1. Introduction
FurnishAR is operated by RENDERNEXT S.R.L. (“FurnishAR”, “we”, “us”). This Privacy Policy describes how we collect and use personal data and what choices you have.
Controller: RENDERNEXT S.R.L., STR PITAR MOŞ, NR.27, ET.5, AP.17, Bucharest, Romania. Contact: office.rendernext@gmail.com.
2. What we collect
- **Account data:** email, authentication identifiers, optional name/avatar, organization membership and role.
- **Workspace data:** organization name and settings, invitations you send, role/permission changes.
- **Customer Content:** 3D files (e.g., GLB), textures, thumbnails, environment images, scene/material/variant configs, and related metadata you upload or generate.
- **Usage & device data:** IP address, device/browser info, pages/actions, timestamps, referrers, and performance logs.
- **Security & audit logs:** sign-in events, access attempts, and administrative/audit events needed to secure the Service.
- **Billing data:** subscription tier/status, invoice metadata, and payment status. Payment details are handled by Stripe (we do not store full card details).
About “Customer Content”
Customer Content includes assets and configuration data you upload or create in FurnishAR. You keep ownership of your Customer Content.
3. AR, camera, and embedded experiences
AR features may require camera access on supported devices to place 3D content in the real world. Camera access is requested by your device and can be disabled in your system settings.
When an experience is embedded on a customer website/app, we may process technical data (e.g., IP address, device/browser information, and viewer events) to load assets, measure performance, and prevent abuse.
End-user notices on embedded sites
Organizations embedding FurnishAR are responsible for providing any required notices/consents to their end users (e.g., for analytics cookies).
5. Security, retention, and your choices
We use reasonable administrative, technical, and organizational safeguards (access controls, encryption in transit, monitoring). No system is 100% secure.
We retain personal data only as long as needed to provide the Service, comply with legal obligations (e.g., billing/tax), and maintain security/audit logs for a reasonable period.
- **Access/correction/deletion:** you may request access to or deletion of your data (subject to legal/security retention).
- **Marketing choices:** you can opt out of marketing communications at any time (transactional emails will still be sent).
- **Cookies:** you can control cookies via browser settings; some features require essential cookies.
For GDPR/EEA users, our legal bases typically include contract, legitimate interests (security/improvement), consent (where required), and legal obligation.