Privacy Policy

Effective Date: October 1, 2025

Last Updated: August 9, 2026

Threadsourced LLC, a Hawaii limited liability company ("Threadsourced," "we," "us," or "our"), is committed to protecting the privacy of every user of our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website at threadsourced.com, use our web application, or interact with our services (collectively, the "Service"). This Privacy Policy is part of, and subject to, our Terms of Use.

By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with these practices, please do not use the Service.

1. Our Role: Controller and Processor

Threadsourced plays two different roles, and the distinction matters.

For information about our own customers — the retailers who subscribe to the Service, their account and billing details, and how they use the platform — we act as a controller and this Privacy Policy describes our own practices.

For Customer Data that a retailer enters into the Service about its own retail customers, group members, and employees, the retailer is the controller (and, under the California Consumer Privacy Act as amended by the CPRA, the business) and Threadsourced is the processor (and service provider). We process that data only on the retailer's instructions and as described here and in our Data Processing Addendum, a copy of which is available on request. If you are a shopper or employee of one of our retailers and want to exercise rights over your information, please contact that retailer; we will forward requests we receive to them.

As a service provider we do not sell or share Customer Data, do not retain, use, or disclose it for any purpose other than the business purposes specified in our agreement with the retailer, do not use it outside our direct business relationship with the retailer, and do not combine it with personal information from another source except as permitted for a service provider.

2. Information We Collect

Information You Provide

When you register for an account, subscribe to the Service, or contact us, we may collect: your name, email address, phone number, and business name; your business address and tax identification information; billing information (payment card and ACH details are collected and stored by our payment processors, not by us — see Section 7); store location details, employee information, and business configuration; and any other information you voluntarily provide, including messages, notes, and support requests.

Information Generated Through Your Use of the Service

As you use the Service, the following data is created and stored: Customer Data — your customer records, individual sales transactions, order details, inventory levels, purchase orders, work orders, group and payroll-deduction elections, and employee information; and Usage Data — information about how you interact with the Service, including features used, pages visited, session duration, clicks, browser type, device information, IP address, and performance metrics.

Information Collected Automatically

We automatically collect certain technical information, including: IP address, browser type, and operating system; device identifiers and configuration; referring and exit URLs; and cookies, local storage, and similar tracking technologies (see Section 10).

3. How We Use Your Information

We use the information we collect to: provide, operate, and maintain the Service; process transactions and manage your subscription; communicate with you about your account, updates, and support requests; improve and develop new features based on usage patterns; generate Aggregate Data (see Section 4) for analytics, benchmarking, and reporting; detect, prevent, and address fraud, abuse, and technical issues; comply with legal obligations and enforce our agreements; and send you relevant product updates and notifications, with opt-out available.

4. Aggregate Data

Aggregate Data means data derived from Customer Data and Usage Data that has been de-identified and aggregated so that it is not reasonably capable of being used to identify any individual, customer, or specific business. We may create, use, and share Aggregate Data for lawful purposes, including: industry benchmarking and trend analysis (for example, regional sales trends and seasonal inventory patterns); product development and Service improvement; anonymized reports shared with manufacturer and vendor partners; and market research and analytics publications.

Aggregate Data is designed and maintained so as not to identify you, your business, your customers, or any individual. We will not attempt to re-identify Aggregate Data, we use commercially reasonable measures — including minimum-cohort thresholds and suppression of small counts — to reduce the risk of re-identification, and we contractually prohibit recipients from attempting to re-identify it or from combining it with other data in order to do so.

You can opt out. You may opt out of having data derived from your account included in manufacturer- or vendor-shared aggregate reports at any time by contacting support@threadsourced.com. We will give effect to your opt-out within thirty (30) days; it applies prospectively.

5. What We Will NOT Share

We are committed to protecting your most sensitive data. We will not sell, share, or disclose: your individual customer records or customer personal information; individual sales transaction details or order-level data; employee personal information; or your login credentials or authentication tokens.

These protections apply to all third parties, including our manufacturer and vendor partners, except in the following narrow cases:

6. Drop-Ship Orders and Manufacturer Partners

Where you configure a drop-ship order — an order the manufacturer ships directly to your retail customer rather than to your store — fulfilling that order necessarily requires us to transmit the order recipient's name, shipping address, and, where the carrier requires it, contact telephone number to that manufacturer or vendor. By configuring a drop-ship order you authorize that transmission for the orders you initiate.

Apart from drop-ship fulfillment, and apart from disclosures required by law, we do not share your individual customer records or individual sales data with manufacturers or vendors. Orders that a customer collects in store are routed to your store, and no end-customer information is sent to the manufacturer for them.

7. Sharing with Service Providers and Subprocessors

To operate the Service we share certain information with the following categories of providers. This list is current as of the Last Updated date above; not every provider is engaged for every customer, since engagement depends on the integrations and payment processor you enable. We will give at least thirty (30) days' notice before adding or replacing a provider that processes Customer Data.

Cloud infrastructure and hosting — Amazon Web Services, Inc. Hosting, storage, compute, and backups. All Customer Data at rest, stored in the United States.

Transactional email — Amazon Simple Email Service. Recipient name and email address, to deliver order, shipping, and account emails.

Payment processors — Stripe, ValorPay, Elavon, PayTrace, North / NMI, and Authorize.Net, depending on the processor you select. Your business contact information, billing details, and transaction amounts necessary to authorize, settle, and tokenize card and ACH payments. Card credentials are held by the processor as tokens or in the processor's vault.

Ecommerce platforms — Shopify and WooCommerce. Catalog, inventory, and order data necessary to synchronize your online store, including order and recipient details for orders placed there.

Manufacturer and vendor partners — your business name, contact information, and account numbers necessary to synchronize product catalogs, transmit purchase orders, and manage vendor relationships, plus recipient details for drop-ship orders as described in Section 6.

Shipping and logistics providers — order recipient names and shipping addresses necessary to rate, fulfill, and track deliveries.

AI and large language model providers — Anthropic. Support-conversation content and operational diagnostics, to power in-product AI-assisted support and internal troubleshooting. We contractually require that the provider process this data only to return a result to us, not use it to train or fine-tune its models, and retain it only as long as necessary to provide the service and monitor abuse. AI-generated output may be inaccurate and is not professional advice. You may request that AI-assisted support features be disabled for your account by contacting support@threadsourced.com.

Support ticketing and chat — DeskPro. Support conversation content and the contact details of the person requesting support.

Analytics and monitoring — Google Analytics on our public website, plus internal logging and monitoring. Usage Data and technical telemetry; no Customer Data content.

All service providers are contractually required to maintain the confidentiality of your information, use it only for the purposes for which it was disclosed, maintain appropriate security measures, and accept data protection obligations no less protective than ours.

8. Data Security and Incident Notification

We implement administrative, physical, and technical safeguards to protect your information, including: encryption of data in transit (TLS) and at rest; encryption of stored payment tokens and authentication credentials; role-based access controls, including per-location authorization, limiting access to data; least-privilege administrative access with review and prompt revocation; application and access logging with alerting on anomalous activity; redundant infrastructure with automated backups and documented, periodically tested restoration procedures; security review of our service providers; confidentiality agreements and security-awareness training for personnel; and a documented incident-response process. We will not materially reduce the overall level of protection while you are a customer.

Security incident notification. If we confirm a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to your Customer Data, we will notify you without undue delay and in any event within seventy-two (72) hours of confirming it. The notification will describe, to the extent then known, the nature and estimated scope of the incident, the categories and approximate volume of data and number of individuals affected, the likely consequences, the measures taken or proposed to contain and remediate it, and a contact point for further information. We will cooperate reasonably with your own notification obligations and provide a written incident summary on request once the investigation concludes.

Payment card security. Where a payment card is entered in the Service, the card details are tokenized in the browser directly against the payment processor's tokenization endpoint; the primary account number is not transmitted to, processed by, or stored on Threadsourced systems. Threadsourced does not store full primary account numbers or sensitive authentication data. We maintain compliance with the applicable requirements of the PCI Data Security Standard for the components of the Service within our cardholder data environment, and validate annually by completing Self-Assessment Questionnaire A-EP together with external vulnerability scanning by an Approved Scanning Vendor. Our then-current Attestation of Compliance is available on written request under confidentiality.

No method of transmission or storage is 100% secure. While we work to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.

9. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Upon account termination you have ninety (90) days to export your Customer Data, and that export access is preserved even during a suspension. After that period we will delete or de-identify your Customer Data within a further ninety (90) days, except where retention is required by law or for the establishment, exercise, or defense of legal claims (for example, billing records and dispute records), and except for routine backups, which age out on our standard backup cycle. Aggregate Data may be retained indefinitely, as it is not reasonably capable of being used to identify you. On written request we will certify deletion.

10. Cookies and Tracking Technologies

We use cookies and similar technologies to: maintain your session and authentication state; remember your preferences and settings; analyze Service usage and performance; and detect and prevent fraud. You can control cookies through your browser settings, though disabling them may affect the functionality of the Service. We do not sell or share personal information for cross-context behavioral advertising. We do not currently respond to "Do Not Track" browser signals, as there is no common standard for them; where required by applicable law we honor Global Privacy Control signals on our public website.

11. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal information: Access — request a copy of the personal information we hold about you; Correction — request correction of inaccurate or incomplete information; Deletion — request deletion of your personal information, subject to legal retention requirements; Data Portability — request your data in a structured, machine-readable format; Opt-Out — opt out of aggregate data sharing with manufacturer and vendor partners; and Unsubscribe — opt out of non-essential communications via unsubscribe links in emails. You will not be discriminated against for exercising these rights.

To exercise these rights, contact us at support@threadsourced.com. We will respond within thirty (30) days, and will tell you if we need more time. Where we act as a processor for one of our retailers, we will forward your request to that retailer, who is the controller.

12. Minors

The Service is a business tool and is not directed to children. Only an individual who is at least eighteen (18) years of age may enter into our Terms of Use or administer an account, and authorized users must be at least sixteen (16) years of age.

Our retailers may, in the ordinary course of their business — for example, school-uniform or group programs — enter information about minors into the Service as Customer Data. In that case the retailer is the controller and is solely responsible for the lawful basis for collecting and using that information, including any parental consent required by law. We process it only as a processor, apply the same safeguards we apply to all Customer Data, and do not knowingly collect personal information directly from children. If you believe a child has provided information to us directly, contact us at support@threadsourced.com and we will promptly delete it.

13. International Data Transfers

The Service is operated from the United States, and information is stored and processed in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, and by using the Service you consent to that transfer and processing. If you transfer information originating outside the United States into the Service, you are responsible for establishing a lawful transfer basis, and we will cooperate in good faith to put in place any additional terms reasonably required, including standard contractual clauses where applicable.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or through a prominent notice in the Service at least thirty (30) days before taking effect. Your continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy. We encourage you to review this page periodically.

15. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, contact us at:

Threadsourced LLC, Attn: Legal — hello@threadsourced.com — support@threadsourced.com — 1.877.808.2348