Skip to main content

Effective September 12, 2026 · Version 2026-09-12

PlyOps Privacy Policy

Knisley 3D Solutions LLC, doing business as PlyOps, is responsible for the personal data covered by this policy. This policy explains what PlyOps handles, why, where it goes, how long it remains, and the choices available to you.

Privacy requests

privacy@plyops.com

Knisley 3D Solutions LLC · Ohio, United States. Use this address for access, correction, deletion, portability, objection, or marketplace-data questions.

1. Scope and local-first boundary

This policy applies to plyops.com, PlyOps accounts, PlyOps Cloud, PlyOps Connect, support, billing, and related services. It does not control the independent privacy practices of marketplaces, payment processors, printer drivers, or websites you choose to visit.

PlyOps Free is local-first. Its workspace records are stored in your browser's IndexedDB or related device storage and are not uploaded to PlyOps merely because you use the site. Data leaves the device when you deliberately enable a cloud or connected feature, submit support, start billing, or send an output to another service.

2. Data PlyOps handles

Browser-local workspace data

Products, variants, descriptions, media saved in the browser, business profile fields, libraries, internal inventory, scan identities, drafts, imports, preferences, backup/export records used by PlyOps Free, and a temporary same-device public-resource result only when you choose to continue it into PlyOps.

Account and PlyOps Cloud data

Email, account and session records, workspace details, region and currency choices, synced products and libraries, inventory movements and balances, private files, import history, mappings, and legal acceptance records.

PlyOps Connect data

Seller-authorized account metadata, encrypted tokens, listing/product/variant identifiers, staging rows, marketplace copy and media references, taxonomy or aspect references, privacy-minimized order and sold-item records when separately authorized, a short-lived shipment recipient display name when the provider supplies one, reviewed shipment details such as carrier and tracking when you use that workflow, and connection or action audit records.

Billing, support, and security data

Plan, subscription and payment status, Stripe identifiers, support messages and consented diagnostics, feedback or feature requests, request metadata, security events, and short-lived rate-limit identifiers.

Public resource measurement

An anonymous, controlled record that a named PlyOps resource started or finished, or that an approved continuation was selected, resumed, invalid, or expired. These records do not contain tool inputs or results, prices, quantities, dimensions, product details, search terms, files, URLs, account IDs, workspace IDs, IP addresses, user agents, referrers, or arbitrary text.

Optional product analytics

When you allow analytics, PlyOps can send PostHog a normalized page category, controlled action category, first referring hostname, and bounded campaign labels. After sign-in, a random analytics-only subject can connect the same browser journey across devices. PlyOps does not send product names, SKUs, descriptions, filenames, marketplace copy, email addresses, internal record IDs, raw URLs, tool inputs or results, or raw errors.

Stripe receives payment-card and billing-address details through its hosted checkout and portal. PlyOps does not receive full card numbers. Request metadata can include IP address, user agent, timestamps, route, and security signals. PlyOps uses short-lived keyed digests, rather than raw email or IP values, for its own application rate-limit buckets; hosting providers may process raw network information in their security logs.

3. Where data comes from

Data comes from you, your browser or device, users you authorize, the sign-in provider you choose, Stripe, a marketplace account you connect, and ordinary security or request logs created while the service operates. PlyOps does not buy consumer profiles or append third-party advertising data to your workspace.

4. Why PlyOps uses data

The legal basis depends on the data, requested feature, and where you live. The main purposes and bases are:

Contract

Create and secure accounts; provide local, cloud, marketplace, billing, support, and requested printing workflows; sync data; and enforce plan limits.

Legitimate interests

Protect PlyOps and users, prevent abuse, troubleshoot failures, measure content-free product and public-resource completion, improve reliability, and understand service capacity without using product content or public-resource inputs and results for analytics.

Consent

Enable optional PostHog product analytics or privacy-limited public-page replay, connect an optional marketplace, attach diagnostics or screenshots to support, publish a moderated roadmap request, or perform another clearly optional action where consent is the appropriate basis.

Legal obligations

Maintain required tax, accounting, transaction, security, and legal records; respond to lawful requests; and protect rights and safety.

PlyOps does not make decisions that produce legal or similarly significant effects using solely automated processing. Suggestions, checks, readiness scores, and matches support your review; they do not decide whether you may sell, publish, or operate a business.

5. Marketplace API data

Each marketplace connection is authorized separately and remains optional. PlyOps requests the least access needed for the current workflow and stores tokens encrypted server-side. Provider-derived data stays source-labeled and is not sent to another marketplace. PlyOps does not send one marketplace's API data to another marketplace and does not use marketplace API data for cross-platform benchmarking or comparative analytics.

Shopify

Seller-authorized product and listing review plus safe draft workflows. Separately authorized order access lets PlyOps read recent order identifiers, dates, status, totals, sold-item details, shipping-service commitments, and the shipping recipient display name. PlyOps retains that name for no more than 90 days from the order date so the seller can identify the order and print its packing slip. If you also authorize fulfillment access and explicitly confirm a reviewed shipment, PlyOps sends the exact packed lines, carrier, tracking number, and your customer-notification choice to Shopify and retains a protected operational record of that attempt. PlyOps does not store customer email, phone, postal address, notes, payment details, Shopify customer profiles, or raw Shopify order payloads; buy postage; or synchronize Shopify inventory.

eBay

Seller-authorized account connection, listing import and review, reference data, and explicitly confirmed listing preparation where enabled. Optional order access uses eBay's Fulfillment permission because eBay does not offer a separate read-only Fulfillment scope. PlyOps retains the shipping recipient display name for no more than 90 days from the order date so the seller can identify the order and print its packing slip. The same deliberate reauthorization can read eBay SHIPPING_LABEL debits and credits so PlyOps can retain only the net seller-paid label cost, currency, source, and timestamp. Marketplace usernames, addresses, email, phone, checkout notes, payment details, transaction identifiers, memos, payout data, and raw order or finance payloads are discarded. PlyOps can use a server-protected match digest to suggest when separate eBay orders may share one recipient and destination; the seller must confirm the shipment, and the original orders remain separate. When you explicitly confirm a reviewed shipment, PlyOps sends the exact packed line quantities, carrier, and tracking number to eBay and retains a protected operational record of that attempt. PlyOps does not buy postage or synchronize eBay inventory. Signed eBay account-deletion notifications are verified and processed.

Etsy

PlyOps uses seller-authorized Etsy access to identify the shop, review listing content, create explicitly reviewed draft listings, and update explicitly reviewed linked listings. Listing-write access is requested separately. Order-read access is requested separately and may retain Etsy's shipping recipient display name for no more than 90 days from the order date, plus Etsy's seller-paid shipping label cost, currency, source, and timestamp when Etsy supplies it. Shipment-update access is requested separately. If you explicitly confirm a reviewed shipment after the whole order is packed, PlyOps sends the carrier and tracking number to Etsy, which sends its normal shipment notification, and PlyOps retains a protected operational record of that attempt. It does not store buyer email, phone, postal address, messages, payment details, transaction identifiers, Etsy user profiles, or raw receipt payloads; buy postage; activate listings automatically; or synchronize live marketplace quantities.

PlyOps does not sell marketplace member or customer data, use it for unrelated advertising or unsolicited marketing, train AI or machine learning models on it without a permitted and explicitly authorized workflow, automatically publish live listings, or manage live marketplace quantities.

6. PlyOps Direct Printing

PlyOps Print Service is an included, device-local Windows helper, currently installed as SpoolRoute. Connection tokens, Windows printer and profile identifiers, saved logical routes, and printer reminders stay on that device and are not uploaded to PlyOps Cloud. When you choose Direct Print, the browser submits the printable output directly to the local PlyOps Print Service. Your printer driver and operating system then handle the job. Browser print or download remains available where supported.

7. Sharing and service providers

PlyOps shares data only as needed to provide a feature you request, run and secure the business, comply with law, protect rights and safety, or complete a business transaction such as a merger or sale. Service providers may process data only for their contracted role.

  • Vercel for application hosting, delivery, and operational security.
  • Supabase for authentication, Postgres data, private file storage, and server-side operations.
  • Stripe for checkout, recurring billing, invoices, payment methods, fraud prevention, and the customer billing portal.
  • Resend and related email infrastructure for sign-in, account, support, and operational emails.
  • PostHog for optional product analytics and separately enabled privacy-limited public-page session replay in the configured TEST or LIVE region.
  • Google or Apple when you choose that sign-in provider.
  • Shopify, eBay, or Etsy only when you separately authorize that marketplace connection.

PlyOps does not sell personal data and does not share personal data for cross-context behavioral advertising or use it for targeted ads.

8. Cookies and device storage

PlyOps uses necessary cookies for authentication, account binding, request protection, provider authorization, and secure session continuity. Local storage and IndexedDB hold local-first workspace records, theme and workflow preferences, device-local print settings, and temporary drafts. Session storage may hold short-lived tool state.

Optional PostHog analytics remains off until you allow it. If allowed, PostHog may use first-party browser storage to keep an anonymous journey together. Broad DOM autocapture is disabled, inputs are masked, URLs are reduced to approved route patterns, and replay is a separate choice and environment switch. You can change either choice from Privacy choices or Account settings; disabling analytics resets the analytics identity and stops further collection on that browser.

PlyOps does not currently use third-party advertising cookies. Because PlyOps does not sell or share personal data for targeted advertising, Global Privacy Control and Do Not Track signals do not change advertising behavior on PlyOps. Browser controls can block or clear storage, but blocking necessary cookies can stop account and connected features from working.

9. Retention

Temporary public-resource handoffs

When you explicitly continue a free-resource result into PlyOps, approved result fields are usable in that browser tab for up to two hours so you can review them after sign-in. They are not put in the URL or anonymous measurement event. An open resource or review screen clears the handoff at expiry. If full-page sign-in or provider navigation replaced that screen, PlyOps rejects and removes the expired values on the next continuation check; closing the tab also clears them. They become workspace data only if you explicitly save them in a PlyOps record.

Account and workspace data

Kept while the account is active and then removed or de-identified through the account-deletion process, except when a longer period is required for legal, security, fraud, tax, or transaction records.

Cloud access after a paid plan ends

The Cloud workspace becomes read-only and self-service recovery remains available to the owner for 30 days. PlyOps queues email notices when the window opens, seven days before it closes, and one day before it closes. The owner can download eligible complete records and original files or move the verified copy into one browser for Free Local use. After the deadline, the retained Cloud copy is not automatically deleted; reactivation, account-specific support, and whole-account deletion remain available.

Marketplace order and shipment records

Privacy-minimized order records and protected shipment-review history, including carrier and tracking values you submitted, remain with the connected workspace until you delete that marketplace's cached data, delete the account, or a verified provider privacy request requires removal. A provider-supplied shipment recipient display name is shown and retained for no more than 90 days from the order date, then hidden and cleared while the non-identifying order history remains. Disconnect stops future access but does not by itself erase the seller's retained order and action history.

Support conversations

Support cases and messages are scheduled for deletion after 180 days. Private support screenshots are scheduled for deletion after 30 days unless a shorter operational need applies.

Feature requests

Original submissions remain private. A moderated public title and summary may remain on the roadmap after the author's account is deleted, without the deleted account attached.

Content-free product usage

Controlled action categories and count ranges are retained for up to 90 days. Daily aggregate service metrics may remain because they do not contain product content or identify an individual product.

Anonymous public resource progress

Controlled resource, completion, and continuation categories are retained for up to 90 days. They are not linked to an account or workspace. Daily aggregate counts may remain because they contain no tool inputs, results, product content, or visitor profile.

Optional PostHog analytics

Controlled analytics events are retained for up to 90 days. Privacy-limited public-page recordings, when separately enabled, use the configured PostHog replay retention period. Private workspace, account, product, order, marketplace, file, support, and public-tool input or result regions are excluded from replay.

Security and rate limiting

Short-lived HMAC digests derived from request identifiers are kept only for the applicable policy window, generally no more than 24 hours. Hosting and infrastructure providers may keep security logs under their own retention schedules.

Billing and legal records

PlyOps and Stripe may retain transaction, invoice, subscription, tax, fraud, dispute, and legal records for periods required by law or legitimate business recordkeeping.

10. Deletion and disconnection

Browser-local data

PlyOps Free data stays in that browser or device. Clearing site data removes it from that browser. Deleting a PlyOps account does not erase a separate local library; export it first if you want to keep it.

Whole-account deletion

A requested deletion has a 48-hour cancellation window. After that window, PlyOps removes eligible active cloud records, private Storage objects, marketplace caches and mappings, the account's random analytics subject and associated PostHog person data when configured, and the account in a protected job normally expected to complete within the next 24 hours. Provider outages can delay a retry. Anonymous public-resource progress records and analytics recorded before identification have no account or workspace link and cannot be attributed to an account-deletion request.

Marketplace disconnect or cache deletion

Disconnecting stops future access and removes or revokes server-side tokens where supported. Cache deletion removes tokens, marketplace links and mappings, staging rows, privacy-minimized order records, saved shipment reviews and attempt records, and other provider cache data. Your separate PlyOps product records remain unless you delete them too.

Backups and generated copies

Active generated and cached cloud copies are removed with eligible account data. When encrypted database backups are enabled, historical database records can remain for up to seven days and expire on the provider schedule. Private Storage objects are removed separately and are not included in those database backups.

Verified provider privacy notifications can require broader removal of provider-derived copy, links, media references, and history. PlyOps processes Shopify privacy webhooks and signed eBay account-deletion notifications through provider-facing endpoints.

11. International processing

PlyOps is operated from the United States. PlyOps and its service providers may process data in the United States and other countries, which may have different privacy laws from your location. Where law requires, PlyOps relies on provider and contractual safeguards for international transfers. Workspace region choices can affect where supported cloud records are stored, but they do not prevent all necessary processing in other locations. Optional PostHog analytics uses the region selected for that separate TEST or LIVE project; that analytics region does not change the region of your PlyOps workspace records.

12. Security

PlyOps uses measures designed to protect data, including encrypted transport, server-side marketplace tokens, private cloud storage, access controls, row-level database security, rate limiting, and environment separation. No internet service or storage method is completely secure, so PlyOps cannot guarantee absolute security. Report a suspected privacy or security issue to privacy@plyops.com.

13. Your privacy choices and rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal data; object to or restrict certain processing; withdraw consent; appeal a denied request; or complain to a privacy regulator. PlyOps will not discriminate against you for exercising an applicable privacy right.

Use the in-app account, export, marketplace disconnect, cache deletion, and whole-account deletion controls when available, or email privacy@plyops.com. PlyOps may verify your identity and authority before acting. An authorized agent must provide proof of authority. You may also complain to the data-protection authority where you live or work if that right applies.

14. Children

PlyOps is intended for adults and business use. It is not directed to children, and account holders must be at least 18. If you believe a child provided personal data, contact privacy@plyops.com so PlyOps can review and remove it where required.

15. Policy changes and contact

PlyOps may update this policy as the service or law changes. The effective date and version will change, and PlyOps will provide additional notice or request renewed consent when required.

The controller is Knisley 3D Solutions LLC, doing business as PlyOps, in Ohio, United States. Send privacy questions or requests to privacy@plyops.com. For service rules, read the Terms of Service.