Beta
Privacy Policy
Last updated April 29, 2026
This policy describes what we collect, how we use it, and the choices you have. Forge ERP is a multi-tenant accounting and operations platform; your organization's administrators control access to your data within the service.
1. What we collect
- Account and signup data: name, email, phone number when provided, authentication metadata, company name, industry, and team-size range.
- Tenant data: the records you and your team submit — transactions, documents, employees, etc.
- Usage data: in-product setup and workflow events used to operate, secure, and improve the service.
- Payment data: processed by our payment provider. We never see raw card numbers.
2. How we use it
We use your data to provide and improve the service, to respond to support requests, to protect against abuse, and to comply with legal obligations. We do not sell your data, and we do not use tenant data to train third-party AI models. When you invoke an AI feature, the relevant input may be sent to the configured model provider to produce the requested response. Live voice sends microphone audio to OpenAI for transcription only after the individual user gives current consent.
3. Who can see it
Within your tenant, access is governed by your admin-configured roles and row-level security policies. Outside your tenant, a small number of our engineers may access data to debug issues, subject to internal controls and audit logging.
4. Subprocessors
Depending on the features you use, service providers may include:
- Supabase (database, auth, storage)
- Stripe (payment processing)
- Plaid (optional bank connections)
- OpenAI (AI responses and consent-gated live voice transcription)
- Vercel (web hosting and request delivery)
- Google (OAuth and managed secret infrastructure)
- Resend (transactional email)
- OpenStreetMap / Nominatim (address validation)
- Procore (optional construction integration)
5. Security
Data is encrypted in transit and at rest. Sensitive fields like bank account numbers are encrypted at the column level and revealed only to authorized roles, with a full audit log. Beta users should still maintain their own backups.
6. Your rights
Self-service controls are available for some profile and feature data. To request access, correction, export, or deletion for other personal data, email us. We honor applicable data-protection requests from users whose data we hold, subject to identity verification and legal retention obligations.
7. Retention
We retain data under the applicable product retention schedule and legal obligations. Retention varies by record type; eligible data is deleted or anonymized after the applicable period, while financial or audit records may be retained longer where required by law.
8. Contact
Privacy questions: privacy@theerpforge.com.