Privacy
What we collect, and what we don't
This site collects very little. There are no advertising trackers, no third-party fonts or scripts loading in the background, and nothing is sold or shared for marketing. This page sets out exactly what happens.
Shopify apps we publish have their own page — Privacy for Shopify apps — because they read shop data that this website never sees.
When you send an enquiry
The contact form asks for your name, email address, an optional company name, and your message. The app support form also asks which app and which shop the message is about. When you submit either, we record the IP address the request came from and your browser's user-agent string — these help us block automated spam and nothing else.
Both public forms run a Cloudflare Turnstile check before a message is stored. That is a bot check, not analytics: Cloudflare sees the token and the address the request came from, and we do not use it to understand how the site is used. A failed check is answered as a success and nothing is recorded, so it is not a way to probe what we accept.
That information is stored in a database on a server we run, and a copy is emailed to us so we see it promptly. We use it to reply to you and to carry on the conversation if it goes further. We don't add you to a mailing list, and we don't pass your details to anyone else.
If you are a client with a client portal account, enquiries sent from this form appear there when the email address on them matches the one you signed in with — alongside their status and any replies from us. That is the only way an enquiry becomes visible to anyone other than us, and it takes a verified email address to happen.
Analytics, only if you agree
We use Microsoft Clarity to understand how the site is used — which pages hold attention, and where people get stuck. It records anonymised session activity such as clicks, scrolling and navigation.
Clarity does not load unless you accept it. If you decline, nothing is requested from Microsoft at all — the script is never fetched, rather than fetched and told to stay quiet. You can change your mind at any time using Cookie settings at the bottom of any page.
If you do accept, your data is handled by Microsoft under the Microsoft Privacy Statement.
Cookies
This site sets no cookies of its own. Your analytics choice is kept in your
browser's local storage under ff-analytics-consent, which never
leaves your device and is not readable by anyone else. If you accept
analytics, Microsoft Clarity sets its own cookies; declining means it never
runs, so it never does.
Server logs
Our web server records each request — time, page, IP address, user-agent — as most servers do. We use these to investigate faults and abuse. They rotate automatically and are deleted after 30 days.
The client portal
People can sign in at myaccount.frontforge.com to see invoices, payment status and tickets. Consulting clients are invited, and a link is sent to the email address on their billing record. Merchants using a Shopify app can sign in themselves — Google, Microsoft, or an email one-time code — through the same Microsoft Entra External ID tenant. We never see or store a password. The sign-in page runs the same Cloudflare Turnstile check as the public forms before Microsoft is asked anything.
If you do use it, more companies are involved, and only then:
- Microsoft — provides the sign-in. Your email address and the fact that you signed in are handled by Microsoft Entra.
- Stripe — holds the billing records a consulting client sees. We read invoices from Stripe when you open the page; we don't copy them anywhere. A Shopify merchant's tickets do not involve Stripe.
We link a portal account to a billing customer only when an invitation is opened — never by matching an email address on its own. A guest support message is attached later if you sign in with the same address you typed on the form.
Who else is involved
- Amazon Web Services — hosts the server this site, the portal and your enquiry run on.
- SMTP2GO — delivers the notification email when you send an enquiry, and portal invitations.
- Microsoft — provides Clarity analytics, and only ever sees anything if you accept it. Also provides sign-in for the client portal.
- Cloudflare — the human check on the public forms. It is not analytics and is not optional on those forms: without it the queue would be anyone's.
- Stripe — our payment provider, and only for clients who are billed. It is never involved in an enquiry from this website.
That's the complete list. No advertising networks, no data brokers, no analytics beyond the above.
How long we keep things
- Enquiries — for up to 24 months after our last contact, so we can pick up a conversation where it left off. Ask us sooner and we'll delete them.
- Server logs — 30 days.
- Your analytics choice — until you clear your browser storage.
- Client portal accounts — while you are a client, and removed on request. Invoices themselves we have to keep for as long as tax law requires, which is longer.
We keep no backups of any of it, so a deletion is immediate and final — there is no archive copy quietly outliving the request. The trade is deliberate: nothing here is worth more to you sitting in an archive than it costs you to have it lying around. Our Shopify apps run on separate infrastructure and are backed up; the app privacy page says what that means for a deletion there.
Your choices
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. We'll do that, and we won't make it difficult. The quickest route is the contact form — say what you'd like and we'll confirm once it's done.
To turn analytics off after previously accepting, use Cookie settings in the footer and choose Decline.
Changes to this page
If what we collect changes, we'll update this page and the date at the top. If the change is significant, we'll ask for your consent again rather than assuming it.
Getting in touch
Questions about any of this, or about how we handle data on a project, go through the contact form. Questions about a Shopify app go to support.