Privacy Policy
Last updated 2026-06-10 · Effective 2026-05-27
DETAILFORGE is operated by GLODUSK (“DETAILFORGE”, “we”, “us”, “our”). This Privacy Policy explains what personal information we collect, how we use and share it, how long we keep it, and the rights you have over it. We’re the data controller for personal information collected directly through our marketing site, sign-up flow, and the DETAILFORGE platform. Where a shop uses DETAILFORGE to handle their own customers’ information, the shop is the controller of that data and we’re a processor acting on the shop’s instructions.
1. Definitions
- Personal information — information that identifies or could reasonably be linked to an individual.
- Shop — a business with a DETAILFORGE account; the data controller for its own catalog, customer, and quote records.
- Customer — an end user who interacts with a shop’s embedded configurator or shared quote link.
- Service — the DETAILFORGE platform, including the marketing site, app, embedded surfaces, and APIs.
- Subprocessor — a third party we engage to process personal information on our behalf.
2. Information we collect
From shops (account holders)
- Account: email address, password hash (via Supabase Auth), workspace name, role.
- Business information you provide: shop name, address, phone, website, owner name, brand assets.
- Catalog content: services, packages, finishes, labor rates, pricing rules.
- Customer and quote records you create within your workspace.
- Billing: payment method tokenized by Stripe; we never see or store full card numbers.
From customers (people using a shop’s embed or share link)
- Name, email, and phone you type into a lead-capture form.
- Mobile number and SMS consent status, when you ask a shop to text you your quote.
- Vehicle selections, reference photos uploaded, and finishes chosen during a quote flow.
- Conversation content with the AI assistant (your typed prompts and the assistant’s replies).
Automatically
- Authentication cookies (Supabase) and an “active workspace” cookie (df_active_tenant) that tracks which shop your URL is scoped to.
- IP address and user-agent for every request, used for rate limiting, abuse detection, and security.
- Performance and error telemetry (page load timings, JavaScript exceptions) via Sentry — anonymous unless an error captures identifying context.
3. How we use your information
We process personal information for the following purposes, under the legal bases noted (relevant for visitors in the European Economic Area, United Kingdom, and Switzerland):
- Provide the Service — render configurators, compute quotes, route AI assistant traffic, send transactional emails. Legal basis: performance of a contract.
- Bill paying shops via Stripe. Legal basis: performance of a contract.
- Improve product quality — aggregate usage metrics without individual identification. Legal basis: legitimate interest.
- Security, fraud prevention, and abuse detection — rate limit, log suspicious activity, investigate incidents. Legal basis: legitimate interest.
- Legal compliance — tax records, statutory retention, response to lawful requests. Legal basis: legal obligation.
- Communications with shop accounts regarding billing, service changes, or security. Legal basis: legitimate interest / performance of a contract.
We do not sell personal information, we do not engage in cross-context behavioral advertising, and we do not use personal information for any purpose materially different from the ones above without further notice.
4. How we share information
We share personal information only with the categories below, and only to the extent necessary for the listed purpose.
Subprocessors
Third parties that process personal information on our behalf under contract:
- Supabase (US) — database, authentication, file storage.
- Vercel (US) — application hosting and edge networking.
- Cloudflare R2 (US) — vehicle assets, customer-uploaded reference photos, AI-generated images.
- Stripe (US) — payment processing for paid plans.
- Resend (US) — transactional email delivery (auth confirmations, job notifications, quote alerts).
- Twilio (US) — SMS delivery when a shop texts a quote link to a customer.
- Sentry (US) — error monitoring, when configured for the deployment.
- Anthropic (US) — Claude AI assistant for shop and customer conversations.
- Google (US) — Gemini for AI-generated images of the configured build.
- Upstash (US) — Redis for distributed rate limiting, when configured.
Other recipients
- Other shops or customers — only when a shop chooses to share a quote with a customer via a share link, or invites a teammate to its workspace.
- Law enforcement or regulators — when we’re legally required to disclose information, and only to the extent required.
- Successor entities — in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality and notification protections.
- Professional advisors — accountants, attorneys, auditors who are themselves under a duty of confidentiality.
5. AI processing
When you use the AI assistant or AI image-generation features, the relevant input — your typed prompt, current selections, vehicle metadata, and any reference photos you upload — is sent to the model provider for processing.
- Per current Anthropic and Google provider terms, inputs are not retained to train their general-purpose models.
- AI outputs are best-effort. They’re intended as preview and pricing guidance; the shop’s final pricing and work scope is what governs the engagement.
- We do not make decisions about you using solely automated processing that produces legal or similarly significant effects on you.
6. Cookies and similar technologies
We use a small number of strictly necessary cookies. We do not use tracking, advertising, or analytics cookies.
- Supabase auth cookies — keep you signed in across requests.
- df_active_tenant — remembers which shop URL you’re currently working in.
You can control cookies via your browser settings. Disabling our essential cookies will sign you out and break shop-scoped routes.
7. Text messaging (SMS) program
DETAILFORGE sends transactional SMS on behalf of the shops that use it. This section is our messaging program disclosure.
- Program — a shop uses DETAILFORGE to text you a link to the price quote you requested, along with occasional related transactional updates about that quote. We do not send marketing or promotional texts.
- How you opt in — you provide your mobile number to a shop (in person, over the phone, or through the shop’s online quote-request form) and agree to receive a text about your quote. The shop confirms your consent before any message is sent. Providing your number for this purpose is the only way the program is initiated; we never buy, rent, or import phone numbers.
- Message frequency — message frequency varies and depends on your interaction with the shop; typically a small number of messages per quote.
- Cost — message and data rates may apply, depending on your mobile carrier and plan.
- Help and opt out — reply HELP to any message for help, or STOP at any time to cancel. After you reply STOP you will receive one confirmation and no further messages. The opt-out is recorded immediately and applies to your number across all shops, not just one.
- What we collect — the mobile number you give the shop, your SMS consent status, and any STOP / START / HELP replies.
- How we use it — only to send the transactional quote-link texts you asked for and to honor opt-outs. We do not send marketing or promotional texts.
- Sharing — your mobile number is shared with our SMS carrier (Twilio, US) only to deliver the message. We do not sell or share mobile phone numbers or SMS consent information with third parties or affiliates for their marketing or promotional purposes.
8. Data retention
- Active accounts — data is retained for as long as the account is active.
- Closed accounts — shop content is removed within 30 days of account deletion, except where retention is required by tax, audit, or legal rules.
- Customer (lead) records inside a shop — retained as part of the shop’s own data. Deletion of an individual customer record by the shop propagates immediately to our systems.
- Billing records — retained for 7 years for tax and audit compliance.
- Backups — encrypted snapshots may persist for up to 90 days beyond a primary deletion, then are purged on schedule.
- Security logs — IP addresses and request metadata retained 90 days for abuse detection, then deleted or aggregated.
9. Your privacy rights
Rights available to all users (where applicable law applies)
- Access — sign in to view everything we have associated with your account.
- Correction — edit your account info, business profile, and catalog at any time from Settings → Workspace.
- Deletion — archive or delete your workspace from Settings → Workspace; we’ll remove your content within 30 days, subject to the retention rules above.
- Portability — shop catalogs, customer lists, quotes, and jobs can be exported from Settings → Workspace.
- Withdraw consent — where we rely on consent, you can withdraw it at any time without affecting prior processing.
Additional rights under GDPR / UK GDPR
If you’re in the EEA, United Kingdom, or Switzerland, you also have the right to:
- Restrict or object to processing where we rely on legitimate interest.
- Lodge a complaint with your local data protection supervisory authority.
Additional rights under CCPA / CPRA (California residents)
California residents have the right to:
- Know — request a copy of the personal information we’ve collected about you and the categories we’ve disclosed.
- Delete — request deletion of personal information, subject to legal exemptions.
- Correct — request correction of inaccurate personal information.
- Limit use of sensitive personal information — to the extent we collect any (we do not currently use sensitive personal information for inferring characteristics).
- Opt out of sale or sharing — we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.
- Non-discrimination — we will not deny service, charge different prices, or provide a different level of service because you exercised any right above.
To exercise any right, email hello@glodusk.com. We’ll respond within the timeframe required by applicable law (45 days for most CCPA requests, one month for most GDPR requests). We may need to verify your identity before fulfilling a request.
10. International data transfers
Our primary processing happens in the United States. Our subprocessors may operate globally. Where we transfer personal information out of the EEA, United Kingdom, or Switzerland to a country that does not have an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), or another lawful transfer mechanism, to protect your information.
11. Data security
We use TLS encryption in transit, encrypted database storage at rest, signed webhooks, per-shop row-level security in Postgres, and encrypted secrets management. Access to production systems is limited to personnel with a need-to-know basis and protected by strong authentication. We don’t currently claim a specific attestation such as SOC 2; work toward formal certification is part of the Enterprise track.
12. Data breach notification
If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we’ll notify the relevant supervisory authority and affected users without undue delay, in line with applicable law (within 72 hours under GDPR where required).
13. Children’s privacy
DETAILFORGE is a business-to-business product intended for commercial users. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child’s information has been provided to us, email hello@glodusk.com and we’ll delete it.
14. Changes to this policy
We’ll update this Policy when the service changes, the law changes, or our subprocessor list changes. Material changes are announced via email and an in-app banner at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.
15. Contact us
Privacy questions, access or deletion requests, or anything else related to this Policy: hello@glodusk.com. For general support, hello@glodusk.com.
