Forgemark privacy policy
Last updated: 26 September 2026
Forgemark is a Shopify app made by Forge Together Ltd ("Forge", "we"), a company registered in England and Wales, number 14911771, at 18 New Road, Weybridge, KT13 9BW. This policy explains what Forgemark collects, why, where it's kept and how to have it deleted. It covers the Forgemark app only; our website has its own policy.
Questions, requests or complaints: [email protected].
1. Who controls the data
- For your account, your store's data and the Google data you connect, Forge is the controller.
- For data about your store's shoppers (the pixel events in section 2), you, the merchant, are the controller and Forge processes it for you, under Shopify's terms and ours.
2. What Forgemark collects
From Shopify, when you install the app
- Your store's domain and name, and the Shopify access token that lets the app work.
- Your store's orders, products and sales reports: order totals, tax, refunds, line items, the shipping country and where the visit that led to each order came from.
- For each customer, a Shopify customer ID, dates, number of orders and amount spent. Forgemark doesn't ask Shopify for shoppers' names, email addresses, phone numbers or postal addresses.
- Your store's customer events, through Shopify's app pixel (below).
From the Forgemark pixel on your store
- What shoppers do on the site: pages viewed, sections seen, scroll, clicks, form steps, page speed, errors and checkout steps, with a random visitor ID.
- The pixel sends nothing unless Shopify's consent settings show the shopper has allowed analytics. Ad click IDs and ad cookie IDs (such as gclid or fbclid) are recorded only when the shopper has also allowed marketing and the store has asked Forge for ad reporting. Forge never uses them to advertise.
- We don't store IP addresses. The collector uses the IP only to look up the country and region, then discards it. We never fingerprint devices.
- Raw events are kept for up to 400 days, then deleted.
From Google, only if you connect it
- The email address of the Google account you connect, and a token that lets Forgemark read your reports. The token is encrypted (AES-256-GCM) before it's stored.
- Google Search Console reports for the site you choose: clicks, impressions, click-through rate and average position, by day, search term and page.
- Google Analytics 4 reports for the property you choose: sessions, engaged sessions, transactions and revenue, by day and channel.
- Forgemark asks Google for read-only access. It can't change anything in your Google accounts.
Public information, for AI visibility
- Your store's public catalogue (product names, types and collections), the buyer questions we write from it, and the answers AI assistants give to those questions. None of this is personal data.
3. How we use it
Only to run Forgemark for your store: to show you your own reports, compare periods, find what's costing you sales and suggest fixes. We also use it to answer your support requests and to keep the service secure. We don't sell data, don't use it for advertising and don't build profiles of shoppers.
4. Who we share it with
Only the providers that run Forgemark, each bound by a data processing agreement:
| Provider | What it does | Where |
|---|---|---|
| Supabase | App database, including store data, Google reports and tokens | London |
| Vercel | Runs the app | London |
| ClickHouse Cloud | Stores pixel events | London |
| Cloudflare | Receives pixel events | Global edge, events stored in London |
| Shopify | The platform the app runs in | Per Shopify |
| DataForSEO, Perplexity | Put our buyer questions to AI assistants | Receive the questions only |
| Anthropic | Writes buyer questions from your public catalogue | Receives the public catalogue only |
No provider receives your Google data except Supabase and Vercel, which store and run it for us. We'll disclose data if the law requires it.
5. Google user data
Forgemark's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice:
- We use Google data only to show you your own reports in Forgemark.
- We don't transfer it to anyone except as needed to run Forgemark (section 4), to comply with the law, or as part of a merger or sale with notice to you.
- We don't use it for advertising, and we don't use it to train AI or machine learning models.
- No person at Forge reads it unless you ask us to (for support), it's needed for security, or the law requires it.
6. How long we keep it
- Google data: while your Google account is connected. Disconnect it in Forgemark (Connections, Google, Disconnect) and we delete the Google token and every Google report we hold for your store straight away. You can also remove Forgemark's access at myaccount.google.com/permissions; the nightly sync then stops and we delete the data within 30 days.
- Pixel events: up to 400 days as raw events, then deleted.
- Everything else: until you uninstall. Shopify tells us 48 hours after an uninstall, and we delete your store's data within 30 days of that.
7. Security
Data travels encrypted (TLS) and is stored encrypted at rest by our providers. Tokens are encrypted again by Forgemark before storage. Access is limited to the Forge staff who run the service.
8. Your rights
Under UK GDPR you can ask for a copy of your data, have it corrected or deleted, restrict or object to its use, and take it elsewhere. Email [email protected] and we'll reply within 30 days. Shoppers' requests reach us through Shopify, and we act on them for you. You can also complain to the Information Commissioner's Office (ico.org.uk).
9. Changes
We'll post changes here and update the date at the top. If a change affects how we use Google data, we'll ask you again before we use it that way.