Privacy Policy & Data Rights Notice
Fully Compliant with EU GDPR, UK GDPR, California CCPA/CPRA, and PCI-DSS Standards β’ Updated: September 2026
1. Identity of the Data Controller
THREADFLOW ("the Store", "we", "us", "our") acts as the independent Data Controller for the personal data collected during your visit to our website and the fulfillment of your apparel orders. We are committed to processing your personal data strictly in accordance with the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), the UK Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act (CCPA as amended by CPRA), and international privacy frameworks.
2. Categories of Personal Data We Collect
We apply strict data minimization principles, collecting solely what is necessary to process, produce, ship, and support your custom garment orders:
- Identification & Contact Data: Full customer name, email address, telephone number.
- Delivery & Logistics Data: Shipping street address, apartment/suite, city, state/province, postal code, and destination country.
- Custom Artwork & Production Files: Graphic images, logos, typography, and positioning coordinates submitted to our studio for garment printing.
- Transaction & Billing Records: Stripe Checkout session identifiers, purchase totals, item descriptions, and timestamps (raw credit card numbers are never stored on our servers).
- Fraud Prevention & Technical Telemetry: Anonymized IP addresses, browser user agent strings, and terms acceptance confirmation timestamps (retained solely for dispute defense and transaction integrity under GDPR Art. 6(1)(f)).
3. Legal Bases for Data Processing (GDPR Art. 6)
4. Payment Card Security & PCI-DSS Level 1 Standards
All payment operations are handled exclusively through Stripe, Inc., an audited PCI-DSS Level 1 Service Provider. Your Primary Account Number (PAN), card expiration, and CVV security code are entered directly into Stripe-hosted encrypted fields. No raw cardholder data ever enters, traverses, or resides on our web servers.
5. Authorized Sub-Processors & Data Sharing
We do NOT sell, rent, monetize, or trade your personal data to data brokers. We share data strictly with vetted sub-processors necessary to run the store:
6. Your Statutory Rights Under GDPR & CCPA/CPRA
You possess enforceable rights regarding your personal information, regardless of your country of residence:
- Right of Access (Art. 15): Request a complete machine-readable copy of your personal data.
- Right to Rectification (Art. 16): Correct inaccurate or outdated information.
- Right to Erasure ("Right to be Forgotten" - Art. 17): Request deletion of your personal data, subject to mandatory tax and financial retention laws.
- Right to Restrict Processing (Art. 18): Pause processing while disputing accuracy.
- Right to Data Portability (Art. 20): Receive your data in a structured, commonly used JSON/CSV format.
- CCPA "Do Not Sell or Share My Information": We affirmatively state we do not sell consumer personal information.
Online Privacy & Data Request Portal (DSAR)
Exercise your GDPR or CCPA rights directly. Submit your verified request and our data privacy officer will process it within thirty (30) calendar days at zero cost.
7. Data Protection Officer (DPO) Contact
For statutory privacy questions or inquiries regarding our data processing agreements, you may contact our designated compliance officer directly at: privacy@threadflow-studio.com.