Skip to content

Privacy Policy

Threadline Systems Inc.

Last Updated: July 22, 2026

Threadline Systems Inc. ("Threadline," "we," "us," or "our") operates a software platform that helps screen printing, embroidery, and apparel businesses manage jobs, orders, communications, and operational workflows (the "Service").

This Privacy Policy explains how we collect, use, store, and protect personal information, including data accessed through Google APIs such as Gmail, when you use the Service.

1. Information We Collect

We collect information in the following ways:

a. Information You Provide Directly

  • Account information (name, email address, company name)
  • Configuration and operational data entered into Threadline
  • Communications you send to us (support requests, feedback)

b. Information Accessed via Google APIs (With Your Consent)

If you choose to connect your Google account (for example, Gmail), we may access Google user data strictly as authorized by you during the OAuth consent process.

Depending on the features you enable, this may include:

  • Email metadata and/or message content
  • Sender, recipient, subject line, timestamps
  • Attachments associated with messages

We do not access your Google data unless you explicitly grant permission.

c. Analytics and Measurement Information

When you visit or use the Service, we and our analytics providers may process information about visits and product use.

  • Page views, navigation, clicks, scrolling, pointer movement, and other interaction events
  • Browser and device details, referrer, campaign parameters, and advertising click identifiers
  • Cookie, local-storage, session, and device identifiers used by the measurement providers
  • Pseudonymous Threadline user and organization identifiers, organization role, plan or billing status, and activation status when you are signed in
  • Product-use, signup, subscription, and conversion events

2. How We Use Google User Data

Threadline accesses and uses Google user data only to provide user-facing features that you explicitly enable within the Service.

Examples include:

  • Importing relevant email messages into a job or order workflow
  • Sending emails on your behalf related to quotes, orders, or production updates
  • Displaying selected email messages inside Threadline at your request

We do not use Google user data for advertising, profiling, or unrelated analytics.

3. Limited Use of Google User Data

Threadline's use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • Google user data is used only to provide or improve user-facing features within Threadline.
  • Google user data is not sold, rented, or shared with third parties for their own advertising or marketing purposes.
  • Google user data is not used to train generalized or third-party AI or machine learning models.
  • Any data displayed to human users is shown only at your explicit request (for example, when you view an email inside the app).

4. Analytics, Advertising Measurement, Lifecycle Communications, and Session Replay

We use Google Analytics, Google Ads, OpenAI Ads, and PostHog to measure visits, campaign attribution, signups, and product use so we can improve the Service. Threadline determines account, onboarding, and lifecycle communications from its own stored account state and uses Resend to deliver those emails.

Threadline initializes the browser analytics tools and sends them analytics data only when our hosting provider identifies the current document request as originating in the United States. We keep them off when a request or browser carries a Do Not Track or Global Privacy Control opt-out signal.

Google Analytics and Google Ads

Google Analytics and Google Ads measure public landing-page visits, campaign attribution, signup events, and paid-subscription events. Threadline does not send raw account email addresses or raw Threadline user or organization identifiers to these tools. For a confirmed account conversion, Threadline may provide Google Ads with the advertising click reference, conversion time, a conversion-specific one-way identifier, and a SHA-256 hash of the normalized account email address for conversion matching. Private, account, and shared-portal routes do not generate Google page-view events and are reduced to generic route classes for conversion context.

OpenAI Ads

OpenAI Ads measurement may receive an OpenAI advertising click reference from a landing-page parameter named "oppref" and retain it in a first-party cookie named "__oppref" for campaign attribution. When a durable real account is created, Threadline sends one standard registration-completed event with a conversion-specific, one-way pseudonymous event identifier. Threadline does not send account email addresses or raw Threadline user or organization identifiers to OpenAI Ads.

PostHog

PostHog measures page and navigation events, product-use events, dead clicks and interaction patterns. Threadline keeps the PostHog SDK's own browser persistence in memory. To connect eligible visits without storing raw page URLs, Threadline separately stores a random browser identifier and a non-identifying account-state flag, along with validated first-touch campaign fields, in local storage. It stores an opaque session identifier and basic session timing metadata in session storage. Those campaign fields are limited to bounded, namespaced advertising parameters and the referring site's origin from classified public acquisition pages. For signed-in users, Threadline uses pseudonymous internal user and organization identifiers and associates product activity with organization context such as role, plan or billing status, and activation status. Threadline does not use the account email address as a PostHog identity or analytics event property; emails and other business data may be visible in a replay when they are displayed in the recorded interface.

We may enable PostHog session replay across Threadline's public website, authenticated application, and shared customer portals. Replays may include visible page text, page structure, images, video, canvas activity, rendered styles and fonts, form interactions and non-password form values, clicks, scrolling, pointer movement, viewport details, and sanitized page paths. Our replay configuration masks password values and explicitly protected text, does not record cross-origin iframe contents, and may include browser console logs. Network request and response headers and bodies are omitted. It removes query strings, page titles, external referrer paths, record identifiers, and access tokens from URL and event metadata.

Lifecycle email and Resend

Threadline stores lifecycle timing, activation, subscription, delivery, and unsubscribe state in its own database. It uses that state to decide whether an account should receive a signup, onboarding, trial, or product follow-up. Resend receives the recipient name and email address, the rendered message, and delivery metadata needed to transport the email. Resend processes this information on Threadline's instructions, not for Resend's own advertising or marketing.

Threadline uses a session-scoped first-party cookie to carry the hosting provider's United States region decision to browser analytics code. Google's and OpenAI's measurement tools may use cookies, local storage, or similar browser technologies after the gate allows them to initialize, and Threadline stores the random PostHog browser identifier described above. Do Not Track and Global Privacy Control are the supported browser-level opt-out signals. You may also contact us using the information below with a privacy request.

Learn more in the Google Privacy Policy, OpenAI Privacy Policy, PostHog Privacy Policy, and Resend Privacy Policy.

5. AI-Assisted Features

At your request, Threadline may use third-party AI services to assist with drafting emails, summarizing messages, or extracting structured order information from emails you select. Email content is sent to AI providers only when you explicitly initiate an AI-assisted action.

Threadline does not allow AI providers to use Google user data to train or improve generalized machine learning models, and does not retain raw email content beyond what is necessary to perform the requested task.

6. Human Access to Data

Threadline employees and contractors do not read or review Google user data unless one of the following applies:

  • You explicitly request assistance and grant permission for support purposes
  • Access is required to investigate security issues, bugs, or abuse
  • Access is required to comply with applicable law

Access is limited to personnel who need it for one of the listed purposes.

7. Data Storage and Security

We take data security seriously and apply industry-standard safeguards.

Security Measures Include:

  • Encryption of data in transit (HTTPS/TLS)
  • Restricted internal access controls
  • Restricted storage of OAuth tokens and credentials

We retain Google user data only for as long as needed to provide the enabled functionality or until you revoke access.

8. Data Sharing and Transfers

We do not transfer or share Google user data with third parties except:

  • To provide the core Service functionality you requested
  • To comply with legal obligations
  • To protect the security and integrity of our systems

We do not:

  • Sell Google user data
  • Share Google user data with advertising platforms
  • Use Google user data for credit scoring or lending decisions

9. Your Choices and Controls

You are always in control of your data.

You may:

  • Revoke Google account access at any time via your Google Account settings
  • Disconnect Gmail or other integrations from within Threadline
  • Request deletion of stored data associated with your account

Disconnecting an integration in Threadline deletes its stored credentials. Revoking access in your Google Account prevents Threadline from using that Google authorization.

10. Data Retention

We retain personal and Google user data only as long as necessary to:

  • Provide the Service
  • Meet legal, accounting, or security obligations

You may request deletion of your data at any time, subject to legal requirements.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If changes materially affect how we use Google user data, we will update this page and, where appropriate, notify users.

12. Contact Information

If you have questions about this Privacy Policy or our data practices, contact us at:

Threadline Systems Inc.

Email: jon@usethreadline.com

Website: https://usethreadline.com

Important Google Disclosure

Threadline's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.