Last updated: March 22, 2026
Privacy Policy
Foreko Inc. (“Foreko,” “we,” “our,” or “us”) is committed to protecting the privacy and security of your business data. This Privacy Policy explains how we collect, use, store, and safeguard information when you use our AI-powered procurement and demand forecasting platform.
1. Scope
This policy applies to all users of the Foreko platform, including customers, authorized users within customer organizations, and visitors to our website (foreko.app). By accessing or using Foreko, you agree to the practices described in this policy.
2. Information We Collect
2.1 Account & Identity Data
Name, email address, job title, and company name provided during account creation or provisioning by your organization's administrator.
2.2 Business & Operational Data
Data you import or connect to Foreko — including inventory records, sales history, purchase orders, supplier information, and demand signals — solely for the purpose of powering your organization's machine learning models and analytics. This data is never shared with, or used to train models for, any other customer or third party.
2.3 Usage Data
Log data, feature usage patterns, session metadata, and error reports used to operate, improve, and secure the platform. This data is aggregated and does not include your business content.
2.4 Authentication Data
Session tokens, two-factor authentication records, and IP addresses used for identity verification and security monitoring. Passwords are hashed using industry-standard bcrypt and are never stored or transmitted in plaintext.
3. How We Use Your Data
- Providing the service: Running demand forecasts, reorder recommendations, and procurement analytics for your organization using models trained exclusively on your data.
- Security & fraud prevention: Detecting unauthorized access, monitoring for anomalies, and enforcing rate limits.
- Product improvement: Analyzing aggregated, de-identified usage patterns to improve platform performance and features.
- Communications: Sending transactional emails (verification codes, password resets, product updates) to authorized users.
- Legal compliance: Retaining records as required by applicable law.
We do not sell, rent, or share your business data with third parties for marketing or advertising purposes.
4. Data Isolation & Machine Learning
Foreko builds and maintains individual machine learning models per customer organization. Your data is used exclusively to train and run models that serve your organization. No customer's data is commingled with another's, and no cross-customer learning or model sharing occurs. Each organization's models and data are logically isolated at the database and compute layer.
5. Data Retention
We retain your business data for the duration of your subscription and for up to 90 days following termination to allow for data export. Authentication logs and security records are retained for 12 months. You may request earlier deletion by contacting us at privacy@foreko.app.
6. Security
Foreko is designed with security as a core principle and is pursuing SOC 2 Type II certification. Our security measures include:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Two-factor authentication (2FA) enforced for all platform logins
- Role-based access controls limiting data access to authorized users
- Continuous security monitoring and anomaly detection
- Regular vulnerability assessments and dependency patching
- Isolated customer environments at the database layer
See our Security Policy for full details.
7. Third-Party Services
Foreko uses a limited set of third-party infrastructure providers to operate the platform, including cloud hosting, payment processing (Stripe), and transactional email. These providers are contractually bound to process data only as directed by Foreko and may not use your data for their own purposes. We do not use third-party analytics or advertising trackers within the authenticated platform.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your personal data
- Object to or restrict certain processing activities
- Receive a portable copy of your data
To exercise any of these rights, contact us at privacy@foreko.app. We will respond within 30 days.
9. International Transfers
Foreko operates in the United States. If you access the platform from outside the U.S., your data may be transferred to and processed in the U.S. We implement appropriate safeguards for such transfers in accordance with applicable law, including standard contractual clauses where required.
10. Changes to This Policy
We may update this Privacy Policy as our practices evolve. We will notify active users of material changes via email at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.
11. Contact
For privacy-related inquiries, data requests, or to report a concern:
