1. Scope
This Privacy Policy applies to forgeproductlab.com, Forge Product Lab products, customer support, checkout, delivery, and related communications. Product-specific notices may add details when a product processes different information.
2. Information we collect
We collect only information reasonably needed to operate, secure, support, and improve the site and products. Depending on how you interact with us, this may include:
- Contact details you submit, such as name and email address
- One-time purchase and settlement records supplied by Stripe
- Build Studio applications, accepted scope briefs, project milestones, preview decisions, delivery references, and support records
- Product access, license, and delivery information
- Support messages and troubleshooting details you choose to provide
- Basic device, browser, referral, page-view, and reliability information
- Fraud-prevention, security, and abuse-detection signals
Forge Product Lab does not request or store complete payment-card numbers. Payment information is handled by Stripe or another checkout provider identified at purchase.
3. How we use information
- Provide, deliver, and maintain purchased products
- Process payments and maintain transaction records
- Answer support requests and diagnose product problems
- Protect customers, products, and infrastructure from abuse
- Measure site reliability, product use, conversion, and retention
- Comply with applicable accounting, tax, and legal obligations
- Improve documentation, usability, and product quality
4. Service providers
We may use carefully selected providers to perform specific functions. Current or planned providers include Stripe for one-time payments, Resend for transactional messages and secure access links, HubSpot for customer support, PostHog or first-party events for privacy-conscious analytics, Cloudflare for hosting and D1 records, and GitHub for isolated repositories. Resend is not used for cold outreach. Each provider processes information under its own terms and privacy commitments.
5. Cookies and analytics
The storefront uses essential browser storage for security, purchase access, and a random first-party visitor identifier. Forge records the page path, traffic source, checkout progress, delivery success, and support-request category needed to understand conversion and reliability. It does not place advertising cookies, build unrelated advertising profiles, or send invoice data from Invoice Chaser into storefront analytics.
Support requests store the contact details and message you submit, a one-way email hash used for abuse prevention, request status, and any connected help-desk ticket reference. Invoice and client records entered inside Invoice Chaser remain device-local and are not included in support records unless you deliberately type them into a request.
6. Sharing
We do not sell personal information. We may share limited information with service providers working on our behalf, when you direct us to, to complete a transaction, to protect rights and security, or when legally required. Providers receive only the information reasonably necessary for their role.
7. Retention
Full Build Studio application and operational project records are retained for up to one year after delivery or terminal rejection, then deleted or de-identified where permitted. Single-use access links expire after 15 minutes, and portal sessions expire after 12 hours. Required payment evidence and non-reversible audit or suppression digests may be retained longer for accounting, security, dispute handling, or legal compliance.
8. Security
We use safeguards designed to protect information, including encrypted connections, restricted credentials, access controls, input validation, secret isolation, audit records, and recovery procedures. No online service can guarantee absolute security.
9. Your choices and rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection. You may also withdraw consent where processing relies on consent. We may need to verify your identity before completing a request.
Send privacy requests to privacy@forgeproductlab.com. We will not discriminate against you for exercising an applicable privacy right.
10. Children
Forge Product Lab products are intended for adults and general business users. The site is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
11. International use
Our services are operated from the United States. If you access them elsewhere, information may be processed in the United States or other locations where our providers operate, subject to applicable safeguards.
12. Changes
We may update this policy as the business or products change. The effective date and version appear on this page. Material changes will be presented through a reasonable notice before they apply when required.
13. Contact
Questions about privacy can be sent to privacy@forgeproductlab.com. General product questions should go to support@forgeproductlab.com.