Legal
ForgeOps Privacy Policy
- Version
- 1.0
- Effective
- 2026-08-18
- Last updated
- 2026-08-18
- Reading time
- 10 min
- Content digest
- e57fc17e…f6a0911e
- Status
- retired
This Privacy Policy explains how VERBLEAD LLC ("ForgeOps", "we") handles information in connection with the ForgeOps platform (the "Service"). ForgeOps is business-to-business software used by fabrication, industrial, construction and field-service companies to run estimating, jobs, materials, quality and finance.
1. Scope, and the two roles we play
ForgeOps handles information in two distinct capacities, and the difference determines who controls what.
Data we control. Account and organization information, billing information, and the technical and security records we need to operate the Service. For this information we are the controller.
Data our customers control. Everything a customer organization puts into its own workspace — jobs, estimates, drawings, purchase orders, employee and personnel records, customer and vendor contacts, quality and inspection records, photographs, receipts, and files uploaded or received by email. We process this on the customer's instructions, as its processor or service provider. The customer decides what to collect, who may see it, and how long to keep it.
If you are an employee, contractor, customer or vendor of a company that uses ForgeOps, and you want to know what that company holds about you, contact that company directly. We will refer such requests to the relevant customer organization, and will assist that organization in responding.
2. Information provided by users
- Account information — name, email address, and (optionally) phone number and avatar image,
stored on a user profile. Passwords are handled by our authentication provider and are stored only as salted hashes; we never see or store a plaintext password.
- Organization information — organization name, facility names and addresses, and the legal and
company information an organization owner chooses to record, which may include legal business name, trading name, entity type, business and billing addresses, legal and privacy contacts, website, and business or tax identifiers where the organization chooses to provide them.
- Invitations — the email address and role of a person an administrator invites. Invitation tokens
are stored only as hashes; the raw token exists only in the invitation link itself.
- Support and feedback — the content of feedback, bug reports and support requests, including any
attachments submitted with them.
3. Customer Data uploaded to the Service
Customer organizations upload and generate substantial business content: drawings and CAD models (including STEP, DXF and PDF files), specifications, spreadsheets, photographs, receipts, quality and weld records, and email attachments received through the Service's inbound intake addresses. This content may contain personal information about a customer's own employees, subcontractors, clients and vendors — for example names, job titles, contact details, timekeeping records, labor rates, certifications and qualification records.
We do not decide what goes into this content. We store it, process it to provide the requested features, and protect it. Each organization's data is isolated from every other organization's data by row-level security enforced in the database itself, not merely in application code.
4. Usage, device and log information
- Application logs — requests to the Service and errors raised by it, retained for operational
and security purposes.
- Audit records — a record of material actions taken inside an organization (who did what, to
which record, and when), visible to that organization's administrators.
- Agreement acceptance records — when an authorized person accepts an agreement on an
organization's behalf, we record the exact document version and content hash, the text they accepted, the time, and the IP address and browser user-agent of the request. This is collected specifically as evidence that the agreement was accepted and by whom, is retained for the life of the agreement relationship and for as long as it may be needed to establish or defend a legal claim, and is not used for analytics, profiling or marketing.
- Push notification tokens — where a user installs the mobile application and enables
notifications, the device push token issued by the operating system's push service.
We do not use third-party analytics, advertising, behavioral profiling or cross-site tracking technologies in the Service, and we do not sell personal information.
5. Cookies and similar technologies
ForgeOps uses cookies that are strictly necessary to operate:
- Session cookies set by our authentication provider, which keep a signed-in user signed in.
They are HTTP-only and, outside local development, secure.
- An active-organization cookie, which remembers which of a user's organizations is currently
selected.
- A theme preference, stored in the browser's local storage.
There are no advertising cookies, no analytics cookies and no third-party trackers. Because we use only strictly necessary cookies, ForgeOps does not present a consent banner; blocking these cookies will prevent sign-in from working.
6. Connected accounts and integrations
An organization may connect third-party systems to ForgeOps. Each connection is initiated by the customer and authorized through that provider's own consent flow, and access is limited to the scopes the customer grants. Connections in the product today include:
- Microsoft 365 / Microsoft Graph — mailbox access for email intake, sending, and document storage
in OneDrive or SharePoint.
- Google — document storage in Google Drive.
- Intuit QuickBooks Online — accounting synchronization of customers, vendors, invoices, purchase
orders, bills, payments and time.
- Procore — one-way import of historical exports the customer supplies.
- Payment processors, including Stripe — payment and payout status for customer invoices. Card
numbers and bank credentials are handled by the processor; we do not store full payment card numbers.
Data shared with a connected provider is governed by that provider's terms and privacy policy. Disconnecting an integration stops further exchange; it does not retrieve data already sent.
7. Artificial intelligence features
Some ForgeOps features use third-party AI models — currently Google Gemini and DeepSeek, reached through the application's AI gateway. These features include document and email extraction, scope drafting, vendor research and in-app assistance.
When such a feature runs, the relevant content — for example the text of an email, an extracted document, or a description of a record — is transmitted to the model provider to produce a result. AI features are gated per organization; where they are not enabled, no content is sent to a model provider.
Outputs are drafts for human review. The Service does not auto-commit an AI-derived record without a person approving it.
8. Email processing
Outbound. Transactional email — invitations, notifications, document delivery — is sent through Amazon Simple Email Service, or through a customer's own Microsoft 365 account where the customer has connected one. We record delivery outcomes (delivered, bounced, complained) to keep sending healthy and to suppress addresses that must not be mailed again.
Inbound. An organization may be issued an intake address. Mail sent to it, including attachments, is received, scanned, and staged for human review inside the organization's workspace. Mail from unknown senders is quarantined rather than acted on automatically.
9. How we use information
We use information to: provide and operate the Service; authenticate users and enforce permissions; process files and produce the features requested; send transactional communications; support and troubleshoot; detect, investigate and prevent security incidents, fraud and abuse; maintain audit and agreement records; bill and collect fees; comply with law; and improve the Service — including through aggregated or de-identified analysis that does not identify any individual or organization.
We do not use Customer Data to train general-purpose machine learning models for the benefit of other customers, and we do not sell personal information or share it for cross-context behavioral advertising.
10. Service providers and subprocessors
We rely on infrastructure and service providers to operate ForgeOps, including hosting, database and authentication, file storage, email delivery, background processing for CAD and document analysis, and the AI model providers named in §7. Each is engaged under terms requiring confidentiality and appropriate security, and is permitted to process information only to provide services to us.
The current list is maintained as the ForgeOps Subprocessor List and is published alongside this policy.
11. Disclosure of information
We disclose information only: to the organization whose workspace it belongs to and the users it has authorized; to service providers and subprocessors as described above; where required by law, legal process or a lawful government request; to establish, exercise or defend legal claims; to protect the rights, safety or property of ForgeOps, our customers or the public; and in connection with a merger, acquisition, financing or sale of assets, subject to the receiving party honoring this policy for the information transferred.
12. Retention
- Customer Data is retained while the customer's subscription is active and for the export window
stated in the Terms of Service, after which it is deleted or de-identified on our retention schedule.
- Agreement acceptance records are retained for the life of the agreement relationship and for as
long as necessary to establish or defend a legal claim. They are not deleted when an ordinary user account is deleted, because they are evidence of an agreement an organization entered into.
- Security, audit and email-delivery logs are retained for [LOG RETENTION PERIOD].
- Financial records are retained for [FINANCIAL RECORD RETENTION PERIOD] as required by tax and
accounting obligations.
- Backups expire on their ordinary cycle, currently [BACKUP RETENTION PERIOD].
13. Security
We enforce row-level security on every tenant table in the database, so isolation between customer organizations does not depend on application code being correct. Access is role-based and permission-checked on the server. Session cookies are HTTP-only and secure. Administrative credentials are held server-side only. Material actions are recorded to an append-only audit log. Uploaded attachments are scanned before they are made available.
No system is perfectly secure. Report a suspected vulnerability to [SECURITY CONTACT EMAIL].
A fuller description is published as the ForgeOps Security & Data Practices notice.
14. Your choices
- Account information — a user may update their own profile in the Service.
- Notifications — notification preferences are configurable, and mobile push can be disabled on
the device.
- Organization data — requests to access, correct or delete records held inside a customer's
workspace are directed to that customer organization, which controls them.
- Marketing — where we send marketing email, every message includes an unsubscribe mechanism.
15. Organization-controlled data and administrator access
Workspace administrators can see, export and delete records within their own organization, including records associated with individual users of that organization. If you use ForgeOps through an employer or another organization, that organization's policies govern how it uses ForgeOps and what it does with the records it holds.
16. Children's privacy
ForgeOps is business software and is not directed to children. We do not knowingly collect personal information from anyone under 16. If we learn we have, we will delete it.
17. U.S. state privacy rights
Residents of certain U.S. states have rights to access, correct, delete, or obtain a portable copy of personal information, and to appeal a refusal. Where ForgeOps is the controller of the information, those requests may be sent to [PRIVACY CONTACT EMAIL]. Where the information sits inside a customer organization's workspace, ForgeOps acts as a service provider or processor and will refer the request to that organization.
We do not sell personal information and do not share it for cross-context behavioral advertising, and we do not use it for profiling that produces legal or similarly significant effects.
18. International users
ForgeOps is operated from the United States and information is processed there. If the Service is offered to customers outside the United States, additional terms and transfer mechanisms will apply.
19. Changes to this policy
We may update this policy. Each update is published as a new numbered version with its own effective date, and prior versions remain available. Where a change is material, we will notify the affected organizations' owners through the Service or by email.
20. Contact
VERBLEAD LLC [LEGAL ADDRESS]
- Privacy: [PRIVACY CONTACT EMAIL]
- Security: [SECURITY CONTACT EMAIL]
Version history
Superseded versions are retained permanently. Their text is never edited.