Legal
Privacy Policy
Effective 30 August 2026 · Last updated 30 August 2026
FrameForge is point-of-sale software for custom picture-framing shops, operated by ForgeWorks. This policy explains what the software collects, who else can see it, how long it is kept, and how to make it stop. It describes what the system actually does today, not what we intend to build.
Two kinds of people are described here
The distinction matters throughout, because our obligations differ.
- Shops. The frame shop or gallery that subscribes to FrameForge, and its staff. We are the controller of that relationship — we decide what we collect about it.
- A shop's customers. The person who brings artwork in to be framed. We hold that information on the shop's behalf. The shop decides what to record; we process it to make the software work. If you are a framing customer and want your details changed or removed, ask the shop first — they can do it themselves, immediately. If you cannot reach them, write to us and we will.
What we collect from shops
- Account: your name, email address, and a bcrypt hash of your password. We never store the password itself.
- Shop details: business name, and optionally your phone, address, email and website — used on quotes and work tickets.
- What you enter: customers, orders, pricing, supplier catalogs, consignment records, and photographs you upload.
- Billing: handled by Stripe. We store your Stripe customer and subscription identifiers. We never see or store your card number.
- Support messages you send through the in-app feedback widget.
- Error reports. When something breaks, we record the technical failure along with your IP address so the bug can be traced. These are deleted after 90 days.
What a shop records about its customers
A shop can store a customer's name (required), plus phone, email, postal address and free-text notes. Orders hold what was framed, the prices, and any photographs taken of the piece at intake. Gallery shops can also record consigning artists and their artwork.
We do not sell this. We do not mine it. We do not use it to advertise to anyone, and we do not use it to train machine-learning models. FrameForge contains no AI or analytics services of any kind.
Texts and emails to a shop's customers
This is the part people most often want to control, so it is spelled out plainly.
- Texts are off unless the customer says yes. A staff member ticks a box recording that the customer agreed to be texted, and we store when that happened and how it was recorded. It is never on by default, and customers imported from other software arrive switched off, because their old system cannot tell us whether they ever agreed.
- Replying STOP works. It stops texts and emails, across every shop on FrameForge that has that number — not just the one that texted you. Reply START to undo it. A shop's staff cannot override your STOP by re-ticking the box; only you can reverse it.
- Every email to a customer carries a one-click unsubscribe link and the standard headers that put an unsubscribe button in most mail apps. It has the same effect as STOP.
- Transactional messages are the only ones we send to a shop's customers: their quote, and the message telling them their piece is ready. We never send marketing to a shop's customers, and neither shops nor we can use FrameForge to do so.
Photographs shared between shops
FrameForge lets a shop photograph the physical moulding and mat corner samples on its wall. Because supplier price lists never include pictures, these photos are pooled: when a shop photographs an item, other shops carrying that same supplier item number can see it, and that shop sees theirs in return.
- Only photographs of supplier samples are shared. No customer, order, pricing, or account information ever crosses between shops.
- Sharing is on by default and can be switched off in Settings. It is reciprocal: a shop that stops contributing also stops receiving.
- Photos are re-encoded when uploaded, which removes embedded camera metadata such as GPS location. A record of which shop contributed a photo is retained.
- Take care what is in frame. A photo of your sample wall may also capture handwriting, price stickers, or paperwork. If a photo needs to come out of the shared pool, email us and we will remove it.
Who else your data reaches
These are our sub-processors. Each receives only what its job requires.
| Service | What it handles |
|---|---|
| Cloudflare (R2, DNS, Turnstile) | Uploaded photographs; DNS; the anti-bot check on signup |
| Stripe | Subscription billing and customer deposit payments |
| Migadu | Email delivery for quotes, order updates and account mail |
| Twilio | Text messages, where a shop has enabled them |
| Our hosting provider | The servers and database running the application |
Two things load from other companies' networks on our pages, including the quote page a
framing customer opens from an email: a styling library from cdn.tailwindcss.com
and typefaces from fonts.googleapis.com. Those companies therefore see the
visitor's IP address and browser. We are working to serve both from our own servers so this
stops being true.
We will also disclose information if the law genuinely requires it. If FrameForge is ever sold, this data moves with it and you will be told before anything changes.
Cookies and what is stored in your browser
FrameForge sets no cookies and runs no advertising or analytics trackers. The
application stores a few values in your browser's local storage: your sign-in token, your name
and role for display, which product tours you have finished, and — if you arrived from a
printed QR code — a short campaign code such as card-front. Signing out clears the
sign-in values. Clearing site data clears everything.
Printed QR codes
Our postcards carry QR codes so we can tell which printed piece brought a shop to us. Scanning one records the campaign code, your browser's user-agent string, and the referring page. No IP address, no cookie, and no identifier for you personally. We can see that a code was scanned 40 times and produced 3 signups; we cannot see which scan was you. These records are deleted after 400 days.
How long things are kept
- Shop and customer records: for as long as the account exists, and for 30 days after it closes so an accidental cancellation can be undone.
- Error reports (including IP addresses): 90 days.
- QR scan records: 400 days.
- Backups: encrypted database snapshots are kept for 7 days, so deleted information can persist in a backup for up to a week after removal.
Your rights
Whatever jurisdiction you are in, these are available to everyone:
- Get a copy. Shops can export customers, orders, catalog and accounting data as CSV at any time from the app — including after a trial or subscription has ended. We never hold data hostage to a payment.
- Correct it. Everything a shop records is editable in the app.
- Erase it. A shop can erase a customer's personal details from within the app; the order history stays for the shop's books, with the personal information stripped out of it. To delete an entire shop account and everything in it, email us and we will do it within 30 days.
- Stop being contacted. Reply STOP to any text, or use the unsubscribe link in any email.
- Object or complain. Write to us. If you are in the UK or EU you may also complain to your data protection authority.
We will not charge you or degrade your service for exercising any of these.
How it is protected
Passwords are hashed with bcrypt. Traffic is encrypted with HTTPS. Every shop's records are isolated from every other shop's, and a request for another shop's data returns "not found" rather than revealing that the record exists. Uploads are size-limited, type-checked and re-encoded. Sign-in and signup are rate-limited.
Being straight with you about the limits: uploaded photographs are encrypted at rest by Cloudflare, but we do not add our own encryption on top of the database, and database backups are stored unencrypted on our own infrastructure. Sign-in tokens last 7 days and cannot be revoked individually before they expire — changing your password does not end sessions already signed in. No system is perfectly secure, and we would rather you knew the shape of ours than trusted a vague reassurance.
Children
FrameForge is business software and is not directed at children. We do not knowingly collect information from anyone under 16.
Where data is held
FrameForge is operated from the United States and data is stored there. If you use it from elsewhere, you are sending your information to the United States.
Changes
If we change this policy in a way that matters, we will email account holders before it takes effect rather than quietly changing the date at the top.
Contact
ForgeWorks — FrameForge
info@getframeforge.com
717-512-0270
Terms of Service · FrameForge · A ForgeWorks Company