Privacy Policy
Last updated: August 24, 2026
This Privacy Policy explains how nisuform ("nisuform", "we", "us") collects, uses, shares, and protects personal data when you use our website and form service (the "Service"). It applies to two groups of people: customers who create accounts and build forms, and respondents who fill in forms powered by nisuform. Depending on the context, we act either as a controller or as a processor, as described below.
1. Our Two Roles
- For account data: When you sign up and use the Service, we act as the controller of your personal data, such as your email address and billing details.
- For Submissions: When respondents complete a form you built with nisuform, you are the controller of that data and we act as a processor, handling Submissions only on your instructions. Our Data Processing Agreement contains the binding processing terms for this role.
2. Data We Collect
Account data you give us
- Contact details: your name and email address when you sign up.
- Authentication data: your login session, secured by our authentication provider.
- Billing data: subscription plan, invoices, and billing country. Card numbers and payment credentials are collected and stored by our payment provider, Polar, and never touch our servers.
- Communications: messages you send to support and your support history.
Submissions you collect
When a respondent completes your form, we receive and store the fields your form asks for, which typically include names, email addresses, and message content, together with technical metadata such as timestamps and the originating page. The content of Submissions is defined entirely by the questions you ask.
Usage and technical data
- Log data: IP address, browser type, operating system, referring URLs, and timestamps, collected when you or respondents interact with the Service.
- Anti-spam signals: we analyze submission patterns and metadata to detect and filter spam and abuse.
We do not run third-party advertising or cross-site tracking technologies on the Service, and we do not sell personal data.
3. How We Use Data
- Provide the Service: create accounts, host forms, receive, store, and forward Submissions, and send email notifications.
- Billing: manage subscriptions, process payments, and issue invoices.
- Support: respond to questions and resolve issues.
- Security and anti-abuse: authenticate users, protect accounts, detect spam, and prevent fraudulent or unlawful use.
- Service improvement: understand aggregate usage so we can fix problems and improve features.
- Legal compliance: meet legal obligations and enforce our Terms of Service.
4. Legal Bases (GDPR)
Where the EU or UK General Data Protection Regulation applies, we rely on:
- Performance of a contract: to provide the Service you signed up for, including account management and processing Submissions.
- Legitimate interests: to secure the Service, prevent abuse and spam, communicate service updates, and improve the Service, always balanced against your rights.
- Legal obligations: to keep billing records and respond to lawful requests.
- Consent: where we ask for it, for example for optional communications, and you may withdraw it at any time.
5. Are You GDPR Friendly?
Yes. nisuform is designed to be GDPR friendly from day one, both for customers who use the Service and for the respondents whose data flows through it. In practice, that means:
- A free Data Processing Agreement for everyone. Our DPA includes the EU Standard Contractual Clauses and the UK Addendum, applies automatically to every customer at no extra cost, and requires nothing extra to sign.
- You stay the controller. Submissions belong to you. We process them only on your instructions, never for our own marketing or profiling, and we never sell personal data.
- Data minimization. We only ask for what the Service needs to run: your name, email address, and billing details. Your forms collect exactly the fields you choose, nothing more.
- Security by design. Data is encrypted in transit and at rest, access is limited to the few people who need it, and built-in spam and abuse protection keeps bad data out.
- Vetted subprocessors. We rely on a short, public list of established providers (Supabase, Resend, Cloudflare, Polar), each bound by data protection agreements, and we notify you before adding new ones.
- Real deletion. When you delete Submissions or your account, the data is deleted within 30 days and purged from encrypted backups within a further 90 days.
- Rights support. Self-service tools let you access, export, correct, and delete data at any time, and we assist you in responding to requests from your respondents.
- No sneaky tracking. No advertising cookies, no third-party analytics on your forms, no cross-site tracking. Only strictly necessary cookies and local storage.
GDPR compliance is a shared responsibility. You are the controller for the data your forms collect, so make sure you have a lawful basis and a clear privacy notice for your respondents. We provide the processor-side guarantees described in this policy and our DPA to make your side as easy as possible.
6. Cookies and Local Storage
We use only strictly necessary cookies and local storage to keep you signed in and to protect the Service against abuse. We do not use advertising or analytics cookies on the landing site or in the app. You can clear cookies and local storage through your browser at any time; signing out will stop working until you sign in again.
7. How We Share Data
We share personal data only with providers that help us operate the Service, each bound by contractual confidentiality and data protection obligations:
- Supabase (database, authentication, and hosting infrastructure).
- Resend (transactional email delivery, such as submission notifications).
- Cloudflare (storage and content delivery).
- Polar (subscription payments and merchant of record).
We may also disclose data if required by law or legal process, or to protect the rights, property, and safety of nisuform, our customers, or the public. We do not sell personal data and we do not share it for third-party advertising.
8. International Transfers
Our providers may process data in countries other than yours, including the United States. Where personal data is transferred out of the EEA, the UK, or Switzerland, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses (and the UK Addendum or Swiss equivalents where relevant), as described in our Data Processing Agreement.
9. Retention
- Account data is kept while your account is active. If you delete your account, we delete it within 30 days, except data we must keep for legal reasons, such as invoices.
- Submissions are kept until you delete them or close your account, after which they are deleted within 30 days. Deleted Submissions are removed from backups on a rolling basis within a further 90 days.
- Log data is kept for up to 12 months for security and abuse prevention.
10. Your Rights
Depending on where you live, you have rights over your personal data, including access, correction, deletion, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. If you are a California resident, you have the right to know and delete personal data, and the right not to be discriminated against for exercising your rights; we do not sell or share personal data as defined by the CCPA.
To exercise any right, contact us at privacy@nisuform.com. We will verify your request and respond within the timeframe required by law. If your request concerns Submissions collected by a nisuform customer, please contact that customer directly, since they control that data; we will assist them as needed.
11. Security
We protect personal data with encryption in transit (TLS) and at rest, strict access controls based on least privilege, and continuous monitoring. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security, but we take incidents seriously and will notify affected customers and regulators as required by law.
12. Children
The Service is not directed at children under 16, and we do not knowingly collect their personal data. Customers must not use the Service to knowingly collect data from children without legally required consent. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy as the Service evolves or the law changes. We will post the updated version here with a new "Last updated" date and, for material changes, notify you by email or through the Service.
14. Contact
For privacy questions or requests, email privacy@nisuform.com.