Legal

Privacy Policy

Last updated: August 13, 2026

This policy explains what SONO XR (operated by MBB 3D Media LLC, Los Angeles, California) collects when you use sonoxr.media and our showcase services, how we use it, and the choices you have. Questions any time: hello@mbb3d.media.

01What We Collect

02How We Use It

We do not sell your personal information, and we do not share it with third parties for their own advertising.

03Service Providers

We rely on a small set of processors to run the service: Netlify (hosting and form processing), Stripe (payments), Cal.com (scheduling), GitHub (code and content deployment), and Google Fonts (typefaces served on some pages). Each processes data under its own privacy terms and only as needed to provide its function.

04Cookies & Local Storage

We keep this minimal. The site uses browser local storage for functional purposes (for example, remembering draft settings in the builder demo). We do not use advertising cookies. Third-party services (Stripe checkout, Cal.com embeds) may set their own cookies when you use them.

05Retention

Form submissions and correspondence are kept as long as needed to handle your inquiry and maintain our business records. Project media is kept for the duration of your service (plus a reasonable backup window) and can be deleted on request after a project ends. Billing records are retained as required by tax law.

06Your Rights & Choices

You can ask us at any time to access, correct, export, or delete the personal information we hold about you — email hello@mbb3d.media and we will act on the request within 30 days. California residents may exercise their rights under the CCPA/CPRA through the same contact; we do not sell or "share" personal information as those terms are defined in the CPRA.

07GDPR — Visitors from the EU/EEA & UK

Where the GDPR applies, MBB 3D Media LLC is the data controller for the information described above. Our legal bases are: contract (providing services you request), legitimate interests (operating and securing the site, responding to inquiries), and consent (newsletter emails — withdrawable at any time). You additionally have the rights to restrict or object to processing and to lodge a complaint with your local supervisory authority. Data is processed in the United States; our processors (Netlify, Stripe, Cal.com, GitHub, Google) rely on standard contractual clauses and/or the EU-U.S. Data Privacy Framework for transfers.

08Data Protection & Security

All traffic to sonoxr.media is encrypted (HTTPS). Access to submissions, project media, and administrative systems is limited to the people who need it to deliver your project. Payment data is handled entirely by Stripe, a PCI-DSS Level 1 provider. No method of transmission or storage is 100% secure, but if we learn of a breach affecting your data we will notify you as required by law.

09Children

The Services are for businesses and are not directed to children under 16. We do not knowingly collect their data.

10Changes

We will post any changes to this policy here with an updated date. Material changes will be highlighted on this page.