Privacy Policy

PRIVACY

Effective date: 2025-12-06

We respect your privacy. This policy describes what we collect, how we use it, and the choices you have. In production, we expect to use Supabase (auth, storage, database) and Stripe (payments) to deliver the service.

1) Information we collect

  • Account & contact: Name, email, company, phone.
  • Project & quote: Materials, quantities, tolerances, notes, uploaded CAD files.
  • Order data: Shipping info, billing details, transaction metadata.
  • Usage & logs: Device, browser, IP, timestamps to operate and secure the site.

2) Cookies & local storage

We do not set cookies or use browser local storage for analytics, advertising, or personalization. If you sign in, our authentication provider (Supabase) may set a short-lived session cookie strictly to keep you logged in. We do not run a cookie banner because we do not place non-essential cookies.

3) How we use information

  • Provide services: Quote, manufacture, and deliver parts.
  • Communicate: Orders, support, and account updates.
  • Improve & secure: Reliability, security, and quality of the site.
  • Comply: Legal, safety, and regulatory requirements.

4) Data storage & retention

In production, files and project data will be stored in Supabase Storage and Postgres with role-based access. We retain data as needed to provide services and meet legal obligations, then delete or de-identify it.

5) Sharing & third parties

  • Service providers: Supabase, Stripe, carriers—processing under their terms and security programs.
  • Legal compliance: Law enforcement or regulators when required.
  • No selling: We do not sell personal data.

6) Security

We use access controls, encryption in transit, and least-privilege principles. No system is perfectly secure; please use strong, unique credentials.

7) Your choices & rights

  • Access/Correct/Delete: Subject to legal limits.
  • Marketing preferences: Manage marketing emails in your profile (when enabled in production).
  • File deletion: Request deletion of uploaded CAD when no orders are active.
  • EU/UK rights: Data portability, objection/restriction, and the right to lodge a complaint with your supervisory authority.

8) International transfers

Data may be processed in the United States or where our providers operate. We rely on appropriate safeguards where required.

9) Children’s data

We do not target or knowingly collect data from children under 16.

10) Changes

We may update this policy. Material changes will be noted by updating the effective date and, where reasonable, providing notice.

11) Contact

Email privacy@rapidmatter.com for privacy questions or requests.