Draft dated 5 October 2026 · 2026-10-05
Privacy Notice
This notice explains what information the current Shoe Charm Factory beta handles, why it is used, and how you can ask about it. It covers the website and account system, not MakerWorld’s separate platform.
This draft is not ready for public release. Confirm the legal operator, jurisdiction, and a monitored contact address before publishing it.
1. Who is responsible
Shoe Charm Factory is the project offering this beta. The operator’s legal name, location, and monitored privacy email must be confirmed before this notice is published. MakerWorld, Supabase, and Resend operate their own services under their respective notices.
2. Information we handle
For an account, we handle your email address, display name, account ID, email-verification state, and authentication events. Supabase Auth receives your password and stores a salted password hash; Shoe Charm Factory does not keep a readable password.
If you redeem a code, we handle the associated pledge ID, MakerWorld ID, reward tier, limited pledge metadata, a hash of the code, and redemption or binding history. A code entered at registration is temporarily placed in Supabase account metadata so it can be processed after email verification; the app requests its removal after that processing.
The website host and service providers may record technical information such as IP address, browser or device details, request times, and errors for delivery, security, and troubleshooting. If you contact us, we also handle the content of your message.
3. Designs and browser storage
Artwork previews and local drafts are processed and saved in your browser. When you request an authorized download, the prepared SVG or 3D mesh is sent to our server to produce your file. The export service processes this data in memory and does not save it as a cloud draft or retain the generated file after the request. Your original uploaded image is not sent by the export flow.
Browser storage also holds language and interface preferences, connector presets, the one-time welcome choice, and Supabase session tokens for staying signed in. Clearing site storage or changing browsers may erase local drafts or sign you out.
4. Why we use information
We use account data to register and verify users, send account and recovery emails, maintain sessions, and answer requests. We use pledge and code data to confirm backer eligibility, prevent code reuse or fraud, and maintain an access audit trail. Technical logs help operate and secure the site. We do not currently send marketing emails from the account system or use advertising trackers in the app.
Where a legal basis must be stated, necessary account and reward processing supports the service you request; security and fraud prevention support our legitimate interests; and some records may be kept to meet legal obligations. We do not rely on a blanket privacy-consent checkbox for processing needed to run an account.
5. Providers and international processing
Supabase provides authentication and the account database. Resend delivers verification and password-recovery email through the configured SMTP service. Our website host serves the public site and may keep access and error logs. These providers may process information in countries outside your own, subject to their terms and applicable safeguards. We do not sell account or pledge information.
6. Retention
We keep account information while the account is active and for as long afterward as reasonably needed to handle requests, disputes, security issues, or legal duties. Pledge and redemption history may need to be retained after an account or active binding is removed so that a one-account code cannot be reused. We will review retention periods when the operator and legal jurisdiction are confirmed.
Local drafts and preferences remain in your browser until you delete them or clear site storage. Service-provider logs and email records follow the providers’ retention settings and our applicable agreements.
7. Your choices and rights
You can edit your display name in your account, remove local drafts in My Designs, and sign out at any time. You may ask for access to, correction of, or deletion of account information, subject to applicable law and any necessary pledge or audit retention. Self-service account deletion is not yet available; requests are handled manually. Depending on your location, you may have additional privacy rights or the right to complain to a regulator.
8. Security and changes
We use HTTPS, restricted database access, and code hashes to reduce risk. No online system is completely secure. Do not share your password or invitation code. We will update this notice when data practices change materially, including if cloud draft storage, server-side design processing, or new analytics are introduced.
Contact
A monitored contact email and the operator’s legal identity will be added before these notices are published. Until then, questions may be sent through the MakerWorld crowdfunding project page. Crowdfunding project ↗