Privacy Policy
Last updated: July 11, 2026
This policy explains what information ForgedHelix LLC (“ForgedHelix,” “we,” “us”) collects through the ForgedHelix website and Revenue Recovery service (the “Service”), how we use and protect it, and the choices you have. The Service is a business-to-business product; the information we handle is primarily business information about your company, plus contact details for the people who work with us.
1. Information we collect
Access requests. When you request access through our website, we collect what you submit: dispensary/business name, contact name, email address, phone number, point-of-sale system, approximate monthly revenue, and any message you include.
Account information. When an account is created, we collect your name, email address, and login credentials (passwords are handled by our authentication provider and are never visible to us in plain text).
Business data you upload. The core of the Service is the point-of-sale export data you choose to upload: products, sales, vendors, invoices, and discounts. Files are read in your browser and only the structured rows are sent to us — we do not retain your raw files.
Payment information.Payments are processed by Stripe. We never receive or store card numbers. We keep only the payment status, Stripe’s reference identifiers, and the amount paid.
Automatically collected. For security, we keep an activity log of significant account events (such as sign-ins, uploads, and report generation) that includes your IP address and browser user-agent, and we set the session cookies described in Section 4.
2. What we deliberately do not collect
- No analytics or tracking. The Service uses no advertising trackers, analytics scripts, or third-party marketing cookies.
- No sale or sharing of data for advertising. We do not sell personal information and do not share it for cross-context behavioral advertising.
- No patient or consumer personal data. The Service analyzes business inventory and sales data only. Our Terms of Service prohibit uploading patient information or customer personal data, and our data model has no place for it.
3. How we use information
- to review access requests and set up accounts;
- to provide the Service: run analyses, generate reports and recommendations, and show them in your portal;
- to process payments and maintain required financial records;
- to communicate with you about your account (activation links, password resets, service updates);
- to secure the Service, prevent abuse, and audit account activity;
- to comply with legal obligations.
4. Cookies
We set only strictly necessary first-party cookies — the signed session cookies that keep you logged in:
- fh_portal_session — client portal sign-in; expires after 30 days;
- fh_admin_session — internal admin console sign-in; expires after 7 days.
Neither cookie is used for tracking or advertising, and we set no third-party cookies.
5. Service providers
We use a small set of providers to run the Service. Each processes data only to provide their service to us:
- Vercel — application hosting;
- Supabase — database, file storage, and authentication;
- Stripe — payment processing;
- Resend — transactional email (such as activation links);
- Anthropic — AI processing used to help generate analysis and recommendation content from your business data.
Beyond these providers, we disclose information only if required by law or legal process, to protect the rights and safety of ForgedHelix or others, or as part of a merger, acquisition, or sale of assets (in which case this policy continues to apply to your information).
6. Data retention
We retain your account information and uploaded business data for as long as your account is active, so your analyses and reports remain available to you. Payment records are retained as required for financial and tax purposes. If you close your account or ask us to, we delete your account and uploaded business data within 30 days of a verified request, except for records we are legally required to keep.
7. Security
Data is encrypted in transit (HTTPS everywhere), sessions use signed, HTTP-only cookies, every customer’s data is isolated to their own account with server-side access controls, and account activity is logged for auditing. No system is perfectly secure, but the Service is built so that one customer can never see another customer’s data.
8. Your rights and choices
Email [email protected] to access, correct, export, or delete the information we hold about you or your business. We will verify the request and respond within 30 days. Depending on where you live, you may have additional rights under local law; we honor verified requests regardless of jurisdiction.
9. Not for individuals or children
The Service is for businesses and is not directed to individuals acting in a personal capacity or to anyone under 21. We do not knowingly collect information from children.
10. Changes to this policy
We may update this policy from time to time. If a change is material, we will notify account holders by email or through the Service before it takes effect. The “Last updated” date above reflects the current version.
11. Contact
Privacy questions or requests: ForgedHelix LLC · [email protected]