Forgemark privacy policy

Last updated: 26 September 2026

Forgemark is a Shopify app made by Forge Together Ltd ("Forge", "we"), a company registered in England and Wales, number 14911771, at 18 New Road, Weybridge, KT13 9BW. This policy explains what Forgemark collects, why, where it's kept and how to have it deleted. It covers the Forgemark app only; our website has its own policy.

Questions, requests or complaints: [email protected].

1. Who controls the data

  • For your account, your store's data and the Google data you connect, Forge is the controller.
  • For data about your store's shoppers (the pixel events in section 2), you, the merchant, are the controller and Forge processes it for you, under Shopify's terms and ours.

2. What Forgemark collects

From Shopify, when you install the app

  • Your store's domain and name, and the Shopify access token that lets the app work.
  • Your store's orders, products and sales reports: order totals, tax, refunds, line items, the shipping country and where the visit that led to each order came from.
  • For each customer, a Shopify customer ID, dates, number of orders and amount spent. Forgemark doesn't ask Shopify for shoppers' names, email addresses, phone numbers or postal addresses.
  • Your store's customer events, through Shopify's app pixel (below).

From the Forgemark pixel on your store

  • What shoppers do on the site: pages viewed, sections seen, scroll, clicks, form steps, page speed, errors and checkout steps, with a random visitor ID.
  • The pixel sends nothing unless Shopify's consent settings show the shopper has allowed analytics. Ad click IDs and ad cookie IDs (such as gclid or fbclid) are recorded only when the shopper has also allowed marketing and the store has asked Forge for ad reporting. Forge never uses them to advertise.
  • We don't store IP addresses. The collector uses the IP only to look up the country and region, then discards it. We never fingerprint devices.
  • Raw events are kept for up to 400 days, then deleted.

From Google, only if you connect it

  • The email address of the Google account you connect, and a token that lets Forgemark read your reports. The token is encrypted (AES-256-GCM) before it's stored.
  • Google Search Console reports for the site you choose: clicks, impressions, click-through rate and average position, by day, search term and page.
  • Google Analytics 4 reports for the property you choose: sessions, engaged sessions, transactions and revenue, by day and channel.
  • Forgemark asks Google for read-only access. It can't change anything in your Google accounts.

Public information, for AI visibility

  • Your store's public catalogue (product names, types and collections), the buyer questions we write from it, and the answers AI assistants give to those questions. None of this is personal data.

3. How we use it

Only to run Forgemark for your store: to show you your own reports, compare periods, find what's costing you sales and suggest fixes. We also use it to answer your support requests and to keep the service secure. We don't sell data, don't use it for advertising and don't build profiles of shoppers.

4. Who we share it with

Only the providers that run Forgemark, each bound by a data processing agreement:

ProviderWhat it doesWhere
SupabaseApp database, including store data, Google reports and tokensLondon
VercelRuns the appLondon
ClickHouse CloudStores pixel eventsLondon
CloudflareReceives pixel eventsGlobal edge, events stored in London
ShopifyThe platform the app runs inPer Shopify
DataForSEO, PerplexityPut our buyer questions to AI assistantsReceive the questions only
AnthropicWrites buyer questions from your public catalogueReceives the public catalogue only

No provider receives your Google data except Supabase and Vercel, which store and run it for us. We'll disclose data if the law requires it.

5. Google user data

Forgemark's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice:

  • We use Google data only to show you your own reports in Forgemark.
  • We don't transfer it to anyone except as needed to run Forgemark (section 4), to comply with the law, or as part of a merger or sale with notice to you.
  • We don't use it for advertising, and we don't use it to train AI or machine learning models.
  • No person at Forge reads it unless you ask us to (for support), it's needed for security, or the law requires it.

6. How long we keep it

  • Google data: while your Google account is connected. Disconnect it in Forgemark (Connections, Google, Disconnect) and we delete the Google token and every Google report we hold for your store straight away. You can also remove Forgemark's access at myaccount.google.com/permissions; the nightly sync then stops and we delete the data within 30 days.
  • Pixel events: up to 400 days as raw events, then deleted.
  • Everything else: until you uninstall. Shopify tells us 48 hours after an uninstall, and we delete your store's data within 30 days of that.

7. Security

Data travels encrypted (TLS) and is stored encrypted at rest by our providers. Tokens are encrypted again by Forgemark before storage. Access is limited to the Forge staff who run the service.

8. Your rights

Under UK GDPR you can ask for a copy of your data, have it corrected or deleted, restrict or object to its use, and take it elsewhere. Email [email protected] and we'll reply within 30 days. Shoppers' requests reach us through Shopify, and we act on them for you. You can also complain to the Information Commissioner's Office (ico.org.uk).

9. Changes

We'll post changes here and update the date at the top. If a change affects how we use Google data, we'll ask you again before we use it that way.