ForgeOps Privacy Policy. This page is ready

ForgeOps Privacy Policy

Last updated: July 26, 2026

1. Who operates ForgeOps

ForgeOps is operated by Mingfeng Yang, Hong Kong ("ForgeOps", "we", "us"). For privacy questions or requests, email [email protected].

2. Scope of this policy

This policy applies to the ForgeOps Shopify application and its creative-generation, review, and file-export features. ForgeOps currently operates as a free Beta.

3. Information we process

  • Shopify store identifiers, installation status, encrypted OAuth credentials, and security or request metadata needed to operate the app.
  • Product catalog information selected by the merchant, including product title, description, handle, status, price, variants, SKU, and product images.
  • Creative briefs, generated images and copy, quality checks, approval decisions, reviewer name, export manifests, and related run history.
  • Limited technical logs needed for reliability, abuse prevention, debugging, and security.

ForgeOps requests only Shopify's read_products scope. It does not request or ingest customer records, orders, payment details, or customer profiles.

4. How we use information

  • Authenticate the Shopify store and display its selected products.
  • Generate, review, retry, package, and download creative assets.
  • Enforce Beta usage limits and prevent duplicate jobs.
  • Maintain security, diagnose failures, and respond to support requests.
  • Comply with Shopify requirements and applicable law.

ForgeOps does not sell personal information and does not send generated assets to Meta or any other advertising platform.

5. Service providers and transfers

We disclose information only as needed to Shopify and to infrastructure providers that support hosting, network delivery, security, backups, and creative generation. These providers process information on our behalf. Because these services may operate in multiple countries, information may be processed outside the merchant's jurisdiction, subject to applicable legal safeguards.

6. Cookies and local storage

ForgeOps uses short-lived, secure cookies to protect the Shopify OAuth flow and verify the initiating browser. The embedded app may store the reviewer name in the browser's local storage to simplify later reviews. We do not use this data for advertising.

7. Retention and deletion

When the app is uninstalled, ForgeOps deletes the stored Shopify access credentials and the gateway's store-to-run ownership records. Generated assets, product snapshots, and operational backups are retained only as needed to provide the Beta, handle support and security issues, and meet legal obligations. Merchants can request deletion at any time; verified requests are handled without undue delay and ordinarily within 30 days.

8. Security

We use HTTPS, encrypted Shopify credentials, restricted service access, signed Shopify requests, least-privilege Shopify scopes, and operational monitoring. No system can be guaranteed completely secure, and merchants should contact us promptly if they suspect unauthorized access.

9. Your choices and rights

Depending on applicable law, merchants and individuals may request access, correction, deletion, restriction, portability, or objection concerning their information. Email [email protected] with the Shopify store domain and the nature of the request. We may verify the requester's authority before acting.

10. Changes

We may update this policy when the Beta, service providers, or legal requirements change. The current version and effective date will remain available at this URL.


ForgeOps is operated by Mingfeng Yang, Hong Kong. Contact: [email protected]