Privacy Policy
Scope and Roles
This Privacy Policy explains how ForecastFix handles personal information and organization data for a hosted SaaS financial reporting and consolidation tool.
For account, billing, security, support, and website data, ForecastFix acts as a controller or business. For trial balances, charts of accounts, mappings, dimensions, financial reports, and other organization content submitted by customers, ForecastFix generally acts as a processor or service provider for the customer organization.
Customer organizations control the content their users upload, configure, generate, or export through the service. If you use ForecastFix through an organization account, privacy requests about organization content may need to be directed to that organization.
Information We Process
We process account identifiers, names, email addresses, phone numbers, organization names, user roles, company access permissions, authentication records, session identifiers, security logs, billing metadata, support communications, and device or network information such as IP address, user agent, approximate location derived from IP address, and cookie or similar service identifiers.
Payment card, bank, and payment-method details are processed by payment providers such as Stripe. ForecastFix generally receives payment metadata, invoice status, subscription status, customer identifiers, last-four payment method details where available, and related billing records rather than full payment card numbers.
If you use SMS features, we process phone numbers, SMS consent and opt-out status, message content, delivery metadata, timestamps, carrier information where available, and related support records.
If you use AI features, we process prompts, selected page context, tool results, customer-submitted accounting metadata, generated responses, model routing metadata, usage counts, and related security and billing records.
Organization data may include trial balances, account names and codes, entity names, dimensions, mappings, FX rates, reports, formulas, generated journals, audit history, and related financial metadata uploaded or configured by users.
If you enable a third-party integration, we may process connection identifiers, account IDs, tenant IDs, company IDs, OAuth tokens or other connection secrets, authorized scopes, sync settings, imported records, exported records, webhook or event payloads, error logs, and related metadata needed to operate the connection.
Sources of Information
We collect information directly from users and organization admins, from files and configurations submitted through the service, from authentication, billing, email, SMS, AI, hosting, security, and support providers, and automatically from browsers, devices, networks, and service logs.
We may also receive information from accountants, consultants, advisors, or other users invited by a customer organization to use ForecastFix.
If a customer organization enables a third-party integration, we may receive information from that connected system according to the permissions, scopes, settings, and records authorized by the customer organization or its users.
Third-Party Integrations
When a customer organization chooses to connect ForecastFix to a third-party system, ForecastFix processes integration data only as needed to authenticate, sync, import, export, transform, display, troubleshoot, secure, and support the requested connection.
Integrations may use OAuth, API keys, webhooks, file transfer, or other provider-supported methods. We store integration tokens or credentials only as needed to provide the connection, restrict operational access, and allow authorized admins to disconnect integrations where available.
Third-party systems remain governed by their own terms, privacy notices, security practices, retention rules, API limits, and account controls. Customer organizations are responsible for having the authority and user permissions needed to connect those systems to ForecastFix.
Accounting and Reporting Content
We process customer-submitted accounting and reporting content to provide the service features selected or configured by users, including reporting, consolidation, mapping, refresh, audit history, dashboard, and export workflows.
ForecastFix does not use that content to independently certify financial statements, determine final GAAP or IFRS compliance, provide audit opinions, provide tax or legal advice, or make professional accounting judgments for the customer organization.
AI and Automated Processing
When AI features are used, ForecastFix may send prompts, selected context, tool outputs, and generated responses to AI service providers to provide the requested feature, enforce abuse controls, measure usage, and maintain service reliability.
AI outputs are generated by software and may be inaccurate. ForecastFix does not use AI outputs to independently certify financial statements, make final accounting judgments, or provide professional audit, legal, tax, or investment advice.
How We Use Information
We use information to provide and secure the service, authenticate users, enforce tenant and company-level access, operate reporting and consolidation features, maintain audit trails, provide support, improve reliability, meet legal obligations, and protect against fraud or misuse.
We also use information to process subscriptions and invoices, manage plan limits and AI credits, send administrative and transactional communications, debug errors, monitor performance, investigate security events, preserve records, enforce agreements, and improve the usability and reliability of ForecastFix.
We use SMS-related information to send requested messages, verify accounts, deliver security and service alerts, respond to HELP requests, honor STOP and other opt-out requests, troubleshoot delivery issues, maintain consent records, and comply with messaging rules.
SMS Messaging Privacy
Customers opt in to SMS messaging by texting our number or by otherwise providing consent through the service. Customers can opt out by texting STOP or by sending another reasonable opt-out request to privacy@forecastfix.com. We will honor SMS opt-out requests as soon as practicable and no later than 10 business days after receipt. Customers can request help by texting HELP.
We do not sell SMS consent records or phone numbers. We may share SMS-related information with messaging providers, carriers, service providers, or legal authorities only as needed to deliver messages, operate the service, comply with law, protect rights and safety, or investigate misuse.
Message and data rates may apply. SMS delivery may depend on your wireless carrier and device settings.
GDPR Legal Bases
Where GDPR applies, we process personal data as needed to perform a contract, meet legal obligations, pursue legitimate interests such as security and service operation, and, where required, based on consent.
Individuals may have rights to access, correct, delete, restrict, object to processing, and receive a portable copy of personal data, subject to legal, security, accounting, and contractual limits.
Where personal data is transferred outside its country of origin, we use appropriate contractual or operational safeguards where required by applicable law. ForecastFix is based in the United States, and service providers may process information in the United States or other countries.
California Privacy Rights
California residents may have rights to know, access, correct, delete, and limit certain uses of personal information, and to be free from discrimination for exercising privacy rights.
ForecastFix does not sell personal information or share personal information for cross-context behavioral advertising as those terms are commonly used in California privacy law.
The categories of personal information we may collect include identifiers, commercial information, internet or electronic network activity, geolocation approximated from IP address, professional or employment-related information, inferences from service usage, and sensitive account credentials or financial information where necessary to secure and operate the service.
We disclose personal information to service providers, contractors, payment processors, communications providers, hosting and security providers, AI providers when AI features are used, professional advisers, authorities where required, and business transaction counterparties as described in this policy.
Sharing and Subprocessors
We may share information with service providers that host infrastructure, store data, send email, process payments, monitor security, provide support, send SMS messages, process AI requests, provide analytics necessary to operate the service, or perform other services on our behalf.
Current service-provider categories may include cloud hosting and storage, database and cache infrastructure, payment processing, email delivery, SMS messaging and carriers, AI model providers, logging and monitoring, customer support, professional advisers, and security providers.
We may also disclose information when required by law, legal process, security investigation, corporate transaction, or to protect rights, safety, and service integrity.
We do not permit service providers to use customer organization content for their own independent marketing. We require service providers to process information for specified purposes and under confidentiality, security, or data-protection obligations appropriate to their role.
Retention and Deletion
For active organizations, current operational data such as trial balances, charts of accounts, mappings, dimensions, report definitions, generated outputs, and uploaded files is retained while the organization remains active or as needed to provide the service.
Audit trails, history records, historical snapshots, and related audit payloads are retained for seven years unless a longer period is required by law, contract, security need, or dispute preservation. After that retention period, those audit and history records may be deleted or archived according to our retention controls.
Subscription cancellation does not automatically erase organization data. A cancelled or inactive subscription may restrict access to the service. If an organization remains inactive or unsubscribed for seven years after the last known service period end, the organization and its data may be permanently deleted unless it is reactivated earlier or a longer period is required by law, contract, security need, or dispute preservation.
If an authorized organization admin requests deletion, the organization enters a 14-day soft-delete grace period. If the organization is not restored, the organization is permanently deleted from active application databases and object storage after that grace period. Disaster recovery backups may persist until their normal backup lifecycle expires and are not used for ordinary processing.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including tenant access controls, authentication, audit records, operational monitoring, encryption in transit, restricted production access, backups, and logging.
No hosted system can be guaranteed completely secure. Customers should use strong passwords, appropriate roles, company access restrictions, and internal review controls.
If we determine that a security incident requires notice under applicable law or a written customer agreement, we will provide notice using available contact information and will take reasonable steps to investigate, contain, and remediate the incident.
Regulated Data, Children, and Sensitive Information
ForecastFix is not intended for protected health information, full payment card numbers, consumer credit reports, government classified information, biometric identifiers, children's data, or other highly regulated sensitive data unless covered by a separate written agreement.
The service is intended for business users and is not directed to children. Do not use ForecastFix to knowingly collect personal information from children.
Marketing, Email, and Communication Choices
We may send transactional, administrative, billing, security, and service communications that are necessary to operate ForecastFix. Users may not be able to opt out of essential service communications while their account is active.
Marketing email recipients may opt out by using the unsubscribe link or by contacting privacy@forecastfix.com. We will honor commercial email opt-out requests within 10 business days where required by law.
Contact
Privacy and data protection requests can be sent to privacy@forecastfix.com, by phone at +1 (843) 418-2524, or by mail to ForecastFix LLC at 8421 Dorchester Rd Ste 109 #355, North Charleston, SC 29420, USA. We may need to verify your identity and authority before acting on a request.