Skip to content
SureForm
  • H.
  • Features
  • Templates
  • Styles
  • Pricing
  • Integrations
English Español Português Italiano
Start building
H. Features Templates Styles Pricing Integrations
Start building

Legal

Privacy, written in plain English.

Last updated · July 22, 2026Applies to all SureForm plans, including Free.

We built SureForm so you could collect data responsibly — so we hold ourselves to the same standard. This policy explains what we collect, why, and the control you have. If anything is unclear, email us; a human will answer.

On this page

  • Overview
  • Our role: controller vs. processor
  • Information we collect
  • How we use information
  • Legal bases (GDPR)
  • Data retention & deletion
  • Sub-processors & international transfers
  • Cookies & tracking
  • Your rights & how to exercise them
  • Security
  • Children
  • Changes to this policy
  • Contact us

01Overview

This Privacy Policy explains what information Purple SaaS, LLC (DBA SureForm) ("SureForm", "we", "us") collects when you use the SureForm website, form builder, and hosted forms (together, the "Service"), why we collect it, how long we keep it, and the rights you have over it.

The most important thing to understand about a form builder is that there are two very different kinds of data involved:

  • Account data — information about you as our customer (your name, email, billing details, how you use the product).
  • Response data — the answers people submit to forms you build. You own this data. We process it on your behalf and never use it for our own purposes.

In short: we don't sell personal data, we don't run advertising trackers, and we don't read your form responses. Response data is processed only to provide the Service to you.

02Our role: controller vs. processor

Data protection law distinguishes between a controller (who decides why and how data is processed) and a processor (who processes data on the controller's instructions). SureForm plays both roles, for different data:

DataYour roleOur role
Account dataData subjectController — we decide how to run billing, security, and product analytics
Response dataController — you decide what your forms ask and whyProcessor — we store and transmit responses strictly on your instructions
Visitor telemetry on our marketing siteData subjectController

When we act as your processor, our processing is governed by the Data Processing Addendum described in Section 10 of our Terms of Service. As the controller of your forms, you are responsible for having a lawful basis to collect the data your forms request, and for posting your own privacy notice to your respondents.

03Information we collect

Information you give us

  • Account registration — name, email address, password (hashed), workspace name.
  • Billing information — billing address, VAT/tax ID, and payment method details. Card numbers are handled entirely by our payment processor; we never see or store full card numbers.
  • Content you create — forms, themes, templates, logic rules, uploaded brand assets, and email campaign content.
  • Support communications — messages you send us, including attachments you choose to share.

Information collected automatically

  • Usage data — features used, clicks, session duration, and error events, used to improve the product. This is collected with privacy-respecting, cookieless analytics wherever possible.
  • Device & log data — IP address, browser type, operating system, and timestamps, retained for security and abuse prevention.
  • Cookie data — see Section 8.

Response data (processed for you)

When someone submits one of your forms, we process whatever your form asks for — which may include names, contact details, files, signatures, or payment details — purely to deliver the submission to you, sync it to your connected integrations, and store it until you delete it or your retention window expires.

04How we use information

We use account and usage data to:

  1. Provide, operate, and secure the Service (authentication, backups, abuse prevention).
  2. Process payments and manage your subscription.
  3. Send transactional messages — receipts, security alerts, password resets, and critical product notices.
  4. Respond to support requests.
  5. Improve the product through aggregated, de-identified analytics (for example, "which field types are used most").
  6. Comply with legal obligations, such as tax and accounting rules.

We send product newsletters only with your consent, and every message includes a one-click unsubscribe. We do not sell personal data, and we do not share it with third parties for their own marketing.

We do not use response data to train machine-learning models. If you use the AI form assistant, your prompts are processed to generate your form and are not used to train models for other customers.

05Legal bases (GDPR)

If you are in the EEA, UK, or Switzerland, we rely on the following legal bases:

PurposeLegal basis
Providing the ServicePerformance of a contract (Art. 6(1)(b))
Billing & tax recordsLegal obligation (Art. 6(1)(c))
Security, abuse prevention, product improvementLegitimate interests (Art. 6(1)(f)) — keeping the Service safe and making it better
Marketing emails & non-essential cookiesConsent (Art. 6(1)(a)) — withdrawable at any time

For response data, you are the controller and are responsible for your own legal basis. Our consent field type records timestamped consent with an audit trail to help you demonstrate it.

06Data retention & deletion

Retention is a feature, not an afterthought:

  • Response data — kept until you delete it, or automatically purged at the end of the retention window you configure per form (options from 24 hours to indefinite). Your plan sets the maximum: paid plans retain responses for as long as the subscription is active, and the Free plan retains them for 360 days, after which they and their uploaded files are removed by an automated sweep. Deleted responses are removed from production immediately and from encrypted backups within 30 days.
  • Account data — kept while your account is active. When you delete your account, personal data is erased or anonymized within 30 days, except where law requires longer retention (for example, 7 years for tax records).
  • Backups — encrypted, access-restricted, and cycled out within 30 days.
  • Logs — security and access logs are retained for 12 months.

07Sub-processors & international transfers

We work with a small list of vetted sub-processors to run the Service — cloud hosting, payment processing, transactional email, and error monitoring. Each is bound by a data processing agreement with confidentiality and security obligations at least as protective as ours. The current list is available on request at privacy@sureform.io, and we give 30 days' notice before adding a new sub-processor, during which you may object.

Data is stored in the EU by default for EU workspaces (EU data residency is available on request for all paid plans). Where data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses and supplementary measures, and we assess each transfer under applicable law.

08Cookies & tracking

We keep this short because our cookie use is genuinely short:

  • Strictly necessary — session authentication, security tokens, load balancing, and your theme preference (light/dark). These cannot be switched off.
  • Analytics (consent-based) — aggregate, cookieless product analytics wherever technically possible; where a cookie is used, it is set only after consent.
  • No advertising cookies. No cross-site tracking. No data brokers.

Forms you publish may set strictly necessary cookies for security (for example, CSRF protection). Marketing cookies on your forms are your responsibility as controller.

09Your rights & how to exercise them

Depending on where you live, you may have the right to access, correct, export, restrict, or erase your personal data, to object to processing, to withdraw consent, and to lodge a complaint with your supervisory authority.

Account data: most rights are self-serve in Settings → Privacy (export, correct, delete). For anything else, email privacy@sureform.io. We respond within 30 days.

Response data: if you submitted a form built with SureForm and want to exercise your rights, please contact the form's owner directly — they are the controller. If you contact us, we will forward your request to them and assist as your processor. Workspace owners get one-click DSAR export and erasure tools in the responses inbox.

California residents: we do not “sell” or “share” personal information as defined by the CCPA/CPRA, and we honor Global Privacy Control signals.

10Security

We protect data with encryption in transit (TLS 1.2+) and at rest (AES-256), hashed passwords, role-based access with least privilege, mandatory SSO and hardware-key 2FA for staff, continuous vulnerability management, and annual third-party penetration tests. File uploads are scanned and served from isolated storage. Payment fields never touch our servers — they go directly to Stripe or PayPal.

No method of transmission or storage is 100% secure. If a breach affects your personal data, we will notify you and the relevant authorities without undue delay and within the timeframes required by law.

11Children

The Service is not directed at children under 16, and we do not knowingly collect their data as a controller. If you believe a child has created an account, contact us and we will delete it. Forms you build may be used in educational contexts; collecting data from minors through your forms is your responsibility as controller and must comply with applicable law (including COPPA where relevant).

12Changes to this policy

We may update this policy as the product and the law evolve. If we make a material change, we will notify you by email and in-product at least 30 days before it takes effect. The "Last updated" date above always reflects the current version, and prior versions are available on request.

13Contact us

Privacy questions, requests, or complaints:

  • Email — privacy@sureform.io (Data Protection Officer)
  • Post — Purple SaaS, LLC (DBA SureForm), Attn: Privacy, 30 N Gould St Ste R, Sheridan, WY 82801, USA
  • EU representative — details available on request for Article 27 inquiries

If you are in the EEA/UK and believe we haven't resolved your concern, you have the right to complain to your local supervisory authority.

SureForm

Forms that feel designed. Built by a small team that obsesses over the details so you don't have to.

Product

  • Features
  • Templates
  • Styles
  • Blog
  • Pricing
  • How we compare
  • Integrations

Resources

  • Docs
  • API reference
  • Community
  • Migration guide
  • Status

Company

  • Careers
  • Contact
  • Press kit

Legal

  • Privacy
  • Terms
  • Fair Usage
  • DPA
  • GDPR
  • Refunds & Disputes
SureForm
© 2026 Purple SaaS, LLC (DBA SureForm) · 30 N Gould St Ste R, Sheridan, WY 82801 All systems operational
Contact usWe're here to help — ask us anything about SureForm and we usually reply within a day.
Need help?