AB
ABForgeExperimentation Platform
Legal

Privacy Policy

Last updated: 2026-05-13

Plain-English summary: We collect what we need to run the service, store it securely, and never sell it. We share data only with the processors required to make ABForge work (Stripe for billing, Cloudflare for hosting, transactional email providers). You can export or delete your data at any time.

1. What we collect

To create your account: name, email, password (hashed with argon2id), country. To process billing: card details and address required by Stripe (held by Stripe, not us). To run the service: every site, experiment, goal, funnel, and configuration you create through ABForge, plus the visitor data we collect on your behalf via the tracker.

Automatically collected: IP address, browser user agent, pages visited, timestamps. Used for security (rate limiting, fraud detection) and product analytics (which pages get used). Retained for 90 days unless tied to a specific audit-log event.

2. How we use it

To run the service. To send you important account, security, and billing notifications. To offer support when you ask. To compute pooled-data benchmarks — in aggregate only, never identifying you to other users.

We do not: sell your data, use it to train AI models, share visitor data across customers, or run third-party ad networks on the dashboard.

3. Who we share with

We do not have advertising partners. We do not run trackers from Facebook, Google Ads, or LinkedIn on the dashboard.

4. Where data is stored

Primary database: US-East (Virginia). Backups: encrypted at rest in a separate region. We're working on EU residency for European customers; contact privacy\.3dshawn.com if this is required for your business.

5. How long we keep it

Active account: as long as your account exists. Cancelled account: 90-day grace period for export, then purged. Transactional records (invoices, tax filings): 7 years per US tax law. Aggregated, anonymized analytics: indefinite (no longer tied to you).

6. Your rights

You can: export all your data (Settings → Data export), delete your account and trigger purge, opt out of pooled-data analytics, request a copy of every audit-log entry tied to your account. EU/UK users have additional GDPR rights (access, rectification, erasure, portability, restriction, objection) — email privacy\.3dshawn.com to exercise them.

7. Security

Encryption in transit (TLS 1.3) and at rest (AES-256). Password hashing with argon2id. Optional 2FA (TOTP). Audit log on every admin action. Role-based access on team accounts. Regular penetration testing. SOC 2 Type II audit underway for 2026.

8. Cookies

We use first-party session cookies to keep you signed in, remember your sidebar-collapsed preference, and prevent cross-site request forgery. We don't run third-party advertising cookies. The ABForge tracker on your sites uses a small first-party cookie to attribute A/B-test bucketing per visitor — this is cleared when the test ends.

9. Children

ABForge is not for users under 16. If you believe a child has created an account, email privacy\.3dshawn.com and we'll investigate within 7 days.

10. Contact

Privacy questions, data requests, GDPR requests: privacy\.3dshawn.com. Security disclosures: security\.3dshawn.com.

This Privacy Policy is a starting template. Before going live with paid customers (especially in the EU/UK), have it reviewed by a privacy attorney.