Controlled-beta draft · owner and legal review required before public launch
Privacy Policy
Crown Studio 3D is operated by Crown Inspect, a registered Canadian corporation located in Richmond Hill, Ontario, Canada. This policy explains how we handle personal information and customer content when you visit or use the controlled-beta service at crown3dstudio.com. Contact info@crowninspect.ca for support, privacy requests, billing questions, or legal notices.
Information we handle
- Account information: your name, email address, password hash and salt, verification and recovery status, account identifiers, plan, session records, and project names or descriptions.
- Customer content: photographs you explicitly upload, metadata embedded in them (which may include GPS location, capture time, camera, or drone information), requested processing settings, temporary processing files, generated GLB 3D models, orthophoto PNG images, and quality or error information. The current public cloud upload accepts supported image files; it does not currently accept customer video uploads.
- Operational and security information: IP address, request time, browser and protocol information, cookie and session identifiers, rate-limit activity, job status, security events, audit events, and limited server or error logs.
- Communications: messages and files you choose to send when requesting support, exercising a privacy right, reporting abuse, or discussing billing.
- Payment information: no paid checkout is active in the controlled beta. If payments are introduced, this policy will be updated before launch. The planned design uses a payment processor so Crown Inspect does not receive full card details.
Purposes and limits on use
We use customer photographs, location data, metadata, and generated outputs only to provide the requested service; secure and operate the service; diagnose a technical problem; provide support you request; investigate credible abuse, legal, or security issues; and meet legal obligations.
We do not use customer content to train artificial-intelligence or machine-learning models, advertise to you, create portfolio examples or demonstrations, publish social-media posts, sell or license datasets, develop unrelated algorithms, or pursue another unrelated commercial purpose. We do not sell personal information and do not use behavioural advertising or cross-site tracking in the controlled beta.
Upload choice, EXIF, and location information
Selecting files in your browser does not upload them. Upload begins only after you choose the cloud-processing action. The processing engine may read metadata embedded in a photo, including location and camera data, when it is present and useful to reconstruction. That metadata remains inside the uploaded source file during processing and may influence a generated result. Remove metadata before uploading if you do not want it processed. Do not upload content or locations you are not authorized to process.
Service providers and processing locations
The primary browser application, account service, and photogrammetry workloads run through an OVHcloud virtual server configured in Beauharnois, Quebec, Canada. Account email is sent through the configured email provider. Hosting-provider support systems and email routing may involve other countries; their exact storage locations are not currently verified. A separate Netlify deployment may be used for code-only web previews, but customer upload and account API routes are served by the production host. Providers receive only the information needed for their role and are not authorized by Crown Inspect to use customer content for advertising or their own model training.
Administrative access
Automated processing does not mean that customer content is inaccessible to administrators. Authorized Crown Inspect operators and hosting provider personnel with infrastructure access can technically access uploads, temporary files, outputs, databases, logs, or backups. Crown Inspect limits such access to service operation, requested support, credible abuse or security investigation, and legal obligations. A separate customer-approved support-access workflow and complete file-access audit trail are not yet implemented; this is a controlled- beta limitation.
Cookies and tracking
The service uses a secure, HttpOnly session cookie that is necessary to keep you signed in. An anti-forgery token is kept in browser memory and is not placed in local storage. Local storage is used for limited workspace preferences and job-resume information, not for passwords. The model viewer loads code and showcase files from the Crown Studio 3D site. No advertising pixel, session replay, or third-party analytics SDK is configured in the controlled beta.
Retention and deletion
Incomplete uploads expire within 24 hours. Source photographs submitted to a job are removed from active processing storage when that job succeeds, fails, or is cancelled. Free Beta results expire after 7 days; Creator results expire after 30 days; and pay-as-you-go results, if introduced, will expire after 14 days. An account or individual project can be deleted through the application when it has no active job. The deletion operation is designed to remove primary account records, hosted uploads, processing files, and results together and to fail without deleting the account record if processing-file deletion cannot be confirmed.
The operational target is to complete supported account-deletion requests from primary systems within 7 days, retain security logs for no more than 90 days unless legitimately required longer, and expire encrypted backups within 35 days. Provider backups and deletion automation must be verified before the controlled beta expands. Legal, tax, fraud, security, dispute, or abuse records may be retained longer when reasonably necessary or required by law. See the Retention and Deletion Policy.
Safeguards and residual risk
Safeguards include encrypted transport, password hashing, HttpOnly sessions, anti-forgery protection, tenant authorization, short-lived signed processing grants, fixed processing commands, upload limits, service isolation, security headers, restricted logs, backups, and monitoring. No system is risk-free. Do not upload content whose compromise would create an unacceptable safety or privacy risk.
Your choices and privacy rights
You can correct basic account details through support, export the account information made available in the application, delete an individual project, delete your account, and download results before expiry. You may also request access, correction, deletion, information about use or disclosure, or make a privacy complaint by emailing info@crowninspect.ca with the subject “Privacy request.” We may verify your identity before acting. There is no marketing-email program in the controlled beta.
Age and international use
You must be at least 18 years old to create an account. Crown Inspect is based in Canada. Incidental international registration may be allowed, but Crown Inspect does not initially target the European Union, United Kingdom, or another specific foreign jurisdiction. Local privacy rights may still apply regardless of marketing intent.
Changes and Canadian privacy context
We will post a revised date and provide appropriate notice before a material change takes effect. This controlled-beta draft is designed around Canada’s Personal Information Protection and Electronic Documents Act and Ontario operations, but it has not received legal approval. Mandatory rights under applicable law are not limited by this policy.