How AssetForge Ltd. handles the information you give us when you browse, register, buy, enrol, or write to support.
Last updated 14 August 2026
Account. Name, email address, and a hashed password. We do not store the password in a form we can read back.
Orders and learning. What you bought or enrolled in, licence tier, payment status, entitlements, download grants, lesson progress and quiz results.
Messages. If you use Contact, we keep the name, email, topic and message so we can reply. The form says so: the address is for the reply and nothing else.
Newsletter. An email address, only if you subscribe. Confirmation goes through a separate step so a typo in the footer does not silently add someone.
Card payments are handled by Stripe. We receive a payment identifier, amount and status so we can match an order to an entitlement. We do not store card numbers.
Sign-in uses HTTP-only cookies. The refresh token lives in a cookie the JavaScript on the page cannot read. The short-lived access token is held in memory for that tab and is never written to localStorage. Replaying a rotated refresh token revokes the whole family, which is why the site coalesces concurrent refreshes rather than firing several at once.
To run your account, fulfil orders, grant and revoke access, stream courses, send the mail you asked for (verification, password reset, newsletter, support replies), and keep the service secure. We do not sell the list.
If error reporting is switched on for a deploy, crash reports may include the page URL and a technical stack so we can fix the break. They are not sent with your name or email attached by default.
Account, order and entitlement records stay for as long as the account does, because they are what prove you own a file. You can close an account from Settings or by writing to us. You can unsubscribe from the newsletter from the mail itself.
Questions or a request to see or delete what we hold: Contact or support@assetforge.com.