Privacy Policy
Last updated October 5, 2026
This policy explains what information Magnovera LLC ("Magnovera", "we") handles when jewelers use Magnovera Showcase (the "Service"), and when their customers open a showcase link. Questions: support@magnovera.com.
Two roles
Jewelers (our customers). For businesses that create an account, we decide how their account information is used; we are the controller.
Their customers. When a jeweler sends a design to one of their customers, the jeweler decides what to include (for example the customer's first name, a note, photos, a PIN), and the Service records how the link is used for them. We store and show that on the jeweler's behalf and only on their instructions; the jeweler is the controller and we are their processor. If you are a jeweler's customer, please contact the jeweler about your information; we will help them respond.
Information about jewelers
- Account: name, email address, mobile phone number (required when you create a store's account; optional for team members), company, role, how you sign in (password, Google or Microsoft). Passwords are stored only as salted, one-way hashes. Mobile numbers are kept in international (E.164) format.
- Agreements and consent records: when you create an account we record which version of the Terms of Service, this Privacy Policy and the notice at collection you accepted, and, separately, whether you agreed to marketing email and whether you agreed to marketing calls and texts (with the number it was for). Each record has the version of the wording you saw, the time, and a keyed one-way hash of your network address (not the address itself). Changes you make later in Branding are recorded the same way.
- Roles and the audit log: each store has one super admin (the account holder, who acts for the business), any number of owners, managers and members. We keep a log of changes to roles (promotions, removals, super admin transfers), store sharing and security settings, the model-training choice, and link security actions (PIN resets, file deletions): who did it, when, and what changed. Owners can see their store's log. Entries are kept for two years.
- Business settings you enter: business name, tagline, logo, website, contact email, colors, fonts, catalog, showcase options, customer email wording, sharing and security settings (whether staff may send the full 3D file, whether customers can use AR, whether links need a PIN or an email confirmation), and whether to be listed in our public directory (on unless you turn it off).
- Business profile: asked on the second step of sign-up and editable in Branding → About your business. Your role and the type of business are required at sign-up; the rest is optional: number of stores, staff size, revenue range, what you sell, services, the software you use, challenges you want help with, preferred way and time to be contacted, how you heard about us, a business phone, and newsletter preference.
- How you found us: the campaign tags in the link you arrived on, the referring website and first page you visited.
- Usage: counts of customer links sent and opened, customer try-ons, augmented-reality views, downloads and enquiries on those links, 3D models and photos uploaded, storage used, team invitations, sign-ins and last activity.
- Files you upload or make: 3D models, photos, logos, lighting and color files, the 360° spins your browser renders from your models, and the low-detail viewing copies made for customers.
- The store benchmark (optional): when your staff time a computer to estimate how long a 360° spin will take, we keep the name they give the machine and a short description of it (browser and version, operating system, graphics chip name, number of processor cores, memory size, screen size and pixel density, refresh rate, and whether it is a phone) with the timing results and a measured upload speed, for your store only. We keep the latest five results per machine and the times of past spins (up to 200) to make estimates better. No fingerprint or identifier of the device is kept, and staff can delete a machine at any time.
Information about jewelers' customers
- What the jeweler puts on a link: the design settings and what to show (a 360° spin, a 3D view, photos, the order they appear in, and the full 3D file only if the jeweler's store allows it and the salesperson chose it), and optionally the customer's first name and a note.
- Email: if a jeweler emails a link from the Service, or asks customers to confirm their email before a link opens, the recipient's email address is used to send that email or the confirmation code and is kept on the link for that purpose.
- Link PINs: a jeweler can protect a link with a PIN they give the customer. We store only a one-way, keyed hash of the PIN, never the PIN itself, and count wrong attempts so a link locks after repeated failures. A correct PIN sets a cookie for that link on that device (30 days).
- How a link is used: when a customer opens a link, we record that it was opened and for how long, which angles and colors of the piece were viewed, which photos were opened, whether try-on, AR or a download was used, the type of device (phone, tablet or computer), and a coarse location (country, region and city) derived at our edge network from the network address. The address itself is not stored. The jeweler sees this per link and as totals; it is not tied to a named person unless the jeweler put the customer's name or email on the link.
- Try-on and camera: hand tracking (Google MediaPipe, served from our own site) runs entirely in the customer's browser. Camera video and hand photos are never uploaded to us or to Google. Saved try-on photos stay on the customer's device.
- Augmented reality: AR shows only the low-detail viewing copy. On iPhone and iPad, Apple's AR Quick Look shows a file made on the device. On Android, Google's Scene Viewer app may download the low-detail copy from us to show it; Google's own terms apply to that app.
The Spin Bench
The Spin Bench is a test page we send to invited testers through a private link to measure how well devices make and play 360° spins. It records the nickname a tester types (optional), detailed device facts (browser, operating system, graphics chip, processor, memory, screen, supported video formats), the test results, the network's country, region and operator (from our edge network), and a salted, one-way hash of the network address used only to group runs and limit abuse. It is not used on customer links. Results are kept for up to 365 days.
Optional model training
A store's super admin can choose to let Magnovera keep the 3D files the store's staff upload and use them to train its software models. It is off unless switched on, and saying no never reduces the Service or changes its price.
- What: the original 3D files staff upload from the day it is switched on (for example STL, 3DM, GLB or OBJ). Not the low-detail copies customers see, spins or photos; not customers' names, emails, notes or viewing statistics; not staff details.
- The training collector: each such file is stored once, in a separate Magnovera store for training (the training collector), and the store's own file points to it. The store sees and uses the file for its links for the usual 7 days, and while training is on these files don't count against the store's storage limit. The collector's copy then follows the rules below.
- Who: Magnovera and contractors working for us under written confidentiality. Never sold, never shown to other stores, never published or offered as designs.
- What for: improving how the Service finds stones and metal parts, the stone shape changer, and rendering.
- How long: no fixed end date: kept while we use it for training and testing, until the store switches it off (then deleted within 30 days) or asks us to remove particular files.
- Withdrawing: switch it off in Branding at any time. We stop collecting at once (new uploads count against the store's storage again) and delete every copy already in the collector within 30 days; a file the store's links still use stays until it expires, then goes. A model already trained can't be "untrained", but the store's files are not used for new training. A store can also ask us to remove particular files sooner.
- Record: we keep who made the choice, when, and the version of the text they saw (currently
training-2026-10-v3), and for each collected file the store, the time, its size and type, and that version.
Sharing settings are separate: whether staff may send the full 3D file, and whether customers can see pieces in AR, are store settings of their own and don't depend on the training choice.
Technical information
- IP addresses are used to prevent abuse and to derive the coarse location above. For rate limits (including on PIN attempts and sign-in), a counter keyed by the address, or by the email address for password resets, is kept for up to a few hours (daily upload allowances: up to three days) and then deleted. A refused administrator sign-in is logged with the address. Otherwise addresses are not stored, except as the salted hash described for the Spin Bench.
- If something breaks, we record the error, the page and the browser type (user agent) to fix it. These records don't identify a person. Our hosting provider also keeps short-lived operational logs.
- Cookies: only strictly necessary cookies: a sign-in session (30 days), short-lived cookies used during Google/Microsoft sign-in, and, on links that require them, a cookie remembering that the customer confirmed their email or entered the link's PIN on that device (30 days each). No advertising or cross-site tracking cookies.
- Local storage in your browser: the Service keeps a few conveniences on your own device that are not sent to us unless you use them: your theme and language, the last 3D model you opened (so a refresh brings it back), your chosen spin quality and customer options, this computer's benchmark score, and, for Spin Bench testers, the test's progress and nickname. You can clear them in your browser's settings.
- Analytics: if enabled, our marketing pages (not the staff app or customer links) use Plausible Analytics, which does not use cookies or collect personal data. Customer showcase pages have no third-party analytics.
- Fonts: every font is served from our own site, including the brand fonts a jeweler can pick (open-source fonts first published through Google Fonts). No page loads fonts from Google Fonts or connects to Google's font servers, so no visitor data goes to Google for fonts.
How we use information
- To provide and secure the Service: accounts, showcases, customer links, PINs and their statistics, emails you ask us to send, storage limits, and your team.
- To send service messages: sign-in and password emails, invitations, role changes, and a monthly usage report for a store's owners (you can turn it off in Branding or with the link in each report).
- To improve the Service and fix problems, including estimates from the store benchmark.
- Marketing email only if you ticked that box (at sign-up or in Branding). Every marketing email identifies us, includes our postal address and an unsubscribe link; unsubscribes are honoured within 10 business days (the US CAN-SPAM Act).
- Marketing calls and texts to your mobile number only with your separate, express written consent (the second box at sign-up, never pre-ticked and never a condition of using the Service). Reply STOP, tell us on a call, untick it in Branding or email us to withdraw it. Without that consent we use your number only for your account and service matters.
- To contact jewelers about our services: we use the business details stores enter (business name, website, contact email, the super admin's name and email, and the business profile) and the store's usage totals to understand which businesses use the Service and to contact them about Magnovera products, as business-to-business contact. You can opt out at any time in Branding → About your business, with the link in our emails, or by emailing us. We send marketing emails where the law requires consent only if you agreed. We never sell personal information and never use your customers' details for this.
- Model training only if the store's super admin switched it on (above).
- To review reports and keep the Service safe (below).
Reports and content review
Customer pages have a Report link. Anyone with a link can use it, without an account, to tell us about something on the page that shouldn't be there.
- What a report holds: the link reported, its store, the reason chosen, any details typed, an email address if the person gives one for a reply, the time, and a keyed one-way hash of their network address (to limit abuse; never the address itself). The business that sent the link is not told who reported it.
- Content review: to review a report, or when we have another good reason to think the Terms are being broken, Magnovera's platform administrators may look at the store's content: its links and the notes and customer first names on them, its photos and spins, its 3D files (the customer's protected view and the original as uploaded) and copies in the training collector. Every such view and action is logged with who did it and when.
- What may follow: we may disable a link, delete a file, or pause the store's access (its staff are told why; its customer links then show that they're unavailable). Changes to a store are also shown in the store's own activity log.
- How long: reports are kept for two years after they are closed; our administrators' log for two years.
Store invitations
While new stores join by invitation, we may send an invitation to an email address, optionally with a store name and a short note. We keep those, when the invitation was sent and whether it was used, so we can resend or withdraw it; an unused invitation is deleted a year after it expires.
Who we share it with (sub-processors)
Service providers that run parts of the Service for us, under contracts that require them to protect it:
- Cloudflare, Inc.: hosting and edge network, database (D1), file storage (R2), rate limiting, sending email (Email Service), the Turnstile bot check on sign-in, and operational logs.
- Google LLC and Microsoft Corporation: only if you choose to sign in with them.
- Sentry (Functional Software, Inc.): error reports, if enabled.
- Plausible Analytics: cookieless statistics on our marketing pages, if enabled.
- Our customer-relationship tool, for business contacts (not your customers).
We also share information with authorities when the law requires it, and with a buyer of our business, with the same protections, if that ever happens. We will tell stores before adding new categories of sub-processors.
How long we keep it
- Accounts, business settings and the business profile: while your account is active.
- Uploaded 3D models, low-detail viewing copies, 360° spins and photos: 7 days from upload, after which links to them stop working. Staff can delete a link's files sooner. Each store can keep up to 5 GB of such files at one time.
- Customer links: each link works for 7 days from when it is sent (sooner if its files expire first or staff revoke it).
- Agreements and consent records: while your account is open; deleted with your account.
- Viewing data (a link's record, how it was opened and its statistics) is not part of the 7 days rule: it stays for the store until the link has not been opened for 365 days, or until the person who sent it deletes their account.
- Uploaded files that nothing uses any more: deleted after two days.
- Audit log: two years. Store benchmark: the latest five results per machine. Spin Bench runs: up to 365 days.
- Model-training copies in the training collector (only if switched on): no fixed end date; deleted within 30 days after the store switches training off.
- Reports from the Report link: two years after they are closed. Our administrators' log: two years. Store invitations: until a year after they expire.
- Backups: the database can be restored to any point in the last 30 days (our hosting provider's point-in-time recovery); uploaded files are not backed up.
Your choices and rights
You can see and change your business information and your store's sharing, security and training settings in Branding (the training choice is the super admin's), download your company's data (Account → Download my data), turn off monthly reports and marketing contact, and delete your account (Account → Delete my account), which removes your account, your business profile and the customer links you created. A super admin must hand the role to another owner before deleting their account while others are still in the store. Depending on where you live you may have further rights (for example to access, correct, delete, port or object); email support@magnovera.com and we will respond within 30 days.
Your California privacy rights
This section is our notice at collection and privacy notice for California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA), and our disclosures under the California Online Privacy Protection Act (CalOPPA). The same summary is shown on the last step of sign-up, before an account is created.
Categories we collect about jewelers and their staff (in the last 12 months, and going forward), where from, and why:
- Identifiers and contact details (name, email address, mobile number, account ID): from you or from Google or Microsoft when you sign in with them. To provide and secure accounts, send service messages, and send marketing only as described above.
- Customer records under Cal. Civ. Code § 1798.80(e) (name, phone number): from you. Same purposes.
- Professional or employment-related information (business name, your role, the business profile): from you. To set up your store and for business-to-business contact.
- Internet or other electronic network activity (sign-ins, usage counts, the page and campaign you arrived from, error reports): from your use of the Service. To run, secure and improve it.
- Inferences (a lead score and suggested next step made from the business profile and usage, seen only by our staff): made by us. To decide which businesses to contact about our products. It has no legal or similarly significant effect on you.
- Sensitive personal information: account log-in (your email with your password). Used only to sign you in and keep the account secure, which the CCPA permits without a right to limit.
- Consent records (described above): from your choices. To show what you agreed to.
About jewelers' customers we act as a service provider to the jeweler (see "Two roles"); requests about that information go to the jeweler.
Disclosures. We disclose the categories above for business purposes only to the service providers listed under "Who we share it with", under contracts that limit their use. We do not sell or share personal information (sharing meaning for cross-context behavioral advertising), have not done so in the last 12 months, and do not knowingly sell or share the information of anyone under 16. Because we don't, there is no "Do Not Sell or Share" choice to make; if that ever changes we will add a "Do Not Sell or Share My Personal Information" link, ask before applying it to information collected before, and treat a Global Privacy Control signal from your browser as a request to opt out. We do not use sensitive personal information to infer characteristics about you.
Retention for each category is under "How long we keep it".
Your rights. You may ask to know what personal information we have collected about you (the categories, sources, purposes, who we disclosed it to, and the specific pieces), to delete it, and to correct it; to opt out of sale or sharing (which we don't do); and to limit the use of sensitive personal information (which we use only as permitted). We won't discriminate against you for using these rights. Email support@magnovera.com with the subject "California privacy request". We will confirm within 10 business days and respond within 45 calendar days (we may extend once by 45 more, telling you why). To protect you, we verify a request by matching it to your account (for example, by asking you to send it from the account's email address or to sign in). You may use an authorized agent, who must show your signed permission; we may still ask you to verify your identity with us directly.
Shine the Light. We do not disclose personal information to third parties for their own direct marketing (Cal. Civ. Code § 1798.83).
Do Not Track. We do not track visitors across other websites, and third parties can't do so through our pages, so we don't respond differently to a browser's Do Not Track signal; we honor Global Privacy Control as described above.
Changes and how to review or change your information: see "Your choices and rights" and "Changes"; the date of this policy is at the top.
Security
Encrypted connections (HTTPS), hashed passwords, session keys and link PINs, signed and expiring addresses for files, strict limits on what each role can do, a protected low-detail copy for customers by default, protections against common web attacks, and access to business-contact records limited to our staff. No system is perfectly secure; if a breach affects your information we will tell you without undue delay.
Children
The Service is for businesses and is not directed at children under 16. We do not knowingly collect information from children. A jeweler's customer link may be opened by anyone the jeweler sends it to; if you believe a child's information has been put on a link, contact the jeweler or us and we will help remove it.
International transfers
Our hosting provider runs a global network: requests are handled at the data centre nearest the visitor, and our database and files are stored in the United States. If you use the Service from elsewhere, your information is transferred to and processed in the United States, under the safeguards the law requires.
Changes
We will post changes here and update the date above. For significant changes we will also email each store's super admin and owners. If we change the model-training text, we ask the store again before relying on the new version.
Contact
Magnovera LLC
[postal address]
support@magnovera.com