Legal
Privacy Policy
What QAForgeHub collects, how it is used and shared, the cookies it sets, how long data is kept, and how to reach us about your data.
- Effective date:
- Last updated:
1. Introduction
This Privacy Policy describes what QAForgeHub, available at qaforgehub.com (the "Service"), does with information. The Service is operated by DleetSoft ("we", "us"). It covers the information described below for visitors, account holders and members of organizations, and should be read together with our Terms of Service.
We have tried to describe only what the Service actually does today. Where we have not established a fact — for example, exactly where our providers process data — we say so instead of guessing.
2. Information you provide
You give us information when you create an account, accept an invitation, verify your email address, set up two-factor authentication, use the Service, or contact us. That includes:
- your email address, your name and a password;
- the organizations you create or join, and your role in each (Owner, Administrator, Project Manager, Developer, Tester or Viewer);
- the content you and your team enter into the Service (see the next section);
- anything you send us when you write to us for support.
Your name, email address and role are visible to other members of the organizations you belong to.
3. Organization, project and application content
The Service stores the content your organization creates in it, including projects, issues, comments, labels, backlogs and boards, sprints, milestones and roadmap items, Planning Poker sessions and estimate votes, and project reports. It also stores test results that a connected QAForge desktop application submits to a project, such as test and step names, error messages, the address of the page or endpoint tested, and browser and operating system details, together with the connected device's name.
This content belongs to your organization (see the Terms) and is visible to its members according to their roles. It can contain personal information about you or others if someone types it in, so please enter only what you are permitted to share. Planning Poker votes stay hidden from everyone, including the facilitator, until the round is revealed.
4. Authentication and session information
To sign you in and keep your account secure, the Service stores:
- your password as a salted, irreversible hash — never the password itself — and, if you turn on two-factor authentication, your two-factor secret (encrypted by the application) and hashed recovery codes;
- a record for each signed-in session: a hash of the session token (not the token itself), when it was created, last used and expires, your browser's user-agent string, and your IP address when the Service is running behind a trusted proxy that supplies it;
- hashed, single-use tokens for email verification, password reset and invitations.
5. Technical and log information
To operate and protect the Service we keep operational records: audit events recording significant actions inside an organization (who did what and when), counters used to rate limit sensitive actions such as sign-in and password reset, and application and server logs. These can include identifiers such as your account, organization, IP address (when available as described above) and user-agent string. We have designed logging to avoid recording passwords, tokens and similar secrets.
7. How we use information
We use information to:
- operate the Service for you and your organization — authenticate you, enforce roles and permissions, and store and show your organization's content;
- keep the Service and accounts secure, and prevent abuse;
- process subscriptions and enforce plan limits;
- send the service emails described below;
- respond to support and privacy requests;
- meet legal obligations and keep reasonable business records.
We do not use your information for advertising.
8. Email and transactional communications
We send email only to operate the Service: email verification, password reset and password change notices, invitations, notices that two-factor authentication was turned on or off, and confirmation that an account was deleted. We do not send marketing email. Delivery is handled by an email delivery provider (see "Service providers"). Notifications shown in the application's notification bell are in-app only.
9. Billing information
The Free plan needs no payment details. If an organization subscribes to a paid plan, payment is handled by Lemon Squeezy, which acts as merchant of record and collects and holds your payment details and billing address directly. We do not collect or store your card number, bank details or full billing address.
We store subscription metadata needed to run the plan: which organization it belongs to, the plan and billing interval, subscription status, renewal and end dates, and Lemon Squeezy reference identifiers for the subscription, customer, product and variant. We also keep a record of the billing notifications (webhooks) Lemon Squeezy sends us. See the Refund Policy for refunds.
10. Service providers
A small number of providers process information on our behalf to run the Service:
- Lemon Squeezy — payments and subscription billing for organizations on a paid plan, as described above.
- Hostinger — hosting infrastructure. The application runs there and its database is stored there.
- An email delivery (SMTP) provider — delivers the service emails described above.
We use these providers only to operate the Service. We do not share personal information with advertisers.
12. Data retention
QAForgeHub retains account, organization, project, issue, audit, billing-metadata and related service data for as long as reasonably necessary to provide and secure the service, maintain legitimate business and operational records, comply with legal obligations, resolve disputes, prevent abuse, and maintain backups. You or an authorized organization representative may request deletion of eligible personal information through the privacy contact below. Some information may be retained where required or permitted by law, for fraud and security prevention, for legitimate recordkeeping, or temporarily in backups and disaster-recovery systems. QAForgeHub does not promise a fixed deletion timetable unless a specific retention period is separately published and operationally enforced.
13. Your choices: access, export and deletion
From Account settings you can export a copy of your own data and delete your account. The export includes your account details, organization memberships, active sessions, and the issues you reported, comments you wrote and Planning Poker votes you cast. It deliberately leaves out credentials, secrets and other people's data.
Deleting your account requires your password (and a two-factor code if enabled), and you must first transfer ownership of, or otherwise resolve, any organization where you are the only Owner. Deleting removes your login credentials and two-factor setup, ends your sessions, removes your organization memberships, and replaces your name and email address on the account record with placeholders. Content you created that is shared with teammates, such as issues and comments, is kept so your team's project history stays intact, but it is no longer connected to your identity. We send a confirmation email when an account is deleted.
To ask us to access, correct or delete personal information in a way Account settings does not cover, contact us as described below. Organization content is controlled by the organization, so requests about it may be referred to its Owners or Administrators.
14. Security
We use measures such as hashed passwords, hashed session and reset tokens, optional two-factor authentication, HttpOnly cookies, HTTPS in production, role-based access with separation between organizations, and rate limiting of sensitive actions. See the Security page for more detail.
No service is perfectly secure, and we cannot guarantee the security of information. We do not hold security or privacy certifications, and we do not claim compliance with any particular regulatory framework. If you believe you have found a security problem, email support@qaforgehub.com with "Security Report" in the subject.
15. Children
The Service is intended for people who are old enough to enter into a binding contract and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will look into it.
16. International processing
Our service providers may process information in countries other than the one where you live. We have not published a list of the locations where they process data, and we do not make representations about cross-border transfer mechanisms.
17. Changes to this policy
We may update this Privacy Policy as the Service changes. When we do, we will post the updated policy on this page and change the "Last updated" date above.
18. Contact
QAForgeHub publishes one contact address, support@qaforgehub.com, for support, privacy and security alike — use the subject line to route your message. For privacy questions or a request to access, correct or delete your data, include "Privacy Request" in the subject. General questions can also go through Contact / Support in the Help Center, or to the organization that invited you to QAForgeHub.