ThreadOps
Log in Get started
Legal

Privacy Policy

Last updated: April 10, 2026 · Effective: April 10, 2026

This Privacy Policy explains how ThreadOps (operated by Polsia) collects, uses, stores, and protects your personal and business data. We are committed to transparency and to protecting your rights under the GDPR and other applicable data protection laws.

1 Who We Are (Data Controller)

ThreadOps is a product of Polsia, operating as the data controller for personal data collected through this platform.

  • Service: ThreadOps — garment factory RFQ and operations platform
  • Location: Sofia, Bulgaria
  • Contact: support@polsia.com

For GDPR purposes, Polsia is the controller of data collected at the account level. Factory users are controllers of the business data (RFQs, quotes) they submit to the platform.

2 Data We Collect

We collect the following categories of data:

Category Data Collected Why
Account data Factory name, email address, encrypted password To create and manage your account
Business data RFQs, quotes, pricing configuration, factory details To provide the ThreadOps service
Contact data (from buyers) Buyer name, email, company name submitted via RFQ forms To route RFQ inquiries to your account
Usage data Login timestamps, session activity, feature usage To maintain security and improve the product
Technical data IP address, browser type, device type For security, fraud prevention, and analytics
Email content Inbound emails parsed for RFQ extraction (webhook) To automatically create RFQ records from email

3 Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process your data on the following legal bases:

  • Contract performance — processing necessary to deliver the ThreadOps service you signed up for
  • Legitimate interests — security monitoring, fraud prevention, product improvement (where not overridden by your rights)
  • Legal obligation — to comply with applicable EU and Bulgarian law
  • Consent — where you have explicitly agreed (e.g., marketing communications)

4 How We Use Your Data

We use your data to:

  • Operate, maintain, and improve the ThreadOps platform
  • Generate AI-assisted quotes using your pricing configuration
  • Send transactional emails (new RFQ notifications, account alerts)
  • Enforce usage limits and prevent abuse
  • Comply with legal obligations
  • Analyze usage patterns to improve product features

We do not use your data for advertising profiling or sell your data to third parties.

5 Data Storage and Retention

Your data is stored on secure cloud infrastructure:

  • Database: Neon PostgreSQL (hosted in the US, with standard TLS encryption)
  • Application server: Render (hosted in the US/EU regions)

We retain your account data for as long as your account is active. After account deletion:

  • Personal account data is deleted within 30 days
  • Business data (RFQs, quotes) is deleted within 90 days
  • Anonymized aggregated analytics may be retained indefinitely

All stored passwords are hashed using bcrypt (minimum 12 rounds) and are never stored in plain text.

6 Third-Party Sharing

We share data with the following third-party service providers only as necessary to operate ThreadOps:

  • Neon — database hosting (processes data as a processor on our behalf)
  • Render — application hosting and deployment
  • Polsia email infrastructure — transactional email delivery (RFQ notifications, account emails)
  • Anthropic — AI model API used for quote generation (processes RFQ data to generate quotes; Anthropic's API data usage policy applies)

We do not sell, rent, or trade your personal data with advertisers, data brokers, or other third parties for commercial purposes.

7 Cookies and Tracking

ThreadOps uses the following cookies and tracking mechanisms:

  • Session cookie — required for authentication; expires after 30 days of inactivity. This is a functional cookie necessary to operate the service.
  • CSRF token — a security cookie that protects against cross-site request forgery attacks.
  • Analytics pixel — a lightweight, cookieless analytics beacon on the public landing page (polsia.com/api/beacon) that tracks anonymous page visits with a randomly generated visitor ID stored in localStorage. No personal data is transmitted.

We do not use advertising cookies or third-party tracking cookies in the authenticated application.

8 Your Rights Under GDPR

If you are located in the European Union or European Economic Area, you have the following rights regarding your personal data:

Your Data Rights

→ Right of access — request a copy of your data
→ Right to rectification — correct inaccurate data
→ Right to erasure — request deletion of your data
→ Right to portability — export your data in a machine-readable format
→ Right to restriction — limit how we process your data
→ Right to object — object to processing based on legitimate interests
→ Right to withdraw consent — where processing is based on consent
→ Right to lodge a complaint — with your national supervisory authority

To exercise any of these rights, email us at support@polsia.com. We will respond within 30 days. Identity verification may be required before we can process your request.

EU users may also file a complaint with the Commission for Personal Data Protection (CPDP) in Bulgaria, or with the supervisory authority in your country of residence.

9 Data Security

We implement the following security measures to protect your data:

  • Passwords hashed with bcrypt (12 rounds)
  • Session tokens with 30-day expiry and secure cookie flags
  • CSRF protection on all state-changing requests
  • HTTPS/TLS encryption for all data in transit
  • Security headers (HSTS, X-Frame-Options, Content-Type-Options)
  • Rate limiting on authentication and API endpoints
  • Input validation and sanitization to prevent injection attacks

No security measure is 100% foolproof. In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority as required by law.

10 International Data Transfers

ThreadOps is operated from Bulgaria (EU). Some of our infrastructure providers (Neon, Render) are based in the United States. Data transfers to the US are made under Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms as permitted under GDPR Chapter V.

11 Children's Privacy

ThreadOps is designed for business use and is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, contact us immediately.

12 Changes to This Policy

We may update this Privacy Policy from time to time. If we make significant changes, we will notify you by email or via a notice on the platform at least 30 days before the changes take effect. Continued use of ThreadOps after changes constitutes acceptance of the updated policy.

13 Contact and Data Requests

For privacy questions, data access requests, or to exercise your rights:

  • Email: support@polsia.com
  • Subject line: "Privacy Request — [your request type]"
  • Response time: within 30 days

Also see our Terms of Service.

Home Pricing Submit RFQ Terms of Service Privacy Policy Log in Contact

ThreadOps · Sofia, Bulgaria · Built by Polsia