ForgeVZ — Privacy

Privacy Policy

Effective: September 22, 2026 — Version 1.0 — GDPR & CCPA Compliant
ForgeVZ is designed to be private by architecture. Script parsing, emulation, and storage occur locally in your browser. We do not sell your data. We minimize collection to what is necessary to provide authentication, billing, and support.

1. Data Controller

ForgeVZ is operated as a subscription software service. For privacy inquiries: privacy@forgevz.com. Our data processing is governed by this Policy and, where applicable, a Data Processing Addendum available upon request.

2. Information We Collect

CategoryExamplesPurpose & Legal Basis
AccountEmail, password hash (via Supabase Auth)Provide Service, contract
BillingStripe customer ID, subscription status, last 4 of card (via Stripe)Billing, contract, legitimate interest
UsageDownload logs (file name, timestamp, user ID), login timestampsSupport, security, legitimate interest
Local OnlyGPC scripts, slot data (localStorage `forgevz.slots.v1`, `forgevz.settings.v1`)Not collected by us; stored in your browser only
TechnicalIP address (via hosting logs), user agent (for OS detection for helper download)Security, fraud prevention, legitimate interest

We do not collect: Full payment card numbers (handled by Stripe), controller input data (processed locally), game data, or contents of your GPC scripts on our servers.

3. How We Use Information

4. Legal Bases (EEA/UK)

We process personal data under: (a) performance of contract (providing subscription service), (b) legitimate interests (security, support, fraud prevention), (c) compliance with legal obligations, and (d) consent where applicable (e.g., marketing, if opted in).

5. Sharing and Processors

We share data only with processors necessary to operate the Service:

We do not sell personal information. We do not share with advertisers.

6. Data Retention

7. Security

We implement industry-standard measures: encryption in transit (TLS), encryption at rest (Supabase), RLS policies on database, private buckets with signed URLs (5-minute expiry), minimal service-role key usage via server-side functions. No system is 100% secure; you are responsible for securing your device and credentials.

8. Your Rights

Depending on jurisdiction, you may have rights to access, correction, deletion, portability, restriction, objection, and to lodge a complaint with a supervisory authority. To exercise: email privacy@forgevz.com. We will respond within 30 days (GDPR) or 45 days (CCPA). For deletion, note that billing records may be retained as required by law.

California residents: We do not sell or share personal information as defined by CCPA/CPRA. You may opt out of any future sale/sharing via privacy@forgevz.com.

9. Cookies and Local Storage

The Service uses:

You may block cookies, but authentication will fail.

10. Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect data from children. If you believe a child provided data, contact us for deletion.

11. International Transfers

Data may be processed in the USA and other regions where our processors operate. We rely on Standard Contractual Clauses and processor DPA for EEA/UK transfers.

12. Third-Party Trademarks Disclaimer

References to Cronus Zen®, PlayStation®, DualSense®, etc., are for compatibility description only and do not imply affiliation. All trademarks are property of their respective owners. ForgeVZ is an independent product.

13. Changes

We will notify material changes via email or in-app notice 14 days prior. Continued use after effective date constitutes acceptance.

14. Contact

privacy@forgevz.com — ForgeVZ Privacy Team