Legal
Privacy Policy
Last updated: January 15, 2025 · Effective: February 1, 2025
1. Who We Are
Spiffy LLC ("Spiffy", "we", "our") is a B2B custom apparel sourcing platform operated by WSI Custom Apparels LLC. Our registered address and contact: [email protected].
2. What Data We Collect
- Account data: name, company name, email, phone, country
- Order data: shipping address, product selections, quantities, payment method
- Usage data: pages visited, builder sessions, cart contents (stored server-side)
- Kit Builder designs: saved design state JSON (colours, layers, placements)
- Payment data: processed by Stripe - we do not store raw card numbers. See Stripe's privacy policy at stripe.com/privacy
3. How We Use Your Data
- Process and fulfil B2B orders
- Issue USD Sourcing Confirmation Documents (SCD)
- Communicate order status, QC results, delivery updates
- Improve the platform (aggregate, anonymised analytics only)
- Comply with legal obligations
4. Hidden Vendor Model
Spiffy operates a Hidden Vendor Model. Your buyer identity (name, company, email, shipping address) is never shared with our manufacturing partners. All vendor communication is handled internally by Spiffy. Our vendors see only production specifications - never buyer PII.
5. Third-Party Services
- Stripe: card payment processing (stripe.com)
- Payoneer: B2B payment transfers (payoneer.com)
- We do not sell or rent your data to any third party for marketing purposes.
6. Data Retention
Account data is retained while your account is active and for 7 years post-closure for legal/tax compliance. Kit Builder design saves are retained indefinitely until you delete them. Order records are retained for 7 years.
7. Your Rights (GDPR)
If you are in the EU/UK, you have the right to: access, rectify, erase, and export your data; restrict or object to processing; and withdraw consent. To exercise any right, email [email protected] with subject 'Data Request'. We respond within 30 days.
8. Cookies
We use session cookies (required for login) and one optional remember-me cookie (30-day, stored securely). We do not use third-party advertising cookies.
9. Security
Data is transmitted over HTTPS. Passwords are hashed using bcrypt (cost factor 12). Payment card data is handled exclusively by Stripe's PCI-DSS compliant infrastructure.
10. Contact
For privacy questions: [email protected] - Contact Form