Last updated August 9, 2026

Privacy Policy

About this policy

Formpost provides hosted form endpoints that receive, store, and deliver form submissions. This policy explains how we handle personal information when you use Formpost, create an account, or submit information through a form powered by Formpost.

Customers decide what information their forms collect and why. Formpost processes submission information to provide the service on their behalf.

Information we collect

We collect account information you provide, including your name, email address, password, form settings, recipient email addresses, and account security settings. Passwords are stored in hashed form.

When a form is submitted, we process the submitted field names and values together with technical information such as the IP address, browser user agent, referring page, timestamps, and delivery, read, and spam status.

We also process limited service and diagnostic information needed to operate, secure, and monitor Formpost. Essential cookies and similar technologies may be used for authentication, account security, and core service functionality.

How we use information

We use information to operate Formpost, deliver submissions, manage accounts and subscriptions, protect the service from spam and abuse, troubleshoot problems, monitor reliability, communicate about the service, and comply with legal obligations.

We do not sell personal information.

Submission retention

Submissions verified by Cloudflare Turnstile are retained for 365 days, regardless of plan, and are then permanently deleted. Submissions that are not verified are retained for 30 days and are then permanently deleted.

These limits also apply to submissions a customer has deleted from their account. Other account, billing, security, and operational records are retained only for as long as needed to provide the service, meet legal obligations, resolve disputes, and protect Formpost.

Service providers

We use service providers to operate Formpost. They process information only as needed to provide their services to us:

  • Laravel Cloud hosts the application and its data.
  • SendGrid delivers email. Submission content may be included in emails sent to a customer's configured recipient address.
  • Laravel Nightwatch monitors application performance, reliability, and errors.
  • Stripe manages subscriptions and payment processing. Formpost does not store full payment card details.
  • Cloudflare Turnstile helps detect automated and abusive submissions and may process IP address and browser information.

These providers may process information in countries other than your own and are subject to their own privacy and security terms.

Access and disclosure

Submission contents are available to the customer who owns the form. Formpost staff accounts cannot access submission contents through the product. Our service providers may process information where necessary to provide their infrastructure, email, monitoring, billing, and abuse-prevention services.

We may disclose information when required by law, to respond to valid legal process, or when reasonably necessary to protect Formpost, our customers, or others from fraud, abuse, or security threats.

Security

We use technical and organizational safeguards designed to protect personal information. No internet service is completely secure.

Your choices and rights

Depending on where you live, you may have rights to access, correct, export, restrict, object to the processing of, or request deletion of your personal information. We may need to verify your identity before completing a request, and some information may be retained where required by law.

To make a privacy or data request, use the contact form.

Changes to this policy

We may update this policy as Formpost changes. The date at the top shows when it was last updated.