Privacy Policy
FormFlow Inc. ("FormFlow", "we", "us", or "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile forms platform and related services.
1. Information We Collect
1.1 Account Information
When you create an account or request early access, we collect:
- Full name and email address
- Company name and size
- Job title or role
- Industry sector
- Intended use case
1.2 Form Submission Data
When your team uses FormFlow to collect field data, the content of form submissions is processed and stored on your behalf. This may include text entries, photographs, GPS coordinates, digital signatures, and other data your forms are configured to collect. You are the data controller for this content; FormFlow acts as a data processor.
1.3 Device and Usage Data
We automatically collect certain technical information:
- Device type, operating system, and browser version
- IP address and approximate location
- Pages visited, features used, and session duration
- Crash reports and performance data
2. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the FormFlow platform
- Process and sync form submissions between devices and cloud
- Send service notifications and product updates
- Respond to support requests and inquiries
- Analyze usage patterns to improve features and performance
- Comply with legal obligations and enforce our terms
3. Data Storage and Security
Form submission data is encrypted using AES-256 at rest and TLS 1.3 in transit. Data captured offline is encrypted on-device immediately upon collection. We store data in SOC 2 Type II certified data centers with geographic redundancy. You may choose your data residency region (North America, Europe, or Asia-Pacific).
4. Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
- Cloud infrastructure providers who host our platform (under strict data processing agreements)
- Analytics services that help us improve the product (aggregated and anonymized)
- Legal authorities when required by law, court order, or to protect our rights
- Business successors in the event of a merger, acquisition, or asset sale
5. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (right to be forgotten)
- Object to or restrict certain processing activities
- Request data portability in a structured, machine-readable format
- Withdraw consent at any time where processing is based on consent
To exercise these rights, contact us at privacy@formflow.app.
6. GDPR Compliance
For users in the European Economic Area, we process personal data under the following legal bases: contractual necessity (to provide our services), legitimate interest (to improve our platform), consent (for marketing communications), and legal obligation (to comply with applicable laws). Our Data Protection Officer can be reached at dpo@formflow.app.
7. Data Retention
We retain account information for the duration of your account plus 30 days after deletion. Form submission data is retained according to your organization's configured retention policy. Usage and analytics data is retained for 24 months in aggregated form.
8. Cookies
We use essential cookies for platform functionality and optional analytics cookies to improve our service. See our Cookie Policy for full details.
9. Children's Privacy
FormFlow is not intended for use by individuals under 16 years of age. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the platform. Continued use of FormFlow after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, contact us at: privacy@formflow.app.