Privacy Policy
Last updated: July 17, 2026
SKUforge ("we", "our", "us") operates the website skuforge.ai and the platform at studio.skuforge.ai. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our services.
1. Information we collect
Account information
When you register, we collect your full name, company name, email address, phone number, and password (stored as a secure hash).
Usage data
We collect information about how you use the platform, including job submissions, SKU processing history, wallet transactions, and feature usage patterns.
Product images
Images you upload for catalog processing are temporarily stored for AI analysis. We do not claim ownership of your product images.
Payment information
Payment transactions are processed through Razorpay and Stripe. We do not store your credit card or bank details directly — these are handled by our payment partners under their own security standards (PCI-DSS compliant).
Analytics data
We use Google Analytics and Microsoft Clarity to understand how users interact with our website and platform. These tools collect anonymous usage data such as pages visited, session duration, device type, browser, approximate location (country/region), and interaction patterns. This data helps us improve the product experience.
2. Google services and third-party account access
Google Drive integration (optional)
SKUforge offers optional integration with your Google Drive account for uploading and hosting product images. Connecting Google Drive is entirely optional — the platform works without it using our default image storage.
When you choose to connect your Google Account, we request access using the drive.file OAuth scope. This is a narrow, non-sensitive scope that only allows SKUforge to access files it creates itself within a "SKUforge" folder in your Drive. Specifically:
- SKUforge cannot read, see, or modify any of your existing files in Google Drive
- SKUforge can only upload new files it creates, and only manage those specific files afterwards
- We store your Google OAuth access token and refresh token securely in our database so we can upload images on your behalf and refresh access when the token expires
- We store your Google account email address to display the connected account name in your Settings
- You can disconnect Google Drive at any time from your SKUforge Settings page, or by revoking access directly at myaccount.google.com/permissions. When you disconnect, we mark your credentials inactive and stop using them.
Limited Use disclosure (Google API Services User Data Policy)
SKUforge's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we commit to the following:
- We only use Google user data to provide the catalog automation and image storage service you signed up for
- We do not transfer Google user data to third parties except as necessary to provide the service, for security purposes, or to comply with applicable law
- We do not use Google user data for advertising or to build advertising profiles
- We do not allow humans to read Google user data, except (a) with your explicit consent, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data is aggregated and used for internal operations in accordance with applicable privacy rules
3. How we use your information
- To provide and maintain the SKUforge platform and services
- To process your catalog automation jobs using AI engines
- To manage your account, wallet balance, and transactions
- To upload and host your product images on the storage provider you have selected (our default storage or your connected Google Drive)
- To send verification codes during registration (via SendGrid for email, Twilio for SMS)
- To send service-related notifications (job completion, account updates, low balance alerts)
- To improve AI accuracy using anonymized correction data from the Editor
- To analyze aggregate usage patterns and improve the product
- To respond to support requests
4. Data sharing
We do not sell your personal data. We share data only with the following categories of service providers, and only to the extent necessary to operate the platform:
- AI providers (Google Gemini, OpenAI, Anthropic Claude, DeepSeek) — product images are sent for analysis. These providers process data under their own privacy policies and enterprise data-use terms.
- Image storage providers (ImageKit, Dropbox, Cloudinary, ImgBB, and your own connected Google Drive if enabled) — for hosting uploaded product images. If you connect your own Google Drive, images are uploaded to your Drive account, not ours.
- Email & SMS (SendGrid, Twilio) — for sending verification codes and notifications
- Payment processors (Razorpay, Stripe) — for processing wallet top-ups
- Analytics providers (Google Analytics, Microsoft Clarity) — for anonymous usage analytics only. These providers may set their own cookies as described in the Cookies section below.
- Hosting infrastructure (Railway, Vercel, Cloudflare) — for platform infrastructure and content delivery
5. Data storage and security
Your data is stored on PostgreSQL databases hosted on Railway (cloud infrastructure). We use HTTPS encryption for all data in transit, secure password hashing (bcrypt), and JWT-based authentication tokens. OAuth tokens for connected Google Drive accounts are stored as JSON in our database and are accessible only to the SKUforge backend service. Access to production databases is restricted to authorized personnel only.
6. Data retention
Account data is retained as long as your account is active. Job history and processed catalog data are retained for 12 months unless you request earlier deletion. Google OAuth tokens are retained until you disconnect Google Drive from Settings or revoke access from your Google account. You can request deletion of your account and all associated data at any time by contacting hello@skuforge.ai — we will delete or anonymize your data within 30 days of your request, subject to any legal retention obligations.
7. Your rights
Under applicable Indian data protection laws (DPDP Act 2023) and international regulations, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your personal data
- Withdraw consent for data processing
- Request a copy of your data in a portable format
- Disconnect any third-party account (such as Google Drive) at any time
To exercise any of these rights, contact us at hello@skuforge.ai.
8. Cookies and tracking technologies
We use the following cookies and similar technologies:
- Essential cookies — required for authentication (JWT tokens stored in browser localStorage) and session management. The platform cannot function without these.
- Analytics cookies — set by Google Analytics (_ga, _gid and related) and Microsoft Clarity (_clck, _clsk and related) to help us understand usage patterns. These collect anonymous data and are not used for advertising.
We do not use advertising cookies, retargeting cookies, or cookies from third-party ad networks. You can control or disable cookies through your browser settings; disabling analytics cookies will not affect platform functionality.
9. Children's privacy
SKUforge is a B2B platform designed for businesses. We do not knowingly collect data from individuals under 18 years of age.
10. Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Material changes affecting how we handle Google user data will be communicated via email to affected users at least 30 days before taking effect. Continued use of the platform after changes constitutes acceptance of the updated policy.
11. Contact us
If you have questions about this Privacy Policy or our data practices, or wish to exercise any of your rights, contact us at:
SKUforge
Email: hello@skuforge.ai
Website: skuforge.ai
Location: Surat, Gujarat, India