hosting and email providers, accountants or legal advisers, and competent authorities where required by law.

Data-processing agreements are used where required, and providers receive only what they need for their task. Carriers and Stripe may also act as independent controllers for their own services.

Where a provider processes data outside the European Economic Area, a GDPR-compliant transfer mechanism is used, such as a European Commission adequacy decision or standard contractual clauses, with supplementary measures where required.

STRIPE PRIVACY INFORMATION ↗

05

Cookies and browser local storage

The 3DForge store does not currently use analytics, advertising or tracking cookies. It therefore does not display an unnecessary consent banner. If such technologies are added later, they will remain off until voluntary consent and withdrawing consent will be as easy as giving it.

The site uses browser local storage to remember the cart, favourites, selected language, collection theme, and delivery country and method. This data stays on your device and can be removed through your browser’s site-data or history controls. Blocking local storage may prevent the cart and preferences from persisting between pages.

When the store is delivered through Cloudflare, technical security cookies such as _cf_bm and __cfuvid may be set to protect the service and prevent automated abuse. They are not used for advertising or behavioural profiling; Cloudflare processes them under its own privacy information.

During payment, you are redirected to Stripe’s secure page. Stripe may use cookies on its own domain that are necessary for fraud prevention, security and payment functionality under its own privacy notice.

06

Your rights

Depending on the circumstances, you have the right to information and a copy of your data, correction, erasure or restriction, portability of data processed under contract or consent, and objection to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.

To make a request, write to 3dforge.trade@gmail.com. To protect personal data, we may request reasonable proof of identity before responding. We normally respond within one month.

If you believe your data has been processed unlawfully, you may complain to the Estonian Data Protection Inspectorate or the supervisory authority in your usual EU place of residence.

ESTONIAN DATA PROTECTION INSPECTORATE ↗

07

Security and changes

3DForge OÜ uses access controls, HTTPS, server-side input validation, restricted administrator access, backups and careful provider selection. No system is entirely risk-free; qualifying breaches will be notified as required by law.

This notice is updated when processing or legal requirements change. Material changes will be announced on the site or directly where they significantly affect an existing customer relationship.