How IRIS Systems LLC handles information when operating the ForgeSystems platform.
IRIS Systems LLC, a Texas limited liability company, operates ForgeSystems. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you interact with ForgeSystems as an agency owner, team member, developer, website visitor, or end client of an organization using the platform.
This policy applies to all services provided through ForgeSystems, including Invoicing & Payments, Contracts & E-Signatures, Custom Forms, Scheduling & Booking, Client Messaging, Email & SMS Marketing, Client Feedback, Onboarding & Checklists, Portfolio & Case Studies, Landing Pages, and Analytics & Reporting.
Because ForgeSystems operates as a white-label platform, our privacy responsibilities depend on the type of data involved. We operate under a three-tier model:
Understanding the three-tier model: ForgeSystems plays different roles depending on whose data is being processed. This distinction matters for your privacy rights and for determining who is responsible for what.
We act as the Data Controller for information related to agency accounts, billing, and platform usage. This includes the data agencies provide when they sign up, their payment information, and how they use the platform. We decide why and how this data is processed.
When agencies use ForgeSystems to manage their own clients, we act as a Data Processor. We process agency client data on the agency's behalf and according to their instructions. We do not use this data for our own purposes beyond providing the service.
Agencies that use ForgeSystems are Data Controllers for their own clients' data. They determine what data to collect, why, and how it is used within the platform. Agencies are responsible for maintaining their own privacy policies that inform their clients about data practices.
If you are the client of an agency using ForgeSystems: The agency you work with is the primary controller of your data. Please review their privacy policy for details on how they handle your information. This policy covers how ForgeSystems processes that data on the agency's behalf.
You can control cookies through your browser settings. Disabling essential cookies may prevent certain features from working correctly. Disabling analytics cookies will not affect your ability to use the platform.
If you install or use the ShopForge Shopify app, we collect and process the minimum information needed to connect your Shopify store to your ForgeSystems workspace and provide store, checkout, and shipping controls. This may include your Shopify shop domain, Shopify installation/session records, the ForgeSystems workspace identifier you link to the store, Shopify API access tokens, Storefront API tokens, product and inventory data, selling plan metadata, checkout validation status, and technical logs related to app installation and operation.
ShopForge Public does not store Shopify customer records in the public app database. Shopify customer privacy webhooks for data requests and redaction are handled by acknowledging the request and confirming that the public app does not maintain customer records. Shopify shop redaction requests delete local app sessions and the linked shop record.
We use information for the following purposes, each tied to a legal basis:
We do not sell personal information. We share data only in the following circumstances:
We use third-party service providers to operate ForgeSystems. The current provider categories and purposes are maintained in our Subprocessor List. A provider processes only the data needed for enabled services and integrations.
| Provider | Purpose | Data Processed |
|---|---|---|
| Amazon Web Services (AWS) | Email delivery via SES, infrastructure | Email content, recipient addresses, delivery metadata |
| Stripe | Payment processing (PCI DSS Level 1 certified) | Payment card details, billing addresses, transaction amounts |
| Supabase | Database hosting, authentication, file storage | Account data, application data, uploaded files, auth credentials |
| Netlify | Application hosting, serverless functions | Request data, access logs, function execution data |
| Shopify | ShopForge app installation, product and inventory synchronization, storefront access, checkout and shipping validation | Shop domain, app installation/session data, product data, inventory data, selling plan metadata, checkout validation metadata, Storefront API token data |
For details on how each provider handles data, see their respective privacy policies:
We retain data for the minimum period necessary to fulfill the purposes described in this policy. Specific retention periods are:
| Data Type | Retention Period |
|---|---|
| Account data | Duration of account + 90 days post-deletion |
| Payment and billing records | 7 years (legal requirement) |
| Communication logs (email, SMS, chat) | 24 months |
| ShopForge Shopify app installation and linked shop records | Duration of active installation, then deleted or anonymized after uninstall, shop redaction, or account deletion as legally required |
| Usage analytics | 24 months |
| Server and access logs | 90 days |
| Agency client data | Deleted within 30 days of agency request or account termination |
When data reaches the end of its retention period, it is securely deleted or anonymized so it can no longer be linked to an individual.
We take the security of your data seriously and implement multiple layers of protection:
ForgeSystems's infrastructure is hosted primarily in the United States through AWS and other US-based providers. If you are located outside the US, your data may be transferred to and processed in the United States.
For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally recognized transfer mechanisms, to ensure an adequate level of data protection.
If you are located in the European Union, European Economic Area, or the United Kingdom, you have the following rights under the General Data Protection Regulation:
We respond to all GDPR requests within 30 days. You also have the right to lodge a complaint with your local supervisory authority if you believe your data has been mishandled.
If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act provide you with the following rights:
We respond to all CCPA/CPRA requests within 45 days.
We comply with applicable state privacy laws, including those in Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy legislation. If your state provides additional privacy rights, please contact us to exercise them.
ForgeSystems does not sell personal information. We do not share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (CCPA). Because we do not engage in these practices, a "Do Not Sell or Share My Personal Information" link is not necessary, but we honor such requests regardless if received.
ForgeSystems provides controls designed to help senders comply with the CAN-SPAM Act. Senders remain responsible for configuring and using those controls correctly. Commercial email should include:
Unsubscribe requests are honored within 10 business days.
ForgeSystems provides consent, sender-identification, and opt-out controls designed to support compliant messaging. Use of those controls does not itself make a campaign lawful. Senders remain responsible for the TCPA, carrier rules, provider policies, and other requirements that apply to their messages. See the Messaging Terms.
Mobile information and consent: We do not share mobile numbers, SMS opt-in data, or SMS consent with third parties or affiliates for their marketing or promotional purposes. Service providers may process this information only as needed to deliver and support the messaging program.
Program disclosures: Message frequency varies by program and is described when you opt in. Message and data rates may apply.
Agencies using ForgeSystems are responsible for obtaining proper consent from their contacts before sending communications. ForgeSystems provides the tools for compliance, but agencies must ensure they have the appropriate permissions and consents in place.
ForgeSystems is a business platform and is not directed at children under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at the email address listed below.
In the event of a data breach that affects your personal information, we will:
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
Continued use of ForgeSystems after the notice period constitutes acceptance of the updated policy. If you disagree with any changes, you may close your account before the changes take effect.
If you have questions about this Privacy Policy, want to exercise your privacy rights, or have concerns about how your data is handled, please reach out:
Email: support@forgesystems.io
Operator: IRIS Systems LLC, Amarillo, Texas
Subject line: "Privacy Request"
Formal notices: A physical mailing address is available upon request.
Operational publication prepared for licensed-attorney review. This status does not represent attorney approval.