Site document
Privacy Policy
This page contains the terms of using the website and information about cookies that the user accepts when continuing to use the site.
Draft version: not finalized yet
Complete the business details and public support contacts before treating this legal page as final.
- Add the legal entity name or FOP full name.
- Add the registration / tax identifier.
- Add the registered legal address.
- Add the return / claims address.
PRIVACY POLICY
Version dated 04.06.2026
This Privacy Policy is governed by the Law of Ukraine "On Personal Data Protection" No. 2297-VI of 01.06.2010, as amended. By registering or using the 3Desher service, you acknowledge that you have read this Policy and consent to the processing of personal data for the purposes stated herein.
──────────────────────────────────────
1. DATA CONTROLLER
──────────────────────────────────────
The data controller is the Administration of the 3Desher service.
Contact: [email protected]
──────────────────────────────────────
2. DATA WE COLLECT
──────────────────────────────────────
2.1. Data provided by the User:
— First and last name;
— Email address;
— Phone number;
— Delivery address (city, Nova Poshta branch or home address);
— Seller profile data (business name, description, photos);
— Published content (product photos, 3D models, descriptions, reviews).
2.2. Automatically collected data:
— IP address;
— Browser type and operating system;
— Cookies and session identifiers;
— Access logs;
— Device data (in the mobile app);
— Firebase FCM token (for push notifications).
2.3. Transaction data:
— Order information (items, amounts, statuses);
— Delivery data (waybill number, tracking status);
— Payment transaction identifiers (card details are processed exclusively by LiqPay, not stored by us).
2.4. We do NOT store full card numbers, CVV/CVC codes or payment system passwords.
──────────────────────────────────────
3. PURPOSES OF PROCESSING
──────────────────────────────────────
We process personal data for:
a) Service delivery: registration, authentication, order processing and fulfilment, delivery coordination, payment processing, notifications;
b) Security: user verification, fraud detection and prevention, protection against unauthorised access;
c) Support: responding to enquiries, technical communications, change notifications;
d) Analytics: aggregate analysis of service usage (without identifying specific individuals);
e) Legal compliance: data retention and disclosure as required by law.
──────────────────────────────────────
4. LEGAL BASIS FOR PROCESSING
──────────────────────────────────────
— Performance of a contract: processing is necessary to provide the services you have requested.
— Legitimate interest: fraud detection, Platform security protection.
— Legal obligation: data retention and disclosure as required by applicable law.
— Consent: sending marketing communications (with your explicit consent; you may withdraw consent at any time).
──────────────────────────────────────
5. SHARING DATA WITH THIRD PARTIES
──────────────────────────────────────
5.1. We share data with the following categories of third parties:
NOVA POSHTA (novaposhta.ua)
Purpose: delivery organisation, waybill creation.
Data: Buyer's name, phone number, delivery address.
LIQPAY / PRIVATBANK (liqpay.ua)
Purpose: payment processing.
Data: order amount, order ID, email address.
GOOGLE / FIREBASE
Purpose: OAuth authentication, push notifications.
Data: email and name (when signing in via Google), FCM device token.
LAW ENFORCEMENT AUTHORITIES
Purpose: fulfilment of legal requirements.
Data: any data pursuant to a lawful request (Article 14, Law of Ukraine "On Personal Data Protection").
5.2. We do not sell, rent or exchange personal data with advertising agencies or data brokers.
──────────────────────────────────────
6. DATA RETENTION PERIODS
──────────────────────────────────────
— Account data: until account deletion + 30 days (backup copies).
— Transaction and order data: 5 years (accounting legislation requirements).
— Access logs: 12 months.
— Data related to violation investigations: until proceedings are concluded.
──────────────────────────────────────
7. DATA SECURITY
──────────────────────────────────────
— Data in transit: TLS 1.2/1.3 (HTTPS).
— Passwords: bcrypt hashing (original passwords are never stored).
— Sessions: HttpOnly, Secure cookies, SameSite=Lax.
— Database access: restricted to authorised personnel.
— Backups: regular encrypted backups.
No security system is absolutely impenetrable. In the event of a data breach that may cause significant harm, we will notify affected Users and the relevant supervisory authority within the timeframes prescribed by law.
──────────────────────────────────────
8. YOUR RIGHTS
──────────────────────────────────────
Under Article 8 of the Law of Ukraine "On Personal Data Protection" you have the right to:
ACCESS — request a copy of your personal data.
RECTIFICATION — request correction of inaccurate or outdated data.
ERASURE — request deletion of your data (subject to lawful grounds for retention).
RESTRICTION — request restriction of processing in cases provided by law.
OBJECTION — object to processing on the basis of legitimate interest.
WITHDRAWAL OF CONSENT — withdraw consent to marketing or push notifications at any time.
COMPLAINT — lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua) or a court.
To exercise your rights, send a request to: [email protected]
We will respond within 30 calendar days.
──────────────────────────────────────
9. COOKIES
──────────────────────────────────────
ESSENTIAL (cannot be disabled):
— JSESSIONID: login session identifier;
— CSRF token: cross-site request forgery protection.
FUNCTIONAL:
— Theme preference (dark/light mode);
— Language settings.
You may configure or disable cookies in your browser settings. Disabling essential cookies may affect site functionality.
──────────────────────────────────────
10. MINORS
──────────────────────────────────────
The Platform is not intended for persons under 18 years of age. We do not knowingly collect personal data from minors. If you become aware of a minor registering without parental consent, please contact [email protected].
──────────────────────────────────────
11. CHANGES TO THIS POLICY
──────────────────────────────────────
We will notify Users of material changes via a site banner or email no less than 7 days before the changes take effect. The current version is always available at 3desher.com/privacy.
──────────────────────────────────────
12. CONTACT INFORMATION
──────────────────────────────────────
Email: [email protected] (subject: [Personal Data] or [Privacy])
Website: 3desher.com/support
Parliamentary Commissioner for Human Rights: ombudsman.gov.ua
Business details
- Support email
- [email protected]
- Support phone
- +380938416330