← Back to ForgeFox

Privacy Policy

Last updated: September 2026

ForgeFox ("we", "us", "our") is operated by ForgeFox Ltd, a company registered in England and Wales (company no. 17271363). Registered office: 124 City Road, London, EC1V 2NX. We are committed to protecting your personal data and complying with the UK GDPR and the Data Protection Act 2018.

1. Who this policy covers

This policy applies to:

2. Data we collect

Operators: Name, email address, business name, payment information (processed by Stripe — we never store card details), business address, and usage data relating to your ForgeFox account.

End customers (collected on behalf of operators): Name, email address, phone number, booking history, signed waiver documents — which may include special category / health data (for example, medical conditions or contraindications declared in a fitness or activity waiver, where the operator collects it) — and any notes added by the operator. This data belongs to the operator — ForgeFox processes it as a data processor on their behalf. The operator, as data controller, is responsible for the lawful basis and for obtaining any consent required, including explicit consent for health data under Article 9 UK GDPR, under our Data Processing Agreement with them. The operator’s own privacy notice explains how they use your information; if you have a question about it, or want to use your data protection rights, contact the operator first.

Health and intake information (end customers): Health, medical and similar information is special category data. It is only collected if the operator asks for it (for example in a waiver or intake form), and only with your explicit consent, which you give when you fill in and sign that form. ForgeFox stores it for the operator and does not use it for anything else. You can withdraw your consent by contacting the operator. Signed waivers are kept for a limited time after your booking so the operator can deal with any legal claim (see section 5).

Payment cards (end customers): Card payments are taken by the operator's own payment provider (Stripe or Square) on the provider's secure payment page. Neither ForgeFox nor the operator ever sees or stores your card number, expiry date or security code. If an operator offers a deposit or a saved-card option and you choose it, the payment provider keeps your card securely so the operator can charge a no-show or late-cancellation fee under the policy you agree to when you book. ForgeFox stores only the provider's reference to the saved card, not the card itself, and deletes that reference when your data is erased. A saved card is only charged by the operator, without you being present, for the fees and in the circumstances explained to you when you booked — never for anything else. You're sent a receipt for any such charge, and you can ask the operator (or us) to remove a saved card at any time.

Booking text messages (end customers): If you give a mobile number when you book, the operator may send you text messages about that booking, such as a confirmation and a reminder. These are service messages, not marketing. You can turn them off by unticking the text-message option on the booking form (where the operator’s form shows one), or at any time by asking the operator. Operators may only send you marketing texts if you have agreed to receive them.

Attendance strikes and booking pauses (members): Some operators set attendance rules for members, for example recording a “strike” for a missed or very late booking and pausing online booking for a few days after a set number of strikes. This is the operator’s choice and their rules; the operator should tell you what they are before you join. ForgeFox records the strikes and applies any pause on the operator’s instruction. A strike recorded automatically (for example when a late arrival is marked as a no-show by the system) does not count until someone at the business has checked and confirmed it. You will get an email when a strike is confirmed and when a pause starts, saying how long it lasts and how to contest it. If you think a strike or pause is wrong, contact the operator, who can review and remove it.

Operator team members: If the operator gives their staff their own ForgeFox logins, those staff may see and update customer information, but only as the operator allows and on the operator’s instructions. The operator is responsible for who on their team has access.

3. How we use your data

We do not sell your data. We do not use your data for advertising. We do not share your data with third parties except where necessary to provide the service (Stripe, Square, SumUp and PayPal for payments, Supabase for database hosting, Vercel for application hosting, Brevo for email and SMS delivery, Twilio for SMS messaging, Cloudflare Stream for video hosting, PostHog for product analytics, and Upstash for rate-limiting, which is not currently in use). The full list of companies that process customer data for us is in Annex 3 of our Data Processing Agreement.

4. Data storage and security

Data is stored on Supabase infrastructure hosted in the European Union. Each operator's data is isolated using row-level security — no operator can access another's data. Data is encrypted at rest and in transit.

5. Data retention

Operators: We keep your account data while you subscribe. When your account closes, your booking page goes offline straight away and we keep your data for 30 days, in case you change your mind. After 30 days we permanently delete or anonymise it. We keep financial records (payments, invoices and your acceptance of our terms) for 6 years from the end of the financial year they relate to, for HMRC and company-law purposes, with customers’ names and contact details removed.

If you cancel your subscription, you can export all your customer data at any time before deletion. We will also send you an automatic data export on cancellation.

End customers: The operator decides how long to keep their customers’ information. ForgeFox deletes or anonymises a customer’s personal data when the operator tells us to (for example, when they act on a request from you to erase your data), and in any case 30 days after the operator’s account closes. Payment amounts linked to your bookings are kept, without your name or contact details, as part of the operator’s financial records.

Signed waivers (end customers): A signed waiver, including any health information in it, is kept for 6 years after the date of the booking it relates to or, if it was signed for someone under 18, until that person turns 21, whichever is later. It is then deleted. We keep it for that time even if the operator’s account closes or you ask for your other data to be erased, because the operator may need it to deal with a legal claim. It is stored securely and used for nothing else.

6. Your rights

Under UK GDPR you have the right to:

To exercise any of these rights, email us at info@forgefox.uk. We will respond within 30 days.

7. Cookies

The forgefox.uk website sets no cookies and stores nothing on your device; we count visits anonymously without cookies (no IP address is stored). The ForgeFox app and booking pages use only strictly necessary cookies and browser storage — to keep you signed in, to complete a sign-in, and to remember a choice you made, such as dismissing a prompt. We do not use advertising or tracking cookies. No analytics scripts are loaded on this website or on the pages your customers see (booking, gift card, member and similar pages). PostHog product analytics runs only inside the operator app, in memory, and sets no cookies. See our Cookie Policy for the full list.

8. Contact

For any privacy-related questions:
Email: info@forgefox.uk
ForgeFox Ltd, 124 City Road, London, EC1V 2NX, United Kingdom

9. Changes to this policy

We may update this policy from time to time. We will notify active subscribers of material changes by email. The date at the top of this page shows when it was last updated.