retireforge

Privacy policy

Draft — pending attorney review
DRAFT — PENDING ATTORNEY REVIEW. The text below is a working draft only. It has not been reviewed or approved by counsel, is not final, and must not be relied on as binding legal language until an attorney signs off. Every open legal determination is flagged inline as Pending counsel review.

1. Who this covers

This policy describes how RetireForge ("we", "us") handles data submitted by advisory firms, their personnel, and the retirement plan sponsors and participants whose plan data those firms enter into the platform, while RetireForge is in a closed early-access program with a small number of participating advisors.

Pending counsel review: confirm the correct contracting entity name and registered address for this notice, and whether a separate participant-facing notice is required once the platform reaches the participant recordkeeping phase (Master Build phase 3).

2. Categories of data we collect

  • Advisor/user account data: name, email address, and organization membership, managed through our authentication provider (Clerk).
  • Retirement plan business data: plan and sponsor identifiers (EIN/PN), plan design terms, asset and participant counts, fee schedules, and related documents an advisor uploads or that are sourced from public DOL Form 5500 filings.
  • Census and participant personal data: when an advisor uploads a plan census, this can include name, Social Security number, date of birth, compensation, and prior-year FICA wages.
  • Audit and activity logs: a record of actions taken in the platform (who did what, when), kept for security and fiduciary-process transparency.
Pending counsel review: confirm whether any additional disclosure is required for data sourced from public DOL Form 5500 filings, and finalize language on cookies/analytics once a specific analytics vendor (if any) is selected.

3. How sensitive fields are protected

The Social Security number, date of birth, compensation, and prior-year FICA wages fields on a plan census are encrypted at rest using field-level AES-256-GCM encryption — each field is encrypted individually before it is written to the database, not merely protected by disk- or database-level encryption. Access to these fields is scoped by tenant (organization) and logged in our audit trail.

RetireForge maintains internal control evidence and testing practices consistent with pursuing a SOC 2 report. As of this draft, RetireForge has not completed a SOC 2 audit and does not hold a SOC 2 certification — this sentence must not be read as a certification claim.

Pending counsel review: confirm the precise, attorney-approved phrasing for describing our security posture (avoid any implication of certification we do not hold), and confirm data-subject rights language (access, correction, deletion) applicable to the jurisdictions of our early-access participants.

4. Where data is hosted

Application data is hosted on Supabase-managed PostgreSQL in the us-west-1 AWS region. The web application is deployed on Vercel. Both are listed, with the data categories shared with each, on our subprocessor register.

5. Data sharing

We share data only with the service providers necessary to operate the platform (our subprocessors), and only to the extent needed to provide the service. See the subprocessor registerfor the current list, each vendor's purpose, and the data categories shared with it. We do not sell personal data.

6. Retention

Pending counsel review: define and document a real, attorney-reviewed retention schedule (per data category — account data, census PII, audit logs) rather than an invented time period. No retention period is stated in this draft pending that determination.

7. Contact

Pending counsel review: add a real privacy-inquiries contact address/process once determined.
Copyright (c) 2026 RetireForge. All rights reserved.Back to the app