Privacy Policy

Last updated: October 19, 2025

TL;DR

We collect the minimum personal data necessary to operate FormCraft (account email, profile). We do not sell your data. You can request data export or deletion anytime.

1. What We Collect

Account Information

Email address, display name, avatar (optional), and authentication metadata from your sign-in provider (Google, email/password).

Form Responses

When users submit forms, responses are stored for the form owner to review. Owners control retention and export via the dashboard.

Metadata

Timestamps, IP addresses (limited retention), user agent strings, and basic device info for security and abuse detection.

2. How We Use Data

  • Provide and improve our services (auth, forms, analytics)
  • Security and abuse prevention
  • Customer support and communications
  • Legal obligations and responding to lawful requests
  • Analytics to understand usage patterns (anonymized)

3. Data Sharing & Third Parties

We may use subprocessors for email delivery, analytics, and hosting (e.g., Vercel, Firebase). Subprocessors are contractually required to protect data. We never sell your personal data to third parties.

4. Data Retention

Account data is kept until you delete your account. Form responses are retained until the owner deletes them or a retention policy applies. Deleted data is permanently removed within 30 days.

5. Security

We apply industry-standard controls: TLS encryption in transit, encrypted storage for sensitive data, regular security audits, and access controls. No system is perfect — report security incidents to shawprem217@gmail.com.

6. Your Rights

Depending on your jurisdiction, you can request:

  • Access — a copy of personal data we hold about you
  • Rectification — correct inaccurate information
  • Deletion — erase your personal data
  • Restriction / objection — limit or object to certain processing
  • Data portability — export your data in a machine-readable format

To exercise these rights, contact shawprem217@gmail.com. We'll verify your identity before responding.

7. International Transfers

Data may be processed or stored outside your country where our services or subprocessors operate. We use standard contractual clauses where required by law.

8. Children's Privacy

We do not knowingly collect personal data from children under 16. If you believe we have such data, contact us immediately for removal.

9. Changes to This Policy

We'll post updates here with a new "Last updated" date. Significant changes will be communicated through email when feasible.

10. Contact

Privacy inquiries: shawprem217@gmail.com