Crochet 3D

Privacy Policy

Last updated: 15 September 2026

This policy explains what Crochet 3D does with personal information: what we collect, why, who else sees it, how long we keep it, and what you can ask us to do about it. It covers the website at crochet3d.com and everything you can reach from it — the pattern editor, the gallery and your account.

1. Who we are

  • Legal name: Individual Entrepreneur George Papashvili (sole proprietor under Georgian law), trading as Crochet 3D
  • Identification number: 01015001988
  • Registered address: Angisa II Lane, N 8, Building B, Flat 1002a, Batumi, Georgia
  • Contact: hello@crochet3d.com

We are the controller of the personal information described here. The business is registered in Georgia (the country) as an individual entrepreneur — a sole proprietorship, so the controller is the owner in person — and you can verify it independently at the National Agency of Public Registry.

2. What we collect

Only what the product actually needs. In the language of the US state privacy laws:

  • Identifiers — your email address, and the display name you choose. If you sign in with Google, we receive your email address, name and profile picture from Google; we never receive your Google password. The picture is copied once into our own storage so that your browser never has to request it from Google, it is shown only to you, and you can remove it at any time under Settings → Profile. If you choose one of our built-in profile pictures instead, that choice replaces it — and unlike the Google picture, the drawing you pick is public: it appears beside your name on any pattern you share in the gallery. It is one of our own illustrations, not a photograph of you.
  • Account credentials — your password, stored only as a salted hash by our authentication provider. We cannot read it.
  • Your choices — whether you asked for marketing email and when you told us, and which version of these documents you accepted when the account was created. A consent nobody can evidence is worth nothing to either of us, which is why the answer is dated rather than merely stored.
  • Content you create — the crochet patterns you write, their names and settings, the 3D preview images generated from them, and anything you choose to publish to the gallery.
  • Commercial information — if you buy a paid plan: which plan, its status, the currency and amount agreed, the renewal date, and the order, payment and invoice records the law requires us to keep.
  • Billing details — the name, billing country and, if you give one, the tax id you enter at checkout. You enter them on our payment partner’s page, not ours: the partner is the merchant of record and needs them for the receipt and the tax. What comes back to us is your billing country and the currency of your plan.
  • Payment datawe never receive or store your card number. You type it on our payment provider’s own page. What comes back to us is the outcome of the payment, the last details needed to identify it, and a token that stands in for the card so that a renewal or a refund can be made against it. The token is useless anywhere else and cannot be turned back into a card number.
  • Internet activity and device data — IP address, browser type and pages requested, recorded in server logs for security, abuse prevention and diagnosing faults.
  • Activity on your account — a short, recent record of what you did here: opening the planner, viewing or opening a shared pattern, liking one, renaming, sharing or unsharing your own, changing your display name or profile picture, using one of the free tools, opening the pricing page, sending a bug report, and reaching the payment page. It holds the event and the name of the thing it was about — never what you wrote in a pattern, and nothing read from your browser or connection. It is how we can answer “I pressed Share and nothing happened” instead of guessing, and it is limited on purpose: the last 500 events, and nothing older than 180 days, whichever comes first. You can read it too — ask us and we will send you your own, exactly as we see it.
  • How far you have got with the product — a short list of first-time marks on your account: that you opened the planner, worked your first stitch, reached ten rounds, saved a pattern, asked for an export or were refused one, filled your plan’s pattern shelf, saw an upgrade prompt, reached the payment page, subscribed, and whether you came back a day and a week after signing up. Each is recorded once, the first time it happens, with the date and nothing else — never a pattern, never a page address, never anything read from your browser or your connection, and never a second entry however often you do the same thing again. It is how we can see where people get stuck instead of guessing. You can read yours too — ask us, or it comes with the copy of your information.
  • Anonymous product counts — how many times a day something happened here: a pricing page opened, a plan card pressed, an export asked for, a survey answered. These are totals and nothing else. They carry no account, no identifier of any kind, no address and nothing that could be traced back to you or to your device — which is why they are also counted for visitors who never sign in, and why there is nothing in them for us to show you, correct or delete.
  • Things stored in your browser — preferences, locally saved patterns and the sign-in session. These stay on your device; the full list, including how long each one lasts, is in the cookie notice.
  • Correspondence — what you write to us, so we can answer.

We do not collect special-category data (health, biometrics, political or religious views, and so on), and we ask you not to put such information into pattern names or descriptions.

3. Why we use it, and on what legal basis

  • To provide the service — creating your account, saving and rendering your patterns, running the gallery, and delivering a paid plan you bought. Legal basis: performance of a contract.
  • To keep it working and safe — preventing bots, abuse and fraud, keeping backups, and fixing faults. Legal basis: legitimate interests.
  • To support you — the recent activity record described above, so that a question about your own account can be answered from what actually happened. It is kept per account and read by us only to help you or to look into a problem; it is never used to profile you, to decide anything about you automatically, or for advertising. Legal basis: legitimate interests, balanced against the limits in section 7.
  • To see where the product falls short — the first-time marks and the anonymous counts described above, so that “most people stop before they have saved anything” is something we can know rather than suspect, and so that what we build and what we charge for follow from it. Read only as totals, never to profile you, never to decide anything about you automatically, and never for advertising. Legal basis: legitimate interests, balanced against the limits in section 7.
  • To communicate — sign-in links, password resets, and notices about your account or material changes to this policy. Legal basis: contract and legal obligation.
  • To send you news about the product — occasional email about new features, patterns and offers, only if you opted in. It is a separate choice from the account itself, you can change it whenever you like under Preferences in your account settings, and every such message will carry an unsubscribe link. Legal basis: consent.
  • To understand how the product is used — aggregate statistics, only if you allow analytics. Legal basis: consent (EU/UK), or your opt-out right (US).
  • To meet our obligations — accounting and tax records for paid orders. Legal basis: legal obligation under Georgian law.

4. Who else processes it

We use the service providers below. Each acts on our instructions under a data processing agreement, and none of them may use your information for their own purposes.

  • Supabase, Inc.Accounts and authentication, and the database holding your profile, pattern metadata and subscription status. (United States (company); our database instance is hosted in Canada (Montréal). privacy policy)
  • Cloudflare, Inc.Hosting, content delivery, DNS, storage of your pattern files and preview images (R2), bot protection on the sign-in forms (Turnstile), and delivery of account email — sign-in links, email confirmations, password resets and account notices. (United States, with delivery from data centres worldwide. privacy policy)
  • Google LLC (Google Analytics)Aggregated statistics about how the site is used — which pages are opened, which features are reached, and how people find us. IP addresses are shortened by Google before storage and are not used to identify you. If you decline analytics, it runs in a cookieless mode that stores nothing on your device and creates no identifier for you. (United States and Ireland; certified under the EU–US Data Privacy Framework, with standard contractual clauses for other transfers. privacy policy)
  • Meta Platforms, Inc.Measuring our ads and showing Crochet 3D to people with similar interests on Facebook and Instagram. Only with your consent to advertising cookies; purchases are also reported from our server, under the same consent. (United States and Ireland; certified under the EU–US Data Privacy Framework. privacy policy)
  • Reddit, Inc.Measuring our Reddit ads and showing Crochet 3D to people with similar interests on Reddit. Only with your consent to advertising cookies. (United States; standard contractual clauses for transfers. privacy policy)
  • Pinterest, Inc.Measuring our Pinterest ads and showing Crochet 3D to people who save similar crochet ideas. Only with your consent to advertising cookies. (United States and Ireland; standard contractual clauses for transfers. privacy policy)
  • Creem (Armitage Labs OÜ)Selling the paid plans as merchant of record: taking the card payment on its own checkout page, charging renewals, collecting and remitting any tax due on the sale, issuing the receipt for each payment, and paying refunds back. Your card details are entered on their page and never reach us; what comes back to us is the outcome of each payment, the subscription's status and your billing country. Their name appears on your card statement. (Estonia (European Union); card processing by its payment partners in the EU and the United States. privacy policy)

These are not in use yet — each arrives with the feature that needs it, and none of them has had any of your information. They are listed now so that there is no gap between switching one on and telling you about it:

  • Brevo (Sendinblue SAS)Sending the newsletter, if you subscribe to it. (France (European Union). privacy policy)
  • Anthropic PBCTurning a written description into a draft pattern, once AI pattern generation launches. Only the text of the request would be sent — not your account details — and it would not be used to train their models. (United States. privacy policy)

Anything that runs in your browser — analytics or advertising technology, present or future — is listed in the cookie notice, which is generated from the same configuration the site loads from and is therefore always current.

5. Do we sell or share your personal information?

Yes, in the specific sense those words carry under California law. Some advertising technology on this site shares identifiers with advertising partners for cross-context behavioural advertising, which the CCPA/CPRA treats as “sharing” even though no money changes hands. You can switch this off at any time using the Your Privacy Choices link in the footer, and we honour Global Privacy Control signals automatically. We do not sell your information for money, and we do not knowingly sell or share the information of anyone under 16.

6. Where your information goes

We are established in Georgia, our database instance is hosted in Canada, and the providers listed above are established in the United States, the European Union, Georgia and India. Personal information therefore crosses borders. For transfers out of the EEA or the UK we rely on the European Commission’s adequacy decision for Canada, and on Standard Contractual Clauses (with the UK Addendum where relevant) for the rest — you can ask us for a copy of the safeguard that applies to a given provider.

7. How long we keep it

  • Account and content — for as long as your account exists. Delete your account and it goes with it, as described below.
  • Patterns published to the gallery — removed with your account, except that copies other users have already saved to their own devices are outside our reach.
  • Orders and invoices — for the retention period Georgian accounting law requires, even after the account is deleted. The billing name and address you gave are part of the invoice and stay on it, because an invoice cannot be rewritten after it is issued. This is an obligation we cannot waive, and it is the one thing deleting your account does not reach.
  • The card token — kept on your subscription record while the account exists, and deleted with the account. Once a subscription is cancelled the token is not used again: the agreement behind it is revoked at the payment provider, so there is nothing left for it to authorise.
  • Your marketing choice, and the dated record behind it — for as long as the account exists. Withdrawing stops the email and is itself recorded; deleting the account removes the choice and the record together.
  • The activity record — the last 500 events on your account, and nothing older than 180 days, whichever limit comes first. Older entries are deleted as new ones arrive, not on a schedule we might forget to run, and the whole record goes when the account does.
  • The first-time marks — for as long as the account exists, one row per mark, and the whole set goes when the account does. There is no history behind them to expire: a mark is written once and never again.
  • The anonymous counts — kept as daily totals. They contain no account and nothing that identifies anybody, so there is nothing in them that could be deleted with one.
  • Server logs — up to 90 days, then discarded.
  • Support email — up to 24 months after the conversation ends.

8. Your rights and how to use them

Wherever you live, you can ask us to give you a copy of your information, correct it, or delete it, and we will not treat you worse for asking. If you are in the EEA or the UK you also have the rights to restrict or object to processing, to portability, and to withdraw consent at any time without affecting what was lawful before. If you are in California, Colorado, Connecticut, Texas, Virginia or another US state with a privacy law, you have the equivalent rights to know, delete, correct, opt out and — where the law provides it — appeal a refusal.

The practical routes:

  • Delete everything yourself — the account menu has “Delete account”. It removes your profile, your patterns, your uploaded files, your gallery entries, your activity record, your first-time marks and your billing details. It is immediate and cannot be undone. If a paid subscription is still running, cancel it on the billing page first — that stops the payment provider before the account it belongs to goes, so nothing can be charged afterwards. Invoices already issued stay, for the reason given in section 7.
  • Marketing email — the switch under Preferences in your account settings, at any time. Every message we send will carry an unsubscribe link too, and either route is the same decision: we hold one record of it, and the switch is what it reads. Withdrawing has no effect on anything else — your account, your patterns and any paid plan are untouched.
  • Cookies and trackers — the “Cookie settings” link in the footer, at any time. We honour Global Privacy Control automatically.
  • Everything else — email hello@crochet3d.com. We answer within 30 days, and will tell you if we need longer. We may ask you to confirm control of the email address on the account before acting, so that nobody can use these rights against you. You may use an authorised agent where the law allows it.

If you think we have got it wrong, tell us first — but you can also complain to a regulator: the data protection authority of your country of residence in the EEA or the UK, the Personal Data Protection Service of Georgia, or your state attorney general in the US.

9. Children

Crochet 3D is not intended for children under 13, and we do not knowingly collect their personal information. If you believe a child under 13 has created an account, write to us and we will delete it. Where the GDPR applies, users under 16 need a parent’s or guardian’s permission before consenting to optional cookies.

10. Security

Traffic is encrypted in transit (TLS), passwords are stored only as hashes, and access to the database is restricted by row-level security so one account cannot reach another’s data. Administrative access inside our team is limited to who needs it and is logged. No system is perfectly secure; if a breach affects your personal information we will notify you and the relevant authorities as required by law.

11. Changes

When this policy changes materially we will update the date at the top and, where it matters to you, tell you by email. The cookie notice tracks its own date automatically, because it is generated from what the site actually loads.

12. Contact

hello@crochet3d.com, or by post to Individual Entrepreneur George Papashvili, Angisa II Lane, N 8, Building B, Flat 1002a, Batumi, Georgia.

See also our Terms of Service and the cookie notice.