Privacy Policy
3DRedBox Studio KFT is the data controller for this website. This page explains, in plain language, what we collect and why — including how we count visits, which is the part most sites describe least honestly.
Last updated 19 August 2026
01What we collect
When you buy something: your email address, your name if you give it, and the contents of your order. If you arrived through a tagged link that day, the order also records the campaign tags that were on it — utm_source, utm_medium, utm_campaign — so we can tell which of our own posts brought somebody here. Payment card details go directly to Stripe and never reach our servers.
When you create an account: your email address, your name if you give it, and a bcrypt hash of your password. We never hold the password itself, and the six-digit sign-in code we email you is stored only as a hash. Each sign-in also writes a session record, which holds your browser's user-agent string and, where our hosting provider reports it, the IP address the sign-in came from.
When you use the contact form: your name, your email address, the subject if you give one, and the message you write.
When you subscribe to the newsletter: your email address, and nothing else. Entering it does not put you on the list — we email that address one link, and until somebody clicks it we never send anything else to it. If you did not ask for the newsletter and got that email, someone typed your address into our form; ignore it and the request expires by itself within a week.
When you read a page: one row in our own analytics table. That is the part of a privacy policy usually covered by a sentence, so the next section sets it out field by field.
02How we count visits
Every page you open sends one short message to our own server. It records the path you opened — the path only, never the query string — the page that referred you and the site that page was on, any campaign tags on the URL, whether the layout you saw was desktop, mobile or tablet, which browser family it was (Chrome, Safari, Firefox, Edge, Opera, Samsung Internet or Other, with no version number), a two-letter country code where our hosting provider tells us one, the time, and a visitor id.
Six further things are counted by name: viewing a product, viewing a course, adding something to the cart, starting checkout, completing a purchase, and starting a download. Each carries a short record of what it was about — a product's slug, title and price; the item count and total on a purchase; the file and edition on a download.
The visitor id is not a cookie and not a device fingerprint. It is a SHA-256 hash of your IP address, your user-agent string, and a random 32-byte salt that is generated fresh at UTC midnight, kept only in the server's memory, and never written down. Within one day the same browser hashes to the same 22-character id, which is what lets us count visitors instead of requests. When the day turns, that salt is gone — not archived, and not derived from any master key, so it cannot be recomputed. Yesterday's ids can never be matched against today's. Nobody, ourselves included, can follow you from one day to the next or turn an id back into an address. (Where our host reports no address at all, the id is built from the browser family and device class alone, which is coarser still.)
Your IP address is used to compute that hash and is then discarded. Neither analytics table has a column to put it in.
Two things can point at a person rather than at a visitor, and both sit on those six named events — never on a page view. If you are signed in when one fires, the row records your account id; and a completed purchase records your order number, which resolves to an order carrying your email address. Both are now removed after 30 days, leaving the count and nothing else. Inside those 30 days, that event is linkable to you, and we would rather say so here than let you find out from the schema.
Within a single day, page views sharing one id can be read in sequence — that is how our dashboard works out which page a visit began on and which it ended on. So it is fair to say we hold one day of anonymous reading. It is not fair to say we hold nothing. Across days there is no sequence left to read.
The beacon is JavaScript that runs after the page has drawn. With JavaScript off, or with that one request blocked, nothing is sent and nothing is recorded — and the site behaves exactly the same. We do not try to measure around it.
03What we deliberately do not do
We do not use advertising trackers, we do not build behavioural profiles for targeting, and we do not run third-party analytics that follow you across other websites. There is no Google Analytics here, no advertising pixel, no tag manager, and no third-party script of any kind. The measurement described above is entirely first-party: the beacon posts to this domain, the rows are written to our own database, and nobody else ever receives them.
That choice costs us real answers, and it is worth naming which. An identifier that expires nightly cannot tell us how many visitors came back this month, how long the path from first visit to purchase is, or anything else that spans more than a day. We would rather not be able to answer those than hold an identifier that could.
It is also why there is no consent banner. Consent is required for storing or reading something on your device — a cookie, a local-storage key, a fingerprint — and we do none of those for measurement, so there is nothing to ask permission for. Deriving an id from a salt that is thrown away every night is the more expensive way to build this. It is the reason you were not asked to click anything.
Every response from this site also carries an interest-cohort opt-out, which excludes it from the browser's own advertising-topics scheme, and a strict-origin referrer policy, so a link you follow away from here tells the destination that you came from this site and never which page you were on.
04Why we use it
To deliver what you bought and to keep your download page working.
To answer your questions and handle refunds or licensing requests.
To send occasional emails about new releases, if and only if you asked for them.
To see which pages and products people actually read, which links bring them here, and where the shop loses them. The measurement above is read as counts on an internal dashboard. It is never used to decide what any individual visitor is shown, and it is never used to advertise to you.
To meet our legal obligations — Hungarian and EU law requires us to keep transaction records for accounting purposes.
05Legal basis
Order and account data is processed to perform a contract with you. Contact messages are processed on the basis of legitimate interest in answering enquiries. Newsletter emails are processed on the basis of your consent, which you can withdraw at any moment.
Site measurement is processed on the basis of our legitimate interest in understanding how our own shop is used, under Article 6(1)(f). The balancing test is what shaped the design rather than something written up afterwards: the identifier expires nightly, nothing is stored on your device, your address is never kept, the data never leaves our servers, and it is never used to target you.
06Who we share it with
Stripe, to process payments. Our email provider, to deliver order confirmations, sign-in codes and any newsletter you asked for. Our hosting provider, which stores the database.
That is the complete list. No analytics data leaves our servers at all. We do not sell data, and we do not share it for marketing purposes with anyone.
One thing on the site does involve a third party, and it should be stated plainly rather than left in a footnote: the videos on course and product pages are hosted by YouTube. Nothing is requested from YouTube until you press play — the still image you see first is served from this domain, not theirs. Once you press play the player loads from youtube-nocookie.com, and from that moment Google receives your IP address and can record that the video was played, under their policy rather than ours.
07How long we keep it
Page views and named events: 395 days, about 13 months. This is not a promise to remember — a deletion job in the site enforces it, running when the server starts and once a day after that, and the studio can run it by hand against a restored backup.
The account id and order number attached to an event: 30 days, removed by the same job. After that the event is a count with nobody attached to it.
Contact messages: 2 years, then deleted by the same job.
Newsletter subscriptions: until you unsubscribe. The unsubscribe link deletes the record outright — we do not keep a list of the people who left.
Sign-in sessions and emailed codes: deleted as soon as they expire, which removes the user-agent string and IP address stored with them.
Order records: eight years, as Hungarian accounting law requires. Nothing deletes an order automatically, and an erasure request cannot remove the invoice-level record before those eight years are up. That is the one item on this page the law decides rather than we do.
Why 13 months and not longer: it is the longest window our own reports can ask for, plus a month so that window is never half-empty. Nothing here is kept on the grounds that it might be useful one day.
08Cookies, local storage and video
This site sets no advertising cookies and no analytics cookies. It sets two cookies in total, both strictly necessary: one when you sign into your account, one when the studio signs into the admin panel. Both are HttpOnly, neither is readable by JavaScript, and both are removed when you sign out or when the session expires.
Your shopping cart is kept in your browser's local storage. It never leaves your device until you go to checkout.
Pressing play on a video hands you to youtube-nocookie.com, which may set storage of its own under Google's policy. Until you press it, nothing from YouTube is loaded at all — not even the thumbnail, which we fetch on our own server and serve from this domain.
09Your rights
Under GDPR you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable format.
One honest limit, which follows from the design above rather than excusing it: we cannot find you in the analytics data. A page view carries an id we cannot reverse and cannot recompute once its day has passed, so there is nothing there to hand over, correct or delete on request. The exception is an event still inside its 30-day window, which may carry your account id — ask and we will clear it early. Article 11 says we are not required to collect more information about you in order to be able to identify you in that data, and we would rather not.
Write to contact@3dredboxstudio.com and we will action the request within thirty days. If you are not satisfied with our response, you have the right to complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
10Security
All traffic is encrypted in transit. Passwords — yours and ours — are stored as bcrypt hashes, never in plain text. Session tokens and emailed sign-in codes are stored only as SHA-256 hashes, so a copy of the database cannot be replayed as a login. Access to the production database is limited to the studio.