Privacy notice
Last updated: 17 September 2026
This notice describes the Shadow Studio free preview and paid account workspace provided under the Shelterscape brand. Privacy enquiries: contact@shelterscape.com.au.
Plan files and calculation data
When you import a PDF or image, the application first reads the file in your browser to display the plan. Importing alone does not upload that PDF or image. In the free preview, the original file remains on your device and its displayed copy stays in the current browser session. In the paid workspace, choosing Enable saving uploads the project and its source files as described below.
Shadow calculations run on Cloudflare, so calculation data leaves your browser. The application sends drawing geometry, building and fence heights, roof settings, site scale and orientation, terrain settings, location coordinates, study date, time and time-zone settings. These inputs are needed to calculate the massing and shadows returned to your browser. This request does not include the PDF or image, project address text, building names or client notes. Coordinates and detailed geometry can still reveal information about a property; this preview is not an offline tool.
The calculation endpoint uses those inputs to produce its response; it does not itself save an editable project. The free preview has no project storage, autosave or recovery. Refreshing or closing the page, or a browser interruption, can lose the session. Signing in elsewhere does not make a free-preview session save automatically.
Saving in the paid workspace
Saving starts only after an explicit Enable saving action in the account workspace. It sends editable model geometry and settings, project names, address text, labels and notes, the displayed plan image, any original PDF, and any separate aerial image to Cloudflare. Later saved changes update that project. Original PDFs are retained to support reopening a multi-page plan. Only upload material you have permission to store.
Editable project data is held in a private Cloudflare D1 database; plan, PDF and aerial files are held in private Cloudflare R2 storage. Access is checked against the signed-in account. The application does not create public file links. Cloudflare processes the information to provide hosting and storage; this is not a promise of storage only in Australia.
The workspace retains the current saved project and one previous successful editable revision. A failed or conflicted save must be resolved before closing the tab; unsaved edits are not a backup. The current limits are 20 projects, 500 MiB of file storage per account, 30 MiB per file, and 100 files per project. Older uploaded file versions continue to count towards storage until you delete their project; automatic cleanup of unused file versions is not implemented.
You can list and delete existing saved projects after paid-feature access expires, and authenticated access to their saved data remains available. Opening the paid editor, changing saved data and uploading new files require active access. Deleting a project removes its editable revisions and associated source files. If a storage operation fails, the application keeps the deletion pending so it can be retried. A minimal deletion record may remain to prevent an interrupted upload from recreating the project. Provider backups and security records follow the provider's retention arrangements. Deleting a project does not itself delete your account or billing records.
Drawing exports
When you request an export in the paid workspace, drawing geometry, study settings and drawing annotations are sent to Cloudflare to generate the selected output. A PDF may use plan and aerial images already saved with your project. Saving a project is required before those images can appear in a server-generated PDF. Export generation does not make a public link to your project or source files.
Address suggestions
After you pause while typing into the address search field, the entered text is sent directly from your browser to the Photon address service, which uses OpenStreetMap data. The request necessarily exposes connection information such as your IP address to that service. It does not include the contents of your imported plan or your model.
You can use manual latitude and longitude without typing into address search. Do not put client names, access codes or confidential notes in the address field. Third-party services have their own data practices; this notice does not promise how long Photon retains its request logs.
Website delivery and security
Serving the website requires the hosting provider to process connection and request information, which can include an IP address, browser information, requested page and request time. Cloudflare hosts the website and runs the calculations. Connection information is also used to limit request rates and help protect the service. Infrastructure-level traffic and security records may be processed under Cloudflare's own arrangements; no promise is made that all provider records disappear when a calculation completes. See Cloudflare's privacy policy for its handling of end-user traffic data.
We have not added advertising trackers, session recording or visitor analytics. The application does not save projects in browser storage. Authentication, checkout and hosting providers may use their own session cookies, connection records and necessary technologies. Your browser may cache application files; that is separate from saving your project.
When you contact us
If you email support, we receive the information and attachments you choose to send. We use them to respond, investigate your request and keep necessary business records. Send only the information needed to explain the issue, and remove unrelated personal or confidential details from screenshots where possible.
Authorised staff and service providers supporting our email, hosting and business systems may process information needed for those purposes. Some providers may process information outside Australia. We may also disclose information where legally required. We do not sell your personal information or automatically add support enquiries to a marketing list.
We keep support correspondence only for as long as reasonably needed to resolve the issue, maintain necessary records and meet legal obligations. Service-provider logs follow the provider's applicable retention arrangements. We do not promise that third-party logs are deleted when you close a browser tab.
Accounts and payments
Clerk provides managed sign-in for the paid workspace. It processes the account and sign-in information needed for authentication. Our server uses the verified account identifier to associate access and saved projects with the correct owner. The account page can display your email from Clerk. Authentication information and provider logs are separate from project files.
Stripe hosts the checkout and billing-management pages for subscriptions. Live checkout takes real payments; any test checkout is explicitly labelled and does not charge real money. Do not enter real payment-card information into a test checkout. Our application stores account-linked Stripe customer and subscription identifiers, access status and relevant billing-event metadata in Cloudflare D1. It does not receive or store full payment-card numbers. Stripe may process the identity, contact and transaction details entered into its pages under Stripe's privacy policy.
Signing out does not delete saved projects. To request account and associated personal-data deletion, contact us using the address below. We may need to retain records required for security, dispute handling or legal obligations; we will explain any applicable limitation when responding.
Your choices and questions
You may ask about personal information we hold about you, or request access, correction or deletion, by emailing contact@shelterscape.com.au. We may need to confirm your identity. We will explain any legal reason that prevents us from fulfilling a request and respond to privacy complaints within a reasonable time. These requests cannot recover a session that the application did not save.
If you are dissatisfied with our response, you may contact the Office of the Australian Information Commissioner or another privacy authority available to you.
We will update this notice when our data practices change and show the revision date. Postal address: Suite 1208/530 Little Collins Street, Melbourne VIC 3000, Australia.