Skip to content
Forthio
ProductHow it worksCapabilities
Sign inGet started

Legal

Privacy Policy

How Forthio handles information when people use our website, application, intake forms, proposal pages, and related services.

Effective September 17, 2026

Forthio is a product of Velaris Digital Group, LLC. In this Policy, “Forthio,” “we,” “us,” and “our” refer to Velaris Digital Group, LLC.

1. About Forthio and our role

Forthio is a U.S.-focused business-to-business software service that helps service businesses collect and manage inquiries, coordinate follow-up, and track proposals and commercial outcomes.

Organizations use Forthio to configure forms, invite team members, and process information relating to their customers and prospective customers. For information submitted to or managed through an organization’s workspace (“Customer Content”), the organization generally decides what to collect and how to use it. Forthio processes that information to provide the Service to the organization.

Forthio is directly responsible for information it uses for account administration, security, support, and business operations. Organizations are responsible for configuring their forms appropriately and providing any notices or obtaining any permissions required for the information they choose to collect.

2. Information we handle

Depending on how the Service is used, we may handle:

  • Account and authentication information, such as name, email address, account status, authentication identifiers, and security-related account information. Forthio does not receive or store users’ plaintext passwords.
  • Organization and team information, such as organization name, member roles, invitations, services, form configurations, and workspace settings.
  • Inquiry and customer information, such as names, contact details, inquiry details, form responses, notes, assignments, follow-up information, and status history.
  • Proposal information, such as proposal descriptions, amounts, statuses, public responses, and commercial outcomes.
  • Support and communication information, such as messages sent to Forthio and information provided when requesting help.
  • Transactional service communication information, such as recipient email addresses, bounded invitation or proposal-delivery context, message and template identifiers, timestamps, and delivery, delay, bounce, complaint, failure, or suppression status.
  • Google Calendar connection information, such as the connected Google account identifier and email; calendar identifiers, names, primary status, and effective access role used to identify writable calendars; OAuth scopes and encrypted credential metadata; the selected destination calendar; and external event identifiers and mappings needed for synchronization. Forthio does not import or store a user's general Google Calendar history.
  • Technical and security information, such as IP address, browser or device category, request metadata, session information, timestamps, error information, and abuse-prevention signals generated while operating the Service.
  • Limited first-party product analytics, such as account, organization, and role identifiers; coarse product-area use; inquiry-detail access; public intake flow identifiers; event timestamps; and bounded event classifications.
  • Pilot and business information, such as pilot participation, feedback, commercial discussions, and billing contacts if applicable.

We receive information from account users, organizations using Forthio, people submitting public forms or responding to proposals, and the systems used to operate the Service.

3. How we use information

We use information to create and administer accounts; authenticate users; provide organization workspaces and role-based access; publish and process intake forms; manage inquiries, proposals, and customer responses; deliver requested invitations and proposal-access communications; diagnose delivery failures and prevent repeated delivery to suppressed addresses; provide support; protect against misuse and security threats; comply with legal obligations; administer pilots; and improve the Service using operational feedback.

Forthio uses limited first-party product analytics to understand whether pilot organizations complete setup, return to the Service, use major workflow areas, process inquiries, and complete public intake flows. These analytics are used internally to improve the Service and are kept separate from customer-facing reports and business audit evidence.

When a user connects Google Calendar, Forthio uses Google Workspace API information only to identify a writable destination calendar and provide one-way synchronization of assigned Forthio appointments. Forthio may send the appointment title, start and end times, time zone, and optional location or meeting URL. Forthio does not send customer names, customer contact details, inquiry responses, internal notes, proposal content, or AI output to Google Calendar.

Product analytics do not include form answers, inquiry notes, proposal content, customer contact details, full URLs or query strings, IP addresses, geolocation, raw user-agent strings, session replay, advertising identifiers, or persistent anonymous visitor profiles. Forthio does not sell personal information or use Customer Content for targeted advertising.

AI-assisted processing

Inquiry information may be processed using third-party AI or model infrastructure to provide AI-assisted Forthio features. This processing may include summarization, intake-completeness analysis, Service-fit assistance, Qualification assistance, identifying risks or useful follow-up questions, and suggesting next actions.

Forthio minimizes information sent for AI processing. The current pre-assignment inquiry-intelligence feature excludes the customer's name, email address, and phone number from model context. AI output is advisory and does not automatically alter authoritative Qualification, Service, assignment, next-action, proposal, or commercial-outcome state.

Forthio uses AI routes capable of Zero Data Retention by default. When necessary to maintain service availability, Forthio may use an approved commercial AI provider under bounded-retention and no-model-training-use terms. The same data-minimization and advisory-authority safeguards apply to that emergency processing.

Relevant infrastructure and AI/model service providers may act as subprocessors or service providers. Forthio applies its configured data-retention and data-use controls to AI processing.

Google Workspace API data is not sent to Forthio's AI or model providers and is not used to create, train, or improve generalized artificial-intelligence or machine-learning models. Forthio's use and transfer of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How we disclose information

  • At an organization’s direction. Information may be available to authorized members of the organization that collected or manages it.
  • Infrastructure and service providers. Forthio uses Supabase for database, authentication, encrypted Google OAuth credential storage, and backend infrastructure; Vercel for application hosting, execution, and delivery; Resend for application transactional-email delivery; Twilio as a messaging service provider/subprocessor for transactional SMS; and relevant AI/model service providers for AI-assisted processing. These providers process information only as needed to provide their respective functions, subject to their applicable agreements and policies.
  • User-authorized connected services. Google processes information when a user authorizes and uses the Google Calendar connection. Google Workspace API data is not transferred to Forthio's AI/model providers, advertisers, data brokers, or unrelated third parties.
  • Professional advisers and contractors. We may provide limited information to advisers or contractors assisting with legal, accounting, security, support, or business operations, subject to appropriate responsibilities.
  • Legal and safety reasons. We may disclose information when reasonably necessary to comply with law, respond to lawful process, investigate fraud or security incidents, or protect rights and safety.
  • Business transactions. Information may transfer as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law and appropriate confidentiality protections.
  • With consent. We may disclose information when the relevant person or organization directs or authorizes us to do so.

We do not disclose Customer Content for an unrelated commercial purpose merely because it is stored in the Service.

5. Data retention

We generally retain active organization and account data while the organization uses Forthio.

Raw anonymous public-intake analytics are retained for up to 30 days. Authenticated product-usage analytics are retained for up to 180 days during the pilot. Operational security records and authoritative business or audit evidence follow their separate retention requirements.

Temporary encrypted invitation and proposal delivery credentials are removed after successful delivery submission or terminal failure. Recipient addresses and bounded transactional-email payload data are redacted from Forthio's delivery outbox within 30 days after a terminal state. Normalized provider delivery evidence may be retained for up to 180 days during the pilot. Keyed suppression records may be retained while reasonably needed to avoid repeated harmful or unwanted delivery.

Forthio's application transactional email is used for service communications, not marketing campaigns. Forthio does not use email-open tracking, click tracking, advertising profiling, or customer engagement tracking in these messages.

Encrypted Google OAuth credentials are retained while a connection is active and, if provider authorization cleanup is temporarily unavailable, only while bounded revocation retry is pending. Future Forthio synchronization stops immediately when disconnect begins. On final disconnect, Forthio deletes the stored credentials and connected Google account email. Existing events previously written to Google Calendar remain. Forthio may retain the opaque Google account identifier, selected-calendar identifier and name, and external event mappings needed to prevent duplicates, distinguish an account change, and support continuity when the same account reconnects. If another active Forthio connection still relies on the same project-level Google authorization, Google authorization may remain until that connection no longer requires it.

Following termination, we may retain operational and customer data for up to 30 days to support transition, recovery, account administration, or correction of an accidental closure. After that period, we delete or anonymize the data through ordinary operational processes, subject to reasonable exceptions for legal obligations, security or fraud prevention, dispute resolution, enforcement, financial and business recordkeeping, and other legitimate purposes permitted by law.

Deletion may not be immediate across every system. Backup copies expire through ordinary retention cycles and may not be individually editable during those cycles. Information retained in backups remains subject to applicable protections and is not restored for ordinary business use except as part of legitimate recovery operations. Organizations should export information they need before ending their use of Forthio.

6. Security

Forthio uses safeguards proportionate to the current Service and the information it handles. These include tenant-isolation controls, role-based access controls, authentication and session measures, server-side authorization checks, and controls intended to limit access to authorized users.

Google OAuth credentials are encrypted at rest, handled only on the server, and cryptographically bound to the applicable organization, user, provider, and calendar-connection identity.

No online service can guarantee absolute security. Users are responsible for protecting account access and promptly reporting suspected unauthorized use to security@getforthio.com.

7. Your choices and requests

Depending on the circumstances and applicable law, you may ask whether Forthio holds information about you or request access, correction, or deletion. Send requests to support@getforthio.com. We may need to verify your identity and authority before acting.

When information belongs to an organization’s Customer Content, we may direct you to the organization that collected it or coordinate with that organization. A request may be limited where retaining or using information is necessary to provide a requested service, protect security, comply with law, maintain legitimate business records, or exercise legal rights.

Users may disconnect Google Calendar in Forthio and may also remove Forthio through their Google Account permissions. Requests to delete retained Google connection metadata may be sent to support@getforthio.com. Forthio may verify the requester's identity and authority before acting.

8. Children’s privacy

Forthio is a business-to-business service and is not directed to children. Organizations control the forms they publish and the information they request. Depending on an organization’s use, a form could contain information relating to a minor. Organizations should avoid collecting information from or about children unless they have a legitimate purpose and any permissions required by applicable law.

If you believe information about a child was submitted inappropriately, contact the organization responsible for the form or Forthio.

9. U.S. use

Initial External Pilot availability is limited to the United States. Forthio and its infrastructure providers may process information in the United States and other locations where those providers operate. International-transfer commitments required for a particular customer must be addressed separately before use.

10. Changes to this Policy

We may update this Policy as the Service, business, or legal requirements change. We will post the revised version with a new effective date and provide additional notice when reasonably appropriate for a material change affecting existing information.

11. Contact

Velaris Digital Group, LLC
9324 Spring Water Path, Jessup, MD 20794
Support and privacy: support@getforthio.com
Security: security@getforthio.com

12. Transactional SMS and consent records

When you choose to receive texts about an inquiry, Forthio uses the phone number you provided to operate the participating organization’s transactional messaging through Forthio. Messages identify the business as “Organization Name via Forthio.” We record your affirmative consent with the inquiry, form/version, disclosure version, phone number at consent, timestamp, and public intake page. We also process message content and delivery/status metadata needed to provide and troubleshoot the service.

Twilio processes messaging information as our messaging service provider/subprocessor. Operational information is disclosed to service providers only as needed to deliver and operate the service. We do not sell SMS phone numbers or consent data, or share or transfer mobile opt-in consent to unrelated third parties for marketing. SMS opt-in does not grant marketing permission. These protections supplement our existing no-sale and no-targeted-advertising commitments.

We retain consent evidence and STOP/opt-out records under our retention practices to document preferences, prevent unwanted texts, and maintain compliance evidence. Opting out stops future texts from the shared sender; it does not erase the original consent or opt-out history. START/UNSTOP may clear suppression but does not create new inquiry consent.

Forthio

New business operations, organized.

Collect customer details, understand each request, follow up, and keep notes and next steps together.

ProductHow it worksCapabilitiesGet started
AccessSign inCreate account
LegalPrivacyTermsSupport
© 2026 Forthio. Forthio is a product of Velaris Digital Group, LLC. All rights reserved.Move new business forward.