Last updated: 29 July 2026
DForge (“DForge”, “we”, “us”) is a no-code website builder for the Deriv API. It lets you create, configure, and publish trading websites without writing code, and it handles the hosting behind those sites. The trading on them is powered by Deriv.
This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what control you have over it. It applies to dforge.site, home.dforge.site, and the DForge dashboard and APIs served from those domains.
Sites that DForge customers publish on their own custom domains are operated by those customers. DForge processes data on their behalf as described in section 9, but those site operators are responsible for their own privacy notices.
We collect the following categories of data:
Your name and email address, and — where you sign in with Google — the basic profile information Google returns. DForge does not store your password.
You can link a Deriv account to DForge. Linking happens on Deriv’s own authorisation screen and simply confirms to us that you hold a Deriv account. From it we receive your Deriv account identifiers, email address, and name, which we store to map your DForge account to your Deriv one.
DForge does not trade on your behalf, does not access your balances, and does not act on your Deriv account. We never receive your Deriv password. You can remove the link at any time from your Deriv account settings or from the DForge dashboard.
The content and settings of the sites and bots you build: branding, copy, images, domain names, trading parameters, markets, payment settings, and deployment history. This is the material your published site is generated from.
Pages viewed, features used, referral and marketing attribution parameters, approximate location derived from IP address, browser and device type, timestamps, and error diagnostics. We use this to keep the service working, detect abuse, and understand which features are worth building on.
Transaction amounts, currency, status, timestamps, the M-Pesa phone number or Paystack reference used, and the resulting receipt identifiers. See section 4.
We do not sell your personal data, and we do not share it with third parties for their own independent marketing.
DForge accepts payments through M-Pesa (via Safaricom’s Daraja API) and Paystack. Both are independent payment processors.
DForge never stores your card details. Card numbers, expiry dates, and CVV codes are entered directly into Paystack’s hosted checkout and are handled entirely by Paystack; they never reach DForge servers. For M-Pesa, the payment is authorised on your own handset via the Safaricom STK prompt — we receive only the phone number, amount, and the transaction result.
We retain the resulting transaction records (amount, currency, status, reference, timestamp) because we need them for accounting, refunds, dispute handling, and tax compliance.
We share data with a small number of service providers, and only what each one needs to do its job:
These providers are bound by contract to process your data only for the purposes above and not for their own. Some operate outside your country, so your data may be processed abroad.
We may also disclose data where we are legally required to, or where it is necessary to establish, exercise, or defend legal claims.
We use the Meta Pixel (pixel ID 834400099316769), a tracking technology provided by Meta Platforms, Inc. It runs on dforge.site and home.dforge.site.
The pixel places cookies and sends Meta information about your visit, such as the pages you view, actions like registering, your IP address, and your browser and device. We use it to measure how our advertising performs and to reach people who have visited our site.
We also send some of these events to Meta directly from our servers under the same pixel ID, so that measurement still works when the browser pixel is blocked. Where we have them, your contact details are included in hashed form, so Meta does not receive them in readable form. Because this does not rely on your browser, blocking the pixel alone will not stop it — email support@dforge.site to opt out.
Meta processes this data as described in the Meta Privacy Policy. You can control how Meta uses your data for advertising through Meta’s ad settings, and you can block the pixel entirely with a browser that blocks third-party trackers or with a content blocker.
We keep account details, site configuration, and linked Deriv account records for as long as your account is active. If you delete your account, we delete or irreversibly anonymise this data within 30 days, and the link to your Deriv account is removed immediately.
Payment and transaction records are kept for seven years after the transaction, because tax and accounting law requires it. Server and security logs are kept for up to 12 months. Aggregated statistics that can no longer identify you may be kept indefinitely.
Sites built with DForge are powered by Deriv. All trading and all transactions on those sites are carried out by Deriv through the Deriv API. DForge does not execute trades and does not process trading transactions.
When you publish a site with DForge, visitors to that site may create end-user accounts, link their own Deriv accounts, and make payments. In that arrangement you are the operator of the site and we process that data on your behalf.
If you operate a site, you are responsible for publishing your own privacy notice, for having a lawful basis to process your visitors’ data, and for honouring their access and deletion requests. If you are a visitor to a site built with DForge and want your data removed, contact the operator of that site first; you can also write to us at support@dforge.site and we will help route the request.
You can ask us to:
Email support@dforge.site from the address on your account and we will respond within 30 days. We may ask you to verify your identity before acting on a request.
Data is transmitted over encrypted connections and stored with access controls and encryption at rest. Access to personal data is limited to the people and systems that need it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
DForge is not intended for anyone under 18, and trading with the Deriv API is restricted to adults. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
We may update this policy as the service changes. The “last updated” date at the top always reflects the current version. If a change materially affects how we handle your data, we will notify account holders by email before it takes effect.
Questions about this policy, or requests about your data, go to: