Privacy policy.
Operated by Waelas Ltd · last updated September 2026
Waelas Ltd processes personal data when you use Forge. This page explains what we collect, why we collect it, and how to control it. Plain English. No tricks.
1. Who we are
Forge is a calendar and scheduling product operated by Waelas Ltd, a company registered in England and Wales (Company No. 16397759) with registered office at 71–75 Shelton Street, London WC2H 9JQ. We are the data controller for your Forge account and for how we run the service.
If you booked with, or are a client of, someone who uses Forge: that person or business decides how your details are used, and is the controller of them. We process them on their behalf, under our Data Processing Agreement with them. Their own privacy notice, if they have linked one, is shown under their booking form; for anything about how they use your details, ask them first.
2. What we collect
- Account data: your email address, name, password (stored only as a salted hash — we never hold the password itself), and account creation date.
- Profile data: anything you choose to add to your public booking page — booking link slug, photo, biographical text, timezone.
- Calendar data: when you connect a calendar — Google, Microsoft 365 or Outlook, or iCloud and other CalDAV servers — we store the address of the connected mailbox and, encrypted, the credentials that let us reach it: the access and refresh tokens the provider issues, or for iCloud the app-specific password you generate. We then keep a copy of the events in the calendars you sync, so your Forge calendar renders instantly and your booking page never offers a time you are already busy.
- What that copy contains, precisely: for Google and Microsoft, the event title, description, location, start and end times, the name, email address and RSVP of every attendee, who organised it, any video-call link, whether it repeats, and a link back to the event at the provider. For iCloud and other CalDAV calendars, the title, description, location and times. This is more than free/busy, and calendar entries can be revealing, so it is worth saying plainly. The copy is also synced to your own browser and kept there while you use the app, so the calendar redraws without waiting on us; disconnecting the calendar removes it from both places.
- What we write back: the events you authorise through Forge. A booking is written to every calendar account you have set to write mode, and it carries your booker’s name in the title and their name and email address in the description — so whichever providers you have connected receive them.
- Booking data: when someone books a meeting with you, we store their name, email, the event type they booked, the time, and any optional message they include.
- Technical data: server logs (IP address, user agent, request paths) for security and debugging, plus error reports sent to Sentry when something goes wrong, with personal data redacted where reasonable.
Google user data — Limited Use
Forge’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practice: we sync the events from the Google calendars you connect — including their titles, descriptions, locations, attendees and organisers, as set out above — so that your calendar renders and your booking page does not offer a time you are already busy, and we write the events you authorise through Forge. That is the whole of it. We do not use Google Calendar data for advertising, we do not sell it, we do not pass it to our AI drafting features, and we do not share it with anyone beyond the infrastructure providers listed below that store and process it on our instructions. Nobody at Waelas Ltd reads it, except where you ask us to while we help with a support request, where we have to investigate a security problem, or where the law requires it.
3. Why we collect it
- To provide the service: account, profile, calendar, and booking data are processed under contract (UK GDPR Article 6(1)(b)) — we cannot run Forge without them.
- To secure and improve the service: technical data is processed under legitimate interest (UK GDPR Article 6(1)(f)) for security monitoring and bug fixing.
- To send transactional email: booking confirmations, password resets, and account notifications are processed under contract.
We do not run marketing email, retargeting, or profile advertising. We do not sell data. Ever.
4. Who else receives your data
Two different things belong under this heading, and running them together would misdescribe both. Some companies handle your data because we asked them to. Others receive it because you connected them yourself.
4.1 Companies that process data on our instructions
Forge relies on a small set of companies to run. Each of these processes your data on our instructions, under an agreement with us.
| Company | Purpose | Region |
|---|---|---|
| Neon, LLC (a Databricks company) | Postgres database, hosted in AWS London | UK (London) |
| Fly.io, Inc. | Application hosting, job queue, rate limiting | Apps in London; account data US |
| Tigris Data, Inc. | File storage: profile photos, gallery images, logos, brand fonts, booking-page backgrounds and videos, photos poll voters add, and private attachments you store on client records. Public images on your booking page load from Tigris in your visitors’ browsers | Global |
| Plus Five Five, Inc. (Resend) | Sending email: booking and account emails, and the few marketing emails you can unsubscribe from | US |
| Anthropic Ireland, Limited | AI-drafted replies and summaries | US |
| Stripe Payments Europe, Limited | Payments and subscription billing (see note below) | US / global |
| Functional Software (Sentry) | Error monitoring | US |
| Porkbun LLC | Domain DNS, support email forwarding | US |
| Slack Technologies Limited | Passing feedback you send us (the in-app feedback form and the beta survey) to our team, with your name and email | US / global |
On the AI drafting: Forge can draft replies and short summaries for you — an invoice chase, a follow-up to an enquiry, a weekly digest. To do that it sends the relevant record (an enquiry message, a booking, an invoice) to Anthropic. Anything written this way that would go to someone else is a draft: you see it and approve it, and nothing is sent on your behalf without you reading it first. The one exception is your own weekly digest, where the summary is written for you and emailed only to you. Anthropic’s commercial terms state that data sent through their API is not used to train their models. Your connected calendar is never part of any of this — see the Limited Use section above.
And on the command bar: when you press ⌘K and type what you want in your own words rather than picking a command from the list, that phrase goes to Anthropic so Forge can work out which screen or action you meant — the phrase and today’s date, and nothing else from your account.
Stripe is not a straightforward processor, and it would be misleading to leave it in the list without saying so. It processes on our instructions when it services your subscription, but it also acts on its own account for fraud prevention, anti-money-laundering checks and its banking relationships, which we neither direct nor control.
Most of the companies above put a data processing agreement in place automatically as part of their standard terms, and those are in force. Three are not there yet, and we would rather say so than imply otherwise: we are completing the paperwork with Fly.io and Sentry, and moving the forwarding of email sent to support@forge.page away from Porkbun, which does not offer such an agreement at all. Until that move is done, please don’t send anything sensitive to that address.
On browser notifications: if you turn on push notifications, each alert (the event name, the booker’s name and the time) travels through the push service your own browser uses, such as Google’s, Mozilla’s or Apple’s. It is encrypted so that only your browser can read it.
We will give 14 days notice before adding a new company to this list.
4.2 Calendars and apps you connect
These are not our subprocessors. You connect them yourself, under an account agreement you already hold with the provider, and you can disconnect them at any time. Each acts as its own controller for the data it holds, so they are listed here rather than in the table above.
| Provider | What reaches them | Where they are |
|---|---|---|
| Google LLC | Google Calendar sync and Google Meet links. We read your events and write bookings back, including the booker’s name and email address. If you sign in with Google, Google tells us your name, email address and profile photo. | US |
| Microsoft Corporation | Microsoft 365 / Outlook calendar sync and Teams meetings, through the Microsoft Graph API. We read your events and write bookings back, including the booker’s name and email address. | US; if you sign in with a work or school account, your organisation’s Microsoft tenant — which may be in the UK |
| Apple Distribution International Limited (Hollyhill Industrial Estate, Hollyhill, Cork, Ireland) | iCloud Calendar over CalDAV. We connect with an app-specific password you generate in your own Apple Account and can revoke at any time. Bookings written to iCloud carry the booker’s name and email address. | Ireland (the Apple company UK and EEA users contract with; iCloud in the US is provided by Apple Inc., and Apple stores iCloud data globally) |
| Any other CalDAV server you nominate — self-hosted, workplace, or a provider such as Fastmail | The same events and bookings. We have no relationship with whoever runs it, and cannot tell you where it is located or what safeguards apply — that is between you and them. | Determined by you |
| Notion Labs, Inc. | If you connect Notion, each booking’s event, time, and the booker’s name and email are added to the Notion database you choose. | US |
| Webhook and automation addresses you add — for example a Zapier, Make or Slack webhook | Booking details, including the booker’s name and email, sent to the address you entered. Whoever runs it is your choice and your relationship. | Determined by you |
| The video host of an intro video you embed — YouTube, Vimeo or Loom | Nothing until a visitor presses play. The video’s player then loads from that company, which receives the visitor’s IP address and browser details and may set its own cookies. | US |
Why these are separate. When you connect a calendar you authorise the provider directly. They do not process on our instructions, we cannot instruct or audit them, and — in Microsoft’s case — their developer terms state in terms that nothing in them creates a processor–subprocessor relationship with us. With iCloud we have no agreement with Apple of any kind: your iCloud calendar is your own service, and we simply hold a password you issued us. If you sign in to Microsoft with a work or school account, the calendar belongs to your organisation, your organisation is its controller, and its agreement with Microsoft governs what happens to it — we are not party to that and cannot vary it.
Taking Microsoft access away. You can disconnect a Microsoft calendar inside Forge whenever you like. You can also revoke Forge’s access at Microsoft’s own end at any time, without going through us: for a personal Microsoft account at account.live.com/consent/Manage, and for a work or school account at myapps.microsoft.com.
5. How long we keep it
- Account data: until you delete your account, plus 30 days for backup retention.
- Calendar OAuth tokens: until you disconnect your calendar or delete your account.
- The copy of your calendar events: kept on a rolling window while the calendar is connected, and deleted when you disconnect it or delete your account.
- Booking records: 24 months after the booking date, or until you delete your account, whichever comes first.
- Server logs: 30 days.
- Sentry error reports: 90 days.
- Marketing unsubscribes: if you unsubscribe from our marketing emails, we keep your email address on a do-not-email list, even after you delete your account, so we never email you marketing again by mistake. It holds your address and nothing else; email support@forge.page to have it removed.
6. Your rights
You can:
- Access the personal data we hold about you — email us and we will put a copy together. There is no self-serve button for this yet. (Forge does have a CSV export under Reports, but that is a business report of your bookings, invoices, leads and clients, not a copy of everything we hold about you.)
- Correct anything inaccurate (most data is editable directly from your account)
- Delete your account and everything associated with it — go to Settings → Profile and use “Delete my account”. It erases everything straight away rather than within 30 days, and it cannot be undone. If you own a team, hand it to another member or delete the team first. You can still email us instead and we will do it for you.
- Object to processing where we rely on legitimate interest
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk
To exercise any right, email support@forge.page.
7. International transfers
Several of the companies in 4.1 are based in the United States, or process data there — the Region column says which. Those transfers are covered by the EU-US Data Privacy Framework and its UK Extension, or by Standard Contractual Clauses, whichever that company’s standard terms provide. The safeguard sits in our agreement with them. We do not rely on your consent for any of it, and using Forge is not treated as consenting to it.
The providers in 4.2 are different, and cannot be covered the same way: we have no agreement with them in which to put a safeguard. You connect them, so a transfer to them travels under the account agreement you already hold with that provider. The company we name for iCloud, Apple Distribution International Limited, is in Ireland rather than the United States, so that leg is not a transfer out of the UK at all — though Apple stores iCloud data globally, under your Apple Account terms rather than ours.
The calendar providers operate globally, and this matters more than it might sound: when Forge writes a booking to your Google, Microsoft or iCloud calendar, your booker’s name and email address go to that provider along with it. So does the copy of your own calendar we sync back. Both travel under the account agreement you already hold with them.
8. Cookies
Forge does not use tracking, analytics or advertising cookies, and does not record your sessions. Everything it stores in your browser is there to make the service work or to remember a choice you made:
- your sign-in session, and a short-lived cache of it;
- a flag that tells our homepage you are signed in, so it can offer “Open Forge”;
- short-lived security cookies while you connect a calendar or confirm your age at sign-up;
- your monthly/annual choice on the pricing page, and your recent ⌘K commands;
- a draft of a form you are filling in, kept only in that browser tab so a page reload does not lose it.
These are strictly necessary or remember something you asked for, so there is no cookie banner. If a host has embedded a YouTube, Vimeo or Loom video on their booking page, that company’s player — and any cookies it sets — loads only when you press play.
9. Changes to this policy
If we make material changes, we will email registered users at least 14 days before they take effect. Minor or clarifying changes will be reflected here with an updated date.
10. Contact
Waelas Ltd (Data Controller)71–75 Shelton Street, London WC2H 9JQ
support@forge.page