Privacy Policy

Last updated: May 2026

StockForge provides cloud-based inventory, purchasing, production, and operations software for businesses. This Privacy Policy explains how StockForge collects, uses, shares, retains, and protects information when you visit our website, create an account, use our service, or connect third-party services.

Information We Collect

We collect information needed to operate StockForge and support your account, including:

  • Account and contact information, such as name, business name, email address, role, and support messages.
  • Business operations data you provide or import, such as inventory items, stock levels, bills of materials, vendors, purchase orders, sales orders, locations, production batches, forecasts, shipping details, and related metadata.
  • Billing and plan information needed to administer subscriptions. Payment card details, when collected, are processed by our payment provider rather than stored directly by StockForge.
  • Website and product usage information, such as pages viewed, features used, device and browser information, IP address, log data, and approximate location inferred from network information.
  • Integration data from services you choose to connect, such as e-commerce, accounting, shipping, marketplace, CRM, or similar business systems that StockForge makes available.

Third-Party Integrations and OAuth Data

When you connect a third-party service, StockForge uses the authorization method provided by that service, usually OAuth. We request only the permissions we need for the features you enable. Depending on the connector and your settings, the data we access may include:

  • Commerce and marketplace data, such as products, variants, inventory levels, fulfillment status, locations, orders, line items, customer shipping details, and seller account identifiers.
  • Accounting and finance data, such as items, vendors, customers, invoices, purchase orders, sales receipts, tax metadata, classes, accounts, and sync status.
  • CRM and sales data, such as companies, contacts, deals, tickets, lifecycle stages, pipelines, and activity records needed to connect operations workflows.
  • Shipping and carrier data, such as shipper account identifiers, addresses, package dimensions, rates, labels, tracking events, and shipment status.

We use OAuth access tokens, refresh tokens, API keys, client secrets, and similar credentials only to provide and maintain the integration you authorized. We do not ask for your third-party account password. Tokens and secrets are treated as confidential information, access is limited to systems and personnel with a business need, and tokens are revoked or deleted when no longer needed or when you disconnect the integration where the provider supports revocation.

How We Use Information

We use information to:

  • Provide, secure, maintain, and improve StockForge.
  • Authenticate users, administer accounts, process subscriptions, and provide customer support.
  • Sync data between StockForge and integrations you authorize.
  • Create operational reports, forecasts, alerts, replenishment suggestions, and workflow automation for your business.
  • Monitor reliability, troubleshoot errors, prevent abuse, and protect customer data.
  • Send service, security, billing, product, and support communications.
  • Comply with legal obligations and enforce our Terms of Service.

Integration Data Restrictions

We do not sell your business data or integration data. We do not use data from connected services for advertising, unrelated profiling, or training generalized AI models. We do not transfer integration data to another application unless necessary to provide StockForge, comply with law, protect security, or as you direct through the service.

If Shopify protected customer data is enabled, we request only the minimum customer data needed for the merchant-facing StockForge feature and use it only for that feature, support, security, legal compliance, or your instructions. Access to protected customer data is logged for security and compliance review.

If StockForge supports Amazon Selling Partner API features, we will use Amazon seller and customer data only for the authorized inventory, order, fulfillment, reporting, and support workflows you enable. We will not aggregate Amazon data across selling partners, use it for unrelated advertising, or disclose it except as needed to provide StockForge, comply with law, or follow your instructions. If restricted Amazon data is needed, we will request it only for the authorized workflow that requires it. We will retain Amazon customer personally identifiable information for no longer than 30 days after order delivery unless longer retention is required by law for tax, regulatory, or similar compliance purposes.

How We Share Information

We share information only in limited circumstances:

  • With service providers that help us host, secure, operate, support, analyze, and bill for StockForge, subject to confidentiality and data protection obligations.
  • With third-party services you connect, so data can be read from or written to those services as directed by you.
  • With your organization administrators and authorized users according to account roles and permissions.
  • For legal, safety, fraud prevention, or rights-protection reasons when we believe disclosure is required or appropriate.
  • In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to continued protection of customer data.

User Controls

You can update account information, manage users, configure roles, connect or disconnect integrations, and request export or deletion of your data. Disconnecting an integration stops future syncs, but it may not delete data already imported into StockForge or data already present in the connected service. You can also revoke StockForge's access from the third-party provider's account or app settings.

Data Retention and Deletion

We retain account, business, integration, support, billing, and log data for as long as needed to provide StockForge, comply with legal obligations, resolve disputes, maintain security, and enforce agreements. Provider-specific retention commitments in this policy control where they are stricter. After account termination, we may keep data for a limited period to allow export, backups, legal compliance, fraud prevention, and auditability. When deletion is requested and no longer legally or operationally required, we delete or de-identify the data. Backup copies are overwritten on their normal backup cycle.

Security

We use administrative, technical, and organizational safeguards designed to protect customer data, including encryption in transit, encryption for sensitive secrets at rest, access controls, least-privilege permissions, logging, monitoring, secure development practices, and vendor access controls. No online service can guarantee absolute security, and you are responsible for maintaining secure passwords, user permissions, devices, and third-party accounts.

International Data Transfers

StockForge may process and store information in the United States and other locations where we or our service providers operate. If you use StockForge outside the United States, you understand that information may be transferred to and processed in countries with privacy laws different from those in your jurisdiction.

Children's Privacy

StockForge is intended for business use and is not directed to children under 13. We do not knowingly collect personal information from children under 13.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the date above and provide notice as required by law or through the service.

Contact

For privacy inquiries, data requests, or integration data questions, contact privacy@stockforge.ai. For support, contact support@stockforge.ai.