Legal

Privacy Policy

Effective date: April 5, 2026 Last updated: April 5, 2026

1. Introduction

This Privacy Policy explains how CabiCAD ("we", "us", "our"), operated as a sole proprietorship, collects, uses, stores, and shares your personal data when you use the CabiCAD platform, website, and related services (collectively, the "Service").

We are committed to protecting your privacy and handling your data transparently and responsibly. This policy applies to all users of the Service worldwide, including users in the European Union (subject to the General Data Protection Regulation — GDPR), the United States, Israel (subject to the Israeli Privacy Protection Law, 5741-1981 and its regulations), and all other jurisdictions.

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

Contact: CabiCAD, Atlit, Israel — info@cabicad.com

2. Who This Policy Applies To

This policy applies to:

3. Data We Collect

3.1 Data You Provide Directly

DataWhoPurpose
Email addressAll usersAccount creation, authentication, communications
Password (hashed)All registered usersAuthentication
First and last nameAll registered usersAccount personalization
Company nameDesigners, ManufacturersAccount profile
CountryManufacturers, WaitlistService delivery, compliance
Primary product categoryManufacturersPlatform configuration
Machine count and brandManufacturersMachine setup, post-processor matching
Logo / branding assetsDesignersBranded PDF export feature
Project designs and 3D modelsAll registered usersCore service delivery
Messages and commentsAll registered usersCollaboration and Q&A features
Price quotesManufacturersRFQ workflow
Payment informationPaid tier subscribers (at GA)Billing — processed by Stripe, not stored by us
VAT numberEU business subscribersTax compliance
Waitlist form responsesWaitlist registrantsPre-launch qualification

3.2 Data We Collect Automatically

When you use the Service, we automatically collect:

3.3 Data We Receive from Third Parties

4. How We Use Your Data

We use your data for the following purposes, each grounded in a legal basis:

PurposeLegal Basis
Creating and managing your accountPerformance of contract
Delivering the core platform featuresPerformance of contract
Processing RFQs and connecting designers with manufacturersPerformance of contract
Sending transactional emails (verification, notifications, billing)Performance of contract
Processing payments via StripePerformance of contract
Enforcing feature flag entitlements per subscription tierPerformance of contract
Sending product updates and feature announcementsLegitimate interests (you may opt out)
Improving the platform through usage analyticsLegitimate interests
Detecting fraud and preventing abuseLegitimate interests / legal obligation
Maintaining audit logs for GDPR complianceLegal obligation
Responding to legal requestsLegal obligation
Sending marketing communications (with consent)Consent

We do not sell your personal data to third parties. We do not use your data for automated decision-making that produces legal or similarly significant effects.

5. Data Sharing

5.1 Within the Platform (by design)

CabiCAD's three-party collaboration model requires controlled sharing of data between parties:

5.2 Service Providers (Data Processors)

We share data with trusted third-party processors who act on our instructions:

ProviderPurposeLocation
RailwayCloud infrastructure, hosting, databaseUSA (data center location varies by Railway configuration)
StripePayment processingUSA / Global
Email provider (TBD)Transactional and notification emailsTBD

All processors are bound by data processing agreements and are required to handle data in accordance with applicable law.

5.3 Legal Requirements

We may disclose your data if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, your safety, or the safety of others.

5.4 Business Transfers

If CabiCAD is acquired, merged, or its assets are transferred, your data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website prior to your data becoming subject to a different privacy policy.

6. Data Roles — Manufacturers

For data relating to manufacturers' own customers, employees, and internal production processes that manufacturers upload or process through CabiCAD:

To request a DPA: info@cabicad.com

7. Your Rights

7.1 Rights Available to All Users

7.2 Additional Rights for EU/EEA Users (GDPR)

All rights listed in 7.1 apply. Additionally:

7.3 Additional Rights for Israeli Users

Under the Israeli Privacy Protection Law:

7.4 Additional Rights for California Users (CCPA)

California residents have the right to:

7.5 How to Exercise Your Rights

Submit requests to: info@cabicad.com

We will respond within:

We may need to verify your identity before processing your request.

8. Cookies and Tracking

8.1 What We Use

Cookie TypePurposeCan be declined?
Strictly necessaryAuthentication session, security (CSRF), language preferenceNo — required for the Service to function
AnalyticsUnderstanding how users interact with the platform (aggregate, anonymized)Yes
PreferenceRemembering your UI settingsYes

We do not use advertising or tracking cookies. We do not share cookie data with advertising networks.

8.2 Managing Cookies

You can manage cookie preferences through:

Declining non-essential cookies does not affect your ability to use the core Service.

9. Data Retention

Data TypeRetention Period
Account dataDuration of account + 90 days after deletion request
Project designs and filesDuration of account + 90 days after deletion request
Audit logs3 years (legal/compliance obligation)
Billing records7 years (tax and accounting obligation)
Waitlist dataUntil 12 months after general availability launch, then deleted
Server logs90 days
Deleted account dataPurged within 90 days of deletion (except audit logs and billing records)

When you delete your account, your personal data is anonymized or deleted within 90 days. Project data shared with manufacturers during active RFQs may be retained by those manufacturers independently — CabiCAD cannot control data stored outside our platform.

10. Data Security

We implement industry-standard technical and organizational measures to protect your data:

No method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it responsibly to info@cabicad.com.

11. International Data Transfers

CabiCAD is operated from Israel. Your data may be processed in countries outside your country of residence, including the United States (via Railway and Stripe infrastructure).

For EU/EEA users: These transfers are made on the basis of:

12. Children's Privacy

The Service is not directed at children under the age of 16 (or 13 in jurisdictions where that is the applicable minimum). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at info@cabicad.com and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact & Complaints

CabiCAD
Atlit, Israel
Email: info@cabicad.com

If you are an EU/EEA resident and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. A list of EU DPAs is available at: edpb.europa.eu

If you are an Israeli resident, you may contact the Israeli Privacy Protection Authority: gov.il/en/departments/the_privacy_protection_authority

This Privacy Policy was last reviewed on April 5, 2026. CabiCAD is operated from Atlit, Israel. Governing law: State of Israel.