Privacy Policy
Effective 1 May 2025
Threed.Systems ("we", "us", "our") operates the threed.systems platform. This policy explains what personal data we collect, how we use it, and your rights in relation to it.
1. Data we collect
Account and authentication data. When you log in we collect your email address to authenticate you via magic link. We store your email alongside a provider slug and role in a session token.
Business and pipeline data. Data you enter into the platform (enquiries, quotes, orders, tasks, customer contact details) is stored in our Postgres database and scoped to your provider account.
Court design data. Configurations created in the Court Designer (dimensions, colours, sport layers, equipment) are stored against your account and, where you choose, shared via a public link.
Usage data. We may collect anonymised analytics (page views, feature usage) to improve the platform. No personally identifiable information is included in analytics events.
2. How we use your data
- To authenticate you and maintain your session
- To operate the platform and provide the services you have subscribed to
- To send transactional emails (magic links, order notifications)
- To improve and develop platform features
- To comply with legal obligations
We do not sell your personal data to third parties.
3. Third-party services
We use the following third-party services which may process personal data on our behalf:
- Vercel, website hosting and delivery; privacy-friendly, cookieless page analytics. Data shared: technical and usage data; data submitted in transit. Processed outside the EEA under standard contractual clauses.
- Supabase, secure database for enquiries, quotes and orders. Data shared: contact, enquiry and order data. Processed outside the EEA under standard contractual clauses.
- Sanity, content management and image delivery. Data shared: limited account and technical data. Processed outside the EEA under standard contractual clauses.
- Resend, sending transactional and account emails. Data shared: your email address and message content. Processed outside the EEA under standard contractual clauses.
- Stripe, payment processing at checkout. Data shared: email, billing address and payment details (card data is handled by Stripe). Processed outside the EEA under standard contractual clauses.
- Anthropic, aI features, such as prioritising and helping us respond to enquiries. Data shared: enquiry contact name and message content. Processed outside the EEA under standard contractual clauses.
- Upstash, security and abuse prevention (rate limiting). Data shared: iP address, held transiently. Processed outside the EEA under standard contractual clauses.
- Cloudflare Stream and YouTube, embedded product and guide videos. Data shared: your IP address and viewing data when a video loads. Processed outside the EEA under standard contractual clauses.
- Google reCAPTCHA, protecting our forms against spam and abuse. Data shared: iP address, device signals and a risk token. Processed outside the EEA under standard contractual clauses.
- Mapbox, aerial imagery of your site when you use the site-plan feature (satellite map tiles). Data shared: your IP address and the map area you view — the approximate location of the site you place a court on. Processed outside the EEA under standard contractual clauses.
- Google Maps, turning the address you type into a map location when you use the site-plan feature (geocoding). Data shared: the address you enter. Processed outside the EEA under standard contractual clauses.
4. Data retention
We retain your data for as long as your provider account is active. On account closure we delete or anonymise personal data within 90 days, unless we are required by law to retain it longer. Conversations with the assistant on a provider's website or court designer are kept for 90 days. After that we remove personal details from them and keep the anonymised conversation to improve our help content.
5. Your rights
Depending on your jurisdiction you may have the right to access, correct, or delete the personal data we hold about you, or to request a copy of it. To exercise any of these rights, contact us at scott@threed.systems.
6. Cookies
We use strictly-necessary cookies to keep you signed in and secure. These require no consent. With your consent, we also use analytics and marketing cookies (for example Google Analytics and advertising tags) to measure traffic and improve our marketing.
When you first visit, a banner lets you accept all, reject everything non-essential, or choose by category. Non-essential cookies and third-party tags stay blocked until you opt in, and we use Google Consent Mode so Google tags remain disabled by default. You can review or change your choice at any time via the "Cookie settings" link in our footer.
We remember your choice for 6 months and then ask again. We also keep a record of each choice on our servers for 12 months, so we can show what you agreed to and when. That record holds no name, email or IP address. It is linked to you only by a random consent ID stored in your browser, which you can see in the cookie settings panel.
7. Security
We use industry-standard security practices including HTTPS, encrypted database connections, and short-lived authentication tokens. No system is completely secure; if you believe your account has been compromised, contact us immediately.
8. Changes to this policy
We may update this policy from time to time. Material changes will be communicated to registered providers by email. The effective date at the top of this page indicates when the current version was last updated.
9. Contact
Questions about this policy? Email us at scott@threed.systems.
Have questions about how we handle your data? We're happy to help.
Contact us