// Trust & Privacy

Security & Privacy

This page is maintained by CustomCNC to answer common security and privacy questions about our service. It is not an independent certification or audit report.

// 01

What we collect

We collect only the information needed to quote and manufacture your parts:

  • Your name and email address (to send quotes and communicate about your order)
  • CAD files you upload (STL, STEP, IGES, OBJ) — these are stored temporarily while we prepare your quote
  • Part specifications: material, finish, tolerance, quantity, and any notes you provide

We do not collect payment information on this site. Invoicing and payment are handled separately via email.

// 02

How we use your data

Your information is used solely for:

  • Preparing and sending you a fixed-price quote
  • Communicating about your order status and delivery
  • Routing your job to the appropriate manufacturing partner

We do not sell, rent, or share your data with third parties for marketing purposes. Manufacturing partners receive only the technical files and specifications required to produce your parts.

// 03

Retention & deletion

Uploaded CAD files are retained for the duration of quote preparation and order fulfilment, then automatically deleted. Quote requests and associated metadata are retained for business records in accordance with New Zealand tax and commercial law.

You can request deletion of your personal data at any time by emailing us at the address below.

// 04

Security practices

Our application is built on managed cloud infrastructure with the following controls:

  • Row-level security (RLS) on all database tables — users can only access their own data
  • Signed, time-limited URLs for file uploads and downloads
  • HTTPS-only traffic with modern TLS configuration
  • Server-side validation of all user inputs

These are platform-level capabilities we configure; the underlying infrastructure is operated by our hosting provider. We do not operate our own data centres or network edge.

// 05

Shared responsibility

Platform security (physical infrastructure, network, hypervisor, and managed database services) is the responsibility of our cloud hosting provider. Application security (access controls, data handling, and application logic) is our responsibility.

As a customer, you are responsible for:

  • Maintaining the security of your email account (since quotes and order updates are sent via email)
  • Ensuring any CAD files you upload do not contain sensitive intellectual property you do not wish to share for manufacturing purposes
  • Verifying that part specifications you provide are accurate and complete
// 06

Contact & reporting

For privacy requests, data deletion, or security questions, please contact us through the quote form or at the email address associated with your quote communication.

If you discover a security vulnerability, we welcome responsible disclosure. Please contact us via the same channels and allow reasonable time for remediation before public disclosure.

Last updated: June 2025. This page is maintained by CustomCNC as project-owned content. It is not an independent security certification, audit report, or legal agreement.