Privacy Policy
1. Who we are
ForthSource ("we", "us", "our") provides a Shopify app that helps merchants discover, evaluate, and manage overseas suppliers. This Privacy Policy describes how we collect, use, and protect personal data when you install or use the ForthSource app, our website at <a href="https://forthsource.io">forthsource.io</a>, or our app at <a href="https://app.forthsource.io">app.forthsource.io</a>.
2. Data we collect
We collect the following categories of data:
- <strong>Shop & account data</strong>: shop domain, shop owner name and email, plan, locale, currency, and Shopify access tokens needed to operate the app.
- <strong>Merchant configuration</strong>: search filters, favorites, RFQ templates, and other in-app preferences you create.
- <strong>Supplier data</strong>: publicly available supplier and product information that we collect from third-party directories on your behalf, plus any notes or files you upload (e.g. legal verification reports).
- <strong>Usage data</strong>: pages viewed, features used, search queries you run inside the app, and timestamps. Used for product analytics and abuse prevention.
- <strong>Billing data</strong>: plan, billing history, and invoice metadata. Card numbers are handled directly by Shopify Billing or Stripe and never reach our servers.
- <strong>Support & communications</strong>: messages you send us via email or live chat, and our replies.
- <strong>Technical data</strong>: IP address, user agent, request paths, and error logs, retained for security and debugging.
3. How we use data
- To deliver the supplier-discovery, scoring, and RFQ features you have requested.
- To operate, secure, debug, and improve the app.
- To bill you for paid plans and send transactional notifications.
- To respond to support requests.
- To detect and prevent abuse, fraud, and Shopify Terms of Service violations.
- To comply with legal obligations.
We do <strong>not</strong> sell personal data, and we do not use merchant or shopper data to train third-party AI models.
4. Legal bases for processing (GDPR)
- <strong>Contract</strong>: to provide the app you have installed.
- <strong>Legitimate interest</strong>: to secure the service, prevent abuse, and improve the product.
- <strong>Legal obligation</strong>: to meet tax, accounting, and lawful-request obligations.
- <strong>Consent</strong>: for non-essential cookies (such as live chat) and optional marketing email.
5. Sharing & sub-processors
We share personal data only with sub-processors that help us run the service. The full, current list — including each provider's purpose and processing region — is published at <a href="https://forthsource.io/sub-processors">forthsource.io/sub-processors</a>. Today this includes, at minimum:
- <strong>Shopify</strong> — app authentication, billing, and merchant identity (global).
- <strong>Replit</strong> — application hosting and Postgres database (United States, us-east).
- <strong>Stripe</strong> — payments for direct (non-Shopify) billing (US + EU).
- <strong>Resend</strong> — transactional email (United States).
- <strong>OpenAI</strong> — supplier scoring and AI assistance (United States).
- <strong>Crisp</strong> — in-app live chat (European Union).
We notify merchants by email at least 30 days before adding or removing a sub-processor that handles merchant personal data.
6. Where your data is stored
ForthSource hosts merchant data on Replit-managed infrastructure located in the United States (us-east region). This includes application servers, the primary Postgres database, and uploaded files such as legal verification reports and data exports. We do not maintain a replica in another region. Some sub-processors process data in their own regions as listed above.
7. Data retention
- <strong>Active shop data</strong>: kept while your app is installed.
- <strong>Uninstalled shops</strong>: shop, merchant, and search data are deleted within 30 days of uninstall, unless we are legally required to retain them (e.g. invoices kept for 7 years for tax purposes).
- <strong>Support emails</strong>: retained up to 24 months after the last interaction.
- <strong>Server & security logs</strong>: rotated within 90 days.
You can request earlier deletion at any time (see "Your rights" below).
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion ("right to be forgotten").
- Receive a portable copy of your data.
- Object to or restrict certain processing.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local data-protection authority.
These rights apply under the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and China's Personal Information Protection Law (PIPL). To exercise any right, email <a href="mailto:privacy@forthsource.io">privacy@forthsource.io</a> from the shop owner's address. We will respond within 30 days.
9. Cookies & tracking
ForthSource uses a small number of cookies and similar browser-storage technologies. We split them into two categories: <strong>essential</strong> (always on, required for the app to work) and <strong>functional</strong> (loaded only with your consent). We do not set advertising, marketing, cross-site tracking, or third-party analytics cookies.
9.1 Essential cookies
These are strictly necessary to deliver the service you have requested (signing you in, keeping you signed in, and protecting against abuse). They do not require consent under the EU ePrivacy Directive / GDPR, and the cookie banner does not gate them.
| Name | Set by | Purpose | Type | Retention |
|---|---|---|---|---|
session |
ForthSource (Flask) | Signed session cookie that keeps you logged in to the standalone app and stores short-lived flash messages and CSRF state. | First-party, HTTP cookie (HttpOnly, Secure, SameSite=Lax) | Session (cleared when you close the browser) or up to 31 days if "remember me" is selected. |
shopify_app_session / Shopify session token |
Shopify (when ForthSource is opened from your Shopify admin) | Authenticates the embedded app request and identifies the shop. Issued and verified by Shopify; ForthSource only reads the signed token. | First-party, short-lived JWT in request headers / cookie | Up to 24 hours per token; refreshed automatically by Shopify. |
forthsource_cookie_consent |
ForthSource | Remembers whether you accepted or rejected non-essential cookies, so we don't show the banner on every page. | First-party, browser <code>localStorage</code> entry (not a network cookie) | Persistent until you clear browser storage or change your choice from "Cookie settings". |
9.2 Functional cookies (consent required)
These are only loaded after you click <strong>Accept all</strong> in the cookie banner. If you reject them, the related feature is disabled but the rest of the app continues to work normally.
| Name / pattern | Vendor | Purpose | Type | Retention |
|---|---|---|---|---|
crisp-client/*, __cfruid (set on <code>client.crisp.chat</code>) |
Crisp IM SARL (European Union) — see <a href="https://crisp.chat/en/privacy/" target="_blank" rel="noopener">crisp.chat/privacy</a> | Powers the in-app live-chat widget: keeps a stable visitor ID across page loads so an ongoing conversation, unread badge, and operator replies survive navigation. | Third-party cookies + <code>localStorage</code> entries set by the Crisp script | Up to 6 months. After you withdraw consent we stop loading the Crisp script, but any cookies and <code>localStorage</code> entries Crisp already placed in your browser will remain until they expire or you clear them via your browser settings. |
9.3 Managing or withdrawing consent
You can change your choice at any time, in any of these ways:
- Click <strong>Cookie settings</strong> in the footer of any page (or any link marked <em>Cookie settings</em>) to re-open the consent banner and choose again.
- Click <strong>Reject non-essential</strong> in the banner to keep only the essential cookies above.
- Clear cookies and site data for <code>forthsource.io</code> / <code>app.forthsource.io</code> in your browser settings — the banner will reappear on your next visit.
<strong>Effect of withdrawing consent:</strong> the Crisp live-chat widget will no longer load and the chat bubble will not appear. You can still reach us by email at <a href="mailto:hello@forthsource.io">hello@forthsource.io</a>. Existing Crisp cookies already stored in your browser are not transmitted by us, but you can delete them from your browser's cookie settings. Withdrawing consent does not affect the lawfulness of any processing that took place before you withdrew it. Essential cookies cannot be turned off because the app cannot function without them.
10. Security
We use HTTPS everywhere, encrypt data at rest, scope database credentials per-environment, follow Shopify's session-token authentication for embedded-app requests, and enforce least-privilege access for our team. Suspected incidents can be reported to <a href="mailto:security@forthsource.io">security@forthsource.io</a>.
11. Children's data
ForthSource is a B2B tool and is not directed to children under 16. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to the shop owner at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact us
ForthSource — Privacy Team<br>Email: <a href="mailto:privacy@forthsource.io">privacy@forthsource.io</a><br>Support: <a href="mailto:hello@forthsource.io">hello@forthsource.io</a>