This Privacy Policy explains how FormFlow ("we", "us") handles personal data. FormFlow is a headless form backend: our customers point their own HTML forms at a FormFlow URL, and we receive, filter, store, and forward the resulting submissions.
1. Our two roles
FormFlow handles two different kinds of data in two different roles:
- Account data — we are the controller. Information about our customers (the people who hold FormFlow accounts) and their billing. We decide how and why it is used.
- Submission data — we are the processor. The contents of the forms our customers collect. The customer decides what is collected and why; we process it on their behalf and on their instructions.
The people who fill out a customer's form are "Submitters". If you are a Submitter and want to exercise your rights over data you provided, contact the customer whose form you used — they control that data. We will assist that customer as their processor.
2. Account data we control
When you create and use a FormFlow account, we hold:
- Identity: your name, email address, and a securely hashed password.
- Team and billing: your team name, plan, billing contact email, and Paddle customer and subscription references. We never store full card numbers; Paddle handles payment details.
- Usage: records needed to run the service, such as when submissions were received and read.
We use this data to provide and secure the service, to bill you, to send service and transactional emails, and to comply with our legal obligations. We keep it for as long as your account is open, and then as described in section 6.
3. Submission data we process
For each submission received at a customer's form, we process:
- The form payload — the field values the Submitter entered. This is defined entirely by the customer's form; we do not read inside payloads to repurpose them.
- Request metadata — a one-way, HMAC-keyed representation of the Submitter's IP address (we never store the raw IP), the browser user-agent, and the request origin. This metadata supports spam filtering.
We process submission data only to provide the service to the customer: filtering spam, storing submissions, and delivering them to the customer's chosen destinations. The HMAC-keyed IP and user-agent are automatically purged after 30 days. When a customer deletes a form, its submissions are deleted with it.
Refused submissions. When a customer's own settings cause us to reject a submission — a schema rule it did not satisfy, a site not on their allowlist — we keep the same data for the same 30 days, so the customer can see what was refused and why, and recover it if the rejection was a mistake on their part. Refused records are deleted outright at the end of that window rather than kept in a reduced form.
Preflight stalls. When a Submitter has answered a field, FormFlow has shown one of its own error messages, and that attempt does not go on to submit, we may keep the Form, field name, error message, and a short-lived random attempt key so the customer can see which setting deterred people. We do not store the answer, raw IP, HMAC-keyed IP, or browser user-agent for a stall. A later passing check or submission resolves it immediately; otherwise it becomes abandoned after the configured period (30 minutes by default) and is deleted with the other form evidence after 30 days.
4. Cookies
FormFlow uses strictly necessary cookies to keep you signed in and to protect against request forgery. Our spam protection uses Cloudflare Turnstile, which may set its own cookies when a form is submitted. With your consent, FormFlow uses Google Analytics on the FormFlow landing page to understand aggregate page views; it runs only after you allow analytics. Google Analytics may set first-party cookies such as _ga and receives page-view and browser/device information for that purpose. The measurement sends no account, Team, Form, Submitter, or Submission data to Google Analytics. You can change your choice at any time with the Privacy choices control on the landing page. We do not use advertising or cross-site tracking cookies.
5. Service providers, Paddle, and international transfers
Paddle is the merchant of record and an independent controller for payment, tax, fraud-prevention, invoice, refund, and chargeback data. Paddle is not FormFlow's subprocessor for those purposes. Its own privacy notice governs that processing.
We share data with a small number of service providers who process it on our behalf:
- Cloudflare Turnstile — bot and spam verification (a Submitter's IP and browser signal at submission time).
- Hostinger — hosting and database infrastructure, and delivery of submission digests and transactional emails, which may include submission contents the customer chose to be notified about.
- Google Analytics — aggregate page-view measurement for the FormFlow landing page after a visitor allows analytics. See Google's Privacy Policy.
These providers may process data outside the United Arab Emirates. Where they do, we rely on appropriate safeguards for the transfer. A Data Processing Addendum listing our subprocessors is available to customers on request at info@formflow.digital.
6. Data retention and account closure
We keep account and submission data while your account is open. If you close your account we retain your data for 30 days — so you can return or export it — and then permanently delete it, with backups aging out on their normal cycle. You can delete forms and their submissions yourself at any time, and we will honour a verified deletion request sooner where you ask us to.
Ending or canceling a paid subscription moves the Team to the Free plan and does not close the account or begin deletion. Only an explicit account-closure request starts the 30-day closure period.
7. Security
We protect data with measures including password hashing, one-way HMAC keying of Submitter IP addresses, encryption of traffic in transit, and access controls. No system is perfectly secure, but we work to protect data proportionately to its sensitivity.
8. Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your account data, and you may object to or restrict certain processing. To exercise these rights over your account data, contact us at info@formflow.digital. If your data was submitted through someone else's form, that customer is the controller — contact them, and we will support them as their processor.
9. Children
FormFlow is not directed at children and is intended for account holders aged 18 or over. Customers must not use their forms to knowingly collect data from children without appropriate consent.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and change the "last updated" date above.
11. Contact
For any privacy question, or to exercise your rights, contact us at info@formflow.digital.