Privacy notice
Privacy Notice
Notice version: cfg-privacy-2026-08-13-v1 · Effective date: August 13, 2026
Cornerstone Forge Group (“CFG,” “we,” “us,” or “our”) respects your privacy and seeks to handle personal information with care, integrity, and responsible stewardship.
Information We Collect
When you submit CFG’s general inquiry form, we collect: your name; your email address; an optional message; technical and source information associated with the submission, such as the referring page or campaign information when available; and records needed to authenticate, process, audit, secure, and troubleshoot the inquiry. CFG’s initial inquiry form does not request a phone number.
Why We Collect It
We use this information to receive, review, and respond to your inquiry; route the inquiry to an appropriate authorized CFG operator; maintain accurate relationship and source records; prevent spam, abuse, duplicate processing, and security incidents; monitor, reconcile, and improve the reliability of CFG’s systems; and meet applicable operational, legal, and governance responsibilities. Submitting a general inquiry gives CFG permission to respond to that inquiry. It does not provide marketing consent and does not enroll you in a marketing campaign or newsletter.
How Information Is Handled
CFG uses authorized technology providers to operate this process. These may include Framer for the public website and inquiry form; CFG Integration Core for secure coordination, identity, audit, and reconciliation; Supabase/PostgreSQL for CFG-controlled application records; DigitalOcean for application hosting; Notion for minimized, authorized operational visibility; and Brevo for permitted inquiry-response contact synchronization. Each provider is intended to receive only the information needed for its approved purpose. CFG does not place database credentials or privileged provider secrets in the public website. Information may be processed in jurisdictions where an authorized provider operates, subject to applicable provider safeguards and CFG’s contractual, privacy, residency, and governance decisions.
Consent and Communications
The V1 general inquiry form records inquiry-response permission only. CFG does not interpret submission of this form as consent to marketing. Marketing consent, if introduced later, will require a separate and explicit choice. Spam-marked or suspicious submissions may be quarantined for review and will not automatically trigger downstream communication.
Retention
CFG currently preserves inquiry, attribution, consent, operational, and audit records without automated deletion while professionally reviewed retention requirements are being established. This is a temporary V1 governance posture, not a permanent commitment to indefinite retention. CFG intends to adopt appropriate retention and deletion requirements as its legal, privacy, accounting, operational, and multi-jurisdiction obligations are confirmed.
Security
CFG uses reasonable technical and organizational measures intended to protect inquiry information, including encrypted connections, access controls, least-privilege provider access, protected credentials, audit records, retry-safe processing, monitoring, backup, and recovery procedures. No system can guarantee absolute security.
Access, Correction, and Privacy Inquiries
To ask about personal information submitted to CFG, request correction, or raise a privacy concern, contact Cornerstone Forge Group at hello@cornerstoneforgegroup.com. CFG may need to verify a requester’s identity before acting on a request.
Changes to This Notice
CFG may update this notice as its operations, providers, jurisdictions, or governance requirements develop. Material revisions will receive a new notice version and effective date. The notice version associated with an inquiry is preserved so CFG can identify which notice applied when the inquiry was submitted.