PipeForge
← Back to home

Privacy Policy

Effective date: April 1, 2026 · Last updated: April 1, 2026

1. Who We Are

PipeForge ("we", "us", "our") operates the data pipeline automation platform available at https://www.pipeforge.net. We are the data controller for personal data collected through this platform.

Questions about this Privacy Policy or your personal data should be directed to: privacy@pipeforge.net

2. What Data We Collect

We collect the following categories of personal data:

2.1 Account and Identity Data

  • Full name and email address (provided at registration)
  • Hashed password (we never store passwords in plain text)
  • Account preferences and settings

2.2 Billing and Transaction Data

  • Subscription plan and billing history
  • Payment method details are handled exclusively by Paddle (our payment processor) — we do not store card numbers or banking details
  • Paddle customer and subscription identifiers

2.3 Usage and Technical Data

  • Pipeline configurations, prompts, and generated code
  • Pipeline execution logs and run history
  • Connector types connected (not the underlying credentials in plain text)
  • Feature usage patterns and session metadata
  • IP address, browser type, and device information
  • Timestamps of login, pipeline creation, and execution events

2.4 Connector Credentials

When you add data connectors (e.g. Shopify, Snowflake, PostgreSQL), you provide API keys and credentials. These are encrypted at rest using AES-256 encryption and are only decrypted at runtime to execute your pipelines. We do not read, share, or use your connector credentials for any purpose other than executing the pipelines you explicitly trigger.

2.5 Data You Process Through Pipelines

Your pipelines may extract, transform, and load data from your own systems (e.g. your Shopify orders, your database records). We act as a data processor for this data — it belongs to you. We process it only as instructed by your pipeline configurations and do not analyse, sell, or share it.

3. How We Use Your Data

We use personal data for the following purposes and legal bases:

PurposeLegal Basis
Providing and operating the ServiceContract performance
Processing payments and managing subscriptionsContract performance
Sending transactional emails (welcome, alerts, receipts)Contract performance
Enforcing usage limits and plan restrictionsContract performance
Improving and developing new featuresLegitimate interests
Security monitoring and fraud preventionLegitimate interests
Complying with legal obligationsLegal obligation
Sending product update emails (opted-in users only)Consent

We do not sell your personal data to third parties. We do not use your data to train AI models without your explicit consent.

4. Third-Party Services We Use

We share data with the following trusted third parties who process data on our behalf:

ProviderPurposeData Shared
PaddlePayment processing & tax complianceName, email, subscription details
Anthropic (Claude AI)AI pipeline generationYour pipeline prompts
ResendTransactional emailsName, email address
RenderCloud infrastructure & hostingAll data (processed in their data centres)
VercelFrontend hostingIP address, browser metadata

All third-party processors are contractually bound to process data only as instructed and to maintain appropriate security standards.

5. AI and Your Prompts

When you describe a pipeline in natural language, your prompt is sent to Anthropic's Claude API to generate the pipeline configuration and code. Anthropic's privacy policy governs how they handle API inputs. We do not send any of your Customer Data (pipeline execution data, connector credentials, or third-party records) to Anthropic — only the natural language prompt you type.

We do not use your prompts or generated pipelines to train our own AI models.

6. Data Retention

We retain personal data for as long as your account is active and as necessary to provide the Service. Specific retention periods:

  • Account data: Retained until account deletion, then purged within 30 days
  • Pipeline execution logs: Retained for 90 days, then automatically deleted
  • Billing records: Retained for 7 years to comply with financial regulations
  • Connector credentials: Deleted immediately upon connector removal or account deletion
  • Audit logs: Retained for 12 months for security purposes

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data. We honour these rights for all users regardless of jurisdiction:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Portability: Receive your data in a structured, machine-readable format
  • Restriction: Ask us to restrict processing of your data in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Where processing is based on consent, withdraw it at any time

To exercise any of these rights, email privacy@pipeforge.net. We will respond within 30 days. We may need to verify your identity before processing requests.

8. GDPR — European Users

If you are located in the European Economic Area (EEA) or United Kingdom, you have rights under the General Data Protection Regulation (GDPR) and UK GDPR respectively. The legal bases for our processing are set out in Section 3.

Where we transfer personal data outside the EEA/UK (e.g. to US-based processors such as Anthropic, Render, and Vercel), we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) or adequacy decisions where applicable.

You have the right to lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk.

9. CCPA — California Users

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale. We do not sell personal information. To exercise your rights, contact privacy@pipeforge.net.

10. Cookies and Tracking

We use a minimal set of cookies necessary to operate the Service:

  • Authentication: Session tokens stored in localStorage to keep you logged in
  • Preferences: UI settings stored locally in your browser

We do not use third-party advertising cookies, tracking pixels, or behavioural analytics tools. We do not use Google Analytics or similar surveillance-based analytics platforms.

11. Security

We implement the following security measures to protect your data:

  • All data in transit is encrypted using TLS 1.2 or higher
  • Connector credentials are encrypted at rest using AES-256 (Fernet)
  • Passwords are hashed using bcrypt with a minimum cost factor of 12
  • Pipeline execution runs in an isolated sandbox environment
  • Access to production systems is restricted to authorised personnel only
  • JWT tokens expire after 24 hours and must be refreshed

In the event of a data breach that affects your personal data, we will notify you and applicable regulators within 72 hours of becoming aware of it, where required by law.

12. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us at privacy@pipeforge.net and we will take steps to delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting a notice in the dashboard at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the changes.

14. Governing Law

This Privacy Policy is governed by the laws of England and Wales. Any disputes arising in connection with this policy shall be subject to the exclusive jurisdiction of the courts of England and Wales, except where applicable consumer protection law in your country of residence provides otherwise.

15. Contact Us

For any privacy-related questions, data subject requests, or to report a concern:

PipeForge — Privacy Team
Email: privacy@pipeforge.net
Website: https://www.pipeforge.net
Response time: within 30 days

Terms of ServiceBack to PipeForge