Forgecroft logo forgecroft
Infrastructure Platform
Pricing Docs Login
forgecroft › Privacy Policy

Privacy Policy

Last Updated: March 29, 2026  ·  Terms of Service  ·  privacy@forgecroft.com

This Privacy Policy describes how Forgecroft, Inc. ("Forgecroft," "we," "us," or "our") collects, uses, and shares information about you when you use our services, software, and websites (the "Service").

1. Information We Collect

1.1 Account Information

When you create an account, we collect information such as your name, email address, organization name, and billing information.

1.2 Usage Data

We collect information about how you use the Service, including run logs, audit events, API requests, and configuration data associated with your workspaces and infrastructure runs.

1.3 Technical Data

We automatically collect certain technical information when you use the Service, including IP addresses, browser type, operating system, referring URLs, and device identifiers.

1.4 Customer Data

Customer Data includes infrastructure code, state files, credentials (which are encrypted and never read by Forgecroft staff), and other content you submit to the Service. Forgecroft accesses Customer Data only as necessary to provide the Service and as described in these Terms.

1.5 Communications

If you contact us, we collect the contents of your messages along with any information you provide.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Service;
  • Send transactional notifications and service-related communications;
  • Respond to your requests, questions, and support needs;
  • Detect, prevent, and address security issues and abuse;
  • Comply with legal obligations;
  • Analyze usage trends to improve our products.

We do not sell your personal information or Customer Data to third parties.

3. Credential Security

Cloud provider credentials you provide to Forgecroft are encrypted at rest using AES-256 and in transit using TLS 1.2+. Credentials are injected into execution environments at run time and are never logged, persisted unencrypted, or accessible to Forgecroft personnel in plaintext. Access to decryption keys is strictly controlled and audited.

4. Data Retention

We retain account and usage data for the duration of your account and for a reasonable period thereafter to fulfill the purposes set out in this Policy. Run logs and audit trails are retained according to your plan's default retention policy. Enterprise customers may configure custom data retention periods. Upon account termination, Customer Data is deleted within 90 days unless a longer retention period is required by law.

5. Data Deletion Requests

You may request deletion of your personal information at any time by emailing privacy@forgecroft.com with the subject line "Data Deletion Request." Include the email address associated with your account and specify whether you are requesting deletion of specific data or complete account and data deletion.

We will verify your identity via the email address on your account before processing the request. We will acknowledge your request within 5 business days and complete deletion within 30 days of verification. If additional time is needed (up to 90 days for complex requests), we will notify you with a reason and expected completion date.

Upon a verified request, we will delete your personal information from our active systems, remove your Customer Data, and instruct our service providers to do the same. We may retain certain information where required by law, for fraud prevention, to resolve disputes, or to enforce our agreements. Backup copies may persist for up to 90 days before being overwritten in normal rotation. We will confirm completion of the deletion by email.

6. Sharing Your Information

6.1 Service Providers

We share information with trusted third-party service providers who assist us in operating the Service. These providers have access only to the information necessary to perform their functions and are contractually obligated to protect it. Our key service providers include:

  • Cloud Infrastructure: Amazon Web Services (AWS), Microsoft Azure, DigitalOcean, and Cloudflare for hosting, compute, and network services
  • Database: Neon (NeonDB) for managed database services
  • Payment Processing: Stripe for payment and billing
  • Authentication: Google and GitHub for single sign-on

6.2 Legal Requirements

We may disclose information if required by law, regulation, legal process, or governmental request.

6.3 Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction.

7. Data Security

We implement and maintain commercially reasonable technical and organizational security measures designed to protect your information against unauthorized access, loss, disclosure, or alteration. These measures include encryption at rest and in transit, access controls, and regular security reviews. No security system is impenetrable, and we cannot guarantee absolute security.

Breach Notification

In the event of a security breach affecting your personal information, we will investigate promptly and take appropriate steps to contain and remediate the incident. We will notify affected users and relevant authorities without undue delay and within the timelines required by applicable law. Notifications will include the nature of the breach, the categories of data affected, likely consequences, and the measures we have taken or propose to take to address the breach.

8. Your Rights

Depending on your location, you may have rights regarding your personal information, including:

  • Access: Request a copy of information we hold about you;
  • Correction: Request correction of inaccurate information;
  • Deletion: Request deletion of your personal information (see Section 5);
  • Portability: Request your data in a portable format;
  • Objection: Object to certain processing of your information.

To exercise any rights, contact us at privacy@forgecroft.com. We will respond within the timeframes required by applicable law.

9. Cookies and Tracking

Cookies We Use

  • Essential (Authentication/Session): Required for the Service to function. These handle login sessions, CSRF protection, and security tokens. These cannot be disabled.
  • Payment (Stripe): Set by our payment processor for fraud detection and secure payment sessions. Required when using billing features.
  • Analytics (optional): We may use analytics cookies to understand how users interact with the Service. These are optional and can be disabled.

Managing Your Preferences

You can manage non-essential cookie preferences through your browser settings. Note that disabling essential cookies will prevent the Service from functioning. We plan to honor "Do Not Track" browser signals; implementation of this feature is in progress.

10. Third-Party Services

The Service integrates with and may link to third-party websites and services, including Google and GitHub for authentication, Stripe for billing, and external code repositories. Your interactions with these third-party services are governed by their respective privacy policies and terms. We encourage you to review the privacy practices of any third-party service you access through the Service.

11. International Transfers

Your information may be transferred to and processed in countries other than your own. We take steps to ensure that any such transfers comply with applicable data protection laws, including through the use of standard contractual clauses where required.

12. Intended Audience

The Service is a business-to-business platform intended for use by organizations and their authorized personnel. It is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from individuals outside of this professional context.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice within the Service. Your continued use of the Service after any changes constitutes acceptance of the updated Policy.

14. Contact Us

For questions about this Privacy Policy or our data practices:
Forgecroft, Inc.  ·  privacy@forgecroft.com

Forgecroft forgecroft

Operational Intelligence Platform

Product

Infrastructure Platform Pricing Docs

Resources

Contact Us Terms of Service Privacy Policy

© 2026 Forgecroft, Inc. All rights reserved.