Privacy

What data this site uses

The public information pages do not create accounts or use tracking. The separately activated private-order route can upload one model for manual review and can open hosted payment only after you accept a reviewed final price.

Data controller

3D Print Maastricht — controller: Sipers Mechatronics (sole proprietorship). Registered business address: Heideweg 2, 6301 RE Valkenburg, Netherlands (no walk-ins; visits by appointment only). KVK 98949578. VAT ID NL005363496B77. Email contact@sipersmechatronics.com. Privacy and complaints contact: support@sipersmechatronics.com; Heideweg 2, 6301 RE Valkenburg, Netherlands.

Private-order data collection remains disabled until the complete launch checklist is approved and verified.

Quote requests

A request may include your contact details, print description, material choice, deadline, file name, and any information you add yourself. The form prepares message text only; the selected file is not uploaded by this website.

Private model requests and processors

If separately activated, an STL or 3MF model goes directly to private Vercel Blob storage. Contact, contract-confirmation queue, and order state are held in Upstash Redis. Vercel and Upstash act as processors. Stripe receives only the order and payment data needed for hosted Checkout. The first charge is no more than 50%; the remaining balance is offered only after delivery or at handover. The configured processor regions, safeguards, and any applicable international transfers must be approved before activation.

Why the data is used

The information is used to answer your request, review printability, propose a price and timing, and handle an approved job, pickup, or discussed delivery. Administrative information for an approved job may also be needed for business records.

Purposes and legal bases

Request and order data is processed to take steps at your request and to perform an accepted contract. Required invoice and accounting records are processed to meet legal obligations. Security, abuse prevention, and limited operational logs rely on legitimate interests in protecting the private service, balanced against your rights. Optional marketing requires a separate valid basis and is not part of this route.

Email and WhatsApp

You choose whether to send the prepared message by email or, when available, WhatsApp. That external service processes the message and attachments under its own terms. Do not send information that is not needed for the request.

No cookies or analytics

The current site does not set tracking cookies and does not include analytics scripts. After publication, a static hosting provider may process technical request or security logs under its own privacy terms.

Files and photos

If you attach files or photos in your chosen email or WhatsApp client, they are used to assess printability, estimate material and print time, and complete the print only after you approve the quote.

Retention

Information for a request that does not become a job is deleted when it is no longer needed to answer or reasonably follow up. Information for an approved job is kept only as long as needed for fulfilment, service questions, and applicable administrative duties. Unnecessary files and personal details are deleted.

In the private-order route, an abandoned temporary upload is deleted after 24 hours. A retained order model enters cleanup after 89 days. The contact-bearing private order record expires no later than 90 days (day 90). If model deletion cannot yet be verified, a minimal non-contact record containing only the opaque storage pointer and retention dates remains solely to retry deletion; it is removed immediately after private storage confirms the model is absent. Rejecting or closing a request uses the same verified deletion sequence. Legally required invoice or accounting records may follow a separate statutory retention period.

Your privacy choices

Where applicable, you can ask to access, correct, or delete your personal information, and to restrict or receive it, object to processing, or withdraw consent where consent applies. Use the verified controller contact and include enough information to identify your earlier contact. You may also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).