Privacy Policy
Last updated June 13, 2026
This policy explains what personal data ZedroForge collects, how and why we use it, who we share it with, the cookies we use, and the rights you have under the GDPR.
1. Who we are
This Privacy Policy explains how ZedroForge (“ZedroForge”, “we”, “us”) collects, uses and protects your personal data when you use our marketplace (the “Platform”). For data-protection purposes, ZedroForge is the data controller.
We are based in Hungary and process personal data in line with the EU General Data Protection Regulation (GDPR) and applicable Hungarian law. You can reach us at zedroforge@gmail.com or via our Support page. ZedroForge is operated by Nagy Áron, a sole proprietor (egyéni vállalkozó) registered in Hungary, with registered address 2141 Csömör, Vasút sor 1; our full operator details are set out in our Terms of Service.
2. The data we collect
Depending on how you use the Platform, we may collect:
- Account data — your name, email address, username, a permanent account ID, and a password (stored only as a secure hash, never in plain text).
- Profile data — anything you add to your profile: avatar, short bio, country, languages and skills.
- Sign-in data — if you sign in with Google or Discord, the basic profile they share (an account ID, email, name and, for Google, a profile picture).
- Content you create — listings, order briefs and requirements, messages, uploaded files and deliverables, reviews, and support tickets.
- Transaction data — your orders, amounts, and payment/payout status. Card details are entered with and processed by our payment provider (Stripe); ZedroForge does not see or store your full card number.
- Technical data — IP address, browser/device information and server logs created when you use the Platform.
3. How and why we use your data
We use your data for the following purposes, each with a legal basis under the GDPR:
- To provide the Platform — create your account, list and order services, process payments and payouts, deliver work and run buyer protection (basis: performance of our contract with you).
- To keep the Platform safe — authentication, fraud and abuse prevention, moderation, and enforcing our Terms (basis: our legitimate interests and, where relevant, legal obligations).
- To communicate with you — verification and password-reset emails, order and account notifications, and support replies (basis: contract and legitimate interests).
- To comply with the law — tax, accounting and responding to lawful requests (basis: legal obligation).
- For anything else we ask your permission for (basis: your consent, which you can withdraw at any time).
4. Cookies and similar technologies
We keep cookies to a minimum. This is everything we store in your browser:
- A session cookie (zv_session) that keeps you logged in after you sign in.
- Short-lived sign-in cookies set during Google/Discord login to protect against cross-site request forgery, then deleted right after.
- A consent cookie (zv_consent) that remembers your cookie choice for 12 months.
- Optional: a referral cookie (zv_ref) that remembers for 30 days which member invited you, so we can credit them if you join. Choose “Essential only” in the cookie banner and we won’t use it.
- Your light/dark theme preference, stored in your browser.
5. No tracking or ad cookies
We do not use advertising cookies or third-party analytics/tracking cookies. The essential cookies above are strictly necessary to provide a service you asked for and work without consent; the referral cookie is optional, and you can decline or later clear it at any time. If we ever introduce analytics or marketing cookies, we will ask for your consent first.
6. Who we share data with
We do not sell your personal data. We share it only as needed to run the Platform:
- Other users — the people you transact with see what an order needs (your brief, messages and deliverables); your public profile and reviews are visible to others.
- Payments — Stripe processes payments and seller payouts (Stripe Connect).
- File storage — uploaded images and deliverables are stored with our object-storage provider (Cloudflare R2).
- Email — Resend sends our transactional emails.
- Infrastructure — our hosting and infrastructure providers run the Platform on our behalf.
- Authorities — when we are legally required to, or to protect users, the public or our rights.
7. International transfers
Some of our service providers process data outside the European Economic Area, including in the United States. Where they do, the transfer is protected by appropriate safeguards under the GDPR: where a provider is certified under the EU–U.S. Data Privacy Framework we rely on that framework (an adequacy decision); otherwise we rely on the European Commission’s Standard Contractual Clauses incorporated into our data-processing agreement with the provider. In particular, Stripe (payments) and Cloudflare (file storage) provide these safeguards through their data-processing terms, and Resend (email) transfers are covered by Standard Contractual Clauses. You can ask us for details of the safeguards that apply to any specific provider.
8. How long we keep it
We keep your personal data while your account is active and for as long as needed for the purposes above — for example, to provide the service, resolve disputes, and meet legal, tax and accounting obligations. When you delete your account, we delete or anonymise your personal data, except where we must keep certain records by law.
9. Your rights
Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to certain processing, receive it in a portable format, and withdraw consent where we relied on it. To exercise any of these, contact us at zedroforge@gmail.com or through Support.
You also have the right to lodge a complaint with a data-protection authority. In Hungary, this is the National Authority for Data Protection and Freedom of Information (NAIH).
10. How we protect your data
We use measures such as hashing passwords, encrypting data in transit, holding payments in escrow, and limiting who can access data. No online service can be guaranteed 100% secure, but we work to protect your information and to respond quickly if something goes wrong.
11. Children
ZedroForge is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will remove it.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes we will take reasonable steps to let you know, and we will update the “last updated” date above.
13. Contact
Questions about your privacy or this policy? Email zedroforge@gmail.com or use the Support page.
See also our Terms of Service and Refund Policy.
