Privacy Policy
Effective date: 29 March 2026
CostForge ("we", "our", or "us") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights in relation to it. By using our service you agree to the practices described below.
1. Information We Collect
We collect information in the following ways:
- Account data — when you register, we collect your name, email address, business name, and a chosen account slug.
- Usage data — we automatically collect information about how you interact with the platform, including pages visited, features used, and timestamps.
- Business data — content you enter into CostForge, such as client details, job records, and quote line items. This data belongs to you.
- Device & log data — IP address, browser type, operating system, and referring URLs for security and diagnostics.
We do not collect payment card data directly. Billing is handled by our payment processor, which has its own privacy policy.
2. How We Use Your Information
- To create and maintain your account and tenant workspace
- To provide, operate, and improve the CostForge service
- To send transactional emails (account confirmation, password resets, team invitations)
- To send product updates and announcements — you may opt out at any time
- To detect and prevent fraud, abuse, or security incidents
- To comply with applicable legal obligations
We do not sell your personal data to third parties.
3. Data Sharing
We share personal data only in the following limited circumstances:
- Service providers — we use third-party vendors (e.g. cloud hosting, email delivery, analytics) who process data on our behalf under strict data processing agreements.
- Within your organisation — team members you invite to your CostForge workspace can access the business data within that workspace according to their assigned role.
- Legal requirements — we may disclose data when required by law, court order, or to protect the rights and safety of CostForge or its users.
- Business transfers — in the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.
4. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law.
Business records (jobs, quotes, clients) entered into your workspace are retained on your behalf and deleted when you request account closure.
5. Cookies
CostForge uses cookies and similar technologies to maintain your session, remember preferences, and analyse usage patterns. The following categories are used:
- Strictly necessary — session cookies required for authentication and security. These cannot be disabled.
- Analytics — aggregate, anonymised data to understand how the product is used. You may opt out via your browser settings.
6. Security
We implement industry-standard security measures including TLS encryption in transit, encrypted storage at rest, role-based access controls, and regular security reviews. No system is completely secure; we encourage you to use a strong, unique password and to report any suspected security issues to info@costforge.co.uk.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — request deletion of your personal data
- Portability — receive your data in a machine-readable format
- Objection — object to certain types of processing
- Withdraw consent — where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, contact us at info@costforge.co.uk. We will respond within 30 days.
8. Children's Privacy
CostForge is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us with personal data, please contact us so we can delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by a prominent notice in the application at least 14 days before the changes take effect. Continued use of the service after that date constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions or concerns about this Privacy Policy or how we handle your data, please contact us at:
CostForgeinfo@costforge.co.uk