Privacy Policy
Effective date: July 23, 2026
Last reviewed: July 23, 2026
3D Home Designs respects your privacy. This Privacy Policy explains what information we collect through our website and project-inquiry form, why we use it, when service providers may process it for us, how long we keep it, and the choices available to you.
Information we collect
Information you provide. The project-inquiry form may collect your name, email address, project location, project type, requested service, project stage, approximate size, budget range, desired timing, plans-or-photos status, preferred follow-up method, project details, consent version, and submission time. Version 1 does not accept files or attachments. If a project moves forward, we may receive plans, photographs, property information, and contract, billing, or other business records through later communications.
Website, analytics, and security information. Our website, infrastructure, analytics, and security providers may process information such as IP address, browser and device type, operating system, page or referring page, approximate location derived from an IP address, date and time, cookies or similar identifiers, TLS and user-agent signals, and request or security events.
The FORM-004 application does not persist IP addresses, user-agent strings, Cloudflare Turnstile tokens, arbitrary or full referrers, raw request headers, cookies, raw provider requests, or raw webhook bodies in its lead databases. Cloudflare and other infrastructure or security providers may process some of those signals transiently or under their own service-controlled security, abuse-prevention, and operational practices. Cloudflare explains Turnstile-specific signal processing in its Turnstile Privacy Addendum.
How we use information
We use information to:
- evaluate and respond to project inquiries;
- communicate about requested or active services;
- durably record an inquiry before attempting email delivery;
- send a project-inquiry notification to our team;
- prevent duplicate processing and reconcile delivery, bounce, complaint, or failure events;
- provide, administer, recover, monitor, and secure the website and form service;
- measure aggregate website and form lifecycle activity;
- detect abuse, prevent fraud, maintain backups, and troubleshoot incidents;
- keep appropriate business, tax, and legal records; and
- comply with law and protect people, property, and rights.
We do not sell personal data. We do not use personal data for targeted advertising or for profiling that produces legal or similarly significant decisions.
The initial service-hostname MVP confirms successful storage on screen and does not send a visitor acknowledgment email. If that practice changes, this policy and the associated suppression, retention, and mailbox procedures must be reviewed before the feature is enabled.
Cookies, Turnstile, and analytics
The site uses cookies or similar technologies that support site operation, security, and traffic measurement. The project-inquiry form uses Cloudflare Turnstile to distinguish people from automated abuse. Turnstile may process security signals such as IP address, TLS fingerprint, user-agent header, site key, and associated origin. The application validates the resulting token with Cloudflare but does not persist or log the token.
The initial FORM-004 service-hostname MVP does not send form lifecycle events to Google Analytics and has no Google Analytics identifier. Other website pages may use Google Analytics to understand aggregate website usage. Where it is active, Google may receive device, browser, page, approximate-location, IP-address, and identifier information as part of providing that service. Google explains how it uses information from sites that use its services at Google’s partner-sites information page.
If FORM-004 analytics is enabled in a later reviewed release, it may send only fixed lifecycle metadata, such as whether a valid inquiry was durably accepted. It may never send names, email addresses, project details, locations, budgets, form values, submission identifiers, security tokens, raw URLs, referrers, provider identifiers, or message content.
You can limit cookies through your browser settings and may use the Google Analytics opt-out browser add-on. Blocking cookies or scripts may affect some site features.
When information is shared
We may disclose information to service providers only as needed to operate the site and business, including:
- Cloudflare for the dedicated Worker service hostname, Worker execution, static assets, durable databases, queues, rate controls, Turnstile, platform security, and point-in-time recovery; Cloudflare authoritative DNS, custom-domain routing, or whole-site reverse proxying would require a later reviewed change;
- GoDaddy or a successor provider for WordPress hosting, infrastructure, and website backups outside the FORM-004 service;
- Google for analytics on website pages where it is enabled; the initial FORM-004 service does not send Google Analytics events;
- Defiant/Wordfence for firewall, malware scanning, login protection, and security logging;
- Resend or a successor transactional-email provider to transmit and troubleshoot the team notification;
- Microsoft 365 or another business mailbox provider to receive, filter, retain, search, and delete business mailbox copies; and
- professional advisers or contractors who need information to support a requested project or provide accounting, legal, privacy, security, or technical services.
The transactional-email provider receives the business mailbox destination and the message content needed to transmit the team notification. That notification contains the inquiry values needed for follow-up, including the visitor email address. The initial MVP does not ask the provider to send a visitor acknowledgment. The provider may retain message and event data under its service terms and settings. Service providers may process information in the United States or other locations where they operate.
We may also disclose information when required by law; to respond to lawful process; to protect people, property, or rights; to investigate abuse; or as part of a merger, financing, acquisition, or transfer of business assets.
Retention
We keep information only as long as reasonably needed for the purposes described above:
- general inquiries that do not become projects are deleted from the active FORM-004 lead database no later than 24 months after acceptance;
- normalized delivery events are scheduled for deletion after 90 days unless a shorter approved period is configured before production;
- outbox, provider-correlation, and delivery-risk records are retained only as needed for safe delivery, deduplication, incident handling, and the linked inquiry’s approved retention period;
- privacy-deletion tombstones and recipient suppressions contain keyed or opaque identifiers rather than inquiry content and are retained for their approved privacy, safety, and compliance purpose;
- team-mailbox notification copies follow the approved business mailbox retention and privacy-request procedure;
- the selected transactional-email service currently documents 30-day email-data retention across standard plans; provider suppressions and legally required records may follow different service-controlled periods;
- provider-created exports must be access-controlled outside the repository and are allowed to expire; the selected provider currently documents seven-day access to generated exports;
- point-in-time database history expires on the platform’s plan-specific schedule; current Cloudflare documentation states seven days on Workers Free and up to 30 days on Workers Paid; and
- client, project, contract, billing, tax, and related business records may be kept for the duration of the relationship and generally up to seven years afterward, or longer when required for an active dispute or by law.
Deletion from active systems may not immediately remove information from isolated, rotating point-in-time history or other backups. Those copies expire according to the approved provider schedule, are not used for ordinary business access, and must not be restored without replaying privacy deletions and suppressions before service reopens. If an independent encrypted export is approved, it must have a documented owner, access controls, expiration date, destruction procedure, and restore drill.
Your choices and privacy requests
Depending on where you live and subject to legal exceptions, you may have the right to ask whether we process your personal data, access or receive a copy of it, correct it, delete it, restrict or object to processing, or opt out of certain processing. You may also withdraw consent where consent is the basis for processing.
To submit a privacy request, email aaron@3dhomedesigns.com with the subject “Privacy Request,” or use our contact page. Describe your request and the email address you used when contacting us. We may take reasonable steps to verify your identity and authority before acting. We search only the systems reasonably linked to that person and request, and we do not export unrelated inquiries to answer a request.
A verified deletion request is completed across the active lead database, delivery state, independently protected deletion tombstones, local and provider suppression state where applicable, transactional-email records where supported, and business mailbox copies, subject to legal exceptions and backup expiration. The service remains closed after a restore until approved tombstones, suppressions, and retention rules have been replayed.
If we decline a request and applicable law provides an appeal right, use the published privacy-request contact method and explain why the decision should be reconsidered. You may also contact the Texas Attorney General or the privacy regulator where you live.
Security
We use reasonable administrative and technical measures intended to protect personal information, including access controls, least-privilege credentials, multi-factor authentication, encryption in transit, managed secret storage, input validation, abuse controls, durable storage, backups or point-in-time recovery, duplicate-delivery safeguards, and privacy-safe monitoring. No internet transmission or storage system can be guaranteed completely secure.
Children’s privacy
This site and our services are not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, use the published privacy-request contact method so we can review and delete it where appropriate.
External links and embedded services
The site may link to or embed content from third-party websites. Those services may collect information under their own privacy policies. We encourage you to review the privacy practices of any third party you visit.
Changes to this policy
We may update this policy when our practices, services, or legal obligations change. We will post the updated version and revise its effective or last-reviewed date.
Contact
3D Home Designs
Lakeway, Texas
aaron@3dhomedesigns.com
Contact 3D Home Designs
