Privacy Policy
Last updated: 1 May 2026
1. Introduction
formbuild.io ("we", "us", or "our") is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the formbuild.io website, application, and related services (the "Service").
This Policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 ("DPDP Act").
2. Information We Collect
a) Information you provide
- Account information: Name (optional), email address, and password when you create an account.
- Payment information: Billing details processed securely through Razorpay. We do not store your credit/debit card numbers, UPI IDs, or bank account details on our servers.
- Form submissions: Data that your end-users submit through forms you create using the Service.
- Communications: Information you provide when you contact us for support.
b) Information collected automatically
- Usage data: Pages visited, features used, timestamps, and interaction patterns.
- Device and browser data: IP address, browser type, operating system, and device identifiers.
- Cookies: We use essential cookies for authentication and session management. We do not use third-party tracking cookies.
3. How We Use Your Information
- To provide, maintain, and improve the Service.
- To process payments and manage your subscription.
- To send transactional emails (account verification, password resets, security alerts).
- To respond to your inquiries and provide customer support.
- To detect, prevent, and address fraud, abuse, and security issues.
- To comply with legal obligations under applicable Indian law.
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We may share your information only in the following circumstances:
- Service providers: With trusted third-party service providers who assist in operating the Service (e.g. Razorpay for payments, Resend for transactional emails, Vercel for hosting). These providers are contractually bound to protect your data.
- Legal requirements: When required by law, court order, or governmental authority under applicable Indian law.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to you.
5. Data Storage and Security
- Your data is stored on secure servers. All connections are encrypted using HTTPS/TLS.
- Passwords are hashed using industry-standard algorithms and are never stored in plaintext.
- We implement reasonable security practices and procedures as required under the IT (Reasonable Security Practices) Rules, 2011.
- While we take all reasonable measures, no method of electronic storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
- We retain your personal data for as long as your account is active or as needed to provide the Service.
- Upon account deletion, your personal data will be permanently deleted within 90 days, except where retention is required by law.
- Form submission data is retained as long as the associated form and account exist. You may delete individual submissions or entire forms at any time.
7. Your Rights
Under the DPDP Act, 2023 and applicable regulations, you have the following rights:
- Right to access: Request a summary of your personal data that we hold.
- Right to correction: Request correction of inaccurate or incomplete personal data.
- Right to erasure: Request deletion of your personal data, subject to legal retention requirements.
- Right to withdraw consent: Withdraw your consent for data processing at any time. This may affect your ability to use the Service.
- Right to grievance redressal: File a complaint with our Grievance Officer or escalate to the Data Protection Board of India.
To exercise any of these rights, contact us at security@formbuild.io.
8. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a minor, we will take steps to delete it promptly.
9. Cross-Border Data Transfers
Your data may be processed on servers located outside India (e.g. for hosting and email delivery). We ensure that any such transfer is compliant with applicable provisions of the DPDP Act and that adequate safeguards are in place.
10. Grievance Officer
In accordance with the Information Technology Act, 2000, the details of our Grievance Officer are:
Grievance Officer
Email: security@formbuild.io
We shall acknowledge your grievance within 24 hours and resolve it within 15 days from the date of receipt.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or by posting a notice on the Service at least 15 days before taking effect. Your continued use of the Service constitutes acceptance of the updated Policy.
12. Contact Us
For any questions or concerns about this Privacy Policy, reach out to us:
formbuild.io
Email: security@formbuild.io