Pupae Studio Legal

Privacy Policy

For ThreadPrint, provided by Pupae Studio.

Effective date: August 4, 2026 Last updated: August 4, 2026 See also: Terms of Use →
On this page
  • 1. Who This Covers
  • 2. Information We Collect
  • 3. How We Use It
  • 4. Third-Party Services
  • 5. Data Retention
  • 6. Your Rights
  • 7. Children's Privacy
  • 8. Data Security
  • 9. International Transfers
  • 10. Changes to This Policy
  • 11. Contact Us
Drafted from an actual review of what ThreadPrint's code collects and which third-party services it calls — not a generic template. Sections marked "needs your input" should be completed, and the whole document reviewed by a licensed attorney, before you treat it as final.

1. Who This Policy Covers

This Privacy Policy explains how Pupae Studio ("we," "us," or "our") collects, uses, and shares information in connection with ThreadPrint (the "Service"). It applies to the account administrators and users your organization (the "Customer") authorizes to use the Service, and to visitors to our marketing website.

ThreadPrint is a business-to-business product. We collect the personal data described below about the individual people who use the Service on your organization's behalf — not about your end consumers, since ThreadPrint doesn't interact with your customers directly.

2. Information We Collect

This list reflects what the ThreadPrint application actually collects as of this draft, organized by how it's collected.

2.1 Information you provide directly

DataWhy we collect it
Brand (company) nameTo identify your organization's workspace
Admin user email addressAccount login and identification
PasswordAccount authentication. We never store your password itself — only a one-way cryptographic hash (bcrypt) that cannot be reversed to recover it
Garment SKU specificationsFiber composition, weights, production region, freight, and use-phase details you enter, to run the assessment you request. This is business/product data, not personal data
Supplier-submitted factor data (House/Maison)Verified factor values you choose to enter to override the default library for your own assessments
CommunicationsIf you email us for support, we keep that correspondence to respond and to improve the Service

2.2 Information collected automatically

DataWhy we collect it
IP addressUsed transiently by our rate-limiting and security infrastructure to prevent abuse; not linked to your account profile
Session token (JWT)Stored in your browser to keep you signed in. It expires automatically and is not a tracking cookie
Basic server logsStandard request/error logs for operating and debugging the Service

As of this draft, ThreadPrint does not use tracking cookies, browser fingerprinting, or any analytics pixel. If that changes, this section and Section 4 need to be updated together, since analytics tools are exactly the kind of third-party service this policy needs to disclose.

2.3 Information we do not currently collect

Stated explicitly because these are common in similar products and their absence is a real, verifiable fact about this codebase, not an oversight:

  • No payment or billing information — ThreadPrint does not yet process payments through the Service (see Section 4).
  • No precise location, camera, microphone, contacts, or other device-permission data — ThreadPrint is a web application and requests none of these.
  • No data about your end consumers — ThreadPrint's SKU and assessment data describes garments, not people.

3. How We Use Information

  • To provide the Service — authenticate your account, run the calculations and optimizations you request, and store your assessment history.
  • To maintain security — rate-limiting, abuse prevention, and detecting unauthorized access attempts.
  • To communicate with you — responding to support requests, and (only if you're notified in advance) material changes to the Service or these policies.
  • To improve the Service — understanding aggregate, non-identifying usage patterns to prioritize development.

We do not sell your personal data, and we do not use your Customer Data to train any model or share it with any other customer.

4. Third-Party Services and SDKs

This is the direct answer to "what does ThreadPrint share with third parties" — compiled from an actual audit of the codebase's dependencies, not assumed.

CategoryCurrent status
Analytics / trackingNone integrated — no Google Analytics, no ad-network SDK, no tracking pixel
Payment processingNone integrated — subscription changes are currently handled directly by our team, not a payment SDK
AuthenticationNone third-party — login is handled entirely by our own code; no "Sign in with Google" integration
Email deliveryNone integrated — the Service does not currently send transactional or marketing email
Customer support / chatNone integrated — no embedded chat widget
Error / crash reportingNone integrated — no third-party error-tracking service receives application data
Needs your inputName your actual hosting provider here (e.g. Render, Railway, Fly.io, or your own infrastructure) — they process data solely as our hosting infrastructure, and should be named for completeness.

The code libraries ThreadPrint depends on (its web framework, password hashing, session tokens, and its calculation engine) all run within our own server or your own browser — none of them transmit your data to an external company. If you're asked "does your app use any SDKs" on a compliance questionnaire, the accurate answer today is no data-collecting third-party SDKs are integrated — update this the moment that changes.

5. Data Retention

Needs your inputConfirm your actual retention practice. As built, assessment history is kept indefinitely as an append-only record, and there is currently no self-service account-deletion flow — deletion requests are handled by contacting us directly. If that's accurate, say so; if you build self-service deletion before launch, update this section to describe it.

6. Your Rights

Depending on where you're located, you may have rights to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. To exercise any of these rights, contact us at hello@pupaestudio.com.

6.1 If you're in the European Economic Area or UK (GDPR)

Needs your inputState your lawful basis for processing (likely contract performance for account data, legitimate interest for security logs), confirm whether you act as data controller or processor for Customer Data (likely processor), and describe how international transfers are safeguarded if your infrastructure isn't EU-based. Get attorney input here if you have or expect EU/UK customers.

6.2 If you're a California resident (CCPA/CPRA)

Needs your inputConfirm whether CCPA applies to your business (it has revenue/volume thresholds) and, if so, include the specific required disclosures.

7. Children's Privacy

ThreadPrint is a business tool intended for use by adult professionals on behalf of their employer. It is not directed at, and we do not knowingly collect information from, anyone under 18.

8. Data Security

We maintain technical safeguards appropriate to the data we hold, including:

  • Passwords stored only as one-way bcrypt hashes, never in plain text;
  • Session tokens signed with a private key and validated on every request, with a limited expiration window;
  • Rate limiting on authentication and computationally expensive endpoints to reduce brute-force and abuse risk;
  • Standard security response headers and a restrictive cross-origin policy on the API;
  • Every account's data scoped so one organization's data is not accessible to another's.

No system is perfectly secure, and we can't guarantee absolute security. If we experience a data breach affecting your personal data, we'll notify you as required by applicable law.

9. International Data Transfers

Needs your inputState where your servers are physically located and, if that's a different country from some of your customers, what transfer mechanism applies (e.g. EU Standard Contractual Clauses). Don't state a safeguard you haven't actually implemented.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make a material change, we'll provide notice before it takes effect — for example, by email to your account's admin user or a notice within the Service.

11. Contact Us

Questions about this Privacy Policy, or requests to exercise your data rights: hello@pupaestudio.com.

Needs your inputAdd your registered business address here if you're required to disclose one in your jurisdiction.
Pupae Studio

Wear the Change. Building the infrastructure for fashion's transformation, one product at a time.

Studio

  • About
  • Investors
  • Contact

ThreadPrint

  • Product
  • Live demo
  • Pricing

Legal

  • Terms of Use
  • Privacy Policy
© 2026 Pupae Studio. All rights reserved. hello@pupaestudio.com