Legal

Privacy policy

Last updated

In plain language

We store the submissions your forms receive, deliver them to you, and delete them when your plan’s retention window ends. We do not sell data, we do not use advertising trackers, and we do not read your submissions unless you ask us to for support.

For your visitors’ data, you are in charge and we act on your instructions. You can export or delete any of it yourself, at any time.

01Who controls the data

There are two different relationships in play, and they matter for who is responsible for what.

  • Your account data. For the email address, password, and billing details you give us to run your account, we are the controller. We decide what is collected and why.
  • Your form submissions. For the data your visitors type into your forms, you are the controller and we are the processor. We store and deliver it on your instructions and do not decide what your forms collect.

This means that if one of your visitors asks you to delete what they submitted, you can do that yourself from the inbox, and you do not need our involvement.

02What we collect

Account data. Your email address, a hashed password, your workspace name, and your plan. If you subscribe to a paid plan, our payment processor handles card details and we never see or store the card number.

Submission data. Whatever fields your form contains. We do not choose these, you do. Alongside the field values we record the time it was received, the form it arrived on, the originating page, and technical metadata used for spam filtering and rate limiting, including the sending IP address.

Operational logs. Request logs and email delivery results, used to debug failures and to show you why a notification did not arrive.

We do not use advertising trackers, we do not sell data, and we do not build profiles of your visitors.

03Why we process it

  • To provide the service. Receiving, storing, and delivering submissions is the product. Without processing them there is nothing to deliver.
  • To keep it working. Spam filtering, rate limiting, and abuse prevention protect both your inbox and the shared infrastructure.
  • To bill you. Usage counts against your plan and paid plans require payment records.
  • To contact you. Service notices, delivery failures, and quota warnings. These are operational, not marketing.

04How long we keep it

Submissions are retained for a window that depends on your plan. When the window elapses the submission is permanently deleted, including from the spam view, and it cannot be restored by support.

PlanSubmission retention
Free30 days
Pro1 year
AgencyUp to 3 years

Account data is kept while your account is open. If you delete your account, account data and all stored submissions are removed. Export anything you need first, because deletion is not reversible. Billing records are kept for as long as tax and accounting law requires, which is separate from submission retention.

05Who can see it

Submissions are scoped to the workspace that owns the form. Queries enforce this at the data layer rather than filtering in the interface, so a form or submission belonging to another account returns a not-found response instead of data.

Our staff do not read submissions as a matter of course. Access happens only when you ask for support that requires it, or where we are compelled to by law.

We use third-party infrastructure providers for hosting, database, and email delivery. They process data on our instructions in order to run the service. We do not share submission data with anyone else, and we do not sell it.

06How it is protected

Traffic is encrypted in transit over HTTPS. Passwords are hashed, never stored in a recoverable form. Submitted values are treated as plain text everywhere in the product, never rendered as markup, which removes an entire class of injection attack.

Your form endpoint key appears in client-side HTML and is therefore public by design. It is an address, not a credential. Forms are protected by origin restriction, rate limiting, and spam filtering. There is more detail on the security page.

07Your rights and choices

Depending on where you live you may have rights to access, correct, export, or delete personal data we hold about you, and to object to certain processing. You can exercise most of these yourself:

  • Export. Every stored submission can be exported to CSV from the dashboard at any time.
  • Delete. Individual submissions, whole forms, and your entire account can be deleted from the dashboard.
  • Correct or access account data. Email us and we will help.

If one of your visitors contacts us directly about data they submitted through your form, we will refer them to you, because you are the controller of that data.

08Cookies

We set a session cookie when you sign in. It is strictly necessary to keep you authenticated, and the product does not work without it.

We do not use advertising or cross-site tracking cookies, and we do not embed third-party trackers in the pages your visitors see. Your form posts to an endpoint. It does not load a script that follows people around.

09Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change meaningfully affects how your data is handled, notify account holders by email. Continuing to use the service after a change means the updated policy applies.

Questions

For privacy questions, data requests, or anything a procurement team needs, email privacy@maketheform.com.

Contact us