Back

Fortune Forged

Privacy Policy

Last updated: July 30, 2026

This Privacy Policy describes how Fortune Forged ("Fortune Forged," "we," "us," "our") handles information when you use our customer relationship management platform, order tools, customer portal, and related websites and services (collectively, the "Service"), including fortuneforged.space.

This Policy applies to Authorized Users (staff and contractors with CRM accounts) and Portal Users (customers who open a limited order link we provide). It should be read together with our End User Agreement.

1. Who is responsible for your data

Fortune Forged operates the Service for its custom wheel business. For most customer and order information entered into the CRM, Fortune Forged is the business that decides why and how that information is used ("controller" for those purposes).

Third-party providers that host or process the Service (listed below) act as processors on our instructions, except where they require you to accept their own terms directly (for example, when you connect Meta, Stripe, or QuickBooks).

2. Information we collect

Depending on how you use the Service, we may collect:

Account and profile

  • Name, email address, role, and workspace membership
  • Login credentials (passwords are handled by our auth provider; we do not store plain-text passwords)
  • Preferences such as theme and workspace selection

CRM and business content

  • Customer and lead information (names, usernames, contact details, conversation history, order details, invoices, payments, notes, and files your team uploads)
  • Manufacturer and production messages, including WhatsApp-related metadata you connect
  • Audit and activity logs (who changed records and when)

Integrations you enable

If a workspace owner connects integrations, we receive and store only what is needed to run them, for example:

  • Meta / Instagram / WhatsApp: tokens and IDs to receive and send messages
  • Stripe: payment keys and webhook events for checkout
  • QuickBooks Online: OAuth tokens and invoice identifiers; invoice balances may be read from QuickBooks when displaying invoices
  • AI providers: API keys and content your team sends for analysis (per your configuration)

Integration secrets are stored in our database and used only on the server. They are not shown again in the browser after save.

Technical and usage data

  • IP address, browser type, device information, and request logs
  • Cookies and similar technologies for login sessions and preferences
  • Error and performance data from our hosting provider

3. How we use information

We use information to:

  • Provide, secure, and maintain the Service
  • Authenticate users and enforce roles and permissions
  • Sync data with integrations you configure
  • Send operational emails (invites, password reset, ownership transfer)
  • Improve reliability, fix bugs, and prevent abuse
  • Comply with law and respond to lawful requests

We do not sell your personal information. We do not use CRM customer lists for unrelated third-party marketing.

4. How we share information

We may share information with:

  • Service providers that help us run the Service (e.g., hosting, database, email delivery), under contracts that limit their use of data
  • Integration partners you connect (Meta, Stripe, Intuit QuickBooks, AI vendors), under their policies and your configuration
  • Other Authorized Users in your workspace, according to permissions set by the owner
  • Portal Users, limited to what we display on their order portal link
  • Legal and safety when required by law or to protect rights, safety, and security
  • Business transfers in connection with a merger, acquisition, or asset sale, with notice where required

5. Where data is stored

Data is stored using cloud infrastructure (including Supabase and Vercel). Servers may be located in the United States or other countries where our providers operate. By using the Service, you acknowledge that information may be processed in those locations.

6. Retention

We keep information for as long as your workspace needs the Service, as required for legal or accounting obligations, or as needed to resolve disputes. Specifically:

  • Messages, conversations, and AI analyses: retained while the workspace is active, and deleted within 30 days of a valid deletion request.
  • Orders, invoices, payments, and refunds: retained for 7 years to meet tax, accounting, and dispute-resolution obligations. When a deletion request applies to these records, we remove the personal details and keep the financial entry.
  • Integration access tokens: deleted when the integration is disconnected, or when Meta notifies us that a business has removed our app.
  • Encrypted backups: roll off automatically within 35 days, so deleted data can persist in backups for that period.
  • Audit and security logs: retained up to 24 months for abuse prevention and incident investigation.

7. Security

We use access controls, encrypted connections (HTTPS), owner-only secret management, and database row-level security that blocks direct client access to integration secrets. Access tokens and API keys — including Meta and WhatsApp access tokens — are encrypted at rest with AES-256-GCM and are only decrypted on the server at the moment they are used. They are never returned to the browser after being saved. Inbound webhooks from Meta are rejected unless they carry a validX-Hub-Signature-256 signature. No method of transmission or storage is 100% secure; you are responsible for protecting your password and devices.

8. Your choices and rights

Depending on where you live, you may have rights to:

  • Access, correct, or delete personal information we hold about you
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent
  • Receive a portable copy of your data

Authorized Users should contact their workspace owner first. Portal Users should contact Fortune Forged using the contact details below. We will respond within a reasonable time and as required by applicable law.

9. Meta platform data and how to delete it

When a workspace owner connects Instagram or a WhatsApp Business Account, we receive data from Meta: message contents and timestamps, the sender's Meta-scoped user ID, profile name and username, WhatsApp Business Account and phone number identifiers, and access tokens. We use it only to deliver the messaging and CRM features the workspace enabled. We do not sell it, use it for advertising, or transfer it to data brokers.

You can have that data deleted in either of these ways:

Deletion removes conversations, individual messages, and AI analyses, and strips your name and contact details from any remaining record. Invoices and payment records are kept without your personal details where tax law requires it, as described in section 6.

10. California residents

If California law applies, you may have additional rights under the CCPA/CPRA, including knowing what categories of personal information we collect and requesting deletion or correction. We do not sell or share personal information for cross-context behavioral advertising as defined by California law.

11. Children

The Service is not directed to children under 18. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.

12. Third-party links and services

The Service links to or integrates with third-party sites and APIs. Their privacy practices are governed by their own policies, not this one.

13. Changes to this Policy

We may update this Policy by posting a new version at this URL and updating the "Last updated" date. Material changes may be communicated through the Service or by email. Continued use after changes take effect means you accept the updated Policy.

14. Contact

For privacy questions, access requests, or deletion requests, contact Fortune Forged at fortuneforgedwheels@gmail.com or by phone at +1 (760) 998-8686. We acknowledge requests within 5 business days and complete them within 30 days.

Authorized Users may also contact their workspace owner, who can action most requests directly from the CRM.