← Back to QAForgeHub

Privacy Policy

Draft — operational content, not attorney-reviewed. This describes what QAForgeHub actually does with your data during the private beta, in plain language. It is not a substitute for formal legal review, and should not be treated as a binding legal document before any paid public launch.

What we collect

Account details you provide (email, name, password — stored as a salted, irreversible hash, never in plain text), the organizations/projects/issues/Sprints/Planning Poker data you and your team create inside the product, and operational metadata needed to keep the service secure: session records, sign-in IP address (only when running behind a trusted proxy — see docs/SECURITY.md), user-agent string, and audit/security event logs.

If your organization subscribes to a paid plan, we also store subscription and billing metadata: which plan and billing interval you're on, subscription status, renewal date, and a reference id linking your organization to its record with our payment provider. We do not collect or store your payment card number, bank details, or full billing address ourselves — those are collected and held entirely by the payment provider described below.

What we don't do

No advertising, no analytics or tracking cookies, no selling your data to third parties. The only cookie QAForgeHub itself sets is the one that keeps you signed in (see Cookies and session storage, below).

Third-party service providers

A small number of third parties process data on QAForgeHub's behalf, strictly to operate the service — never for advertising or resold to anyone else:

  • Lemon Squeezy — our payment provider, for organizations on a paid plan. Lemon Squeezy acts as merchant of record: it collects and holds your payment details and billing address directly, and tells us only the subscription/billing metadata described above.
  • Hostinger — our hosting infrastructure provider, which stores the application's database and runs the application itself.
  • An SMTP email provider, configured by the operator, used solely to deliver transactional email you've triggered (verification, password reset, invitations) — never marketing email.

We haven't yet confirmed which of these providers, if any, process data outside your own region, or published a full cross-border-transfer statement — see "Sections requiring legal review" below.

Cookies and session storage

QAForgeHub sets exactly one cookie of its own: a session identifier that keeps you signed in, stored server-side as a hash and never used for tracking, advertising, or analytics. Some parts of the interface also use your browser's local storage for non-sensitive, per-device UI preferences (for example, your chosen theme) — never for anything that leaves your device.

Planning Poker vote privacy

Individual estimate votes are never shown to anyone — including the session facilitator — until the round is revealed. This is enforced on the server, not just hidden in the interface.

Your data, your control

From Account settings you can export a copy of your own data at any time, and request account deletion. Deleting your account removes your name and login credentials; content you created that's shared with teammates (issues, comments) is anonymized rather than deleted outright, so it doesn't corrupt your team's project history. See the Account settings page for the exact current behavior.

Data retention

QAForgeHub retains account, organization, project, issue, audit, billing-metadata, and related service data for as long as reasonably necessary to provide and secure the service, maintain legitimate business and operational records, comply with legal obligations, resolve disputes, prevent abuse, and maintain backups. You or an authorized organization representative may request deletion of eligible personal information through the privacy contact below. Some information may be retained where required or permitted by law, for fraud and security prevention, for legitimate recordkeeping, or temporarily in backups and disaster-recovery systems. QAForgeHub does not promise a fixed deletion timetable unless a specific retention period is separately published and operationally enforced.

Sections requiring legal review before a paid public launch

Data-subject rights under applicable regional law (e.g. GDPR/CCPA-style access, erasure, and portability requests), complete sub-processor disclosures, and cross-border transfer language have not been legally reviewed and are not represented as compliant with any specific framework. The data retention approach above reflects the operator's approved policy but, like the rest of this document, has not been legally reviewed.

Contact

QAForgeHub publishes one contact address, support@qaforgehub.com, for support, privacy, and security alike — use the subject line to route your message. For privacy questions or a request to access, correct, or delete your data, include "Privacy Request" in the subject. General questions about this policy can also go through Contact / Support in the Help Center, or the organization that invited you to QAForgeHub. To report a security or vulnerability concern, email support@qaforgehub.com with "Security Report" in the subject — see the Security page for what to include.