Privacy Policy
Last updated: 5 July 2026
This policy explains how the QAForge service (qaforge.app) processes personal data in line with the GDPR. We collect only the data necessary to run the service.
1. Data controller
The data controller is the individual operating the QAForge service, reachable by email at: kontakt@qaforge.app. For any data protection matters, please contact this address.
QAForge is a toolkit for developers and QA teams. We provide free tools (generators, validators, converters) and paid website audit services.
2. What data we process
The scope of data depends on how you use the service:
- Developer tools run entirely in your browser and do not send the data you enter to our server (exception: the meta tag preview fetches the public URL you provide).
- User account: email address, optionally a name, a hashed password (for password login) or a Google account identifier (for Google login).
- Payments: plan and subscription status data. We do not process or store card numbers — Stripe handles them.
- Audit services: the URLs of the pages you submit for checking, and the audit results.
- Technical data: IP address, browser type and logs needed for security and diagnostics.
3. Cookies and browser storage
We use only cookies strictly necessary for the service to work:
- login session cookie — keeps you signed in,
- language preference cookie (qaforge_locale) — remembers your interface language.
We do not use marketing or tracking cookies. Visit statistics (if enabled) are collected in a cookieless and anonymous way, so they do not require your consent.
4. Payments
Subscription payments are handled by Stripe Payments Europe, Ltd. When you proceed to payment, you enter card details directly in Stripe — we have no access to them. We only receive payment and subscription status information from Stripe, necessary to grant you the plan you purchased.
5. Google login
If you sign in with Google, we receive basic data from your Google account: email address and your profile name. We use it solely to create and operate your QAForge account.
6. Error monitoring and statistics
To keep the service reliable, we use technical tools:
- Sentry — records application errors (e.g. error message, page URL, approximate technical data) so we can fix them.
- Plausible Analytics (if enabled) — anonymous, cookieless traffic statistics that cannot identify an individual user.
7. Purposes and legal bases
- Providing the service and managing your account — Art. 6(1)(b) GDPR (performance of a contract).
- Processing payments and tax obligations — Art. 6(1)(b) and (c) GDPR.
- Security, diagnostics and statistics — Art. 6(1)(f) GDPR (legitimate interest).
- Sending messages necessary to operate the account (e.g. email verification, notifications) — Art. 6(1)(b) GDPR.
8. Recipients and technical providers
Data may be entrusted to trusted providers, only to the extent necessary to run the service:
- Stripe — payment processing,
- Google — login (OAuth),
- Sentry — error monitoring,
- Plausible — anonymous statistics (if enabled),
- hosting and database provider,
- email provider (transactional messages).
We do not sell personal data and do not share it with third parties for marketing purposes.
9. Retention periods
- Account data — for as long as the account exists; after deletion we remove it promptly, except data we must keep by law.
- Billing data — for the period required by tax regulations.
- Technical logs — typically no longer than 90 days.
- Email correspondence — no longer than 3 years from the completion of the matter.
10. Your rights
You have the right to: access your data, rectify it, erase it, restrict processing, data portability, object to processing based on legitimate interest, and withdraw consent. You also have the right to lodge a complaint with the supervisory authority (in Poland: the President of the Personal Data Protection Office).
To exercise these rights, write to: kontakt@qaforge.app.
11. Transfers outside the EEA
Some technical providers may process data outside the European Economic Area. Where this happens, it is based on appropriate safeguards, in particular the standard contractual clauses approved by the European Commission.
12. Security
We apply technical and organisational measures to protect data, including encrypted connections (HTTPS), storing passwords only as hashes, and restricted access to data.
13. Changes to this policy
This policy may be updated as the service evolves. We will announce significant changes in the service or by email. The current version is always available on this page.