Privacy policy
Forms (forms.shaheermalik.com) is run by Shaheer Malik. This policy explains what we collect, why, and the choices you have. It covers two groups: owners, who build forms, and respondents, who answer them.
The short version
- We collect what we need to run your account and your forms, and nothing for advertising.
- Answers to a form belong to that form’s owner. For those answers, the owner decides what happens and we process them on the owner’s behalf.
- Card payments in forms go through the owner’s own Stripe account. Card details are entered into Stripe’s secure fields and never reach our servers.
- If an owner connects Google Drive, Forms can only see and create the files it makes itself.
What we collect from owners
- Account details: name, email address, a password (stored only as a salted hash) or your Google sign-in identifier, and your profile picture if you sign in with Google.
- Your forms: their questions, design, logic, settings and published versions.
- Billing: your plan and subscription status. Payments for Forms Pro are handled by Polar, our merchant of record; we never see your full card details.
- Connections you choose: Stripe keys (encrypted at rest with AES-256-GCM) to take payments in your forms, and a Google Drive authorisation (an encrypted refresh token) if you turn on Drive uploads.
- Technical data: a session cookie that keeps you signed in, and basic logs (IP address, browser) kept briefly for security and debugging.
What we collect from respondents
- Your answers to the form, including files, signatures and recordings you choose to send.
- Response details: when you started and finished, your device type (phone or computer), country (from your connection), the page that linked to the form, and any values the owner added to the form link.
- Anonymous usage: a random visitor ID stored in your browser so owners can see how many people viewed and completed a form. It isn’t linked to your identity.
- Saved progress: your answers may be kept in your browser so you can pick up where you left off.
- Payments: if a form takes a payment, Stripe processes it under the owner’s Stripe account and Stripe’s privacy policy. We store only the payment’s reference, amount and status.
- Bookings: if a form lets you book a time, we store the time and your time zone.
The form’s owner is responsible for how they use your answers. If you have a question about a specific form, contact its owner first.
How we use data
- To run Forms: show forms, save answers, send owners their results, notifications and webhooks, and keep everything secure.
- To bill Pro subscriptions and enforce plan limits.
- To prevent spam and abuse (we use Cloudflare Turnstile and rate limits).
- To email you about your account (for example password resets and plan limits). We don’t send marketing email without asking.
We don’t sell personal data, and we don’t use it to train AI models.
Google user data
When an owner connects Google Drive, Forms asks for the drive.file permission, plus your email address to show which account is connected. With it, Forms can create a folder for each form and upload respondents’ files into it. It can’t read, change or delete any other file in your Drive. We store an encrypted refresh token so uploads keep working, and we revoke it and delete it when you disconnect.
Forms’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We don’t use Google user data for advertising, we don’t sell it, and no person reads it except where you ask us to for support or the law requires it.
Who we share data with
We use a small set of providers to run the service, each only for its purpose:
- Cloudflare: hosting, database, file storage, spam protection.
- Polar: billing for Forms Pro.
- Resend: sending account and notification emails.
- Stripe: card payments inside forms, under each owner’s own Stripe account.
- Google: optional sign-in with Google, and Drive uploads for owners who turn them on.
Owners can also send responses to their own systems with webhooks they set up. We may disclose data if the law requires it.
How long we keep data
- Accounts, forms and responses stay until the owner deletes them or closes their account.
- Uploads that never become part of a submitted response are deleted after 7 days.
- Deleted data leaves our nightly backups within 30 days.
Your rights
You can ask to see, correct, export or delete your personal data, and object to how it’s used. Owners can export and delete responses from Results at any time. Respondents should contact the form’s owner, or write to us and we’ll pass the request on. Depending on where you live, you may also complain to your data protection authority.
Security
Data is encrypted in transit, and sensitive credentials are also encrypted at rest. Passwords are hashed, sessions are HttpOnly cookies, and every request to an owner’s data is checked against their account.
Children
Forms isn’t meant for children under 13, and owners must not use it to collect children’s data without the consent the law requires.
Changes
If we change this policy in a way that matters, we’ll update the date above and tell owners by email before it takes effect.