threadquarters

Privacy Policy

Effective 31 July 2026. Threadquarters is operated by Brojas LLC.

Threadquarters ("we", "us") makes costume-department software for film and television productions. This explains what personal information we collect, why, who we share it with, and what you can ask us to do about it. It covers both the app and this site.

Who this affects

What we collect

Account and profile. Your email and name; optionally phone number, emergency contact and dietary restrictions; your role on each production; a hashed password (we never store it in readable form); sign-in timestamps; and cosmetic preferences.

What you create or upload. Approval requests and decisions, comments and notes, tasks and their history, photos and file attachments. Photos commonly show fittings and costume looks, meaning identifiable people. Records about performers may include name, stage name, contact details, measurements and preferences.

Device and technical data. If you turn notifications on, a push token for your device. We and our providers handle IP addresses and ordinary request data to run and secure the service.

Analytics. Usage events and error diagnostics — see below.

We don't sell personal information, and we don't use it to build advertising profiles.

Why we use it

To run and secure the service, to send transactional email (invitations and password resets), to send notifications you've turned on, to diagnose faults and improve the product, and to meet legal obligations.

If you're in the UK or the European Economic Area, the legal bases we rely on are: performance of a contract, to run the service for your production; our legitimate interests, in keeping the service secure and improving it, balanced against your rights; and your consent where it's required, such as notifications you choose to switch on. You can withdraw consent at any time without affecting anything we did before you did.

Who we share it with

We run the service through a small set of specialist providers. Each one gets only what its job needs, and none of them may use it for their own purposes.

What they do What they handle
Application hosting All app traffic; operational logs
Database hosting Stored account and production data
Website hosting and content delivery Visitor IP addresses and requests; static files
File and photo storage All uploaded photos and attachments
Push notification delivery Device tokens; notification text, which includes names and snippets
Transactional email Recipient email address; invitation and password-reset links
Product analytics Usage events; inside the app, your email, name, role and production
Error monitoring Error reports, which carry your user id, email, name, production and role
Waitlist form on this site What you type into it (email; name optional)

A current list of the named providers behind these categories is available to customers on request — write to contact@threadquarters.app.

We may also disclose information if the law requires it, to enforce our terms, or as part of a business transfer, with notice where that's required.

Cookies and analytics on this site

This marketing site measures usage without analytics cookies — it's kept to your current browser session and isn't used to follow you between sites. The app itself sets a sign-in cookie, which is strictly necessary and can't be turned off while you're signed in. The waitlist form is embedded from a third-party form service, which sets its own cookies; their notice governs those.

Where it's stored

The service is operated in the United States, and our providers process data there. If you're outside the US, your information is transferred to and processed in the US. Where we transfer information out of the UK or the European Economic Area, we rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum where it applies, and we require the same of the providers who handle it on our behalf.

How long we keep it

We keep account and production data for as long as the production is active and your account exists, and we delete it when you ask us to. A signed-in session expires automatically after 30 days at the latest, and an invitation or password-reset link stops working the moment it's used, though a record that it existed may remain. Analytics events are kept for up to 12 months, and error reports for up to 30 days.

Your choices

Depending on where you live you may have the right to see, correct, delete or export your personal information, and to object to or restrict some processing. To ask for any of that, write to contact@threadquarters.app. We'll respond within the time the law allows.

Today, deletion and export are done by hand by our team across our databases and file storage; we're building self-service controls. Some things you created — a comment inside a production's shared history, for instance — may be kept or anonymised rather than removed entirely, where the production needs the record.

Security

Every production's content lives in its own separate database. One show's photos, fittings and notes are never stored alongside another's, so there is no way for a request about one production to return another's material. Your account itself sits in a shared directory, which is what lets you work on more than one show with a single login — but the shows' contents stay apart.

Passwords are never stored in a readable form; they're put through a deliberately slow algorithm built for the purpose. Signing in uses a protected cookie that scripts on the page can't read. Administrative access is restricted.

No system is perfectly secure, but we work to protect your information and will tell you about a breach as the law requires.

Children

The service is for professional use and isn't directed at children.

Changes

We'll post changes here and update the date at the top. We'll communicate material changes as required.

Contact

Questions, requests, or anything about this policy: contact@threadquarters.app.