Privacy Policy
Last updated: October 3, 2026
This policy explains what personal information Eh Team Studios ("we") handles for Harness Forge, why, and your choices. We're based in Manitoba, Canada, serve businesses in Canada and the United States, and follow Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Our privacy contact is the Privacy Officer, Eh Team Studios, at hello@harnessforge.ca.
1. This website (harnessforge.ca)
- No accounts, no tracking. The website has no sign-up, analytics, advertising or tracking cookies.
- Workspace sign-in: if you use "Sign in" and tick "Remember on this device", the workspace name is stored in your own browser so the box is filled in next time. It never leaves your device. Your password is only ever entered on your company's own workspace, not here.
- Server logs: our web host (Hostinger) keeps standard logs (IP address, browser, pages requested) for security and troubleshooting, for a limited period.
- Fonts: the site loads its typeface from Google Fonts, so your browser connects to Google, which receives your IP address.
- Email: if you email us, we keep the correspondence to reply and to manage our relationship with you.
2. Harness Forge workspaces
Each customer company has its own dedicated server. For the personal information in a workspace, the customer company decides what is collected and why, and we handle it on its behalf as its service provider. Questions about your information in a workspace are best sent to your company's Harness Forge admin first; we'll help them respond.
A workspace holds:
- Account details: name, work email, role, password (stored only as a one-way hash), two-step sign-in settings, preferences.
- Activity: who changed what and when (project history, comments, tasks, approvals), so teams can work together and trace changes.
- Security records: sign-ins, failed sign-ins, devices (browser type and IP address) and security-relevant changes, kept for one year to protect the account and investigate misuse.
- Feedback: if you send feedback from inside Harness Forge, its text, any screenshots you attach, and technical context (version, browser, the view you were in).
- Quote requests: if a company turns on its quote page, people who send it a request give their name, company, email, phone (optional), what they need and any sketch or files they attach. This goes to that company only, and we handle it on the company's behalf. The sender's IP address is kept with the request to prevent abuse, and requests that are never confirmed by email are deleted after two days.
- Design data: drawings and documents may themselves contain names (e.g. "drawn by"). This is the customer's data.
3. How we use it
Only to provide, secure, back up, support and improve the service for the customer: signing people in, sending the emails people ask for (invites, password resets, mentions, approvals), keeping security records, and fixing problems. We don't sell personal information, don't use it for advertising, and don't use workspace content to train AI models.
4. Where it's stored, and who helps us
- DigitalOcean hosts workspaces and their backups in its New York (United States) data centre, unless another region is agreed for your workspace (a Toronto, Canada data centre is available on request). Information stored in the United States may be accessible to courts, law enforcement and national security authorities there under US law.
- Hostinger hosts this website and our email.
- Your company may also connect its own email server or single sign-on provider (such as Microsoft or Google) to its workspace.
These providers only process information to provide their service to us, under their own security and privacy commitments.
5. Security
Workspaces are separate servers reached only over HTTPS. Passwords are hashed, backups are encrypted, two-step sign-in and single sign-on are available, server access is restricted to key-based administration, and security events are logged. No system is perfectly secure; if a breach creates a real risk of significant harm, we'll notify affected customers and, as required, the Privacy Commissioner of Canada.
6. How long we keep it
Workspace information is kept while the customer's subscription is active. Security records are kept for one year. After a subscription ends, the workspace and its backups are deleted as set out in our Terms of Service. Website server logs are kept for up to 90 days.
7. Your rights
You can ask to access or correct your personal information, or withdraw consent where that's the basis for using it. For information in a workspace, contact your company's admin, who can usually make changes directly, or email us and we'll work with them. You can also complain to the Office of the Privacy Commissioner of Canada.
In the United States: we don't sell personal information or share it for targeted advertising. Depending on your state, you may have rights to know, access, correct or delete personal information about you; contact your company's admin or email us, and we'll respond as the law where you live requires. We'll verify the request before acting on it.
8. Changes
We'll post updates here and, for material changes, email workspace admins.