Effective August 13, 2026 · Version 2026-08-13

PlyOps Privacy Policy

Knisley 3D Solutions LLC, doing business as PlyOps, is responsible for the personal data covered by this policy. This policy explains what PlyOps handles, why, where it goes, how long it remains, and the choices available to you.

Privacy requests

privacy@plyops.com

Knisley 3D Solutions LLC · Ohio, United States. Use this address for access, correction, deletion, portability, objection, or marketplace-data questions.

1. Scope and local-first boundary

This policy applies to plyops.com, PlyOps accounts, PlyOps Cloud, PlyOps Connect, support, billing, and related services. It does not control the independent privacy practices of marketplaces, payment processors, printer drivers, or websites you choose to visit.

PlyOps Free is local-first. Its workspace records are stored in your browser's IndexedDB or related device storage and are not uploaded to PlyOps merely because you use the site. Data leaves the device when you deliberately enable a cloud or connected feature, submit support, start billing, or send an output to another service.

2. Data PlyOps handles

Browser-local workspace data

Products, variants, descriptions, media saved in the browser, business profile fields, libraries, internal inventory, scan identities, drafts, imports, preferences, and backup/export records used by PlyOps Free.

Account and PlyOps Cloud data

Email, account and session records, workspace details, region and currency choices, synced products and libraries, inventory movements and balances, private files, import history, mappings, and legal acceptance records.

PlyOps Connect data

Seller-authorized account metadata, encrypted tokens, listing/product/variant identifiers, staging rows, marketplace copy and media references, taxonomy or aspect references, privacy-minimized order and sold-item records when separately authorized, and connection or job audit records.

Billing, support, and security data

Plan, subscription and payment status, Stripe identifiers, support messages and consented diagnostics, feedback or feature requests, request metadata, security events, and short-lived rate-limit identifiers.

Stripe receives payment-card and billing-address details through its hosted checkout and portal. PlyOps does not receive full card numbers. Request metadata can include IP address, user agent, timestamps, route, and security signals. PlyOps uses short-lived keyed digests, rather than raw email or IP values, for its own application rate-limit buckets; hosting providers may process raw network information in their security logs.

3. Where data comes from

Data comes from you, your browser or device, users you authorize, the sign-in provider you choose, Stripe, a marketplace account you connect, and ordinary security or request logs created while the service operates. PlyOps does not buy consumer profiles or append third-party advertising data to your workspace.

4. Why PlyOps uses data

The legal basis depends on the data, requested feature, and where you live. The main purposes and bases are:

Contract

Create and secure accounts; provide local, cloud, marketplace, billing, support, and requested printing workflows; sync data; and enforce plan limits.

Legitimate interests

Protect PlyOps and users, prevent abuse, troubleshoot failures, measure content-free feature completion, improve reliability, and understand service capacity without using product content for analytics.

Consent

Connect an optional marketplace, attach diagnostics or screenshots to support, publish a moderated roadmap request, or perform another clearly optional action where consent is the appropriate basis.

Legal obligations

Maintain required tax, accounting, transaction, security, and legal records; respond to lawful requests; and protect rights and safety.

PlyOps does not make decisions that produce legal or similarly significant effects using solely automated processing. Suggestions, checks, readiness scores, and matches support your review; they do not decide whether you may sell, publish, or operate a business.

5. Marketplace API data

Each marketplace connection is authorized separately and remains optional. PlyOps requests the least access needed for the current workflow and stores tokens encrypted server-side. Provider-derived data stays source-labeled and is not sent to another marketplace. PlyOps does not send one marketplace's API data to another marketplace and does not use marketplace API data for cross-platform benchmarking or comparative analytics.

Shopify

Seller-authorized product and listing review plus safe draft workflows. If you separately authorize order access, PlyOps may read recent order identifiers, dates, status, totals, sold-item details, and shipping-service commitments for its order queue. PlyOps does not select or store customer names, email, phone, postal addresses, notes, payment details, or raw Shopify order payloads, and it does not fulfill orders or change Shopify inventory.

eBay

Seller-authorized account connection, listing import and review, reference data, and explicitly confirmed listing preparation where enabled. Optional order access uses eBay's Fulfillment permission because eBay does not offer a separate read-only Fulfillment scope; PlyOps limits this workflow to order reads and does not submit fulfillment updates. Buyer identity, addresses, checkout notes, payment details, tracking identifiers, and raw order payloads are not stored. Signed eBay account-deletion notifications are verified and processed.

Etsy

PlyOps uses seller-authorized Etsy access to identify the shop, review listing content, create explicitly reviewed draft listings, and update explicitly reviewed linked listings. Listing-write access is requested separately from import review. Order-read access is requested separately. If you authorize order access, PlyOps may read receipt status, dates, totals, sold-item details, and shipping commitments for its order queue. It does not store buyer identity, addresses, messages, payment details, tracking identifiers, or raw receipt payloads; activate listings automatically; fulfill orders; or synchronize live marketplace quantities.

PlyOps does not sell marketplace member or customer data, use it for unrelated advertising or unsolicited marketing, train AI or machine learning models on it without a permitted and explicitly authorized workflow, automatically publish live listings, or manage live marketplace quantities.

6. Direct Printing with SpoolRoute

SpoolRoute is optional device-local Windows software. Connection tokens, Windows printer and profile identifiers, saved logical routes, and printer reminders stay on that device and are not uploaded to PlyOps Cloud. When you choose Direct Print, the browser submits the printable output directly to the local SpoolRoute service. Your printer driver and operating system then handle the job. Browser print or download remains available where supported.

7. Sharing and service providers

PlyOps shares data only as needed to provide a feature you request, run and secure the business, comply with law, protect rights and safety, or complete a business transaction such as a merger or sale. Service providers may process data only for their contracted role.

  • Vercel for application hosting, delivery, and operational security.
  • Supabase for authentication, Postgres data, private file storage, and server-side operations.
  • Stripe for checkout, recurring billing, invoices, payment methods, fraud prevention, and the customer billing portal.
  • Resend and related email infrastructure for sign-in, account, support, and operational emails.
  • Google or Apple when you choose that sign-in provider.
  • Shopify, eBay, or Etsy only when you separately authorize that marketplace connection.

PlyOps does not sell personal data and does not share personal data for cross-context behavioral advertising or use it for targeted ads.

8. Cookies and device storage

PlyOps uses necessary cookies for authentication, account binding, request protection, provider authorization, and secure session continuity. Local storage and IndexedDB hold local-first workspace records, theme and workflow preferences, device-local print settings, and temporary drafts. Session storage may hold short-lived tool state.

PlyOps does not currently use third-party advertising cookies. Because PlyOps does not sell or share personal data for targeted advertising, Global Privacy Control and Do Not Track signals do not change advertising behavior on PlyOps. Browser controls can block or clear storage, but blocking necessary cookies can stop account and connected features from working.

9. Retention

Account and workspace data

Kept while the account is active and then removed or de-identified through the account-deletion process, except when a longer period is required for legal, security, fraud, tax, or transaction records.

Marketplace order records

Privacy-minimized order records remain with the connected workspace until you delete that marketplace's cached data, delete the account, or a verified provider privacy request requires removal. Disconnect stops future access but does not by itself erase the seller's retained order queue.

Support conversations

Support cases and messages are scheduled for deletion after 180 days. Private support screenshots are scheduled for deletion after 30 days unless a shorter operational need applies.

Feature requests

Original submissions remain private. A moderated public title and summary may remain on the roadmap after the author's account is deleted, without the deleted account attached.

Content-free product usage

Controlled action categories and count ranges are retained for up to 90 days. Daily aggregate service metrics may remain because they do not contain product content or identify an individual product.

Security and rate limiting

Short-lived HMAC digests derived from request identifiers are kept only for the applicable policy window, generally no more than 24 hours. Hosting and infrastructure providers may keep security logs under their own retention schedules.

Billing and legal records

PlyOps and Stripe may retain transaction, invoice, subscription, tax, fraud, dispute, and legal records for periods required by law or legitimate business recordkeeping.

10. Deletion and disconnection

Browser-local data

PlyOps Free data stays in that browser or device. Clearing site data removes it from that browser. Deleting a PlyOps account does not erase a separate local library; export it first if you want to keep it.

Whole-account deletion

A requested deletion has a 48-hour cancellation window. After that window, PlyOps removes eligible active cloud records, private Storage objects, marketplace caches and mappings, and the account in a protected job normally expected to complete within the next 24 hours. Provider outages can delay a retry.

Marketplace disconnect or cache deletion

Disconnecting stops future access and removes or revokes server-side tokens where supported. Cache deletion removes tokens, marketplace links and mappings, staging rows, privacy-minimized order records, and other provider cache data. Your separate PlyOps product records remain unless you delete them too.

Backups and generated copies

Active generated and cached cloud copies are removed with eligible account data. When encrypted database backups are enabled, historical database records can remain for up to seven days and expire on the provider schedule. Private Storage objects are removed separately and are not included in those database backups.

Verified provider privacy notifications can require broader removal of provider-derived copy, links, media references, and history. PlyOps processes Shopify privacy webhooks and signed eBay account-deletion notifications through provider-facing endpoints.

11. International processing

PlyOps is operated from the United States. PlyOps and its service providers may process data in the United States and other countries, which may have different privacy laws from your location. Where law requires, PlyOps relies on provider and contractual safeguards for international transfers. Workspace region choices can affect where supported cloud records are stored, but they do not prevent all necessary processing in other locations.

12. Security

PlyOps uses measures designed to protect data, including encrypted transport, server-side marketplace tokens, private cloud storage, access controls, row-level database security, rate limiting, and environment separation. No internet service or storage method is completely secure, so PlyOps cannot guarantee absolute security. Report a suspected privacy or security issue to privacy@plyops.com.

13. Your privacy choices and rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal data; object to or restrict certain processing; withdraw consent; appeal a denied request; or complain to a privacy regulator. PlyOps will not discriminate against you for exercising an applicable privacy right.

Use the in-app account, export, marketplace disconnect, cache deletion, and whole-account deletion controls when available, or email privacy@plyops.com. PlyOps may verify your identity and authority before acting. An authorized agent must provide proof of authority. You may also complain to the data-protection authority where you live or work if that right applies.

14. Children

PlyOps is intended for adults and business use. It is not directed to children, and account holders must be at least 18. If you believe a child provided personal data, contact privacy@plyops.com so PlyOps can review and remove it where required.

15. Policy changes and contact

PlyOps may update this policy as the service or law changes. The effective date and version will change, and PlyOps will provide additional notice or request renewed consent when required.

The controller is Knisley 3D Solutions LLC, doing business as PlyOps, in Ohio, United States. Send privacy questions or requests to privacy@plyops.com. For service rules, read the Terms of Service.