Privacy Policy
Last updated: September 26, 2026
At Static Forms, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our form to email service. Please read this privacy policy carefully. If you disagree with the terms of this privacy policy, please do not access the service.
Data Controller
Static Forms (operated by Qualascend) is the data controller responsible for your personal data. For any privacy-related inquiries, please contact us at info@staticforms.dev.
Information We Collect
We collect information that you provide to us when you:
- Register for an account
- Update your account information
- Process form submissions through our service
- Contact our support team
- Subscribe to our newsletter
This information may include:
- Email address
- Name (optional)
- Website URL (optional)
- API keys
- Form configurations
- CAPTCHA settings (reCAPTCHA, Cloudflare Turnstile, or Altcha)
- Payment information (processed by Stripe)
- Form submission data processed through our service
Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contract Performance: Processing necessary to provide you with our services, including account management, form processing, and email delivery.
- Consent: For optional features like analytics cookies, marketing communications, and form submission storage.
- Legitimate Interest: For service improvement, security monitoring, fraud prevention, and customer support.
- Legal Obligation: When required by law to retain or disclose data.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process and deliver form submissions to your specified email address
- Monitor and analyze usage patterns and trends (with consent)
- Prevent fraudulent form submissions using CAPTCHA verification
- Communicate with you about service-related issues
- Send product updates and marketing communications (with consent)
- Process payments and manage subscriptions
- Enforce our terms, conditions, and policies
Form Submission Data
When your website visitors submit forms through our service, we process this data to deliver it to your specified email address. We act as a data processor for this information, while you (our customer) act as the data controller.
Storage of submissions: Form submissions are delivered to your email address and are also stored as records in your account dashboard. Storage applies on all plans:
- Form submissions are stored securely in your account and can be viewed through your dashboard
- Stored submissions are retained for the retention period for your plan — up to 1 year on the Free plan, enforced automatically at the database level; paid plans retain submissions indefinitely by default. Every plan can configure a shorter period per form, from 30 days upward — or until you delete them, whichever comes first
- You can export (CSV) or delete stored submissions individually or in bulk at any time, and you can delete your entire account and its stored data
- Operational metadata and logs are retained separately as described in our Data Processing Agreement (Section 3.5)
Because Static Forms stores the submissions your forms collect, you are responsible for ensuring you have appropriate consent from your form submitters. See our Data Processing Agreement for more details on our processor obligations.
Agent and Connector Access
On paid plans, you can connect an external AI agent or MCP client to one Static Forms workspace through OAuth. You choose the workspace and permissions during connection. Static Forms applies your current workspace role and form access to every request, and you can revoke the connection from Agent access at any time.
When you ask a connected agent to use Static Forms, we send the requested tool result to the agent provider you selected. Depending on the permissions and action, this can include form configuration, workspace and team details, submission fields, sender information, delivery status, and links back to signed-in Static Forms pages. We exclude passwords, access tokens, API keys, verification codes, payment details, stored integration secrets, and attachment contents from agent tool results.
- We process tool requests and results to provide the action you requested, enforce authorization, prevent abuse, diagnose failures, and keep a bounded activity record.
- The selected agent provider receives the tool inputs and results needed for your request and handles its copy under its own privacy policy and account settings.
- OAuth connection records include the provider-supplied client identity, granted permissions, workspace, user, expiry, and revocation state. Access ends when the connection expires, you revoke it, your workspace access changes, or your account is deleted.
- Form submissions retain the same Static Forms retention period whether you read them in the dashboard or through an authorized agent.
Third-Party Services & Data Processors
We use the following third-party services to operate our business. Each service has their own privacy policy governing how they handle data:
Infrastructure & Hosting
- Amazon Web Services (AWS) - Cloud hosting, database (DynamoDB), and email delivery (SES). Data is stored in AWS data centers. Privacy Policy
- Vercel - Website hosting and edge network. Privacy Policy
Analytics
For anonymous visitors, analytics are loaded only after explicit cookie consent. For authenticated users, analytics are processed under our legitimate interest in operating, securing, and improving the service (and were disclosed at the time you accepted our Terms). You may opt out at any time by contacting us.
- Google Analytics - Website analytics for understanding user behavior. Privacy Policy
- PostHog (EU) - Product analytics for understanding feature usage and improving the service. Data is processed in the European Union. We send account identifiers, profile information, subscription details, and product usage events; we do not send form-submission content. Privacy Policy
- Vercel Speed Insights - Performance monitoring. Privacy Policy
AI-assisted spam evaluation
Static Forms uses TypeSafe AI (Jev), through Vercel AI Gateway, to evaluate form submissions for spam. We plan to extend availability across all customer accounts, regardless of selected data-residency region, following the DPA notice and objection process. This describes the planned rollout; processing is not necessarily enabled for every account yet. It is separate from the optional AI reply feature.
Requests contain selected, length-limited form fields and, where available, the form website hostname. We filter fields identified as sensitive and redact recognized credentials, email addresses and certain number patterns. Redaction does not make free-text submissions anonymous: personal data can remain. Attachment contents and request IP addresses are not included in this evaluation payload.
Requests use the Gateway's zero-data-retention and no-prompt-training controls. Provider obligations and exceptions are governed by the applicable provider agreements; see TypeSafe's Data Processing Addendum, Vercel's DPA and Vercel's AI Product Terms. Vercel documents Jev's support for these controls in its Jev announcement. These references do not replace Static Forms' obligations under our DPA.
Static Forms separately stores evaluation results and selected redacted input samples in AWS us-east-1 for spam-quality review. These records are scheduled to expire within 15 days, or earlier where the source submission's retention requires it; database expiry deletion is asynchronous. Account, form and submission deletion also removes associated evaluation records. This storage is separate from the providers' retention controls.
Security & Spam Prevention
- Google reCAPTCHA - Spam protection for forms. Processes IP addresses and browser data. Privacy Policy
- Cloudflare Turnstile - Privacy-friendly CAPTCHA alternative (optional).Privacy Policy
- Altcha - Privacy-focused CAPTCHA alternative (optional).Privacy Policy
Payments
- Stripe - Payment processing for subscriptions. We do not store your credit card information. Privacy Policy
International Data Transfers
Your data may be transferred to and processed in countries outside of your country of residence, including the United States. These transfers are necessary to provide our services and are protected by appropriate safeguards such as Standard Contractual Clauses (SCCs) where required by law.
Accounts that select European Union data residency when they sign up have their form data — submissions, file attachments and delivery logs — stored in the EU (AWS eu-central-1, Frankfurt) rather than the United States. Account and billing data, transactional email delivery and operational request logs remain US-processed for every account. The exact scope is set out in Section 8 of our Data Processing Agreement.
Cookies and Tracking
We use cookies and similar tracking technologies to enhance your experience. For detailed information about the cookies we use and how to manage your preferences, please see our Cookie Policy.
Security
We implement appropriate technical and organizational measures to protect the security of your personal information, including:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of sensitive data at rest
- Regular security assessments
- Access controls and authentication
- Employee security training
However, please be aware that no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee the absolute security of your data.
Data Retention
We retain your account information for as long as your account is active or as needed to provide you services. We may retain certain information as required by law or for legitimate business purposes.
Form Submission Data: Form submissions your forms collect are stored as records in your account on all plans:
- Stored form submissions are retained for the retention period configured for your plan (up to 1 year on the Free plan, enforced automatically at the database level; paid plans retain submissions indefinitely by default; every plan can configure a shorter period per form, from 30 days upward), or until you delete them, whichever comes first
- How long submissions are retained is separate from how far back the dashboard displays them: the inbox, its CSV export and the submissions API show the most recent 30 days on the Free plan and the full stored history on paid plans. Submissions outside the display window are retained, not deleted, and a data subject access request or account export always returns everything stored
- You can delete individual submissions or all submissions at any time through your dashboard
- If you downgrade to the Free plan, stored submissions come under the Free retention period: each is kept until 1 year after it was received, and anything already older than that is deleted shortly after the downgrade. You can export your data at any time from Settings
Account Deletion: When you delete your account, we will delete all your personal data within 30 days, except for data we are required to retain for legal or regulatory purposes.
Your Rights (GDPR & CCPA)
Depending on your location, you have the following rights regarding your personal data:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restriction: Limit how we process your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time for consent-based processing
- Right to Lodge a Complaint: File a complaint with a supervisory authority
Exercising Your Rights: You can exercise most of these rights directly through your account settings:
- Export your data via the settings page
- Delete your account via the settings page
- Manage email preferences via settings or unsubscribe links
- Manage cookie preferences via the cookie settings in the footer
For other requests, please contact us at info@staticforms.dev. We will respond within 30 days.
California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know if your personal information is sold or disclosed
- Right to opt-out of the sale of personal information
- Right to non-discrimination for exercising your rights
We do not sell your personal information.
Children's Privacy
Our service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you learn that a child has provided us with personal information, please contact us so we can take steps to delete such information.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date
- Sending an email notification for significant changes (if you have an account)
You are advised to review this Privacy Policy periodically for any changes.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
- By visiting our contact page
- By email: info@staticforms.dev
If you are in the European Union and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.







