Privacy Policy
Last updated and effective: October 2, 2026
At Pivot, your privacy is a priority. This policy explains what data we collect, why, and what your rights are. The data controller for the data described below is U-TREMA (EURL, RCS Nanterre 940 083 306), 1 rue Henri Pigeon, 92600 Asnières-sur-Seine, France, operating as "Pivot". Contact: pivot.support@u-trema.org.
1. Data we collect
If you join our early-access list: your email address, the language of the page, and, if you arrived through an ad or campaign link, the campaign tags (UTM parameters) present in the URL, along with the time of your consent.
If you use Pivot as a merchant: your Shopify store domain and the access credentials Shopify provides us to operate the app; your product catalog metadata (titles, images); the name of the iPhone(s) you pair and their last activity; the product captures you submit (photos or video, plus technical capture metadata such as camera positions); the 3D assets generated from them; your per-product viewer settings; and support emails you send us.
If you visit this website: the pages you open and the elements you interact with, measured without any identifier stored on your device (see section 6). One exception: our advertising pixel sets a cookie that gives your browser a random identifier, and if you submit the early-access form, your email address is also sent to our advertising provider in hashed form together with your IP address and browser, so the signup can be attributed to the ad you saw (see sections 3 and 6).
Your customers (storefront visitors): the 3D viewer embedded on your product pages sets no cookies, requires no account and collects no personal data. Standard technical server logs (IP, user agent) may be processed transiently for security and rate limiting.
2. How we use data
- To provide the service (contract): process captures into 3D assets, publish them to your store, operate pairing and support.
- To contact you about early access and product updates (consent): we email the address you gave us; every email includes an unsubscribe link, and you can withdraw consent at any time.
- To measure our advertising: when we run ads, our advertising pixel reports page views and form submissions back to the ad platform so we can tell which ad brought you here. Section 6 explains how to refuse it, and you can object at any time (section 7).
- To secure and improve the service (legitimate interest): logs, error diagnostics, aggregate usage. We do not sell personal data, ever.
3. Processors and third parties
We share data only with the providers needed to run the service:
- Shopify: app platform, store authentication, product data, and (at launch) billing.
- Cloudflare, Inc.: object storage and delivery of capture media and 3D assets.
- KIRI Engine (KIRI Innovations): our specialized 3D reconstruction provider, which receives capture media solely to generate your 3D assets.
- Our hosting provider: application servers and database, hosted in the European Union.
- PostHog, Inc. (United States): audience measurement on this website, in cookieless mode (see section 6).
- Google Ireland Limited (and Google LLC, United States): Google Analytics audience measurement on this website, in cookieless mode (see section 6).
- Meta Platforms Ireland Limited (and Meta Platforms, Inc., United States): advertising measurement on this website. The Meta pixel reports the pages you open, and when you submit the early-access form our server sends Meta the same event with your email address hashed (SHA-256), your IP address and your browser user agent, so the signup can be attributed to the ad you saw.
Some providers may process data outside the European Economic Area; where that is the case, transfers are covered by appropriate safeguards such as standard contractual clauses.
4. Retention
- Raw captures (photos/videos): deleted automatically from storage shortly after processing (currently 10 days).
- Generated 3D assets and settings: kept while your account is active.
- On uninstall: your shop is deactivated immediately and paired devices are revoked; Shopify then instructs us to erase the shop's data, which permanently deletes your database records and stored files.
- Backups: encrypted database backups are retained for 14 days.
- Early-access emails: kept until you unsubscribe or ask for deletion.
5. Published 3D content is public
When you publish a 3D view to your product page or share an embed link, the corresponding 3D assets become accessible to anyone with the link. That is how your customers see them. Unpublish or delete the scan to withdraw access.
6. Cookies
Audience measurement: no cookies. We measure how the site is used with PostHog and Google Analytics, both in cookieless mode: events such as page views and clicks are sent without storing any identifier on your device, so separate visits cannot be linked to each other or to you.
Advertising: one cookie. The Meta (Facebook) pixel sets a first-party cookie named _fbp, kept for 90 days, which gives your browser a random identifier so that a visit or a signup can be attributed to one of our ads. It is set when the page loads. You can refuse it with a tracker blocker or by blocking cookies for this site in your browser, and you can object at any time by writing to us (section 7); the site works identically without it.
The only other thing stored in your browser is your light/dark theme preference (local storage). Campaign tags (UTM) are read from the URL and stored only if you submit the early-access form.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, port, and restrict or object to the processing of your personal data, and to withdraw consent at any time. Write to pivot.support@u-trema.org. We answer within 30 days. You may also lodge a complaint with your supervisory authority (in France, the CNIL, cnil.fr).
8. Security
All traffic is encrypted in transit (HTTPS). Device session tokens are stored hashed. Access to production systems is restricted and uploads go directly to storage through short-lived signed URLs. No system is perfectly secure; we notify affected users of any breach as required by law.
9. Children
The service is intended for professional use and not directed at children under 16. We do not knowingly collect data from children.
10. Changes
We may update this policy from time to time. Material changes will be announced by email or through the service. The date at the top always reflects the latest version.