Legal

Privacy Policy

Last updated: 25 June 2026

This policy explains what personal data NetForge collects, why we collect it, and your rights under UK GDPR. NetForge is operated as a sole trader based in the United Kingdom.

1. Who We Are

NetForge ("we", "us", "our") is an online network engineering training platform available at netforgens.com. For data protection queries, contact us at support@netforgens.com.

2. What Data We Collect

Account data — when you create an account or sign in, we collect your email address. If you sign in with Google, we also receive your display name and profile photo via Google OAuth. We store your email and display name in our database (Supabase). We never store passwords in plaintext — password authentication is handled securely by Supabase.

Payment data — if you purchase a Pro or Bundle plan, your payment is processed by Stripe. We never see or store your card details. We receive a record of your purchase status (paid/not paid) from Stripe.

Usage data — we store which labs you have completed in your browser's local storage. This data does not leave your device unless you are signed in, in which case progress may be associated with your account.

Technical data — standard web server logs may record your IP address, browser type, and pages visited. These are retained for security purposes only.

3. Why We Use Your Data

  • To create and maintain your account
  • To verify your Pro/Bundle purchase and grant access to premium content
  • To remember your progress through labs
  • To respond to support requests
  • To detect and prevent fraud or abuse

Our legal basis for processing is contract (to deliver the service you signed up for) and legitimate interests (platform security and fraud prevention).

4. Third-Party Services

  • Google OAuth — used for sign-in if you choose the "Continue with Google" option. Governed by Google's Privacy Policy.
  • Supabase — our database and authentication backend, hosted in the EU. Data processed under a Data Processing Agreement.
  • Stripe — payment processor. Your card data goes directly to Stripe and is never seen by us. Stripe is PCI-DSS certified.
  • Fasthosts — UK-based web hosting for our static site files.

We do not sell, rent, or share your personal data with advertisers or other third parties.

5. Cookies

We use minimal cookies. Your theme preference and lab progress are stored in localStorage on your device — not transmitted to our servers. Supabase sets an authentication session cookie when you sign in.

We do not use advertising cookies or third-party tracking.

6. Data Retention

We retain your account data for as long as your account is active. If you request deletion, we will remove your personal data from our systems within 30 days, except where we are legally required to retain records (e.g., payment records for HMRC purposes, retained for 6 years).

7. Your Rights (UK GDPR)

Under UK GDPR you have the right to:

  • Access — request a copy of the data we hold about you
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interests

To exercise any right, email support@netforgens.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

8. Security

We use HTTPS for all data in transit. Authentication is handled by Supabase and Google, both of which employ industry-standard security practices. We do not store passwords.

9. Changes to This Policy

We may update this policy from time to time. The date at the top of this page reflects the most recent revision. Continued use of the service after changes constitutes acceptance of the updated policy.

10. Contact

For any privacy-related queries: support@netforgens.com