Last Updated: March 27, 2026

Legal

Privacy Policy

At ProposalForge, we take your privacy seriously. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over your data. It applies to all users of forgeproposals.com and related services.

1. Introduction & Scope

This Privacy Policy applies to personal information processed by ProposalForge("we," "us," or "our") in connection with theProposalForge platform — an AI-powered proposal and invoice generation service for contractors and tradespeople — accessible at forgeproposals.com.

This policy covers information collected from:

  • Registered users of the Service (“Contractors”)
  • Recipients of proposals and invoices (“Clients”) — limited to what is necessary to deliver documents
  • Visitors to our website

By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please discontinue use of the Service.

2. Information We Collect

2.1 Information You Provide

When you register and use the Service, you provide:

  • Account information: email address, name, profile picture (via Google OAuth)
  • Contractor profile: business name, phone number, email, contractor license number
  • Business defaults: preferred intro language, scope templates, payment terms, warranty text
  • Proposal content: client name, client email, project address, scope of work, line items, pricing
  • Invoice content: client name, client email, invoice amounts, line items, due dates
  • Support communications: messages sent to our support team
  • Review/testimonial content: rating and quote text (only if you opt in)

2.2 Information Collected Automatically

When you use the Service, we automatically collect:

  • Session information: authentication session tokens (stored as secure cookies)
  • Usage data: proposal generation events, PDF downloads, email sends (via Plausible — anonymized, no PII)
  • Device fingerprint: a hashed identifier derived from your browser characteristics, used solely to prevent multi-account fraud on the free tier
  • IP address: hashed (SHA-256) before storage; used for proposal response rate limiting
  • Interaction timestamps: when proposals and invoices are viewed, sent, responded to, or signed
  • Log data: server request logs, error logs (standard infrastructure logging)

2.3 Information from Third Parties

  • Google OAuth: your name, email address, and profile picture when you sign in with Google
  • Stripe: subscription status, customer ID, and subscription ID (we do not receive your card number or full payment details)

2.4 AI Inputs (Proposal Generation)

When you generate a proposal using our AI feature, the information you enter into the proposal form — including contractor details, client name, project scope, and line items — is transmitted to Anthropic's Claude API for processing. This data is sent over an encrypted connection. Please see Section 6 for details on how Anthropic handles this data.

3. How We Use Your Information

We use the information we collect for the following purposes:

Service Delivery

To create and maintain your account, generate AI-powered proposals, create invoices, send documents to clients via email, process digital signatures, and generate PDF files.

Billing & Subscription Management

To process payments through Stripe, manage your subscription tier, enforce plan limits, and send billing receipts.

Email Communications

To deliver proposals and invoices to your clients, send automated reminders (if proposals are unread or unsigned), and send you transactional notifications about your account. We do not send marketing emails without your explicit opt-in.

Fraud Prevention & Security

To detect and prevent fraudulent account creation (via device fingerprinting), enforce rate limits, and protect the integrity of the Service.

Product Improvement

To understand aggregate usage patterns using anonymized analytics data (Plausible), diagnose technical issues, and improve Service features.

Affiliate Program

To track referrals, attribute sign-ups to affiliate codes, calculate commissions, and process affiliate payouts.

Legal Compliance

To comply with applicable laws, respond to legal requests, and enforce our Terms of Service.

5. Cookies & Tracking

For complete details, see our Cookie Policy.

5.1 Cookies We Use

We use a minimal set of cookies:

CookieTypePurpose
next-auth.session-tokenStrictly necessaryMaintains your authenticated session
next-auth.csrf-tokenStrictly necessaryProtects against cross-site request forgery

5.2 Analytics

We use Plausible Analytics, a privacy-first analytics tool that does not use cookies and does not track individual users across sessions. Plausible collects only anonymized, aggregate data (e.g., page views, event counts) and is fully GDPR compliant without requiring a cookie consent banner. No personal data is sent to Plausible.

5.3 No Marketing Cookies

We do not use advertising, retargeting, or marketing cookies. We do not serve ads.

5.4 Managing Cookies

The session and CSRF cookies are strictly necessary for the Service to function and cannot be disabled without logging out. You can clear cookies at any time using your browser settings, which will log you out of the Service.

6. Data Sharing & Disclosure

6.1 Service Providers (Subprocessors)

We share data with the following service providers, only to the extent necessary to deliver the Service. Each provider is bound by contractual data protection obligations:

Anthropic

USA

Data shared: Proposal form content (contractor details, client name, scope, line items)

Purpose: AI proposal text generation

Privacy Policy →

Stripe, Inc.

USA

Data shared: Email address, subscription tier, user ID

Purpose: Payment processing and subscription management

Privacy Policy →

Resend

USA

Data shared: Client email addresses, proposal/invoice content, contractor details

Purpose: Transactional email delivery

Privacy Policy →

Google LLC

USA

Data shared: Name, email, profile picture (only when signing in with Google)

Purpose: OAuth authentication

Privacy Policy →

Upstash

USA

Data shared: Hashed user IDs and hashed IP addresses (rate limit counters, ~1 hour TTL)

Purpose: API rate limiting

Privacy Policy →

FingerprintJS

USA

Data shared: Browser fingerprint (processed client-side; only a hash is stored by us)

Purpose: Device-based fraud prevention for free tier

Privacy Policy →

Plausible Analytics

EU

Data shared: Anonymized event names only (no PII, no cookies)

Purpose: Aggregate usage analytics

Privacy Policy →

Neon (database host)

USA

Data shared: All data stored in our database

Purpose: PostgreSQL database hosting

Privacy Policy →

6.2 Business Transfers

If ProposalForge is involved in a merger, acquisition, financing, or sale of business assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service before your information is transferred and becomes subject to a different privacy policy.

6.3 Legal Requirements

We may disclose your information if required to do so by law, regulation, court order, or government request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of ProposalForge, our users, or the public.

6.4 We Never Sell Your Data

ProposalForge does not sell, rent, or trade your personal information to third parties for their marketing or commercial purposes. This applies to California residents under the CCPA and all other users.

7. Data Retention

We retain personal data for as long as necessary to provide the Service and fulfill the purposes described in this policy. Specific retention periods:

Data TypeRetention Period
Account & profile dataDuration of account + 90 days after deletion request
Proposals & invoicesDuration of account + 90 days after deletion request
Client email addressesRetained within proposals/invoices per above
Billing records (Stripe IDs)As required by applicable tax law (typically 7 years)
Rate limit data (Upstash Redis)Automatically expires within 1 hour (sliding window)
Device fingerprint dataUntil account deletion or 2 years of account inactivity
Session tokensExpire per NextAuth session configuration (typically 30 days)
Anonymized analytics eventsAggregated; no personal data retained by Plausible

To request account deletion, email privacy@forgeproposals.com with the subject line "Account Deletion Request." We will process your request within thirty (30) days.

After an account deletion request is processed, we will delete or anonymize personal data within 90 days, except where retention is required by law (e.g., financial records) or necessary to resolve disputes or enforce agreements.

8. Data Security

We implement technical and organizational measures to protect your personal information:

  • All data transmitted between your browser and our servers is encrypted using TLS (HTTPS)
  • Database connections require SSL/TLS encryption
  • Payment data is processed directly by Stripe and never stored on our servers; Stripe is PCI DSS Level 1 certified
  • Device fingerprints and IP addresses are hashed (SHA-256) before storage — raw values are never retained
  • API keys and secrets are stored as environment variables, never in source code
  • Stripe webhook payloads are verified using cryptographic signatures before processing
  • HTTP security headers are configured (X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy)
  • API endpoints implement rate limiting to prevent abuse
  • Access to production systems is restricted to authorized personnel

Despite these measures, no method of transmission over the internet or electronic storage is 100% secure. In the event of a data breach that affects your personal information, we will notify you in accordance with applicable law. EU/EEA users will be notified within 72 hours of our becoming aware of a breach affecting their rights and freedoms, as required by GDPR.

9. International Data Transfers

ProposalForge is based in the United States. If you access the Service from outside the United States, your personal data will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your country.

Our primary service providers (Anthropic, Stripe, Resend, Google, Upstash, Neon) are U.S.-based companies. Where these transfers involve personal data of EEA/UK residents, we rely on:

  • The provider's participation in the EU-U.S. Data Privacy Framework (where applicable)
  • Standard Contractual Clauses (SCCs) adopted by the European Commission
  • Other adequacy decisions or transfer mechanisms approved under applicable law

For details on how we process data on your behalf, see our Data Processing Agreement. You may request a copy of the applicable transfer safeguards by contacting us at privacy@forgeproposals.com.

10. Your Privacy Rights

10.1 GDPR Rights (EEA / UK)

If you are located in the EEA or UK, you have the following rights under GDPR:

Right of Access

Request a copy of the personal data we hold about you

Right to Rectification

Correct inaccurate or incomplete personal data

Right to Erasure

Request deletion of your personal data (“right to be forgotten”)

Right to Data Portability

Receive your data in a machine-readable format

Right to Object

Object to processing based on legitimate interest (including automated reminders)

Right to Restrict Processing

Request that we limit how we use your data in certain circumstances

Right to Withdraw Consent

Withdraw any previously given consent (e.g., for marketing or review display) at any time

You also have the right to lodge a complaint with your local supervisory authority. In the EU, find your authority at edpb.europa.eu.

10.2 CCPA Rights (California Residents)

California residents have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Right to Know

Know what personal information we collect, use, share, or sell (we do not sell)

Right to Delete

Request deletion of your personal information

Right to Correct

Request correction of inaccurate personal information we hold about you

Right to Opt-Out of Sale/Sharing

We do not sell or share personal data for advertising purposes

Right to Non-Discrimination

We will not discriminate against you for exercising your CCPA rights

10.3 How to Exercise Your Rights

To exercise any of the above rights, contact us at privacy@forgeproposals.com with "Privacy Request" in the subject line. Please include your account email address so we can verify your identity.

We will respond to verified requests within thirty (30) calendar days. For complex requests, we may extend this period by an additional 60 days with prior notice.

11. Children's Privacy

The Service is intended for use by adults who are contractors, tradespeople, or business owners. We do not knowingly collect personal information from individuals under the age of 16.

If you believe we have inadvertently collected information from a minor, please contact us at privacy@forgeproposals.com and we will promptly delete such information.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other business reasons. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this page
  • Send an email notification to the address on your account
  • Display a notice within the Service for a reasonable period

Your continued use of the Service after the effective date of the updated policy constitutes your acceptance of the changes.

13. Contact & Data Protection

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our privacy team:

ProposalForge — Privacy Team

Florida, USA

Email: privacy@forgeproposals.com

EU/UK Representative & DPO

If you are located in the EU or UK and have concerns about how we handle your data, you may also contact your local data protection authority (see Section 10.1 for links).

© 2026 ProposalForge. Built for the trades.