Legal
Privacy Policy
Last updated: September 15, 2026
Overview
This page is maintained by Forge to explain how we collect, use, and protect information when you use our software. It is not a certification. If anything here is unclear, contact us at notifications@forgeapp.ca.
Information we collect
- Account information — name, email, password, company name, and role.
- Business content — customers, quotes, jobs, tasks, messages, and files you add to your workspace.
- Usage data — pages visited, actions taken, browser and device information, IP address.
- Payment information — processed by Stripe. Forge does not store full card numbers.
How we use information
- Provide and operate the Forge service.
- Send AI-generated follow-ups on your behalf to your customers.
- Process payments and manage subscriptions.
- Send service, security, and account-related communications.
- Improve product reliability, detect abuse, and support customers.
Sharing and subprocessors
We share the minimum information needed with trusted service providers who help us deliver Forge, including:
- Hosting and database infrastructure
- Stripe (payments)
- Email and SMS delivery providers you connect (e.g. Gmail, Outlook, Twilio)
- OpenAI and Google, accessed through the Lovable AI Gateway (AI features — only with your explicit permission; see "AI features and data sharing")
AI features and data sharing
Forge offers optional AI-powered features — the AI Assistant, drafting replies, improving quote descriptions, creating follow-ups, cleaning up work notes, and generating business insights. To provide these features, information needed to complete your request may be sent securely to third-party AI services operated by OpenAI and Google, accessed through the Lovable AI Gateway. This may include relevant customer information, job and work-order details, quotes and invoices, messages, tasks, notes, and other business information needed for the specific AI request.
This information is sent solely to provide the Forge AI feature you requested. No data is sent to AI services until you give explicit permission: the first time you use an AI feature, Forge shows a disclosure and asks you to allow or decline AI data sharing. You can change your choice at any time under Settings → Privacy & Security → AI Data Sharing. If you decline or withdraw permission, AI features stop processing your information from that point on; the rest of Forge continues to work normally. Your consent choice is recorded per user with a timestamp and the version of the disclosure you saw.
This information is sent solely to provide the Forge AI feature you requested. No data is sent to AI services until you give explicit permission: the first time you use an AI feature, Forge shows a disclosure and asks you to allow or decline AI data sharing. You can change your choice at any time under Settings → Privacy & Security → AI Data Sharing. If you decline or withdraw permission, AI features stop processing your information from that point on; the rest of Forge continues to work normally. Your consent choice is recorded per user with a timestamp and the version of the disclosure you saw.
Accounting integrations (QuickBooks Online)
Forge can connect to third-party accounting services such as Intuit QuickBooks Online when you choose to connect them. Connecting uses Intuit's official OAuth authorization process — Forge never collects or stores your QuickBooks username or password.
Depending on the features you use, Forge may exchange accounting and business information with the connected service, including customer information, estimates/quotes, invoices, payments, and related accounting identifiers and sync information. The purpose is to keep business and accounting records in sync between Forge and your accounting service. Forge only accesses this information after you authorize the connection.
Disconnecting QuickBooks from Forge stops future synchronization. Certain identifiers, record mappings, and audit or sync history may be retained where reasonably necessary for record integrity, security, legal obligations, or accounting history, subject to the retention and deletion practices described below. When information is processed by Intuit, Intuit handles it under its own privacy terms.
Depending on the features you use, Forge may exchange accounting and business information with the connected service, including customer information, estimates/quotes, invoices, payments, and related accounting identifiers and sync information. The purpose is to keep business and accounting records in sync between Forge and your accounting service. Forge only accesses this information after you authorize the connection.
Disconnecting QuickBooks from Forge stops future synchronization. Certain identifiers, record mappings, and audit or sync history may be retained where reasonably necessary for record integrity, security, legal obligations, or accounting history, subject to the retention and deletion practices described below. When information is processed by Intuit, Intuit handles it under its own privacy terms.
Data retention
We retain your workspace data for as long as your account is active. Cancelling a subscription does not immediately delete your account or your data: access continues until the end of your current paid period, and after that we normally retain your workspace for up to 90 days so you can reactivate and recover your account. After that 90-day period, information we no longer need is permanently deleted or anonymized.
Some information may be retained longer where required for legal, tax, accounting, fraud-prevention, dispute-resolution, security or other legitimate legal obligations — for example invoice and payment records. Where we must keep such records, we restrict access and retain only what is required, in anonymized form where possible. Backups may persist for a limited period after deletion.
Some information may be retained longer where required for legal, tax, accounting, fraud-prevention, dispute-resolution, security or other legitimate legal obligations — for example invoice and payment records. Where we must keep such records, we restrict access and retain only what is required, in anonymized form where possible. Backups may persist for a limited period after deletion.
Cancelling vs deleting your account
Cancelling your subscription stops future billing and ends paid access; it does not delete your data. Deleting your account is a separate, permanent action. You can delete your account and data at any time from Settings → Account → Delete Account & Data, which requires you to explicitly confirm, cancels any active subscription, and permanently deletes or anonymizes your company and customer information that we are not legally required to retain. You can also request deletion by emailing notifications@forgeapp.ca. Once the deletion process is complete, accounts cannot be restored from normal application data or backups.
Security
Forge encrypts data in transit using TLS and stores data with reputable cloud providers. No system is perfectly secure — please use a strong password and enable multi-factor authentication where available.
Your rights
You can access, correct, export, or delete your personal information by contacting notifications@forgeapp.ca. Depending on your location, additional rights may apply under laws such as PIPEDA (Canada) or the GDPR (EU/UK).
Children
Forge is a business tool intended for users 18 and older. It is not directed to children.
Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new "Last updated" date.
Contact
Questions about this policy? Email notifications@forgeapp.ca or visit our Contact page.