Skip to main content
The Forgeby HustleForge

Privacy Policy

Effective: July 20, 2026 · Last updated: September 6, 2026

HustleForge LLC (“HustleForge,” “we,” “us,” or “our”) operates The Forge, a managed business operating environment that helps organizations connect information, coordinate workflows, monitor operations, and authorize actions across their businesses.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you:

This policy also explains the distinction between information HustleForge collects for its own business purposes and information we process on behalf of Forge customers. If you are located in the European Economic Area, the United Kingdom, or Switzerland, Section 14 describes additional rights available to you under the EU/UK General Data Protection Regulation (“GDPR”).

1. Scope and Processing Roles

Information HustleForge collects directly

HustleForge acts as the business or controller for information collected directly from website visitors, prospective customers, account administrators, billing contacts, and people communicating with us.

Information processed for Forge customers

Forge customers may upload, enter, import, synchronize, or generate information concerning their own customers, leads, employees, contractors, vendors, business partners, and other individuals.

For that information, the Forge customer generally determines:

HustleForge processes this information to operate The Forge according to the customer’s instructions, subscription plan, Forge Plan, order form, statement of work, and applicable data-processing agreement.

Individuals seeking to exercise rights concerning information controlled by a Forge customer should ordinarily contact that customer first. We will reasonably assist customers with verified requests where required.

2. Information We Collect

Depending on how The Forge is used, we may collect the following categories of information.

Contact and identity information

Account and access information

We do not store passwords in plaintext.

Business and professional information

Customer-controlled operational information

Customers may choose to enter, import, or synchronize information such as:

The exact information processed depends on the customer’s configured scope.

Integration information

When a customer authorizes an integration, we may process:

Credential material is not included in customer data exports.

Communications and content

We may collect communications sent through or associated with The Forge, including:

The Forge may connect communication events from third-party providers to the relevant operational record. The exact content available depends on the customer’s configuration and provider authorization.

Payment and transaction information

Payments are processed by third-party payment providers such as Stripe. HustleForge may receive:

HustleForge does not store full payment-card numbers.

Device, network, and usage information

We may automatically collect:

On Forge websites, behavioral analytics (page views, clicks, scroll depth, dwell time, and campaign attribution) are collected only with your consent — see Section 8 for how this works. Within the Forge platform, usage information is collected under the customer’s service agreement.

Free-text customer content is excluded from platform error telemetry where technically supported.

Derived and platform-generated information

The Forge may generate:

Derived information may depend on records supplied by a customer or received from connected systems.

Sensitive and regulated information

The Forge is not configured by default to receive:

We process such information only when the specific scope is documented in writing, the customer expressly authorizes it, appropriate controls are available, and any legally required agreement has been completed.

Customers must not enter regulated or highly sensitive information into The Forge unless HustleForge has approved that use in writing.

3. Sources of Information

We may collect information from:

4. How We Use Information

We use personal information to:

We do not use identifiable Customer Data to train a generalized artificial-intelligence model for use outside that customer’s Forge environment unless the customer has expressly opted in through a separate written agreement.

5. Automation, Recommendations, and Human Review

The Forge may use rules, software automation, analytics, or artificial intelligence to:

The Forge is designed to augment customer decision-making, not to replace the customer’s legal or business authority.

Unless separately agreed in writing, The Forge is not intended to make a final decision concerning employment, credit, housing, healthcare, insurance, education, or another legally significant matter without meaningful human review.

Customers are responsible for reviewing recommendations and determining whether an automated or prepared action is appropriate for their organization.

6. How We Disclose Information

We may disclose information to the following categories of recipients.

Service providers and contractors

We use providers that support:

These providers may process information only for the services they perform for us and are subject to contractual confidentiality or data-protection obligations where appropriate. A current list of subprocessors is available at /subprocessors.

Customer-authorized third-party systems

When a customer activates an integration, The Forge may send information to or receive information from that provider according to the customer’s approved configuration.

The customer controls whether a connection is established and may revoke supported connections. The third party’s own privacy policy and service terms govern its independent handling of information.

A customer’s authorized users

Information may be available to users according to permissions established by the customer, including business, legal-entity, location, department, and role restrictions.

Professional advisers

We may disclose information to attorneys, accountants, auditors, insurers, or consultants when reasonably necessary to operate and protect the business.

Legal and safety disclosures

We may disclose information when we reasonably believe it is required to:

Business transactions

Information may be disclosed as part of a proposed or completed merger, financing, acquisition, reorganization, sale of assets, or similar transaction. Where appropriate, the receiving party will be required to use the information consistently with this policy or provide notice of a materially different practice.

7. Sale and Sharing of Personal Information

HustleForge does not sell personal information.

HustleForge does not share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act.

We do not sell or share Customer Data and do not use it for advertising unrelated to operating The Forge.

We do not use Google Analytics, Meta Pixel, or any third-party advertising or cross-site tracking technology. Every analytics signal we collect is first-party, stored in our own infrastructure, and gated behind the consent described in Section 8.

8. Cookies and Similar Technologies

We use a cookie banner with equal “Accept” and “Reject” options because most of the technologies below are not “strictly necessary” and legally require your opt-in consent before they run. You can change your choice at any time via the Cookie Settings link in the footer of every page.

Strictly necessary (always active — no consent required):

Analytics (only set if you click “Accept”):

Rejecting or ignoring the banner means none of the analytics items above are set, and no behavioral data is sent to our analytics storage. Site functionality (browsing, the onboarding form, checkout) works fully either way.

Platform account cookies:

When you sign in to a Forge account, additional cookies are used for session authentication, security, and platform operation. These are essential to the service you have requested and do not require separate consent.

Most browsers also let you block or delete cookies directly in their settings; doing so may require you to make the cookie choice again on your next visit. Disabling essential cookies may prevent account authentication or other platform functions from working.

Global Privacy Control. Some browsers and browser extensions let you send a Global Privacy Control (GPC) signal announcing an opt-out preference automatically, without visiting each site individually. Because analytics on Forge websites are opt-in — set only after you affirmatively click “Accept” on the cookie banner described above, never by default — a visitor who has not clicked Accept is already in the same state a GPC opt-out is meant to produce: no analytics cookies set, no behavioral data sent to our analytics storage. We treat an incoming GPC signal as a valid opt-out preference: when your browser sends one, we honor it by not presenting the cookie banner and treating your visit as declined, exactly as if you had clicked “Reject.” You can still change your choice at any time using the Cookie Settings link in the footer.

9. Call Recording and Transcription

Some Forge customers turn on the AI voice receptionist feature, which answers, places, and handles telephone calls on that customer’s behalf. When this feature is active for a business you are calling or being called by, the call may be recorded and transcribed.

What may be recorded or transcribed. Calls handled by the AI receptionist may have their audio recorded and converted to a text transcript, together with call metadata (phone numbers, timestamps, duration, and outcome such as completed, missed, or voicemail) and structured details captured during the call. This processing is performed by Vapi, listed in our Subprocessor Register, along with Twilio for call handling.

AI identity disclosure. Forge customers using the AI receptionist feature are responsible for disclosing to callers, at the start of the call, that they are speaking with an automated or AI-assisted system rather than a human, where required by applicable law or reasonable expectation.

Consent to recording.Forge customers are responsible for obtaining any consent to call recording required in their jurisdiction before enabling this feature, and for configuring the feature (including any recording announcement) consistently with that requirement. In “two-party” or “all-party” consent states and countries (for example, California), all parties to a call generally must consent to recording before it begins — it is the customer’s responsibility, not HustleForge’s, to configure the feature so that requirement is met for the jurisdictions in which they operate.

Do-not-record pathway. A caller may ask, at any point in the call, not to be recorded or to speak with a human instead. The Forge customer is responsible for configuring their receptionist to honor that request; callers who reach a Forge customer and wish to exercise this option should say so directly on the call, or contact that business through a non-recorded channel.

Retention.Retention of call recordings and transcripts is configurable by the Forge customer and governed by that customer’s account settings and the applicable subprocessor terms. HustleForge does not itself set a fixed retention period for this content; questions about how long a specific recording or transcript is kept should be directed to the business that operated the call, or to us at contact@hustleforge.tech if you are unable to reach that business.

See also our Subprocessor Register and Trust Center for more on the providers and controls involved in this feature.

10. Data Retention

We retain information only for as long as reasonably necessary for the purpose for which it was collected, the customer’s configured retention rules, contractual requirements, security needs, dispute resolution, and legal obligations.

Typical retention practices include:

The Forge currently provides a seven-day cancellation grace period during account offboarding before permanent deletion begins. After that period, Customer Data is deleted in a dependency-safe order, subject to legal retention requirements and temporary backup retention.

Backup copies may remain for a limited period until overwritten through the applicable provider’s normal backup cycle. Backups are maintained for disaster recovery and are not guaranteed to support individual record restoration.

11. Customer Data Ownership, Export, and Deletion

Customer-supplied data remains owned and controlled by the customer organization.

Authorized users may export supported Customer Data according to their permissions. Full-organization exports require appropriate owner authority and additional authentication. Export scope and format may vary by record type.

Exports exclude:

Customers should export information they require before account termination.

Deletion may be delayed or limited where information must be retained to:

12. Security

HustleForge maintains administrative, technical, and organizational safeguards designed to protect information, including:

Security responsibilities are shared. Customers are responsible for:

No electronic system is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or disruption will never occur.

Security vulnerabilities may be reported to security@hustleforge.tech.

13. Privacy Rights and Requests

Depending on your location and applicable law, you may have the right to:

To submit a request, submit a privacy request using our form, or email contact@hustleforge.tech with the subject line “Privacy Request.”

We may need to verify your identity and authority before acting on a request. Verification may include confirming information associated with your account or organization.

An authorized agent may submit a request where permitted by law. We may require proof that the agent is authorized to act for the individual.

Where information is controlled by a Forge customer, we may direct the request to that customer or assist the customer with its response.

We will not unlawfully discriminate against an individual for exercising a privacy right. EU/UK/EEA residents have additional rights and response-time guarantees described in Section 14 below.

14. GDPR — Rights for EU, UK & EEA Residents

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the GDPR (and the UK GDPR) gives you rights over your personal data in addition to those in Section 13, and requires us to identify the legal basis for each way we use it.

Legal basis for processing:

Your rights include the right to:

To exercise any GDPR right, email contact@hustleforge.tech with “GDPR Request” in the subject line. We will respond within 30 days as required by Art. 12(3).

International data transfers. HustleForge LLC is based in the United States. Our infrastructure providers may process data in the United States or other countries outside the EEA/UK. Each maintains its own GDPR compliance program and data processing terms for such transfers (see our Subprocessor Register for current providers and their privacy policies). By using our site and accepting analytics cookies where applicable, you acknowledge this processing may occur outside your home jurisdiction.

15. California Privacy Notice

See also our standalone California Notice at Collection for a shorter, collection-point summary of the categories below.

Where the California Consumer Privacy Act applies, California residents may have rights to:

During the preceding 12 months, HustleForge may have collected the categories described in Section 2 from the sources described in Section 3, used them for the purposes described in Section 4, and disclosed them to the recipients described in Section 6.

HustleForge has not sold personal information or shared personal information for cross-context behavioral advertising during the preceding 12 months.

HustleForge does not knowingly sell or share the personal information of individuals under 16.

Sensitive personal information is used only to provide, secure, administer, and support the requested service, unless a different use is separately disclosed and lawfully authorized.

Where recognized and applicable, HustleForge will process valid opt-out preference signals, including the Global Privacy Control (GPC) signal described in Section 8.

16. Children and Information Concerning Minors

The Forge website and customer accounts are intended for businesses and authorized business users, not for children to create accounts independently.

A Forge customer operating in education, childcare, religious services, or another field involving minors may submit information concerning minors only when:

The Forge is not intended to collect information directly from children under 13 without legally valid authorization.

17. International Processing

HustleForge operates from the United States. Information may be processed in the United States or in other locations where approved service providers operate.

Where required, we use appropriate contractual or legal mechanisms for cross-border processing.

18. Third-Party Services

The Forge may contain links to or integrations with third-party services. HustleForge does not control those providers’ independent privacy practices.

Customers should review the privacy terms of every third-party provider they authorize.

The Forge does not replace the customer’s responsibility to manage agreements, permissions, retention settings, and user access within connected third-party systems.

18A. Google User Data (Google Calendar Connection)

The Forge offers an optional Google Calendar connection. When an authorized user of a customer workspace connects a Google account, The Forge requests a single, read-only Google permission: https://www.googleapis.com/auth/calendar.readonly. This section explains how The Forge accesses, uses, stores, and shares the Google user data obtained through that permission.

What we access. Upcoming calendar events on the connected account (event title, start and end time, and the calendar they belong to) and the basic account identifier Google returns to confirm the connection. We do not access Gmail, Drive, Contacts, or any other Google service through this connection.

How we use it.Solely to display the connected account’s upcoming events inside that customer’s Forge workspace, beside the work, tasks, and appointments already recorded there, so the customer can see their schedule in one place. The Forge does not create, modify, or delete Google Calendar events through this connection, and Google user data is not used to develop, improve, or train generalized artificial-intelligence or machine-learning models.

How we store it. The OAuth tokens Google issues are encrypted at rest and scoped to the customer workspace that authorized them. A short-lived cache of upcoming events is held so the workspace can render them without re-querying Google on every page view. No other copy of Google Calendar data is retained.

How we share it. We do not sell, rent, or share Google user data with third parties, advertisers, or data brokers, and we do not transfer it to anyone other than the processors strictly necessary to host and secure The Forge (see Section 6). It is never used for advertising or shared with other Forge customers.

Disconnecting and deletion.An authorized user can disconnect Google Calendar at any time from the workspace’s Access Panel. Disconnecting revokes the token with Google and deletes the stored tokens and cached events from The Forge. Access can also be removed from the Google account’s own security settings at myaccount.google.com/permissions.

The Forge’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

19. Changes to This Policy

We may update this Privacy Policy as The Forge, our providers, or applicable requirements change.

The updated policy will display a revised “Last updated” date. We will provide additional notice through email, the platform, or another reasonable method when a change materially affects how we use personal information. You can review or change your cookie choice at any time using the Cookie Settings link in the footer, regardless of when this policy was last updated.

20. Contact Us

Questions, concerns, and privacy requests may be directed to:

HustleForge LLC

Email: contact@hustleforge.tech

Security reports: security@hustleforge.tech

Mailing address: 2290 Cheim Blvd, Marysville, CA 95901