Forgemark is an app made by Forge Together Ltd ("Forge", "we"), a company registered in England and Wales, number 14911771, registered office 18 New Road, Weybridge, KT13 9BW. It runs as a Shopify app and, for websites not on Shopify, as a tag added to the site. This policy explains what Forgemark collects, why, where it's kept and how to have it deleted. It covers Forgemark only; the Forge Together website has its own policy.
Questions, requests or complaints: aaron@forgetogether.agency.
1. Who controls the data
- For your account and the accounts you connect (Google, Google Ads, Meta, Klaviyo, HubSpot), Forge is the controller.
- For data about your site's visitors (the pixel and tag events in section 2), you are the controller and Forge processes it for you, under Shopify's terms where they apply and ours.
- For your HubSpot contacts and deals, you are the controller and Forge processes them for you, to show you which visits led to your leads and won deals.
2. What Forgemark collects
From Shopify, when you install the app
- Your store's domain and name, and the Shopify access token that lets the app work.
- Your orders, products and customers, to show you your sales, where they came from and how customers come back. Customer records are kept to what those reports need.
- Your store's customer events, through Shopify's app pixel (below).
From the Forgemark pixel or tag on your site
- What visitors do on the site: pages viewed, sections seen, scroll, clicks, form steps, page speed, errors and checkout steps, with a random visitor ID.
- The pixel and tag send nothing until a visitor accepts analytics cookies. Advertising click IDs are read only with marketing consent.
- We don't store IP addresses. The collector uses the IP only to look up the country and region, then discards it. We never fingerprint devices.
- On a website, an enquiry form's fields are never sent: only that a form was started, how far it got and whether it was sent.
- Raw events are kept for up to 400 days, then deleted.
From Google, only if you connect it
- The email address of the Google account you connect, and a token that lets Forgemark read your reports. The token is encrypted (AES-256-GCM) before it's stored.
- Google Search Console reports for the site you choose: clicks, impressions, click-through rate and average position, by day, search term and page.
- Google Analytics 4 reports for the property you choose: sessions, engaged sessions, transactions and revenue, by day, channel and AI assistant.
- Google Ads, connected separately: the account you choose, and its spend, clicks, impressions, conversions and conversion value by campaign and day, and which campaign each ad click belonged to. Google's permission for Google Ads reads as able to change campaigns; Forgemark only reads reports.
From Meta, only if you connect it
- Your Facebook user ID and name, the ad account you choose, and its spend, clicks, impressions, purchases and purchase value by campaign and day. Forgemark asks Meta only for permission to read ads reports. The sign-in token is encrypted before it's stored.
From Klaviyo, only if you connect it
- The Klaviyo account's name, currency, time zone and website, and the orders and revenue Klaviyo credits to each campaign and flow message by day, with their names.
- Forgemark never reads your subscribers or profiles, and never sends anything through Klaviyo.
From HubSpot, only if you connect it
- Your HubSpot account's ID, currency and time zone.
- Each contact's ID, the dates it became a lead, a qualified lead and a customer, and HubSpot's own record of where it came from.
- Each deal's ID, amount, currency, stage, the dates it was created and closed, and which contacts it belongs to.
- Your forms' names, and whether each one carries Forgemark's hidden field.
- Forgemark never reads contacts' names, email addresses, phone numbers, notes, emails or messages, and never changes anything in HubSpot.
On your website, for HubSpot, only where a visitor allows marketing cookies
- The Forgemark tag puts a random reference into a hidden field on your HubSpot forms. When the form is sent, HubSpot keeps the reference on the contact, and Forgemark keeps the same reference with the enquiry. That's how a visit is linked to the contact it became, by ID alone.
- The tag also sends HubSpot's own visitor cookie (hubspotutk) with an enquiry, so a form that isn't HubSpot's can be linked too. Forgemark asks HubSpot which contact the cookie belongs to and keeps only a scrambled version (a one-way hash) as the link.
- A visitor who allows analytics cookies but not marketing cookies is never linked to a contact.
Public information, for AI visibility
- Your site's public pages or catalogue (products, services, collections), the questions we write from them, and the answers AI assistants give to those questions. None of this is personal data.
3. How we use it
Only to run Forgemark for you: to show you your own reports, compare periods, credit your sales and enquiries to where they came from, find what's costing you sales and suggest fixes. We also use it to answer your support requests and to keep the service secure. We don't sell data or use it for advertising. We don't build profiles of your visitors for anyone but you: where you connect HubSpot, Forgemark links a visitor's visits to the contact they became in your HubSpot, only for visitors who allowed marketing cookies, and only so you can see which channels bring leads that close. We never send a conversion to an advertising platform on your behalf unless you switch that on for an account you own.
4. Who we share it with
Only the providers that run Forgemark, each bound by a data processing agreement:
| Provider | What it does | Where |
|---|---|---|
| Supabase | App database, including connected reports and tokens | London |
| Vercel | Runs the app | London |
| ClickHouse Cloud | Stores pixel and tag events | London |
| Cloudflare | Receives pixel and tag events, and serves this website | Global edge, events stored in London |
| Shopify | The platform the Shopify app runs in | Per Shopify |
| DataForSEO, Perplexity | Put our questions to AI assistants | Receive the questions only |
| Anthropic | Writes questions from your public pages and reads AI answers | Receives public information only |
No provider receives your Google, Meta, Klaviyo or HubSpot data except Supabase and Vercel, which store and run it for us. We'll disclose data if the law requires it.
5. Google user data
Forgemark's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice:
- We use Google data only to show you your own reports in Forgemark.
- We don't transfer it to anyone except as needed to run Forgemark (section 4), to comply with the law, or as part of a merger or sale with notice to you.
- We don't use it for advertising, and we don't use it to train AI or machine learning models.
- No person at Forge reads it unless you ask us to (for support), it's needed for security, or the law requires it.
6. How long we keep it
- Google and Google Ads data: while the account is connected. Disconnect it in Forgemark (Connections) and we delete the token and every report we hold from it straight away. If you remove Forgemark's access at myaccount.google.com/permissions, the nightly sync stops and we delete the data within 30 days.
- Meta data: while the ad account is connected. Disconnect it in Forgemark and we end our access and delete it straight away. If you remove Forgemark in your Facebook settings and ask for your data to be deleted, Meta tells us and we delete it at once.
- Klaviyo data: while the account is connected. Disconnect it and we delete it straight away; if Klaviyo refuses our access two nights running, we delete it then.
- HubSpot data: while the account is connected. Disconnect it and we end our access and delete it straight away; if HubSpot refuses our access twice running, we delete it then. When a contact is deleted in HubSpot, including a privacy deletion, HubSpot tells us and we delete it at once. The raw hubspotutk cookie stays only in the tag's events, which are deleted after 400 days like the rest.
- Pixel and tag events: up to 400 days as raw events, then deleted.
- Everything else: until you uninstall or remove the tag and ask us to close your account. Shopify tells us 48 hours after an uninstall, and we delete your store's data within 30 days of that.
7. Security
Data travels encrypted (TLS) and is stored encrypted at rest by our providers. Tokens are encrypted again by Forgemark before storage. Access is limited to the Forge staff who run the service.
8. Your rights
Under UK GDPR you can ask for a copy of your data, have it corrected or deleted, restrict or object to its use, and take it elsewhere. Email aaron@forgetogether.agency and we'll reply within 30 days. Shoppers' requests reach us through Shopify, and we act on them for you. You can also complain to the Information Commissioner's Office (ico.org.uk).
9. Changes
We'll post changes here and update the date at the top. If a change affects how we use Google data, we'll ask you again before we use it that way.