Legal

Privacy Policy

What QAForgeHub collects, how it is used and shared, the cookies it sets, how long data is kept, and how to reach us about your data.

Effective date:
Last updated:

1. Introduction

This Privacy Policy describes what QAForgeHub, available at qaforgehub.com (the "Service"), does with information. The Service is operated by DleetSoft ("we", "us"). It covers the information described below for visitors, account holders and members of organizations, and should be read together with our Terms of Service.

We have tried to describe only what the Service actually does today. Where we have not established a fact — for example, exactly where our providers process data — we say so instead of guessing.

2. Information you provide

You give us information when you create an account, accept an invitation, verify your email address, set up two-factor authentication, use the Service, or contact us. That includes:

  • your email address, your name and a password;
  • the organizations you create or join, and your role in each (Owner, Administrator, Project Manager, Developer, Tester or Viewer);
  • the content you and your team enter into the Service (see the next section);
  • anything you send us when you write to us for support.

Your name, email address and role are visible to other members of the organizations you belong to.

3. Organization, project and application content

The Service stores the content your organization creates in it, including projects, issues, comments, labels, backlogs and boards, sprints, milestones and roadmap items, Planning Poker sessions and estimate votes, and project reports. It also stores test results that a connected QAForge desktop application submits to a project, such as test and step names, error messages, the address of the page or endpoint tested, and browser and operating system details, together with the connected device's name.

This content belongs to your organization (see the Terms) and is visible to its members according to their roles. It can contain personal information about you or others if someone types it in, so please enter only what you are permitted to share. Planning Poker votes stay hidden from everyone, including the facilitator, until the round is revealed.

4. Authentication and session information

To sign you in and keep your account secure, the Service stores:

  • your password as a salted, irreversible hash — never the password itself — and, if you turn on two-factor authentication, your two-factor secret (encrypted by the application) and hashed recovery codes;
  • a record for each signed-in session: a hash of the session token (not the token itself), when it was created, last used and expires, your browser's user-agent string, and your IP address when the Service is running behind a trusted proxy that supplies it;
  • hashed, single-use tokens for email verification, password reset and invitations.

5. Technical and log information

To operate and protect the Service we keep operational records: audit events recording significant actions inside an organization (who did what and when), counters used to rate limit sensitive actions such as sign-in and password reset, and application and server logs. These can include identifiers such as your account, organization, IP address (when available as described above) and user-agent string. We have designed logging to avoid recording passwords, tokens and similar secrets.

6. Cookies and browser storage

QAForgeHub sets a small number of first-party cookies, all of them needed for the Service to function. We do not use advertising, analytics or tracking cookies, and the Service does not load third-party analytics or advertising scripts.

Cookies set by QAForgeHub
CookiePurposeLifetime
__Host-qfh_sessionKeeps you signed in. Only a hash of its value is stored on our side.Until your session ends or you log out
__Host-qfh_mfaCarries you between entering your password and entering your two-factor code.A few minutes
qfh_active_orgRemembers which of your organizations is currently selected. Your access is checked again on every request.Up to one year
qaforgehub_pending_invitationHolds an invitation token briefly so an invitation survives logging in.Up to 30 minutes

These cookies are HttpOnly (browser scripts cannot read them) and, in production, Secure. In development builds the two sign-in cookies have the same names without the __Host- prefix.

The interface also uses your browser's local storage for non-sensitive, per-device display preferences, such as your chosen theme, board density and view, and dashboard view. These stay on your device and are not sent to us.

If your organization subscribes to a paid plan, checkout and billing management take place on pages hosted by Lemon Squeezy, which sets its own cookies under its own policies.

7. How we use information

We use information to:

  • operate the Service for you and your organization — authenticate you, enforce roles and permissions, and store and show your organization's content;
  • keep the Service and accounts secure, and prevent abuse;
  • process subscriptions and enforce plan limits;
  • send the service emails described below;
  • respond to support and privacy requests;
  • meet legal obligations and keep reasonable business records.

We do not use your information for advertising.

8. Email and transactional communications

We send email only to operate the Service: email verification, password reset and password change notices, invitations, notices that two-factor authentication was turned on or off, and confirmation that an account was deleted. We do not send marketing email. Delivery is handled by an email delivery provider (see "Service providers"). Notifications shown in the application's notification bell are in-app only.

9. Billing information

The Free plan needs no payment details. If an organization subscribes to a paid plan, payment is handled by Lemon Squeezy, which acts as merchant of record and collects and holds your payment details and billing address directly. We do not collect or store your card number, bank details or full billing address.

We store subscription metadata needed to run the plan: which organization it belongs to, the plan and billing interval, subscription status, renewal and end dates, and Lemon Squeezy reference identifiers for the subscription, customer, product and variant. We also keep a record of the billing notifications (webhooks) Lemon Squeezy sends us. See the Refund Policy for refunds.

10. Service providers

A small number of providers process information on our behalf to run the Service:

  • Lemon Squeezy — payments and subscription billing for organizations on a paid plan, as described above.
  • Hostinger — hosting infrastructure. The application runs there and its database is stored there.
  • An email delivery (SMTP) provider — delivers the service emails described above.

We use these providers only to operate the Service. We do not share personal information with advertisers.

11. How information is shared

We share information only:

  • Within your organizations. Other members can see your name, email address, role and the content you add, according to their roles. Owners and Administrators manage membership, settings and billing.
  • With service providers listed above, as needed to run the Service.
  • When required or to protect the Service — for example to comply with the law or legal process, or to protect the rights, safety and security of users and the Service.

We do not sell personal information.

12. Data retention

QAForgeHub retains account, organization, project, issue, audit, billing-metadata and related service data for as long as reasonably necessary to provide and secure the service, maintain legitimate business and operational records, comply with legal obligations, resolve disputes, prevent abuse, and maintain backups. You or an authorized organization representative may request deletion of eligible personal information through the privacy contact below. Some information may be retained where required or permitted by law, for fraud and security prevention, for legitimate recordkeeping, or temporarily in backups and disaster-recovery systems. QAForgeHub does not promise a fixed deletion timetable unless a specific retention period is separately published and operationally enforced.

13. Your choices: access, export and deletion

From Account settings you can export a copy of your own data and delete your account. The export includes your account details, organization memberships, active sessions, and the issues you reported, comments you wrote and Planning Poker votes you cast. It deliberately leaves out credentials, secrets and other people's data.

Deleting your account requires your password (and a two-factor code if enabled), and you must first transfer ownership of, or otherwise resolve, any organization where you are the only Owner. Deleting removes your login credentials and two-factor setup, ends your sessions, removes your organization memberships, and replaces your name and email address on the account record with placeholders. Content you created that is shared with teammates, such as issues and comments, is kept so your team's project history stays intact, but it is no longer connected to your identity. We send a confirmation email when an account is deleted.

To ask us to access, correct or delete personal information in a way Account settings does not cover, contact us as described below. Organization content is controlled by the organization, so requests about it may be referred to its Owners or Administrators.

14. Security

We use measures such as hashed passwords, hashed session and reset tokens, optional two-factor authentication, HttpOnly cookies, HTTPS in production, role-based access with separation between organizations, and rate limiting of sensitive actions. See the Security page for more detail.

No service is perfectly secure, and we cannot guarantee the security of information. We do not hold security or privacy certifications, and we do not claim compliance with any particular regulatory framework. If you believe you have found a security problem, email support@qaforgehub.com with "Security Report" in the subject.

15. Children

The Service is intended for people who are old enough to enter into a binding contract and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will look into it.

16. International processing

Our service providers may process information in countries other than the one where you live. We have not published a list of the locations where they process data, and we do not make representations about cross-border transfer mechanisms.

17. Changes to this policy

We may update this Privacy Policy as the Service changes. When we do, we will post the updated policy on this page and change the "Last updated" date above.

18. Contact

QAForgeHub publishes one contact address, support@qaforgehub.com, for support, privacy and security alike — use the subject line to route your message. For privacy questions or a request to access, correct or delete your data, include "Privacy Request" in the subject. General questions can also go through Contact / Support in the Help Center, or to the organization that invited you to QAForgeHub.