Legal

Privacy Policy

Last updated: February 20, 2026

1. Who We Are

FormFast ("we," "us," or "our") operates the FormFast service at formfa.st. FormFast provides form backend endpoints that receive HTML form submissions and deliver them via email, webhooks, and other integrations.

For questions about this policy, contact us at contact@formfa.st.

2. Data We Collect

We collect information in two capacities:

a) As a Data Controller — Your Account Data

  • Name, email address, and password when you create an account
  • Billing information processed through Stripe (we do not store card numbers)
  • Usage data: pages visited, features used, IP address, browser type, and device information
  • Cookies and similar technologies (see Section 9)

b) As a Data Processor — Form Submissions

  • Data submitted through your form endpoints by your end users
  • File uploads attached to form submissions
  • Submission metadata: IP address, timestamp, user agent, and referrer of the submitter

You (the form owner) are the data controller for your end users' submissions. We process this data solely to provide the FormFast service to you.

3. How We Use Your Data

  • To provide, maintain, and improve the FormFast service
  • To process and deliver form submissions via email, webhooks, or the dashboard
  • To handle billing and subscription management
  • To send transactional emails (account verification, password resets, submission notifications)
  • To detect and prevent spam, fraud, and abuse
  • To generate aggregated, anonymized analytics to improve the service
  • To respond to support requests

We do not sell your personal data or form submission data to third parties. We do not use form submission data for advertising, profiling, or any purpose beyond delivering the service.

4. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), we process your data under the following legal bases:

  • Contractual necessity — to provide the service you signed up for
  • Legitimate interest — for fraud prevention, security, and service improvement
  • Consent — where you have explicitly opted in (e.g. marketing emails)
  • Legal obligation — where required by law (e.g. tax records)

5. Third-Party Services

We share data with the following categories of service providers, solely to operate the service:

  • Cloud infrastructure: Amazon Web Services (AWS) — hosts our servers and databases
  • Email delivery: AWS Simple Email Service (SES) — sends submission notification emails
  • Payments: Stripe — processes subscription payments (see Stripe's Privacy Policy)
  • Analytics: Vercel Analytics — collects anonymized usage data
  • Authentication: Secure session management via encrypted cookies

We require all third-party processors to handle data in accordance with applicable data protection laws.

6. Data Retention

  • Account data: retained while your account is active, deleted within 30 days of account deletion
  • Form submissions (Free plan): stored for 30 days
  • Form submissions (Pro plan): stored for 1 year
  • Form submissions (Business/Enterprise): stored indefinitely while the account is active
  • Billing records: retained for 7 years as required by tax law
  • Server logs: retained for 90 days

You can delete individual submissions or your entire account at any time from the dashboard.

7. Your Rights

Depending on your location, you may have the following rights:

GDPR Rights (EEA Residents)

  • Right of access — request a copy of your personal data
  • Right to rectification — correct inaccurate data
  • Right to erasure — request deletion of your data
  • Right to data portability — receive your data in a machine-readable format
  • Right to restrict processing
  • Right to object to processing
  • Right to withdraw consent at any time

CCPA Rights (California Residents)

  • Right to know what personal information we collect and how it is used
  • Right to delete personal information
  • Right to opt out of the sale of personal information (we do not sell data)
  • Right to non-discrimination for exercising your rights

To exercise any of these rights, email contact@formfa.st. We will respond within 30 days.

8. International Data Transfers

FormFast is hosted on AWS infrastructure in the United States. If you are located outside the United States, your data will be transferred to and processed in the US.

For EEA users, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission, which are included in the AWS Data Processing Addendum, to ensure adequate protection for cross-border data transfers.

9. Cookies and Tracking

We use the following types of cookies:

  • Essential cookies: required for authentication and session management — cannot be disabled
  • Analytics cookies: Vercel Analytics collects anonymized page view and performance data

We do not use advertising cookies or cross-site tracking. You can manage cookie preferences in your browser settings.

10. Security

We implement industry-standard security measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS) and at rest
  • Secure password hashing (bcrypt)
  • Role-based access controls
  • Regular security reviews

No system is 100% secure. If you discover a security vulnerability, please report it to contact@formfa.st.

11. Children's Privacy

FormFast is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

12. Data Processing Agreement

If you require a Data Processing Agreement (DPA) for GDPR compliance, please contact us at contact@formfa.st and we will provide one.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or a prominent notice on the service. Continued use of FormFast after changes take effect constitutes acceptance of the updated policy.

14. Contact

If you have questions about this Privacy Policy or your data, contact us at:

contact@formfa.st