HustleForge LLC (“HustleForge,” “we,” “us,” or “our”) operates The Forge, a managed business operating environment that helps organizations connect information, coordinate workflows, monitor operations, and authorize actions across their businesses.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you:
- visit a Forge website;
- contact HustleForge;
- request or purchase a Forge Blueprint;
- create or use a Forge account;
- subscribe to Forge Start, Forge Core, Forge Pro, or Forge Operations;
- participate in Guided Launch or Managed Launch;
- use the Forge platform, integrations, Marketplace, or support services; or
- otherwise interact with us.
This policy also explains the distinction between information HustleForge collects for its own business purposes and information we process on behalf of Forge customers. If you are located in the European Economic Area, the United Kingdom, or Switzerland, Section 14 describes additional rights available to you under the EU/UK General Data Protection Regulation (“GDPR”).
1. Scope and Processing Roles
Information HustleForge collects directly
HustleForge acts as the business or controller for information collected directly from website visitors, prospective customers, account administrators, billing contacts, and people communicating with us.
Information processed for Forge customers
Forge customers may upload, enter, import, synchronize, or generate information concerning their own customers, leads, employees, contractors, vendors, business partners, and other individuals.
For that information, the Forge customer generally determines:
- why the information is processed;
- which records are entered or connected;
- which users may access the information;
- which systems may receive it;
- how long it should be retained;
- which workflows and approvals apply; and
- whether an action should be executed.
HustleForge processes this information to operate The Forge according to the customer’s instructions, subscription plan, Forge Plan, order form, statement of work, and applicable data-processing agreement.
Individuals seeking to exercise rights concerning information controlled by a Forge customer should ordinarily contact that customer first. We will reasonably assist customers with verified requests where required.
2. Information We Collect
Depending on how The Forge is used, we may collect the following categories of information.
Contact and identity information
- Name
- Business email address
- Telephone number
- Job title
- Employer or business name
- Mailing or billing address
- Account and organization identifiers
Account and access information
- Username
- Password hash
- Account activation information
- Assigned business, location, department, and role
- Permission settings
- Authentication events
- Session information
- Administrative changes
- Account recovery and security information
We do not store passwords in plaintext.
Business and professional information
- Company structure
- Business entities and operating locations
- Departments, responsibilities, and reporting relationships
- Software and provider inventories
- Business workflows and operating procedures
- Service requirements
- Launch preferences
- Support and training records
Customer-controlled operational information
Customers may choose to enter, import, or synchronize information such as:
- leads and customer records;
- opportunities, appointments, jobs, projects, and service history;
- employee and contractor records;
- schedules, time entries, assignments, and approval status;
- vendors, purchases, inventory, and fulfillment records;
- invoices, payments, wage summaries, and financial context;
- campaign, source, attribution, and revenue information;
- communications, notes, documents, and attachments;
- business locations, departments, and legal-entity relationships;
- workflow status, exceptions, escalations, and approvals; and
- records received from customer-authorized third-party systems.
The exact information processed depends on the customer’s configured scope.
Integration information
When a customer authorizes an integration, we may process:
- third-party account identifiers;
- OAuth tokens, API tokens, webhook secrets, or similar authorization material;
- connection settings;
- field mappings;
- synchronization history;
- source and destination record identifiers;
- credential-expiration information;
- connection errors, retries, and health status; and
- information transmitted through the authorized connection.
Credential material is not included in customer data exports.
Communications and content
We may collect communications sent through or associated with The Forge, including:
- emails;
- text-message events;
- call metadata;
- support requests;
- form submissions;
- workflow notes;
- uploaded documents;
- approval comments; and
- communications associated with a customer, employee, job, project, or other business record.
The Forge may connect communication events from third-party providers to the relevant operational record. The exact content available depends on the customer’s configuration and provider authorization.
Payment and transaction information
Payments are processed by third-party payment providers such as Stripe. HustleForge may receive:
- customer name;
- billing contact;
- transaction amount;
- payment status;
- subscription status;
- invoice identifier;
- payment-method type;
- limited payment-method details, such as the last four digits; and
- charge, refund, or dispute information.
HustleForge does not store full payment-card numbers.
Device, network, and usage information
We may automatically collect:
- IP address;
- browser and device type;
- operating system;
- date and time of access;
- pages and platform features used;
- referring page;
- session and authentication events;
- request and error logs;
- performance information;
- security events;
- integration activity; and
- interaction with public forms.
On Forge websites, behavioral analytics (page views, clicks, scroll depth, dwell time, and campaign attribution) are collected only with your consent — see Section 8 for how this works. Within the Forge platform, usage information is collected under the customer’s service agreement.
Free-text customer content is excluded from platform error telemetry where technically supported.
Derived and platform-generated information
The Forge may generate:
- operational summaries;
- dashboard metrics;
- workflow status;
- exception flags;
- recommendations;
- forecasts;
- prioritizations;
- integration-health assessments;
- data-quality indicators;
- attribution results;
- approval histories; and
- aggregated or deidentified platform-usage statistics.
Derived information may depend on records supplied by a customer or received from connected systems.
Sensitive and regulated information
The Forge is not configured by default to receive:
- full Social Security numbers;
- bank-account credentials;
- full payment-card information;
- biometric identifiers;
- protected health information;
- regulated student records;
- clinical records;
- sensitive insurance-policy information; or
- other specially regulated personal information.
We process such information only when the specific scope is documented in writing, the customer expressly authorizes it, appropriate controls are available, and any legally required agreement has been completed.
Customers must not enter regulated or highly sensitive information into The Forge unless HustleForge has approved that use in writing.
3. Sources of Information
We may collect information from:
- you directly;
- your employer or organization;
- authorized Forge users and account administrators;
- onboarding and Blueprint submissions;
- customer-uploaded files;
- systems a customer authorizes The Forge to connect with;
- payment processors;
- communications providers;
- implementation and support providers;
- hosting, security, and analytics providers;
- referral sources and business partners;
- public business information; and
- activity generated through the Forge platform.
4. How We Use Information
We use personal information to:
- respond to inquiries;
- evaluate a prospective customer’s requirements;
- prepare and deliver Forge Blueprints and Forge Plans;
- create, administer, and secure accounts;
- configure customer organizations, locations, roles, and permissions;
- migrate and validate customer-authorized records;
- connect and operate approved integrations;
- provide dashboards, reporting, workflows, and operational visibility;
- prepare and execute customer-approved actions;
- provide launch, training, support, monitoring, and optimization;
- process subscriptions, purchases, credits, and refunds;
- diagnose errors and integration failures;
- prevent duplicate or unauthorized actions;
- maintain audit and approval histories;
- investigate security incidents;
- improve reliability and user experience;
- develop generalized platform improvements using aggregated or deidentified information;
- enforce our agreements;
- comply with legal obligations; and
- protect HustleForge, our customers, users, and third parties.
We do not use identifiable Customer Data to train a generalized artificial-intelligence model for use outside that customer’s Forge environment unless the customer has expressly opted in through a separate written agreement.
5. Automation, Recommendations, and Human Review
The Forge may use rules, software automation, analytics, or artificial intelligence to:
- organize information;
- create summaries;
- detect exceptions;
- prioritize work;
- prepare recommendations;
- identify possible inconsistencies;
- route approvals;
- prepare communications or actions; and
- execute actions that the customer has authorized.
The Forge is designed to augment customer decision-making, not to replace the customer’s legal or business authority.
Unless separately agreed in writing, The Forge is not intended to make a final decision concerning employment, credit, housing, healthcare, insurance, education, or another legally significant matter without meaningful human review.
Customers are responsible for reviewing recommendations and determining whether an automated or prepared action is appropriate for their organization.
6. How We Disclose Information
We may disclose information to the following categories of recipients.
Service providers and contractors
We use providers that support:
- cloud hosting and databases;
- website delivery and security;
- payment processing;
- email and communications;
- authentication;
- logging and monitoring;
- customer support;
- analytics;
- data migration;
- implementation;
- orchestration and production services;
- integration development; and
- professional services.
These providers may process information only for the services they perform for us and are subject to contractual confidentiality or data-protection obligations where appropriate. A current list of subprocessors is available at /subprocessors.
Customer-authorized third-party systems
When a customer activates an integration, The Forge may send information to or receive information from that provider according to the customer’s approved configuration.
The customer controls whether a connection is established and may revoke supported connections. The third party’s own privacy policy and service terms govern its independent handling of information.
A customer’s authorized users
Information may be available to users according to permissions established by the customer, including business, legal-entity, location, department, and role restrictions.
Professional advisers
We may disclose information to attorneys, accountants, auditors, insurers, or consultants when reasonably necessary to operate and protect the business.
Legal and safety disclosures
We may disclose information when we reasonably believe it is required to:
- comply with law, regulation, subpoena, court order, or legal process;
- investigate fraud or unlawful conduct;
- protect the security of The Forge;
- enforce an agreement;
- protect the rights or safety of HustleForge, a customer, a user, or another person; or
- respond to a lawful government request.
Business transactions
Information may be disclosed as part of a proposed or completed merger, financing, acquisition, reorganization, sale of assets, or similar transaction. Where appropriate, the receiving party will be required to use the information consistently with this policy or provide notice of a materially different practice.
7. Sale and Sharing of Personal Information
HustleForge does not sell personal information.
HustleForge does not share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act.
We do not sell or share Customer Data and do not use it for advertising unrelated to operating The Forge.
We do not use Google Analytics, Meta Pixel, or any third-party advertising or cross-site tracking technology. Every analytics signal we collect is first-party, stored in our own infrastructure, and gated behind the consent described in Section 8.
8. Cookies and Similar Technologies
We use a cookie banner with equal “Accept” and “Reject” options because most of the technologies below are not “strictly necessary” and legally require your opt-in consent before they run. You can change your choice at any time via the Cookie Settings link in the footer of every page.
Strictly necessary (always active — no consent required):
hf_consent— records your Accept/Reject choice itself, so we don’t ask you again every visit. 400-day cookie.- Cloudflare Turnstile challenge cookies/tokens — invisible bot-abuse check on our “Ask The Forge” widget. No advertising or cross-site tracking use.
forge-theme(browser storage) — remembers your light/dark display preference.
Analytics (only set if you click “Accept”):
__hf_vid— a first-party cookie (HttpOnly, up to 400 days) that lets us recognize the same browser across visits, so we can measure things like repeat visits and, if you later sign in to the Forge platform, connect your earlier anonymous visits to your account. Never readable by page scripts; never shared with a third party.hf_session_id(sessionStorage) — a random id that groups events from the same browser tab; cleared when you close the tab.hf_first_touch_utm(localStorage) — remembers the campaign parameters (UTM) from the link you first arrived on, so a later conversion can be attributed to the right campaign.- The page views, clicks, scroll depth, dwell time, referrer, and approximate geo described in Section 2, sent to our own Cloudflare Analytics Engine / D1 storage.
Rejecting or ignoring the banner means none of the analytics items above are set, and no behavioral data is sent to our analytics storage. Site functionality (browsing, the onboarding form, checkout) works fully either way.
Platform account cookies:
When you sign in to a Forge account, additional cookies are used for session authentication, security, and platform operation. These are essential to the service you have requested and do not require separate consent.
Most browsers also let you block or delete cookies directly in their settings; doing so may require you to make the cookie choice again on your next visit. Disabling essential cookies may prevent account authentication or other platform functions from working.
Global Privacy Control. Some browsers and browser extensions let you send a Global Privacy Control (GPC) signal announcing an opt-out preference automatically, without visiting each site individually. Because analytics on Forge websites are opt-in — set only after you affirmatively click “Accept” on the cookie banner described above, never by default — a visitor who has not clicked Accept is already in the same state a GPC opt-out is meant to produce: no analytics cookies set, no behavioral data sent to our analytics storage. We treat an incoming GPC signal as a valid opt-out preference: when your browser sends one, we honor it by not presenting the cookie banner and treating your visit as declined, exactly as if you had clicked “Reject.” You can still change your choice at any time using the Cookie Settings link in the footer.
9. Call Recording and Transcription
Some Forge customers turn on the AI voice receptionist feature, which answers, places, and handles telephone calls on that customer’s behalf. When this feature is active for a business you are calling or being called by, the call may be recorded and transcribed.
What may be recorded or transcribed. Calls handled by the AI receptionist may have their audio recorded and converted to a text transcript, together with call metadata (phone numbers, timestamps, duration, and outcome such as completed, missed, or voicemail) and structured details captured during the call. This processing is performed by Vapi, listed in our Subprocessor Register, along with Twilio for call handling.
AI identity disclosure. Forge customers using the AI receptionist feature are responsible for disclosing to callers, at the start of the call, that they are speaking with an automated or AI-assisted system rather than a human, where required by applicable law or reasonable expectation.
Consent to recording.Forge customers are responsible for obtaining any consent to call recording required in their jurisdiction before enabling this feature, and for configuring the feature (including any recording announcement) consistently with that requirement. In “two-party” or “all-party” consent states and countries (for example, California), all parties to a call generally must consent to recording before it begins — it is the customer’s responsibility, not HustleForge’s, to configure the feature so that requirement is met for the jurisdictions in which they operate.
Do-not-record pathway. A caller may ask, at any point in the call, not to be recorded or to speak with a human instead. The Forge customer is responsible for configuring their receptionist to honor that request; callers who reach a Forge customer and wish to exercise this option should say so directly on the call, or contact that business through a non-recorded channel.
Retention.Retention of call recordings and transcripts is configurable by the Forge customer and governed by that customer’s account settings and the applicable subprocessor terms. HustleForge does not itself set a fixed retention period for this content; questions about how long a specific recording or transcript is kept should be directed to the business that operated the call, or to us at contact@hustleforge.tech if you are unable to reach that business.
See also our Subprocessor Register and Trust Center for more on the providers and controls involved in this feature.
10. Data Retention
We retain information only for as long as reasonably necessary for the purpose for which it was collected, the customer’s configured retention rules, contractual requirements, security needs, dispute resolution, and legal obligations.
Typical retention practices include:
- Prospective-customer inquiries: generally up to 24 months after the last meaningful interaction.
- Blueprints, Forge Plans, order forms, and contractual records: for the engagement and a reasonable period afterward, generally up to seven years where needed for business, tax, or legal records.
- Account and subscription information: for the active account and a reasonable period after termination.
- Customer Data: according to customer-configured retention settings and the applicable customer agreement.
- Security, authentication, approval, and audit records: for the period reasonably necessary to investigate activity, support accountability, and meet contractual or legal requirements.
- Payment and transaction records: as required for accounting, tax, fraud-prevention, and dispute purposes.
- Consent-gated analytics data (Section 8): retained for internal reporting and deleted on request (Section 13/14); it is never retained longer than needed for that purpose.
- Aggregated or deidentified information: for as long as it remains aggregated or deidentified and is useful for legitimate platform improvement.
The Forge currently provides a seven-day cancellation grace period during account offboarding before permanent deletion begins. After that period, Customer Data is deleted in a dependency-safe order, subject to legal retention requirements and temporary backup retention.
Backup copies may remain for a limited period until overwritten through the applicable provider’s normal backup cycle. Backups are maintained for disaster recovery and are not guaranteed to support individual record restoration.
11. Customer Data Ownership, Export, and Deletion
Customer-supplied data remains owned and controlled by the customer organization.
Authorized users may export supported Customer Data according to their permissions. Full-organization exports require appropriate owner authority and additional authentication. Export scope and format may vary by record type.
Exports exclude:
- passwords;
- authentication secrets;
- integration credential material;
- internal security controls;
- proprietary platform source code; and
- certain platform-generated or aggregated service information.
Customers should export information they require before account termination.
Deletion may be delayed or limited where information must be retained to:
- comply with law;
- resolve a dispute;
- prevent fraud;
- preserve security records;
- enforce an agreement; or
- maintain a record of a completed financial transaction.
12. Security
HustleForge maintains administrative, technical, and organizational safeguards designed to protect information, including:
- encrypted web connections;
- individual user accounts;
- role-based access controls;
- business and location separation;
- activity and approval history;
- integration-health monitoring;
- controlled administrative access;
- platform monitoring;
- managed backups;
- centralized updates; and
- incident-response procedures.
Security responsibilities are shared. Customers are responsible for:
- selecting authorized users;
- assigning appropriate permissions;
- removing former users promptly;
- protecting credentials;
- maintaining secure devices and browsers;
- authorizing integrations;
- reviewing approval requests;
- controlling what information is submitted; and
- following their own privacy, retention, and regulatory requirements.
No electronic system is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or disruption will never occur.
Security vulnerabilities may be reported to security@hustleforge.tech.
13. Privacy Rights and Requests
Depending on your location and applicable law, you may have the right to:
- request access to personal information;
- request correction of inaccurate information;
- request deletion;
- obtain a portable copy of certain information;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent;
- opt out of the sale or sharing of personal information;
- limit certain uses of sensitive personal information;
- opt out of, or change your choice on, analytics cookies — use the Cookie Settings link in the site footer at any time (see Section 8);
- appeal a denied privacy request; and
- receive equal service without unlawful discrimination for exercising a privacy right.
To submit a request, submit a privacy request using our form, or email contact@hustleforge.tech with the subject line “Privacy Request.”
We may need to verify your identity and authority before acting on a request. Verification may include confirming information associated with your account or organization.
An authorized agent may submit a request where permitted by law. We may require proof that the agent is authorized to act for the individual.
Where information is controlled by a Forge customer, we may direct the request to that customer or assist the customer with its response.
We will not unlawfully discriminate against an individual for exercising a privacy right. EU/UK/EEA residents have additional rights and response-time guarantees described in Section 14 below.
14. GDPR — Rights for EU, UK & EEA Residents
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the GDPR (and the UK GDPR) gives you rights over your personal data in addition to those in Section 13, and requires us to identify the legal basis for each way we use it.
Legal basis for processing:
- Consent (Art. 6(1)(a)) — the analytics cookies and behavioral data in Section 8, only after you click Accept. You may withdraw this consent at any time with the same effect as if you had never given it.
- Contract / steps taken at your request (Art. 6(1)(b)) — processing your onboarding-form submission, inquiries, orders, and operating The Forge under your service agreement.
- Legitimate interests (Art. 6(1)(f)) — fraud/abuse prevention (Turnstile), basic connection-level security logging, platform reliability, and keeping the site running, balanced against your right to privacy.
- Legal obligation (Art. 6(1)(c)) — retaining records required by tax, accounting, or other law.
Your rights include the right to:
- Access the personal data we hold about you and receive a copy of it
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”), subject to legal retention exceptions
- Restrict or object to certain processing, including processing based on legitimate interests
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time, free of charge, as easily as you gave it (the footer’s Cookie Settings link)
- Lodge a complaint with your local data protection supervisory authority
To exercise any GDPR right, email contact@hustleforge.tech with “GDPR Request” in the subject line. We will respond within 30 days as required by Art. 12(3).
International data transfers. HustleForge LLC is based in the United States. Our infrastructure providers may process data in the United States or other countries outside the EEA/UK. Each maintains its own GDPR compliance program and data processing terms for such transfers (see our Subprocessor Register for current providers and their privacy policies). By using our site and accepting analytics cookies where applicable, you acknowledge this processing may occur outside your home jurisdiction.
15. California Privacy Notice
See also our standalone California Notice at Collection for a shorter, collection-point summary of the categories below.
Where the California Consumer Privacy Act applies, California residents may have rights to:
- know the categories and specific pieces of personal information collected;
- know the categories of sources;
- know the purposes for collection, use, and disclosure;
- know the categories of recipients;
- request deletion;
- request correction;
- opt out of sale or sharing;
- limit certain uses of sensitive personal information; and
- receive equal treatment when exercising these rights.
During the preceding 12 months, HustleForge may have collected the categories described in Section 2 from the sources described in Section 3, used them for the purposes described in Section 4, and disclosed them to the recipients described in Section 6.
HustleForge has not sold personal information or shared personal information for cross-context behavioral advertising during the preceding 12 months.
HustleForge does not knowingly sell or share the personal information of individuals under 16.
Sensitive personal information is used only to provide, secure, administer, and support the requested service, unless a different use is separately disclosed and lawfully authorized.
Where recognized and applicable, HustleForge will process valid opt-out preference signals, including the Global Privacy Control (GPC) signal described in Section 8.
16. Children and Information Concerning Minors
The Forge website and customer accounts are intended for businesses and authorized business users, not for children to create accounts independently.
A Forge customer operating in education, childcare, religious services, or another field involving minors may submit information concerning minors only when:
- the processing is lawful;
- the information is necessary for the configured service;
- the customer has provided required notices and obtained required consent;
- access is appropriately limited; and
- the use has been approved within the customer’s Forge scope.
The Forge is not intended to collect information directly from children under 13 without legally valid authorization.
17. International Processing
HustleForge operates from the United States. Information may be processed in the United States or in other locations where approved service providers operate.
Where required, we use appropriate contractual or legal mechanisms for cross-border processing.
18. Third-Party Services
The Forge may contain links to or integrations with third-party services. HustleForge does not control those providers’ independent privacy practices.
Customers should review the privacy terms of every third-party provider they authorize.
The Forge does not replace the customer’s responsibility to manage agreements, permissions, retention settings, and user access within connected third-party systems.
18A. Google User Data (Google Calendar Connection)
The Forge offers an optional Google Calendar connection. When an authorized user of a customer workspace connects a Google account, The Forge requests a single, read-only Google permission: https://www.googleapis.com/auth/calendar.readonly. This section explains how The Forge accesses, uses, stores, and shares the Google user data obtained through that permission.
What we access. Upcoming calendar events on the connected account (event title, start and end time, and the calendar they belong to) and the basic account identifier Google returns to confirm the connection. We do not access Gmail, Drive, Contacts, or any other Google service through this connection.
How we use it.Solely to display the connected account’s upcoming events inside that customer’s Forge workspace, beside the work, tasks, and appointments already recorded there, so the customer can see their schedule in one place. The Forge does not create, modify, or delete Google Calendar events through this connection, and Google user data is not used to develop, improve, or train generalized artificial-intelligence or machine-learning models.
How we store it. The OAuth tokens Google issues are encrypted at rest and scoped to the customer workspace that authorized them. A short-lived cache of upcoming events is held so the workspace can render them without re-querying Google on every page view. No other copy of Google Calendar data is retained.
How we share it. We do not sell, rent, or share Google user data with third parties, advertisers, or data brokers, and we do not transfer it to anyone other than the processors strictly necessary to host and secure The Forge (see Section 6). It is never used for advertising or shared with other Forge customers.
Disconnecting and deletion.An authorized user can disconnect Google Calendar at any time from the workspace’s Access Panel. Disconnecting revokes the token with Google and deletes the stored tokens and cached events from The Forge. Access can also be removed from the Google account’s own security settings at myaccount.google.com/permissions.
The Forge’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
19. Changes to This Policy
We may update this Privacy Policy as The Forge, our providers, or applicable requirements change.
The updated policy will display a revised “Last updated” date. We will provide additional notice through email, the platform, or another reasonable method when a change materially affects how we use personal information. You can review or change your cookie choice at any time using the Cookie Settings link in the footer, regardless of when this policy was last updated.
20. Contact Us
Questions, concerns, and privacy requests may be directed to:
HustleForge LLC
Email: contact@hustleforge.tech
Security reports: security@hustleforge.tech
Mailing address: 2290 Cheim Blvd, Marysville, CA 95901