How Zone Forge Technologies, LLC handles your personal information.
Effective date: August 2, 2026 · Last updated: August 2, 2026
This Privacy Policy describes how Zone Forge Technologies, LLC ("Zone Forge," "we," "us") collects, uses, and discloses personal information when you use the Zone Forge software, websites, and related services (the "Service"). Capitalized terms not defined here have the meaning given in our Terms of Service.
This policy is written for users in the United States.
Account information. When you create an account we collect your email address, a password (stored only as a secure hash through our identity provider), any display name you provide, and your date of birth, which we collect at sign-up to confirm you meet our minimum age requirement. If you sign in with Google through our identity provider we receive your email address, a unique account identifier, and any profile information your provider chooses to share.
Profile information. From your profile you may optionally add a phone number and a mailing address. Your phone number, if you add one, is shown to your teammates in shared workspaces and can be used to find you in team search. Your mailing address, if you add one, is stored and used to show local weather, set your default units, and populate your invoice details. You can add, change, or remove either at any time from your profile.
Anonymous-guest sessions. If you use the Service as a guest we create a temporary, anonymous account identifier so the application can hold your work in progress. We do not collect an email address or other identifying information until you choose to convert the guest session into a real account.
User Content. When you use the Service you may upload, create, or import field boundaries, soil sample results, agronomic settings, prescription map definitions, equipment information, prices, documents you upload, and related metadata. You may also create workspaces and invite other people into them. We process this content to provide the Service to you.
Team communications. If you use a shared workspace or team chat, we collect the messages you send there, together with any photos or voice messages you attach to them, so that we can deliver them to the other people in that conversation and keep a record of it for them. If you or a teammate taps Transcribe on a voice message, we send that recording to our AI provider to turn it into text.
Billing information. If you subscribe to a paid plan, our payment processor collects your payment-method details, and we receive and retain billing and invoice records — the plan, the amount, the date, and the billing contact. We do not store full card numbers.
Connected-platform data. If you connect an agricultural platform account, we retrieve organizations, fields, field operations, and related data from the connected platform on your behalf and cache portions of it to operate the Service. We store connected-platform access and refresh tokens in encrypted form.
Usage and device information. We collect log data such as IP address, browser type, operating system, the pages and features you use, the actions you take inside the Service, dates and times of access, and error reports. We use cookies, similar local-storage technologies, and standard web logs to operate, secure, and analyze the Service.
Communications. If you contact us by email or through a contact form we receive the information you provide, including your message and any attachments.
Information from third parties. We may receive information about you from service providers we use to operate the Service, including our identity provider, our hosting and analytics providers, and integrated third-party platforms such as connected agricultural platforms.
Location. Several features use your device's precise location — showing the weather where you are standing, centering the map on your position, opening a new field on the ground you are standing on, filling in your address from where you are, recording where you took a soil sample, and sharing your position with your team while that setting is on. Your device asks for location permission once; after you grant it these features use your location automatically rather than asking again each time, and you can withdraw the permission at any time in your device settings. Depending on the feature, your coordinates either go to our servers or travel straight from your device to a third party: the weather services that return a forecast, the mapping services that turn coordinates into a street address, and the state government parcel-record systems that identify the property you are standing on. Where the request goes directly from your device, that third party also sees your device’s IP address.
We do not create voiceprints or face templates from the photos and voice messages described above, and we do not use them to identify you biometrically. We do not knowingly collect government identifiers, or other categories of sensitive personal information beyond what this section describes.
We use personal information to:
We do not sell personal information, and we do not use it for cross-context behavioral advertising.
We share personal information only as described below.
Service providers (sub-processors). We share information with vendors who process it on our behalf, under contractual confidentiality and security obligations, to provide hosting, identity, payment processing, and similar functions. Our current sub-processors are:
We update this list when we add, change, or remove a material sub-processor. We do not engage sub-processors for advertising or for cross-context behavioral advertising.
Weather, mapping and parcel services. The location features described in Section 1 send your coordinates to services we do not control, so that they can return a result: Open-Meteo and the National Weather Service for forecasts; OpenStreetMap’s Nominatim and the U.S. Census Bureau geocoder to turn coordinates into a street address; and the Delaware and Maryland state parcel-record systems to identify the property you are standing on. The address and parcel lookups are made straight from your device, so those services also see your device’s IP address. These are not sub-processors acting on our behalf — they are public and government services we query — and each is governed by its own terms.
Connected platforms. When you direct us to push prescription maps, soil samples, or other content to the connected platform, we transmit the relevant data and the encrypted access token to the connected platform on your behalf. Information you receive from the connected platform through the Service is governed by that platform's terms and privacy policies in addition to ours.
Artificial-intelligence features. The Service includes optional AI features — an in-app assistant that answers agronomy questions and explains your results, and an importer that reads soil and litter/manure test documents you upload. When you use one of these features, we send the relevant portion of your data — such as the question you submit, a prescription map and the inputs that produced it, or the document you upload — to our AI provider, Anthropic, PBC, to generate a response. These features run only in response to your action (for example, asking the assistant a question or uploading a document for import). Anthropic does not use data submitted through its commercial API to train its models.
Legal and safety. We may disclose information if we believe in good faith that disclosure is required to comply with a law, regulation, legal process, or government request; to enforce our Terms; to protect the security or integrity of the Service; or to protect the rights, property, or safety of Zone Forge, our users, or the public.
Business transfers. If Zone Forge is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will notify users of material changes resulting from such a transfer.
With your consent. We may share information for other purposes with your consent or at your direction.
We use cookies and browser local storage to keep you signed in, remember preferences, secure authenticated sessions, and measure how the Service is used. Most browsers let you block or delete cookies, but parts of the Service may not work correctly without them.
Our public marketing website uses Cloudflare Web Analytics — a privacy-friendly, cookieless analytics service that reports only aggregate traffic (visitor counts and page views). It does not set advertising cookies, does not track you across other websites, and does not store information that identifies you personally.
We retain personal information for as long as your account is active or as needed to provide the Service. When you delete your account, the deletion is scheduled seven days out; your access ends immediately and you can restore the account by signing back in and choosing "Restore my account" at any point in that window. After the seven days elapse we permanently delete your account, fields and boundaries, soil tests, prescriptions, documents, and any workspaces you own that no one else is a member of, and we cancel any paid plan.
We keep billing and invoice records after deletion because tax and accounting law requires it. We also keep, in anonymized form, content that belongs to other people rather than to you — messages you sent in a shared team conversation, fields you drew in a workspace somebody else owns (together with their soil tests, prescriptions and documents), and data inside an organization shared with you by an equipment manufacturer, stay with those owners, with your name removed. Anything you transfer to another person stays with them.
Photos and voice messages are the exception, and they go the other way: any you attached to a conversation are deleted with your account, even though the message they were attached to stays. A voice message is a recording of you speaking, and removing a name from it would not make it anonymous.
One exception keeps your name, and we state it plainly rather than leave you to find out later. If you worked on another grower’s farm as their agronomist, that farm owner keeps their own record of what you did there — the action, the date, and the display name on your account. That record is their audit trail of who worked their fields; only they can read it, and your name stays on those entries. We do not strip it, because closing your account should not quietly erase somebody else’s account of who worked their land.
We also keep the anonymous internal sign-in identifier your deleted account used — not your email, name or any content, and meaningless outside our sign-in provider — solely so a sign-in session issued before the deletion cannot quietly recreate the account afterwards. Signing up again always starts a genuinely new account. We may otherwise retain limited information as required by law, to resolve disputes, to enforce our agreements, or in routine backups for a limited time.
If you use the Service as a guest, closing the guest session ends it and we delete or anonymize the personal information it held within a reasonable period, subject to the same limited retention exceptions described above. We may also delete inactive guest sessions after a defined period of inactivity to free storage and protect your privacy.
Connected-platform data — termination commitment. If a connection to an integrated agricultural platform is terminated — by you, by the platform, or by us under our agreement with that platform — we will destroy all platform-sourced data we hold (including cached organizations, fields, field operations, and uploaded soil and prescription map layers), along with the encrypted access and refresh tokens associated with that connection, within ten (10) days of termination. We can provide written proof of destruction on request.
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, encryption of connected-platform access tokens at rest, identity-provider-managed password hashing, role-based access controls, and audit logging. No system is perfectly secure; we cannot guarantee absolute security. If you believe your account has been compromised, contact us at zoneforge@zoneforgetech.com.
Breach notification. In the event of a confirmed personal-information breach affecting your account, we will notify you without undue delay and no later than seventy-two (72) hours after discovery, where notification is feasible and not prohibited by law enforcement or other lawful order. Notice will describe the nature of the breach, the categories of information affected, the steps we are taking in response, and the steps you can take to protect yourself.
Access and update. You can review and update your account information from your account settings or by contacting us.
Delete your account. You can delete your account and its associated User Content from inside the app, on any device: go to Profile → Delete my account. We walk you through what will be deleted, offer you a copy of your data first, and — if you own a workspace other people are working in — help you hand it to one of them, since deleting it would take their work with it. The deletion is then scheduled seven days out, as described in Section 5, and you can undo it at any time in that window.
If you would rather we do it for you, email zoneforge@zoneforgetech.com. We will verify your identity before honoring the request, and it follows the same seven-day process and the same retention limits in Section 5.
Disconnect a third-party integration. You can disconnect connected agricultural platforms or other services from the Settings page in the Service. Disconnecting stops further data exchange but does not on its own delete data already imported.
Marketing communications. You can opt out of marketing emails using the unsubscribe link in any such email or by contacting us. Opting out does not affect transactional or service messages.
Zone Forge applies the following policies whenever a government, law enforcement, or other public authority requests personal information about a user.
Required review of legality. We review every request to determine whether it is legally valid and properly issued before taking any action. We do not comply with requests that are facially invalid or that exceed the requesting authority's jurisdiction.
Challenging unlawful requests. Where a request is overbroad, lacks proper legal basis, or appears unlawful, we will object, narrow, or formally challenge the request — through counsel where appropriate — rather than comply.
Data minimization. When we do comply with a lawful request, we disclose only the specific personal information the request covers. We do not voluntarily provide additional account data beyond what is legally required.
Documentation. We maintain an internal log of public-authority requests we receive, including the requesting authority, the legal instrument relied on, the data requested, our response, and the legal reasoning applied.
User notice. Where permitted by law, we will notify the affected user of a request for their personal information so they have an opportunity to seek protective relief.
If you are a California resident, the California Consumer Privacy Act and related laws give you additional rights. We have summarized them here and we will honor verifiable requests as required.
Categories of personal information. In the past twelve months we may have collected the following categories of personal information about California residents: identifiers (such as email address, account ID, phone number, and date of birth); customer records (such as name, mailing address, and password hash); commercial information (such as records of products purchased, where applicable); internet or other electronic network activity (such as usage logs); geolocation information, including field boundaries and similar agricultural geography that you upload and, where you have granted location permission, your device’s precise location; audio and visual information (such as photos and voice messages you attach to a team conversation); the contents of communications you send through the Service (such as messages in a shared team conversation); and inferences drawn from the above to provide the Service. We collect these categories from you, from third-party providers like our identity and integration partners, and automatically from your device.
Sensitive personal information. Some of the categories above count as sensitive personal information under California law: your device’s precise geolocation; the contents of communications you send through the Service where Zone Forge is not the intended recipient — a message to a teammate, together with any photo or voice message attached to it; and your account log-in credentials. Your password is handled by our identity provider and we keep only a secure hash of it, and we never receive or store your card number, which goes directly to our payment processor. We collect and use these categories only to provide the features described in Section 1 and to keep the Service secure. That includes passing them to the providers named in Section 3 where the feature needs it — your coordinates to the weather, mapping and parcel services, and a voice message to our AI provider when you or a teammate asks for a transcript. We do not use them to infer characteristics about you, we do not sell them, and we do not share them for cross-context behavioral advertising. We do not create voiceprints or face templates, so we do not collect biometric information for the purpose of identifying you.
Purposes. We use the categories above for the purposes described in Section 2 of this Privacy Policy.
No sale; no sharing for cross-context behavioral advertising. We do not sell personal information and we do not share it for cross-context behavioral advertising.
Your rights. Subject to verification, you have the right to (a) know what personal information we have collected about you, the sources, the purposes, and the categories of recipients; (b) request a copy of your personal information; (c) request correction of inaccurate personal information; (d) request deletion of your personal information, subject to the retention exceptions described in Section 5; (e) limit our use and disclosure of your sensitive personal information; and (f) be free from discrimination for exercising these rights.
Submitting a request. Email zoneforge@zoneforgetech.com with the subject line "California Privacy Request." We may need to verify your identity before responding.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We may require written authorization and may verify the agent's identity and authority.
The Service is not directed to children under 18 and we do not knowingly collect personal information from children under 18. If you believe a child has provided us personal information, contact us at zoneforge@zoneforgetech.com and we will take appropriate action.
We may update this Privacy Policy from time to time. Material changes will be communicated by posting an updated version with a new effective date and, where appropriate, by emailing the address associated with your account.
For questions, concerns, or to exercise the rights described above, email zoneforge@zoneforgetech.com.
Zone Forge Technologies, LLC
Delaware, United States