AiLaiLe Technology Limited · Dot3D
Privacy Policy
Effective date: 19 September 2026 · Last updated: 19 September 2026
This Privacy Policy explains how AiLaiLe Technology Limited (“AiLaiLe”, “we”, “us” or “our”) collects, uses, discloses and protects personal data when you use Dot3D. It applies to the Dot3D website, account, workspace, editor, billing and support experiences.
1. Who controls your data
AiLaiLe Technology Limited is the controller or business responsible for the personal data described in this Policy, subject to the role assigned by applicable law and by a particular customer’s instructions.
RM 102, 1/FTHE CLOUD
111 TUNG CHAU STREET
Tai Kok Tsui, Hong Kong
ailailetech@gmail.com
2. Data we collect
- Account data: email address, password authentication records, display name, avatar, workspace name, membership and invitation records.
- Workspace and model data: uploaded product photographs, model metadata, dimensions, materials, hotspots, scene settings, generated GLB/USDZ files, thumbnails, quality results and export activity.
- Billing data: plan, subscription identifiers, payment-provider customer identifiers, credit transactions and billing status. Stripe processes payment-card details; Dot3D does not store full card numbers.
- Technical data: IP address, browser/device information, request logs, security events, error reports and approximate usage information needed to operate and secure the service.
- Support data: information you send to us by email or support channels.
3. How and why we use data
- To create and secure accounts, authenticate users and manage workspaces.
- To receive photographs, run the requested AI generation workflow, store outputs and provide editing/export features.
- To process subscriptions, allocate credits, prevent fraud and reconcile billing.
- To provide support, send transactional messages and respond to data requests.
- To monitor reliability, diagnose errors, enforce security and prevent abuse.
- To comply with legal obligations and establish, exercise or defend legal claims.
Where GDPR applies, our legal bases may include performance of a contract, compliance with legal obligations, legitimate interests in security and service operation, and consent where consent is required. We do not use User Content to train general-purpose AI models without a separate, clear consent or contractual basis.
4. Service providers and disclosures
We disclose data only as needed for the purposes above to service providers acting under contract or to comply with law. Current categories include:
- Supabase: authentication, database and object storage.
- Vercel: website and API hosting.
- Fly.io: background artifact processing where deployed.
- Tripo: requested AI 3D generation and processing of submitted product images.
- Stripe: payments, subscriptions and billing events.
- Email and monitoring providers: transactional email and error/security monitoring where enabled.
We do not sell personal information and do not share personal information for cross-context behavioural advertising. We do not knowingly collect data from children under 18.
5. International transfers
Our providers and infrastructure may process data in Hong Kong and other countries. Where applicable law requires a transfer mechanism, we will use appropriate safeguards such as contractual protections, adequacy decisions or another lawful mechanism. You may contact us for information about relevant safeguards.
6. Retention
- Account, workspace and billing records are retained while needed to provide the service and meet legal, accounting and fraud-prevention obligations.
- Source photographs, models and thumbnails are retained while the workspace is active or until you delete them through available controls.
- When a workspace is deleted, the application starts deleting its models and storage files. Residual encrypted backups, logs or provider-side copies may remain for a limited period, generally up to 30 days, or longer where required for legal or security reasons.
- Tripo and other processors may have their own limited retention rules for data sent to them. We configure and use them only for the requested processing and do not control their independent legal obligations.
7. Security
We use access controls, row-level authorization, signed or scoped service requests, encrypted transport and server-side secret handling appropriate to the service. No internet service can guarantee absolute security. Please report suspected account or data incidents to ailailetech@gmail.com promptly.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict or object to processing, withdraw consent, and receive information about automated decision-making. California residents may also have rights to know, delete, correct, opt out of sale or sharing, limit certain sensitive-data uses, and receive equal treatment. We do not sell or share personal information for cross-context behavioural advertising, so there is no sale/share opt-out required for that activity.
Submit a request to ailailetech@gmail.com or use Settings → Privacy & data. We may verify your identity before completing a request. We normally respond within one month for GDPR requests and within the time required by applicable California law. You may complain to the data-protection authority in your country or region.
9. Cookies and similar technologies
Dot3D uses essential cookies or equivalent browser storage for authentication, security, session continuity and user preferences. We do not use advertising cookies or cross-site behavioural tracking. If we introduce optional analytics or marketing cookies, we will update this Policy and provide any consent controls required by law.
10. Shopify
If you connect a Shopify store or use a future Shopify app integration, we may process the store domain, Shopify account or staff identity, authorization scopes, access tokens and Shopify data needed for the enabled feature. We will request only the scopes needed, keep tokens server-side, and delete or revoke them when the connection is removed or the app is uninstalled, subject to legal retention requirements.
11. Changes and contact
We may update this Policy when our processing, providers or legal obligations change. We will publish the revised version with a new update date. Questions, rights requests and complaints can be sent to:
AiLaiLe Technology LimitedRM 102, 1/F
THE CLOUD
111 TUNG CHAU STREET
Tai Kok Tsui, Hong Kong
ailailetech@gmail.com