Legal

Privacy Policy

Last updated: 29 July 2026

1. Introduction

Fireform ("we," "us," or "our") is a form builder that lets people design forms, publish them as hosted pages, and collect responses. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website, subscribe to Fireform, use our dashboard, or interact with our services.

This Privacy Policy applies to all information collected through our website, dashboard, platform features, and any related services. It also addresses our role as a data processor for information that our users (the people who build forms) collect from their respondents (the people who complete published forms).

By using our services, you consent to the data practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our services.

2. Information We Collect

2.1 Information from Subscribers (our direct users)

We collect personal information that you provide when you subscribe to and use Fireform, including:

  • Contact information: name, email address, and billing details you provide.
  • Account information: your account is created and secured through our authentication provider, Clerk. This includes your email and an encrypted password managed by Clerk, along with your account preferences.
  • Payment information: payment method details are processed securely by our Merchant of Record, Lemon Squeezy. We do not store full card numbers.
  • Business information: company name, website URLs, and related information you choose to provide.

2.2 Information from Respondents (collected on behalf of subscribers)

When our subscribers build and publish forms, they may collect personal information from respondents. This information is collected on behalf of our subscribers and may include:

  • Contact information: email addresses, phone numbers, and names entered into a form.
  • Form responses: answers, selections, and any other input provided while completing a form.
  • Uploaded files: files a respondent submits, where the form includes a file upload field.
  • Any other information the subscriber chooses to collect through their forms.

Important: this respondent data is stored on our infrastructure and made accessible to the subscriber through their dashboard. Our subscribers are the data controllers for this information, and Fireform acts as a data processor. We do not store respondents' IP addresses with their submissions. Please see Section 4 for more about our role and responsibilities.

2.3 Usage Data

We automatically collect limited information about how subscribers use our dashboard, such as login times, features used, and forms created.

2.4 Technical Data

We collect limited technical information, such as browser type, device type, and the pages you visit on our website, to operate and secure our services. We do not store IP addresses with form submissions.

2.5 Cookies and Tracking Technologies

We use only essential cookies. See Section 7 for details.

3. How We Collect Information

3.1 Directly from subscribers

We collect information directly from you when you subscribe to Fireform, create or access your account, build and publish forms, access reports, contact us for support, or sign up for communications.

3.2 From respondents

We collect information from respondents when they visit and complete forms that our subscribers have published, including any details they submit through a form.

3.3 Automatically

We automatically collect limited information through essential cookies, server logs, and a privacy-focused, cookieless analytics service.

3.4 From third parties

We receive limited information from our Merchant of Record, Lemon Squeezy, in connection with payment processing (such as transaction details and payment method type).

4. Data Processing Roles

4.1 Fireform as data controller

For information collected directly from our subscribers, Fireform acts as the data controller. This includes your account information, payment details, and usage data related to your use of our platform.

4.2 Fireform as data processor

For information collected from respondents through forms created by our subscribers, Fireform acts as a data processor, and our subscribers are the data controllers. As a processor, we:

  • Process respondent data only according to our subscribers' instructions and our Terms of Service.
  • Implement appropriate technical and organizational security measures.
  • Assist subscribers in responding to data subject requests when requested.
  • Delete or return respondent data upon termination of the subscriber's account, subject to legal retention requirements.

4.3 Subscriber responsibilities

As the data controller for respondent information, our subscribers are responsible for:

  • Ensuring they have a lawful basis to collect respondent data.
  • Providing appropriate privacy notices to respondents on their forms.
  • Obtaining any consents required by law.
  • Complying with applicable data protection laws (such as the GDPR and CCPA).
  • Responding to data subject requests from respondents regarding their data.

4.4 Data Processing Agreement

If you require a separate Data Processing Agreement for compliance purposes, please contact us at riddhesh@fireform.app.

5. Your Account

5.1 Account creation

When you subscribe to Fireform, we create a dashboard account for you through our authentication provider, Clerk. This account gives you access to the form builder, response management, reporting, and account settings.

5.2 Account information

Your account stores your credentials (email and an encrypted password managed by Clerk), subscription information, the forms you create, the responses collected through those forms, and your activity history.

5.3 Response data storage

When respondents submit information through your forms, that data is stored securely on our European Union infrastructure, made accessible through your dashboard, available for export to CSV or PDF depending on your plan, and retained according to Section 11.

5.4 Analytics

We track aggregate performance metrics for your forms, such as submission counts and completion rates, to power your dashboard reporting.

6. How We Use Information

6.1 Service provision

  • Process your subscription and manage your account.
  • Provide access to the Fireform platform and features.
  • Host and serve your published forms.
  • Store and manage the responses collected through your forms.
  • Provide reporting and exports.
  • Provide email support and customer service.

6.2 Service improvement

  • Analyze usage patterns to improve the platform.
  • Identify and fix technical issues.
  • Develop new features and improve reliability.

6.3 Communication

We send transactional emails (such as subscription confirmations, account updates, and billing notifications) through our email provider, Mailgun, and respond to your support requests.

6.4 Legal and security

  • Comply with legal obligations.
  • Enforce our Terms of Service and policies.
  • Protect against fraud, abuse, and security threats.

6.5 Marketing (with consent)

With your consent, we may use your information to send you marketing communications about Fireform and its features. You can opt out at any time using the unsubscribe link in our emails or by contacting us directly.

7. Cookies and Tracking Technologies

7.1 Essential cookies

We use essential cookies set by our authentication provider, Clerk, to keep you signed in and to secure your session. These cookies are required for the dashboard to function.

7.2 Analytics

For website and product analytics we use a privacy-focused, cookieless analytics provider (Plausible). It does not use cookies and does not collect personal data. We do not use advertising cookies or cross-site tracking cookies.

7.3 Cookies on published forms

Published forms do not set advertising or tracking cookies. Any cookies used are limited to what is necessary to serve the form.

7.4 Managing cookies

You can control cookies through your browser settings. Disabling essential cookies may prevent you from signing in or using the dashboard.

8. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share information in the following circumstances.

8.1 Merchant of Record

We share payment and transaction information with our Merchant of Record, Lemon Squeezy, to process your subscription payments. Lemon Squeezy handles payment processing in accordance with its own privacy policy and security standards.

8.2 Sub-processors and service providers

We use a small set of trusted service providers to operate Fireform. They are contractually obligated to protect your information and use it only to provide their services to us:

  • Amazon Web Services (AWS): cloud hosting and database (European Union region).
  • Cloudflare R2: storage for files uploaded through forms (European Union region).
  • Clerk: authentication and account management.
  • Lemon Squeezy: payments and Merchant of Record.
  • Mailgun: transactional email delivery.
  • Plausible: privacy-focused, cookieless analytics.

8.3 Subscriber access to respondent data

Respondent data collected through a form is made accessible to the subscriber who created that form. Subscribers can view, export, and manage this data through their dashboard.

8.4 Subscriber-configured integrations

Subscribers may connect integrations to send their own form submission data to services they choose: email notifications, Google Sheets, Slack, and webhooks (including webhooks pointed at automation services such as Zapier or Make.com). The subscriber supplies the destination and authorizes the connection, and controls these integrations. Fireform does not send data to these third parties automatically. The subscriber is responsible for any integration they configure and for the third parties that receive the data. Where an integration requires connecting a third-party account, that connection is stored on the subscriber's workspace and can be selected by other members of that workspace, as described in Section 9.2. Section 9 describes each integration, and sets out in full how we handle Google user data.

8.5 Legal requirements

We may disclose information if required by law, court order, or government request, or where we believe disclosure is necessary to comply with legal obligations, enforce our agreements, or protect the rights, property, or safety of Fireform, our users, or others.

8.6 Business transfers

If Fireform is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

9. Integrations and Google User Data

9.1 The integrations we offer

Fireform lets you connect a form to a destination so that new submissions are delivered there automatically. We currently offer four: email notifications, Google Sheets, Slack, and webhooks. Every integration is opt in and is set up by you. Fireform does not send your data to any of them until you connect that destination yourself, and disconnecting it stops the delivery.

When you route your respondents' data to a service you have chosen, you remain the data controller for that data, and the receiving service handles it under its own privacy policy. You are responsible for selecting the destination and for having a lawful basis to send the data there.

9.2 How the Google Sheets connection works

This section and the ones that follow apply only if you connect the Google Sheets integration. If you never connect it, Fireform never requests or receives any Google user data about you.

You connect a Google account from a form's Google Sheets integration settings, and you can also see and manage connected accounts from your workspace settings. The connection is stored on the workspace, not on the individual form, which has a consequence worth stating plainly:

  • Every form in that workspace can select the connected account as a destination.
  • Anyone you give access to that workspace can select it too, which means they can direct their own form's responses into a spreadsheet that account can reach. They never see the stored credentials. Connect an account only to a workspace whose members you trust with that access.

After selecting an account, you either paste the URL or ID of a spreadsheet you already have, or ask Fireform to create a new one in that account. You then type the name of the tab you want responses written to. Fireform does not list or browse your Google Drive, and does not show you a file picker.

You can connect a Google account and configure the integration on any plan, including Explore. Rows are written only once the form is published, which requires a paid plan.

9.3 The Google user data we access

To connect, you sign in with Google and grant permission through Google's own consent screen, which shows you exactly what is being requested before you approve it. Fireform requests these scopes:

  • openid and email: your Google account identifier and email address, so we can show you which account is connected and keep that connection tied to your workspace.
  • https://www.googleapis.com/auth/spreadsheets: access to Google Sheets, used to write your form responses into the spreadsheet you identified.

With that permission we access and store:

  • Your Google account email address and account identifier.
  • An OAuth access token and refresh token: stored encrypted, and used only to write to the spreadsheet you identified.
  • The spreadsheet ID and tab name you entered: so we know where to deliver responses.
  • The spreadsheet itself: either the one you identified, or a new one we create in that account when you ask us to. We read and write the header row of the tab you named, so that your form fields line up with its columns, and append one row each time someone submits that form.

About the scope we request. Google grants the Sheets scope at the account level, so the permission it issues technically covers spreadsheets in your account rather than a single file. We would rather say that plainly than imply a narrower grant. In practice, and as a matter of policy, Fireform reads and writes only the spreadsheet whose URL or ID you entered, and only the tab you named. We ask for this scope because you can identify a spreadsheet by pasting its URL or ID, including one that someone else shared with you, and because a connected account is shared across a workspace. Google's narrower per-file scope covers only files an app created or that the signed-in person selected through Google's own file picker, and neither fits how this integration works.

Fireform holds no Google Drive permission at all, so we cannot open, read, or change any other kind of file in your Drive, and we cannot delete anything.

Derived and aggregated data. For each delivery we record only whether it succeeded or failed, based on the status code Google's API returns. We do not store the response body, the contents of your spreadsheet, or the rows after they are written. We do not build aggregated, anonymized, or otherwise derived data sets out of Google user data, so we have none to use, share, or sell.

9.4 How we use Google user data

We use it for a single purpose: delivering your form responses into the spreadsheet and tab you connected, and showing you which Google account is connected. We do not:

  • Use it for advertising, ad targeting, or personalization.
  • Use it to develop, train, retrain, or improve generalized or personalized machine learning or artificial intelligence models.
  • Send it to any third-party artificial intelligence or machine learning service, including any service that would use it to train or improve its own models.
  • Use it for credit, lending, or any similar decision about you.

9.5 Who we share Google user data with

We do not sell, rent, or trade Google user data, and we never transfer it to advertisers or data brokers. It is shared only in these cases:

  • Our hosting provider: tokens and connection settings are stored on our European Union infrastructure (Amazon Web Services), listed in Section 8.2. No other sub-processor in that list receives Google user data. It is not sent to our payment provider, our email provider, or our analytics provider.
  • People in your workspace: as described in Section 9.2, a connected account can be selected by other members of the workspace it belongs to.
  • Where security or the law requires it: where necessary to investigate a security incident, or where required by law, court order, or government request.

Our staff do not read your Google user data, except with your explicit consent on a support request you have raised, where necessary for security purposes, or where required by law.

9.6 How we protect Google user data

Access and refresh tokens are encrypted at rest and are never shown to you or to anyone in your workspace. All traffic between Fireform and Google's APIs runs over TLS. Tokens and connection settings are stored on our European Union infrastructure, and access to the systems holding them is limited to the people who need it to operate the service. The wider set of measures in Section 10 applies to this data as well.

9.7 How long we keep Google user data, and how it is deleted

We keep the connection for as long as your account is open and the connection is in place, so that the integration you set up stays ready to use. The stored credentials are deleted in these cases:

  • You disconnect the account. Disconnecting a Google account, either from your workspace settings or from a form's integration settings, deletes the stored access and refresh tokens from our systems immediately. Fireform can then no longer reach that account, and every form in the workspace that was using it stops delivering.
  • You delete the workspace. The tokens for every Google account connected to it are deleted immediately.
  • Your paid access ends and is not renewed within 30 days. We then delete the tokens automatically. That window exists so a failed payment, or a cancellation you change your mind about, does not cost you the connection.

What does not delete them. Removing the Google Sheets integration from a single form, or clearing the spreadsheet URL from it, stops that form's deliveries but leaves the account connected to the workspace and the credentials in place, so your other forms keep working. Disconnecting the account is the action that deletes them.

Revoking access from Google. You can remove Fireform's access at any time from your Google Account permissions page. Doing so ends our access immediately and permanently: the tokens we hold stop working at once and cannot be renewed. Fireform does not detect that you have done this, so the unusable tokens remain in our database until one of the events above removes them. To have them removed straight away, disconnect the account in Fireform, or email us at riddhesh@fireform.app.

Rows that have already been written, and any spreadsheet Fireform created for you, stay in your Google account, because those files belong to you rather than to us. Your integration settings, meaning the connected account's email address, the spreadsheet ID, and the tab name, contain no credentials and are retained on the schedule in Section 11. A fuller plain-language description of this integration is on our Google Sheets integration page.

9.8 Limited Use disclosure

Fireform's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs, including the Google Sheets API, adheres to that policy and its Limited Use requirements.

10. Data Security

We implement appropriate technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS).
  • Encryption of sensitive data at rest.
  • Secure authentication and access controls.
  • European Union based hosting and storage.
  • Limited access to personal information on a need-to-know basis.
  • Regular backups.

No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential, and you should notify us immediately if you suspect unauthorized access to your account.

11. Data Retention

11.1 Active subscriptions

We retain your information for as long as your subscription is active and for as long as necessary to provide our services.

11.2 Response data

Response data collected through your forms is retained while your subscription is active. You can delete individual responses or export your data at any time through your dashboard, depending on your plan.

11.3 After cancellation

If you cancel your subscription, we retain your account data and collected response data for 365 days after cancellation. This allows you to resubscribe and recover your data. After this period, we delete or anonymize the data, except where we are required by law to retain it.

11.4 After a refund

If a refund is issued, we retain your account data and collected response data for 365 days after the refund is processed, after which it is deleted or anonymized, except where legal retention requirements apply.

11.5 Legal requirements

We may retain certain information for longer where required by law, such as financial and tax records.

12. Your Rights

Depending on your location, you may have rights regarding your personal information, which may include:

  • Access: request a copy of the personal information we hold about you.
  • Correction: request correction of inaccurate or incomplete information.
  • Deletion: request deletion of your personal information, subject to legal retention requirements.
  • Portability: request a copy of your data in a structured, machine-readable format.
  • Opt out: opt out of marketing communications at any time.

To exercise any of these rights, contact us at riddhesh@fireform.app. We will respond within 30 days or as required by applicable law. These rights apply under laws such as the GDPR and CCPA.

13. Respondent Rights

If you are a respondent who has submitted information through a form hosted on our platform, the subscriber who created that form is the data controller for your information.

To exercise your data rights, you should first contact the business or person whose form you completed. If you are unable to reach them or need assistance, you may contact us at riddhesh@fireform.app, and we will help facilitate or forward your request where possible.

14. International Data Transfers

We host and store data within the European Union. If you access our services from outside the European Union, your information will be transferred to and processed in the European Union.

Certain sub-processors, such as our authentication provider (Clerk) and our Merchant of Record (Lemon Squeezy), may process limited information outside the European Union. Where they do, we rely on appropriate safeguards, such as Standard Contractual Clauses, to protect your information.

15. Children's Privacy

Fireform is not intended for individuals under the age of 18, and we do not knowingly collect personal information from children under 18.

Subscribers must not use the platform to knowingly collect information from children under 18 (or the applicable age of consent in their jurisdiction) without appropriate consent mechanisms in place. If we become aware that we have collected information from a child without appropriate consent, we will take steps to delete it. If you believe we have collected such information, please contact us at riddhesh@fireform.app.

16. Third-Party Services

16.1 Merchant of Record

Payment processing for Fireform is handled by our Merchant of Record, Lemon Squeezy. Your payment information is processed by Lemon Squeezy in accordance with its privacy policy and security standards. We do not store your full card information.

16.2 Integrations

Where you connect an integration, data may be shared with the service you configured (Google, Slack, your email provider, or the endpoint behind your webhook), according to that service's privacy policy and your settings. See Section 9 for the detail, including our handling of Google user data.

16.3 Links to third-party websites

Our website and hosted content may contain links to third-party websites. We are not responsible for their privacy practices, and we encourage you to read the privacy policies of any third-party sites you visit.

17. Changes to This Privacy Policy

We may modify this Privacy Policy at any time. We will notify you of material changes by posting the updated policy on our website, updating the "Last updated" date above, and, for significant changes, sending an email notification to subscribers. Your continued use of our services after changes take effect constitutes acceptance of the updated policy.

18. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • Email: riddhesh@fireform.app
  • Business address: Fireform, Yogesh Society, Mumbai, Maharashtra, 421301, India

For data subject requests, please include "Data Subject Request" in your email subject line and specify which right you wish to exercise.

19. Related Policies

This Privacy Policy should be read together with our Terms of Service and Refund Policy.