Privacy Policy
Summary: We collect only what we need to run NiftyForger: your email, your account and billing records, and the content you put in your workspace. We don't sell your data, show ads, or use analytics or advertising cookies. Some of our service providers are outside Australia, mainly in the United States. You can ask to access, correct, export or delete your data at contact@niftyforger.com.
- Who we are
- What we collect
- How and why we use it
- Data you store in your workspace
- Who we share it with
- Overseas transfers
- How long we keep it
- Security
- Your rights
- Cookies
- Age limit
- Complaints
- Changes to this policy
1. Who we are
This policy applies to the NiftyForger website and web application (the "Service"), provided by NiftyForger, operated by a sole trader based in Victoria, Australia ("NiftyForger", "we", "us"). We are responsible for the personal information described here. Under the EU and UK General Data Protection Regulation (GDPR), this makes us the "controller".
Contact us about privacy at contact@niftyforger.com or through our contact form. If you need our full legal identity, for example for a formal complaint or legal process, ask at that address and we will provide it.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where the GDPR or UK GDPR applies to you, we also meet their requirements.
2. What we collect
Information you give us
- Account details: your email address and password. We store your password only as a secure one-way hash, never in readable form.
- Team members: the email addresses of any users you invite to your workspace.
- Contact messages: your email address (optional if you're not signed in), subject and message when you use the contact form.
- Workspace content: the parts, categories, projects, suppliers, purchase orders, sales orders and other records you create (see section 4).
Information created when you use the Service
- Account records: when you signed up, when you last logged in, whether your email is verified, failed login attempts and temporary account lockouts, and which version of our Terms you accepted and when.
- Subscription records: your plan, subscription status, billing period dates, scheduled plan changes and cancellation dates.
- Emails we send you: a record of account emails (verification, password reset, activation) and whether they were delivered.
- Technical data: your IP address and basic request details, such as the page requested and your browser type. These are handled by our servers and security tools to deliver pages, limit abuse (rate limiting) and keep server logs. We do not store IP addresses in your account record.
- Error diagnostics: when something breaks, technical details of the error, such as the page, browser and error message, are sent to our error-monitoring provider. We don't send your name or email address with them.
Information from third parties
- Payments: our payment processor, Stripe, tells us whether a payment or subscription change succeeded and gives us customer and subscription identifiers. We never receive or store your full card details. Stripe collects those directly under its own privacy policy.
- Bot protection: Cloudflare Turnstile tells us whether a sign-up, login or password-reset attempt appears to come from a human.
3. How and why we use it
| Purpose | Information used | Legal basis (GDPR, where it applies) |
|---|---|---|
| Create and run your account, and provide the Service | Account details, workspace content, account records | Performing our contract with you |
| Take payments and manage subscriptions | Email, subscription records, Stripe identifiers | Performing our contract with you |
| Send service emails (verification, password reset, invitations, billing-related notices) | Email address | Performing our contract with you |
| Reply to your enquiries | Contact messages | Our legitimate interest in responding to people who contact us |
| Keep the Service secure and prevent abuse, fraud and spam | Technical data, failed login attempts, Turnstile results | Our legitimate interest in protecting the Service and its users |
| Find and fix errors and performance problems | Error diagnostics, technical data | Our legitimate interest in running a reliable Service |
| Keep financial records and meet legal obligations | Subscription and payment records | Compliance with legal obligations (for example tax law) |
We don't send marketing emails. If we ever do, we will ask for your consent first where the law requires it, including under the Spam Act 2003 (Cth), and every message will include a way to unsubscribe. We don't use your information for automated decisions that have legal or similarly significant effects on you.
4. Data you store in your workspace
Your workspace may contain personal information about other people, such as supplier contacts or customer details on sales orders. For that information, you (or your organisation) decide what is collected and why, and we process it only to provide the Service to you. You are responsible for having the right to store that information and for giving those people any notices the law requires. We do not use workspace content for any other purpose.
5. Who we share it with
We do not sell or rent personal information, and we don't share it for advertising. We share it only with the service providers below, and only as needed to run the Service. They may use it only to provide their services to us.
| Provider | What they do for us | Location |
|---|---|---|
| Fly.io | Application hosting | United States |
| Our managed database and cache providers (including Upstash) | Storing account and workspace data, rate-limiting counters and real-time messaging | United States |
| Cloudflare | Website delivery, network security and Turnstile bot protection | Global network (including the United States) |
| Stripe | Payment processing, subscriptions, invoices and the billing portal | United States and other countries |
| Google (Gmail / Google Workspace) | Sending service emails and receiving contact messages | United States and other countries |
| Sentry (Functional Software, Inc.) | Error and performance monitoring | United States |
We may also disclose information if the law requires it, to protect our rights or the safety of others, or to a buyer or successor if the Service is transferred. If the Service is transferred, this policy continues to apply to your information.
6. Overseas transfers
We are based in Australia, but most of our service providers store or process information outside Australia, mainly in the United States. Before disclosing information overseas, we take reasonable steps to make sure the recipient handles it consistently with the Australian Privacy Principles, as Australian Privacy Principle 8 requires.
If you are in the European Economic Area, the United Kingdom or Switzerland, your information is transferred to Australia and the United States. These transfers rely on an adequacy decision where one exists, or on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK equivalent) included in our providers' data processing terms. You can ask us for more information about these safeguards.
7. How long we keep it
- Account and workspace data: while your account is open. A workspace owner can delete their account from their profile at any time, which removes the account, its team members and all of the workspace's data straight away. If you ask us to close your account instead, we delete it within 30 days. In both cases we keep only what we must for legal reasons (below), and copies in backups are overwritten on our providers' normal backup cycles.
- Billing and transaction records: for at least 5 years after the transaction, as Australian tax law requires. Stripe also keeps payment records under its own legal obligations.
- Contact messages and email delivery records: for as long as we need them to respond to you and keep a record of our correspondence. We review them periodically and delete those we no longer need.
- Server logs and error diagnostics: for the limited periods our hosting and monitoring providers keep them.
8. Security
We protect personal information with measures that include:
- encryption in transit (HTTPS)
- hashed passwords and secure, HTTP-only session cookies
- protection against cross-site request forgery
- rate limiting, temporary lockout after repeated failed logins, and bot protection
- separation of each customer's workspace data
No system is perfectly secure. If a data breach is likely to cause you serious harm, we will notify you and the relevant regulators as the law requires.
9. Your rights
Subject to the law that applies to you, you can ask us to:
- access the personal information we hold about you
- correct information that is inaccurate, out of date or incomplete
- delete your information or close your account — a workspace owner can do this immediately in their profile
- export your information in a portable format
- object to or restrict our use of your information, including uses based on legitimate interests
You can change your password in your profile, and if you own a workspace you can delete your account and everything in it there too. For anything else, including changing your account email, email contact@niftyforger.com from the email address on your account. We may need to verify your identity. We aim to respond within 30 days and don't charge for reasonable requests.
If you are a team member in someone else's workspace, requests about that workspace's content may need to go to the workspace owner, and we may pass your request on to them.
Anonymity: you can browse our public pages and use the contact form without giving your name or email. To create an account, we need an email address.
10. Cookies
We use only cookies and browser storage that are strictly necessary to operate the Service or that remember choices you make in the app. We don't use analytics or advertising cookies. Details are in our Cookie Policy.
11. Age limit
The Service is for people aged 18 and over. We don't knowingly collect personal information from anyone under 18. If you believe someone under 18 has given us information, contact us and we will delete it.
12. Complaints
If you have a concern about how we handle your information, please contact us first at contact@niftyforger.com. We will try to resolve it within 30 days.
If you're not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC). If you are in the EEA or UK, you can also complain to your local data protection authority, for example the UK Information Commissioner's Office.
13. Changes to this policy
We may update this policy from time to time. The effective date at the top shows when it last changed. If we make significant changes, we will tell account holders by email or in the app before the changes take effect.