ATELIER THREADFLOW
Bespoke DTGFront & Back
Back to Store
DATA PROTECTION & PRIVACY CHARTER

Privacy Policy & Data Rights Notice

Fully Compliant with EU GDPR, UK GDPR, California CCPA/CPRA, and PCI-DSS Standards β€’ Updated: September 2026

1. Identity of the Data Controller

THREADFLOW ("the Store", "we", "us", "our") acts as the independent Data Controller for the personal data collected during your visit to our website and the fulfillment of your apparel orders. We are committed to processing your personal data strictly in accordance with the EU General Data Protection Regulation (GDPR - Regulation (EU) 2016/679), the UK Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act (CCPA as amended by CPRA), and international privacy frameworks.

2. Categories of Personal Data We Collect

We apply strict data minimization principles, collecting solely what is necessary to process, produce, ship, and support your custom garment orders:

  • Identification & Contact Data: Full customer name, email address, telephone number.
  • Delivery & Logistics Data: Shipping street address, apartment/suite, city, state/province, postal code, and destination country.
  • Custom Artwork & Production Files: Graphic images, logos, typography, and positioning coordinates submitted to our studio for garment printing.
  • Transaction & Billing Records: Stripe Checkout session identifiers, purchase totals, item descriptions, and timestamps (raw credit card numbers are never stored on our servers).
  • Fraud Prevention & Technical Telemetry: Anonymized IP addresses, browser user agent strings, and terms acceptance confirmation timestamps (retained solely for dispute defense and transaction integrity under GDPR Art. 6(1)(f)).

3. Legal Bases for Data Processing (GDPR Art. 6)

Contractual Necessity (Art. 6(1)(b))Processing required to fabricate your garment, route files to printers, charge payment, and deliver to your address.
Legal Obligation (Art. 6(1)(c))Compliance with statutory tax reporting, VAT calculation, and commercial book-keeping mandates.
Legitimate Interests (Art. 6(1)(f))Protecting our business against chargeback fraud, unauthorized access, and cyber attacks.

4. Payment Card Security & PCI-DSS Level 1 Standards

Zero Cardholder Data Retention (PCI-DSS SAQ A)

All payment operations are handled exclusively through Stripe, Inc., an audited PCI-DSS Level 1 Service Provider. Your Primary Account Number (PAN), card expiration, and CVV security code are entered directly into Stripe-hosted encrypted fields. No raw cardholder data ever enters, traverses, or resides on our web servers.

5. Authorized Sub-Processors & Data Sharing

We do NOT sell, rent, monetize, or trade your personal data to data brokers. We share data strictly with vetted sub-processors necessary to run the store:

Printify, Inc. & Certified Print Partners: Receives customer name, shipping address, and print artwork files to physically manufacture and ship custom orders.
Stripe, Inc.: Processes credit card, Apple Pay, and Google Pay payment authorizations.
Postal & Courier Networks (USPS, FedEx, DHL, Royal Mail): Receives shipping address and tracking data to execute physical doorstep delivery.

6. Your Statutory Rights Under GDPR & CCPA/CPRA

You possess enforceable rights regarding your personal information, regardless of your country of residence:

  • Right of Access (Art. 15): Request a complete machine-readable copy of your personal data.
  • Right to Rectification (Art. 16): Correct inaccurate or outdated information.
  • Right to Erasure ("Right to be Forgotten" - Art. 17): Request deletion of your personal data, subject to mandatory tax and financial retention laws.
  • Right to Restrict Processing (Art. 18): Pause processing while disputing accuracy.
  • Right to Data Portability (Art. 20): Receive your data in a structured, commonly used JSON/CSV format.
  • CCPA "Do Not Sell or Share My Information": We affirmatively state we do not sell consumer personal information.

Online Privacy & Data Request Portal (DSAR)

Exercise your GDPR or CCPA rights directly. Submit your verified request and our data privacy officer will process it within thirty (30) calendar days at zero cost.

7. Data Protection Officer (DPO) Contact

For statutory privacy questions or inquiries regarding our data processing agreements, you may contact our designated compliance officer directly at: privacy@threadflow-studio.com.