Last updated: May 20, 2021
Threadloom complies with the requirements of the EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework (collectively “Privacy Shield”), as set forth by the US Department of Commerce and the Federal Trade Commission (“FTC”), regarding the collection, use, and retention of Personal Information transferred from the European Economic Area and Switzerland to the United States. Threadloom has certified to the Department of Commerce that it adheres to the Privacy Shield Principles and Supplemental Principles. If there is any conflict between the terms in this Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view Threadloom’s certification, please visit https:// www.privacyshield.gov. Additionally, Threadloom may protect information through other legally valid methods, including international data transfer agreements.
This Policy applies to all of Threadloom’s operating divisions, subsidiaries, affiliates, and branches, including its US affiliates certified under the Privacy Shield, Threadloom, LLC, and any additional subsidiary, affiliate, or branch of Threadloom that we may subsequently form.
NOTICE FOR CALIFORNIA RESIDENTS
If you are a California resident, please see the section below titled Additional Information for California Residents.
TRANSPARENCY/NOTICE – TYPES OF PERSONAL INFORMATION WE COLLECT AND HOW WE USE IT
The types of Personal Information we may collect (directly from you or from third-party sources) and our privacy practices depend on the nature of the relationship you have with Threadloom and the requirements of applicable law. Some of the ways that Threadloom may collect Personal Information include:
TYPES OF PERSONAL INFORMATION WE COLLECT
Threadloom collects Personal Information regarding its current, prospective, and former clients, customers, users, visitors, guests, and current, temporary, permanent, prospective, or former employees, directors, contractors, workers, or retirees of Threadloom or its subsidiaries worldwide (“Employees”) (collectively “Individuals”).
Information you provide directly to us. When you use our Services or engage in certain activities, such as registering for an account with our Sites and/or Services, responding to surveys, requesting Services or information, or contacting us directly, we may ask you to provide some or all of the following types of information:
Automatic data collection. We may collect certain information automatically through our Services or other methods of web analysis, such as your Internet protocol (IP) address, cookie identifiers, mobile carrier, mobile advertising identifiers, MAC address, IMEI, Advertiser ID, Game Center ID, other device identifiers that are automatically assigned to your computer or device when you access the Internet, browser type and language, geo-location information, hardware type, operating system, Internet service provider, pages that you visit before and after using our Services, the date and time of your visit, the amount of time you spend on each page, information about the links you click and pages you view within our Services, and other actions taken through use of our Services, such as setting preferences.
Information submitted via Services. You agree that Threadloom is free to use the content of any communications submitted by you via our Services, including any ideas, inventions, concepts, techniques, or know-how disclosed therein, for any purpose including developing, manufacturing, and/or marketing goods or Services. Threadloom will not release your name or otherwise publicize the fact that you submitted materials or other information to us unless: (a) you grant us permission to do so; (b) we first send notice to you that the materials or other information you submit to a particular part of a Service will be published or otherwise used with your name on it; or (c) we are required to do so by law.
Information from other sources. We may receive information about you from other sources, including through third-party services and organizations to supplement information provided by you. For example, if you access our Services through a third-party application, such as a Social Networking Site (“SNS”), we may collect information about you from that third-party application that you have made public via your privacy settings. Information we collect through SNS accounts may include your name, your SNS user identification number, your SNS user name, location, sex, birth date, email, profile picture, and your contacts on the SNS. This supplemental information allows us to verify information that you have provided to Threadloom and to enhance our ability to provide you with information about our business, products, and Services.
HOW WE USE YOUR INFORMATION
We do not sell your Personal Information – such as your name and contact information – to third parties to use for their own marketing purposes. We acquire, hold, use, and Process Personal Information about Individuals for a variety of business purposes, including:
To provide products, Services, or information requested. Threadloom may use information about you to fulfill requests for products, Services, or information, including information about potential or future Services, including to:
Administrative purposes. Threadloom may use Personal Information about you for its administrative purposes, including to:
Marketing Threadloom products and Services. Threadloom may use Personal Information to provide you with materials about offers, products, and Services that may be of interest, including new content or Services. Threadloom may provide you with these materials by phone, postal mail, facsimile, or email, as permitted by applicable law. Such uses include:
You may contact us at any time to opt out of the use of your Personal Information for marketing purposes, as further described in the section below titled Opt-Out (Right to Restrict Processing).
Research and development. Threadloom may use Personal Information to create non-identifiable information that we may use alone or in the aggregate with information obtained from other sources, in order to help us to optimally deliver our existing products and Services or develop new products and Services. From time to time, Threadloom may perform research (online and offline) via surveys. We may engage third-party service providers to conduct such surveys on our behalf. All survey responses are voluntary, and the information collected will be used for research and reporting purposes to help us better serve Individuals by learning more about their needs and the quality of the products and services we provide. The survey responses may be utilized to determine the effectiveness of our Services, various types of communications, advertising campaigns, and/or promotional activities. If an Individual participates in a survey, the information given will be used along with that of other study participants. We may share anonymous Individual and aggregate data for research and analysis purposes.
Direct mail, email, and outbound telemarketing. Individuals who provide us with Personal Information, or whose Personal Information we obtain from third parties, may receive periodic emails, newsletters, mailings, or phone calls from us with information on Threadloom’s or our business partners’ products and services or upcoming special offers/events we believe may be of interest. We offer the option to decline these communications at no cost to the Individual by following the instructions in the section below titled Opt-Out (Right to Restrict Processing).
Anonymous and aggregated information use. Threadloom may use Personal Information and other information about you to create anonymized and aggregated information, such as de-identified demographic information, de-identified location information, information about the computer or device from which you access Threadloom’s Services, or other analyses we create. Anonymized and aggregated information is used for a variety of functions, including the measurement of visitors’ interest in and use of various portions or features of the Services. Anonymized or aggregated information is not Personal Information, and Threadloom may use such information in a number of ways, including research, internal analysis, analytics, and any other legally permissible purposes. We may share this information within Threadloom and with third parties for our or their purposes in an anonymized or aggregated form that is designed to prevent anyone from identifying you.
Other uses. Threadloom may use Personal Information for which we have a legitimate interest, such as direct marketing, individual or market research, anti-fraud protection, or any other purpose disclosed to you at the time you provide Personal Information or with your consent.
COOKIES, PIXEL TAGS / WEB BEACONS, ANALYTICS INFORMATION, AND INTEREST-BASED ADVERTISING
Cookies. Cookies are small text files placed in visitors’ computer browsers to store their preferences. Most browsers allow you to block and delete cookies. However, if you do that, our Sites may not work properly.
Pixel tags / web beacons. A pixel tag (also known as a web beacon) is a piece of code embedded on a Site that collects information about users’ engagement on that web page. The use of a pixel allows us to record, for example, that a user has visited a particular web page or clicked on a particular advertisement.
Analytics. We may also use Google Analytics and Google Analytics Demographics and Interest Reporting to collect information regarding visitor behavior and visitor demographics on some of our Services, and to develop Site content. This analytics data is not tied to any Personal Information. For more information about Google Analytics, please visit https://www.google.com/policies/privacy/partners. You can opt out of Google’s collection and Processing of data generated by your use of the Services by going to https://tools.google.com/dlpage/gaoptout.
Our uses of such Technologies fall into the following general categories:
Advertising- or targeting-related. We may use first-party or third-party cookies and web beacons to deliver content, including ads relevant to your interests, on our Sites or on third-party sites. This includes using technologies to understand the usefulness to you of the advertisements and content that has been delivered to you, such as whether you have clicked on an advertisement.
If you would like to opt out of the Technologies we employ on our Sites, Services, applications, or tools, you may do so by blocking, deleting, or disabling them as your browser or device permits.
THIRD-PARTY WEBSITES, SOCIAL MEDIA PLATFORMS, AND SOFTWARE DEVELOPMENT KITS
Our Sites may contain links to other websites and other websites may reference or link to our Sites or other Services. These other domains and websites are not controlled by us, and Threadloom does not endorse or make any representations about third-party websites or social media platforms. We encourage our users to read the privacy policies of each and every website and application with which they interact. We do not endorse, screen or approve, and are not responsible for the privacy practices or content of such other websites or applications. Visiting these other websites or applications is at your own risk.
Our Services may include publicly-accessible blogs, community forums, or private messaging features. Our Sites and Services may also contain links and interactive features with various social media platforms (e.g., widgets). If you already use these platforms, their cookies may be set on your device when using our Sites or other Services. You should be aware that Personal Information which you voluntarily include and transmit online in a publicly accessible blog, chat room, social media platform or otherwise online, or that you share in an open forum may be viewed and used by others without any restrictions. We are unable to control such uses of your information when interacting with a social media platform, and by using such services you assume the risk that the Personal Information provided by you may be viewed and used by third parties for any number of purposes.
HUMAN RESOURCES DATA
Threadloom collects Personal Information from current, prospective, and former Employees, their contact points in case of a medical emergency, and beneficiaries under any insurance policy (“Human Resources Data”). The Human Resources Data we collect may include title, name, address, phone number, email address, date of birth, passport number, driver’s license number, Social Security number or other government-issued identification number, financial information related to credit checks, bank details for payroll, information that may be recorded on a CV or application form, language abilities, contact information of third parties in case of an emergency, and beneficiaries under any insurance policy. We may also collect sensitive Human Resources Data such as details of health and disability, including mental health, medical leave, and maternity leave; information about national origin or immigration status; and optional demographic information such as race, which helps us achieve our diversity goals.
We acquire, hold, use and Process Human Resources Data for a variety of business purposes including:
ONWARD TRANSFER – THREADLOOM MAY DISCLOSE YOUR INFORMATION
INFORMATION WE SHARE
We use vendors and service providers. We may share any information we receive with vendors and service providers. The types of service providers (processors) to whom we entrust Personal Information include service providers for: (i) provision of IT and related services; (ii) provision of information and Services you have requested; (iii) payment processing; (iv) customer service activities; and (v) in connection with the provision of our Sites. Threadloom has executed appropriate contracts with the service providers that prohibit them from using or sharing Personal Information except as necessary to perform the contracted services on our behalf or to comply with applicable legal requirements.
Business partners. Threadloom may share Personal Information with our business partners, and affiliates for our and our affiliates’ internal business purposes or to provide you with a product or service that you have requested. Threadloom may also provide Personal Information to business partners with whom we may jointly offer products or Services, or whose products or services we believe may be of interest to you. In such cases, our business partner’s name will appear, along with Threadloom. Threadloom requires our affiliates and business partners to agree in writing to maintain the confidentiality and security of Personal Information they maintain on our behalf and not to use it for any purpose other than the purpose for which Threadloom provided them.
Privacy Shield. With respect to onward transfers to third parties that process Personal Information at our request, or to which we disclose Personal Information for use on its behalf (“Agents”) under Privacy Shield, Privacy Shield requires that Threadloom remain liable should its Agents Process Personal Information in a manner inconsistent with the Privacy Shield Principles.
Displaying to other users. The content you post to our Sites may be displayed on our Sites. Other users of our Sites may be able to see some information about you, such as your name if you submit a review. We are not responsible for privacy practices of the other users who will view and use the posted information.
Disclosures to protect us or others (e.g., as required by law and similar disclosures). We may access, preserve, and disclose your Personal Information, other account information, and content if we believe doing so is required or appropriate to: (i) comply with law enforcement or national security requests and legal process, such as a court order or subpoena; (ii) respond to your requests; (iii) protect your, our or others’ rights, property, or safety; (iv) to enforce Threadloom policies or contracts; (v) to collect amounts owed to Threadloom; (vi) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation or prosecution of suspected or actual illegal activity; or (vii) if we, in good faith, believe that disclosure is otherwise necessary or advisable.
In addition, from time to time, server logs may be reviewed for security purposes, e.g., to detect unauthorized activity on the Services. In such cases, server log data containing IP addresses may be shared with law enforcement bodies in order that they may identify users in connection with their investigation of the unauthorized activities.
All Personal Information collected via or by Threadloom may be stored anywhere in the world, including but not limited to the United States, the European Union, in the cloud, on our servers, on the servers of our affiliates or the servers of our service providers. Your Personal Information may be accessible to law enforcement or other authorities pursuant to a lawful request. By providing information to Threadloom, you consent to the storage of your Personal Information in these locations.
OPT-OUT (RIGHT TO RESTRICT PROCESSING)
You have the right to opt out of certain uses and disclosures of your Personal Information. Where you have consented to Threadloom’s Processing of your Personal Information, you may withdraw that consent at any time and opt out to further Processing by contacting email@example.com. Even if you opt out, we may still collect and use non-Personal Information regarding your activities on our Sites and/or information from the advertisements on third-party websites for non-interest-based advertising purposes, such as to determine the effectiveness of the advertisements.
EMAIL AND TELEPHONE COMMUNICATIONS
We maintain telephone “do-not-call” and “do-not-mail” lists as mandated by law. We process requests to be placed on do-not-mail, do-not-phone, and do-not-contact lists within 60 days after receipt, or such shorter time as may be required by law.
HUMAN RESOURCES DATA
With regard to Personal Information that Threadloom receives in connection with the employment relationship, Threadloom will use such Personal Information only for employment-related purposes as more fully described above. If Threadloom intends to use this Personal Information for any other purpose, Threadloom will notify the Individual and provide an opportunity to opt out of such uses.
“DO NOT TRACK”
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. DNT is a way for users to inform websites and services that they do not want certain information about their webpage visits collected over time and across websites or online services. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.
COOKIES AND INTEREST-BASED ADVERTISING
As noted above, you may stop or restrict the placement of cookies on your computer or remove them from your browser by adjusting your web browser preferences. Please note that cookie-based opt-outs are not effective on mobile applications. However, on many mobile devices, application users may opt out of certain mobile ads via their device settings.
The online advertising industry also provides websites from which you may opt out of receiving targeted ads from our data partners and our other advertising partners that participate in self-regulatory programs. You can access these, and also learn more about targeted advertising and consumer choice and privacy, at https://optout.networkadvertising.org, or https://www.youronlinechoices.eu and http://optout.aboutads.info. You can also choose not to be included in Google Analytics here.
RIGHTS OF ACCESS, RECTIFICATION, ERASURE, AND RESTRICTION
Although Threadloom makes good faith efforts to provide Individuals with access to their Personal Information, there may be circumstances in which Threadloom is unable to provide access, including but not limited to: where the information contains legal privilege, would compromise others’ privacy or other legitimate rights, where the burden or expense of providing access would be disproportionate to the risks to the Individual’s privacy in the case in question, or where it is commercially proprietary. If Threadloom determines that access should be restricted in any particular instance, we will provide you with an explanation of why that determination has been made and a contact point for any further inquiries. To protect your privacy, Threadloom will take commercially reasonable steps to verify your identity before granting access to or making any changes to your Personal Information.
SECURITY OF YOUR INFORMATION
By using our Sites or providing Personal Information to us, you agree that we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use of our Sites. If we learn of a security system’s breach, we may attempt to notify you electronically by posting a notice on our Sites or sending an email to you. You may have a legal right to receive this notice in writing.
If you are visiting from the European Union or other regions with laws governing data collection and use, please note that you are agreeing to the transfer of your information to the United States and to Processing of your data globally. By providing your Personal Information, you consent to any transfer and Processing in accordance with this Policy.
The Services are not directed to children under 13 (and in certain jurisdictions under the age of 16) years of age, and Threadloom does not knowingly collect Personally Identifiable Information from children under 13 (and in certain jurisdictions under the age of 16) years of age. If you are under the age of 18, you must have your parent’s permission to access the Services. Threadloom urges parents to instruct their children never to give out their real names, addresses, or phone numbers, without parental permission, when online. If you learn that your child has provided us with Personal Information without your consent, you may alert us at firstname.lastname@example.org. If we learn that we have collected any Personal Information from children under 13 (and in certain jurisdictions under the age of 16), we will promptly take steps to delete such information and terminate the child’s account.
REDRESS / COMPLIANCE AND ACCOUNTABILITY
If you are an EU or Swiss citizen and feel that Threadloom is not abiding by the terms of this Policy, or is not in compliance with the Privacy Shield Principles, please contact our EU representative: Rivacy GmbH i.G., Hammerbrookstraße 90, 20079 Hamburg; email: email@example.com.
In addition, Threadloom has agreed to refer unresolved complaints related to Personal Information to JAMS Privacy Shield Dispute Resolution Program and, with respect to Employee and Human Resources data, has committed to cooperate with the panel established by local data protection authorities and comply with the advice given by the panel for EU citizens and with the Swiss Federal Data Protection and Information Commissioner’s authority and advice for such data of Swiss citizens. For more information and to submit a complaint regarding Individual data to JAMS, a dispute resolution provider which has locations in the United States and EU, visit https://www.jamsadr.com/eu-us-privacy-shield.
Such independent dispute resolution mechanisms are available to citizens free of charge. If any request remains unresolved, you may contact the national data protection authority for your EU Member State.
You may also have a right, under certain conditions, to invoke binding arbitration under Privacy Shield; for additional information, see https://www.privacyshield.gov/article?id=ANNEX-I-introduction. The FTC has jurisdiction over Threadloom’s compliance with Privacy Shield.
OTHER RIGHTS AND IMPORTANT INFORMATION
New uses of Personal Information. Additionally, before we use Personal Information for any new purpose not originally authorized by you, we will endeavor to provide information regarding the new purpose and give you the opportunity to opt out. Where consent of the Individual for the Processing of Personal Information is otherwise required by law or contract, Threadloom will endeavor to comply with the law or contract.
ADDITIONAL INFORMATION FOR CALIFORNIA RESIDENTS
This section provides information organized in accordance with the California Consumer Privacy Act (“CCPA”) for residents of California about how we handle certain personal information we have collected over the past 12 months.
Categories of Personal Information
Collect. The section above entitled Types of Personal Information We Collect discloses the categories of personal information that we collect, which include your account and profile information, your content, your communications with us, your information you provide from linked networks, information about your activity on our Sites and Services, and how you engage with us.
Use. The section above entitled How We Use Your Information discloses that the categories of personal information we collect are used to provide our services, for personalization, to provide advertising in order to generate income to operate Threadloom, to promote our services to you, to analyze how our services are used, to comply with law, and to prevent misuse of Threadloom.
Disclose. The section above entitled Information We Share discloses that we share your personal information with, service providers, affiliates, law enforcement authorities, and as needed with third parties to provide our services.
We do not collect personal information from consumers that we know are younger than 16 years old.
Requests for Deletion, Copy and Right to Know Your Information
California consumers have the right to make the following requests, which we endeavor to honor from non-California residents as well:
Deletion. You have the right to request deletion of personal information that we have collected about you.
Copy and Right to Know. You have the right to request a copy of the specific pieces of personal information that we have collected about you over the past 12 months, including the categories of information, sources, and purposes of collection, as well as categories of third parties we have shared it with.
Designated Agent. You may designate an agent to make a request on your behalf. That agent must have access to your account in order for us to verify the request.
You may submit deletion, copy, and right to know requests through the online form here. You can also submit a deletion, copy and right to know request by emailing us at firstname.lastname@example.org. You will need access to the email account associated with your Threadloom account in order to verify your identity and complete this process.
Threadloom will not discriminate against you, including by denying or providing a different level or quality of goods or services should you choose to exercise your options under the CCPA.
Your California Privacy Rights under California’s Shine-the-Light Law
California law permits users who are California residents to request and obtain from us once a year, free of charge, a list of the third parties to whom we have disclosed their Personal Information (if any) for their direct marketing purposes in the prior calendar year, as well as the type of Personal Information disclosed to those parties. Threadloom does not share Personal Information with third parties for their own marketing purposes.
This Policy shall be implemented by Threadloom and all its operating divisions, subsidiaries and affiliates. Threadloom has put in place mechanisms to verify ongoing compliance with Privacy Shield Principles and this Policy. Any Employee that violates these privacy principles will be subject to disciplinary procedures.