Privacy Policy for Formulific

Last Updated: May 21, 2025

Welcome to Formulific ("us", "we", or "our"). We operate the Formulific platform and website (hereinafter referred to as the "Service").

Our Privacy Policy governs your visit to our website and use of our Service, and explains how we collect, safeguard, and disclose information that results from your use of our Service. We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, terms used have the same meanings as in our Terms of Service.

1. Definitions

  • Service means the Formulific website and platform operated by Formulific.
  • Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
  • Usage Data is data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
  • Cookies are small files stored on your device (computer or mobile device).
  • Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your Personal Data collected directly by us for account management and service provision.
  • Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively. When you use Formulific to collect data through forms you create, you are the Data Controller for that data, and Formulific acts as a Data Processor on your behalf.
  • Data Subject is any living individual who is the subject of Personal Data.
  • User is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data. This includes our direct clients and, where applicable, the clients of our Partner Agencies who use the Service through a Partner.
  • Partner Agency (or Partner) refers to a web design agency or other entity that signs up for our partner program to offer or resell our Service to their own clients.

2. Information We Collect and Use

We collect several different types of information for various purposes to provide and improve our Service to you.

2.1. Types of Data Collected

Personal Data Directly Provided by You

While using our Service (e.g., during account creation, profile updates, or when contacting us), we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you ("Personal Data"). Personally identifiable information may include, but is not limited to:

  • Email address
  • Full Name
  • Phone number (e.g., for account verification, SMS notifications if you opt-in, or password recovery)
  • Password (we store a hashed version of your password)
  • Business Name (optional for clients, often required for partners)
  • Company Name (for Partners and some Clients, e.g., when a partner requests an invoice for their client)
  • Payment information (e.g., credit card details, billing address - primarily processed by our third-party payment processor, Stripe)
  • Address, State, Province, ZIP/Postal code, City (primarily for billing purposes through Stripe).
  • Website URL (for Partners applying to the program)
  • Reason for wanting to partner with us (for Partner applications)
  • Information related to client invoicing requests if you are a Partner (e.g., client company name, contact name, email, monthly quote, number of seats)
  • Partner Access Code (a four-word code provided by clients to grant partners access)
  • Notification preferences (e.g., SMS for new submissions)

We may use your Personal Data to contact you with newsletters, marketing or promotional materials, and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send or by contacting us.

Data You Collect Through Forms (as a Client User)

If you are a client using our Service to create forms, you determine what Personal Data you collect from individuals who submit information through those forms ("Form Data"). We act as a Data Processor for this Form Data on your behalf. You are responsible for ensuring that your collection and use of Form Data comply with applicable privacy laws. This includes providing necessary notices and obtaining consents from individuals submitting data through your forms.

Form Data may include any information that your form respondents choose to provide, such as names, email addresses, phone numbers, opinions, or any other personal details. Formulific stores this data as you configure your forms.

Data Provided by Partner Agencies

If you are a Partner Agency, we collect information related to your agency, such as agency name, contact details, payment information for commissions (via Stripe Connect), and information about the clients you onboard to our Service. When a Partner Agency creates an invoice request or sets up an account for their client, they may provide us with client contact information (e.g., client company name, contact person, email).

Homepage Lead Submissions

If you submit your information (e.g., email, name, message) through a contact or trial signup form on our homepage, we collect this information to respond to your inquiry or provide requested information. We may also collect your IP address at the time of submission.

Usage Data

We may also collect information that your browser sends whenever you visit our Service or when you access the Service by or through a mobile device ("Usage Data").

This Usage Data may include information such as your computer's Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data. This data is used for analytics to improve our service.

When you access the Service with a mobile device, this Usage Data may include information such as the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers, and other diagnostic data.

Tracking & Cookies Data

We use cookies and similar tracking technologies to track the activity on our Service and we hold certain information.

Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. We use cookies for session management (e.g., `authToken` to keep you logged in) and security purposes. Other tracking technologies may also be used such as beacons, tags, and scripts to collect and track information and to improve and analyze our Service.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service, particularly authenticated areas.

Examples of Cookies we use:

  • Session Cookies: We use Session Cookies to operate our Service (e.g., to keep you logged in via `authToken`).
  • Preference Cookies: We may use Preference Cookies to remember your preferences and various settings.
  • Security Cookies: We use Security Cookies for security purposes (e.g., for CSRF protection if applicable, and to manage authentication tokens).
  • Analytics Cookies: We may use third-party Analytics Cookies to understand how our Service is used (e.g., to power the analytics dashboard).

Data Collected by SMS Service

Our SMS service, used for features like two-factor authentication (2FA) and SMS notifications for form submissions, collects and processes the following information:

  • Phone Numbers: The phone number to which an SMS is sent (for 2FA or notifications).
  • 2FA Codes: Generated 6-digit 2FA codes are temporarily stored along with the associated phone number and an expiration time (typically 5 minutes). These are deleted after successful verification or expiration.
  • Message Content: For notifications, the content of the SMS message is processed, which may include form titles or snippets of submitted data if configured by the user.
  • API Credentials: The SMS service uses API credentials for VOIP.ms (API username, password, DID number) to send SMS messages. These are stored as environment variables.
  • MongoDB URI: The SMS service connects to a MongoDB database to store and manage 2FA codes.

3. How We Use Your Information

Formulific uses the collected data for various purposes:

  • To provide and maintain our Service; including user account creation, authentication, and form building functionalities.
  • To notify you about changes to our Service;
  • To allow you to participate in interactive features of our Service when you choose to do so (e.g., form builder, analytics dashboard).
  • To provide customer support;
  • To gather analysis or valuable information so that we can improve our Service (e.g., through usage data and analytics).
  • To monitor the usage of our Service;
  • To detect, prevent, and address technical issues;
  • To fulfill the purpose for which you provide it (e.g., responding to homepage lead submissions).
  • To provide you with notices about your account and/or subscription, including expiration and renewal notices, email-instructions, etc.;
  • To provide you with news, special offers, and general information about other goods, services, and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information;
  • To process payments (via Stripe) and manage your account, including subscription status and potential commission payments for Partners.
  • If you are a client, to store and manage the Form Data you collect, and enable features like SMS notifications for form submissions (if you activate this feature and provide necessary phone numbers).
  • If you are a Partner Agency, to manage our relationship with you, process your application, facilitate your reselling of or managing the Service for your clients, and track/pay commissions.
  • To manage our SMS service for 2FA and notifications, including sending codes and messages, and temporarily storing 2FA codes.

4. How We Share Your Information

We may share your Personal Data in the following situations:

  • With Service Providers: We may share your Personal Data with third-party Service Providers to monitor and analyze the use of our Service, to process payments (e.g., Stripe), to provide data storage, to send SMS messages (e.g., VOIP.ms via our SMS service), and to provide other services on our behalf. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
    • Example: Payment processing is handled by Stripe. Their Privacy Policy can be found on their website.
    • Example: SMS notifications are sent via VOIP.ms through our dedicated SMS service. Their privacy policies can be found on their respective websites.
  • With Partner Agencies: If you are a client who was onboarded to our Service by a Partner Agency, or if you grant a Partner access using a Partner Access Code, that Partner Agency may have access to certain information about your account and your use of the Service as necessary to manage their relationship with you and provide support (e.g., creating and managing forms on your behalf). They may also have access to the Form Data you collect if they are managing your forms.
  • For Business Transfers: We may share or transfer your Personal Data in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
  • With Affiliates: We may share your information with our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include our parent company and any other subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.
  • With Your Consent: We may disclose your Personal Data for any other purpose with your consent.
  • For Legal Requirements: Formulific may disclose your Personal Data in the good faith belief that such action is necessary to:
    • To comply with a legal obligation
    • To protect and defend the rights or property of Formulific
    • To prevent or investigate possible wrongdoing in connection with the Service
    • To protect the personal safety of users of the Service or the public
    • To protect against legal liability

5. Data Retention

We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.

Form Data collected by our client users is retained according to the client's instructions and their account status with us. Clients are responsible for managing their Form Data, including its retention and deletion.

2FA codes sent via SMS are stored temporarily and are automatically deleted after verification or expiry (typically 5 minutes by the TTL index in MongoDB).

6. Data Security

The security of your data is important to us but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

We implement security measures such as:

  • HTTPS for data in transit.
  • Password hashing (bcrypt) for user passwords.
  • Use of environment variables for sensitive credentials like API keys and database URIs.
  • Authentication and authorization mechanisms (JWT, cookies, role-based access).
  • Input validation and sanitization where appropriate.
  • Rate limiting on authentication and sensitive API endpoints.
  • Regular review of security practices.

For data processed by our SMS service, 2FA codes are stored with TTL indexes for automatic deletion.

7. Your Data Protection Rights

Depending on your location and applicable law, you may have certain data protection rights. These may include:

  • The right to access, update or delete the information we have on you. Whenever made possible, you can access, update, or request deletion of your Personal Data directly within your account settings section (e.g., Profile Information, Notification Preferences, API Key management, Partner Access Code generation). If you are unable to perform these actions yourself, please contact us to assist you.
  • The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
  • The right to object. You have the right to object to our processing of your Personal Data.
  • The right of restriction. You have the right to request that we restrict the processing of your personal information.
  • The right to data portability. You have the right to be provided with a copy of your Personal Data in a structured, machine-readable, and commonly used format (e.g., CSV export of submissions).
  • The right to withdraw consent. You also have the right to withdraw your consent at any time where Formulific relied on your consent to process your personal information (e.g., opting out of SMS notifications).

Please note that we may ask you to verify your identity before responding to such requests. Please note, we may not be able to provide Service without some necessary data.

If you are a resident of the European Economic Area (EEA), you have certain data protection rights covered by GDPR. Please see our GDPR specific addendum if available, or contact us for more information.

If you are a California resident, you have certain data protection rights covered by CCPA. Please see our CCPA specific addendum if available, or contact us for more information.

You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority.

If you are a form respondent and wish to exercise rights over data submitted through a client's form, please contact the client (the form owner) directly, as they are the Data Controller for that Form Data.

8. Children's Privacy

Our Service is not intended for use by children under the age of 13 ("Children").

We do not knowingly collect personally identifiable information from Children. If you become aware that a Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.

9. Third-Party Links

Our Service may contain links to other sites that are not operated by us (e.g., links to Stripe for payment management). If you click a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

10. International Data Transfers

Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to the United States and process it there.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

Formulific will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

11. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the "Last Updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

12. Contact Us

If you have any questions about this Privacy Policy, please contact us:

  • By visiting our contact page on our website