This Privacy Policy describes how Joseph Ferrieri ("we," "us") handles information in War room, our private operations dashboard, and related integrations.
Last updated: June 4, 2026
Who this applies to
War room is for authorized team members only—not a public consumer website. This policy also covers personal information about prospects and clients that enters the system through connected site forms, inbox ingest, or manual entry by operators.
Information we collect
- Operator accounts. Login uses Supabase Auth (email and credentials). We may use Cloudflare Turnstile on login to reduce abuse.
- Operational data. Client records, work requests, inbox threads, tasks, and related notes stored in our PostgreSQL database.
- Inbox ingest. Contact and booking submissions from connected marketing sites may arrive via our ingest API and be linked to client records.
- Integrations. Optional connections (such as Notion, Vercel, ad platforms) may sync metadata needed to operate client work.
- Technical logs. Hosting and security logs (IP address, request metadata) for reliability and rate limiting.
How we use information
- Authenticate operators and enforce access controls
- Manage client work, requests, and internal communications
- Sync operational data with approved third-party tools
- Protect the platform (rate limits, audit trails, incident response)
Sharing with service providers
We use trusted infrastructure providers including Supabase (auth/database), Vercel (hosting), and other subprocessors required to deliver client services. They process data under their own policies and only as needed for our operations.
We do not sell personal information processed through War room.
Retention
Operator and client records are kept as long as needed for active work, legal obligations, and dispute resolution, then deleted or archived when no longer required.
Your choices
Data subjects may contact joe@ferrieriforge.com to request access, correction, or deletion where applicable law requires. Operators should use internal settings or contact the administrator for account issues.
Security
Access is restricted to authenticated operators. Sensitive credentials are stored in environment configuration, not in client-facing pages. See our engineering security baseline for implemented controls.
Changes
We may update this policy from time to time. The "Last updated" date at the top will change when we do.
Related policies
See also our Terms of Use.