Privacy Policy
Effective date: July 15, 2026
This Privacy Policy explains how ForgePilot (“ForgePilot”, “we”, “us”, or “our”) collects, uses, and protects information when you use our project-management service for millwork and casework shops. It applies to the ForgePilot application and website.
1. Information We Collect
- Account information — your name, email address, role, and organization, provided when your account is set up.
- Business data you enter (“Customer Data”) — project, bid, drawing, material, scheduling, and contact records you and your team add to the service.
- Usage and technical data — basic information needed to operate the service, such as log data, browser type, and interactions, used to keep the service secure and working.
2. How We Use Information
- to provide, maintain, and secure the service;
- to authenticate users and enforce access controls;
- to send transactional messages such as invitations, password resets, and service notices;
- to diagnose problems, prevent abuse, and improve reliability;
- to comply with legal obligations.
We do not sell your personal information, and we do not use Customer Data to advertise to you.
3. Service Providers (Sub-processors)
We use trusted third parties to run the service. They process data only to provide their services to us:
- Supabase — database, authentication, and storage.
- Vercel — application and website hosting.
- Resend — transactional email delivery (invitations, resets, notices).
- Google Analytics — aggregate visitor analytics on our public marketing website only (not used inside the ForgePilot application, and never applied to Customer Data).
4. Cookies and Local Storage
Inside the ForgePilot application, we use cookies and browser local storage only for essential functions — keeping you signed in and remembering your place in the app (navigation state). On our public marketing website (forgepilot.net) we use Google Analytics to understand aggregate visitor traffic, which sets analytics cookies. We do not use advertising or cross-site ad-targeting cookies, and we never use Customer Data for analytics.
5. Tenant Isolation and Data Ownership
ForgePilot is multi-tenant, and isolation between organizations is fundamental to how it is built. Each organization’s data is segregated at the database level using row-level security, so one organization cannot access another’s records. As between you and us, your organization owns its Customer Data.
6. Data Security
We protect data in transit using encryption (HTTPS/TLS) and rely on our infrastructure providers’ security controls for data at rest. Access to production systems is limited. No method of transmission or storage is completely secure, but we take reasonable measures to safeguard your information.
7. Data Retention
We retain Customer Data for as long as your organization uses the service, and for a reasonable period afterward as needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. On request, we will make Customer Data available for export where practicable before deletion.
8. Your Rights
Depending on where you live, you may have rights to access, correct, or delete your personal information, or to object to or restrict certain processing. Because access is organization-provisioned, some requests are best handled by your organization’s administrator. You can contact us to exercise these rights, and we will respond consistent with applicable law.
9. Children’s Privacy
ForgePilot is a business tool intended for use by adults in a professional context. It is not directed to children, and we do not knowingly collect personal information from anyone under 18.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date above and, where appropriate, provide additional notice.
11. Contact
Questions about this Privacy Policy or your data? Reach us through the contact form at forgepilot.net.
See also our Terms of Use.