Legal
Privacy, written in plain English.
We built SureForm so you could collect data responsibly — so we hold ourselves to the same standard. This policy explains what we collect, why, and the control you have. If anything is unclear, email us; a human will answer.
Overview
This Privacy Policy explains what information Purple SaaS, LLC (DBA SureForm) ("SureForm", "we", "us") collects when you use the SureForm website, form builder, and hosted forms (together, the "Service"), why we collect it, how long we keep it, and the rights you have over it.
The most important thing to understand about a form builder is that there are two very different kinds of data involved:
- Account data — information about you as our customer (your name, email, billing details, how you use the product).
- Response data — the answers people submit to forms you build. You own this data. We process it on your behalf and never use it for our own purposes.
In short: we don't sell personal data, we don't run advertising trackers, and we don't read your form responses. Response data is processed only to provide the Service to you.
Our role: controller vs. processor
Data protection law distinguishes between a controller (who decides why and how data is processed) and a processor (who processes data on the controller's instructions). SureForm plays both roles, for different data:
| Data | Your role | Our role |
|---|---|---|
| Account data | Data subject | Controller — we decide how to run billing, security, and product analytics |
| Response data | Controller — you decide what your forms ask and why | Processor — we store and transmit responses strictly on your instructions |
| Visitor telemetry on our marketing site | Data subject | Controller |
When we act as your processor, our processing is governed by the Data Processing Addendum described in Section 10 of our Terms of Service. As the controller of your forms, you are responsible for having a lawful basis to collect the data your forms request, and for posting your own privacy notice to your respondents.
Information we collect
Information you give us
- Account registration — name, email address, password (hashed), workspace name.
- Billing information — billing address, VAT/tax ID, and payment method details. Card numbers are handled entirely by our payment processor; we never see or store full card numbers.
- Content you create — forms, themes, templates, logic rules, uploaded brand assets, and email campaign content.
- Support communications — messages you send us, including attachments you choose to share.
Information collected automatically
- Usage data — features used, clicks, session duration, and error events, used to improve the product. This is collected with privacy-respecting, cookieless analytics wherever possible.
- Device & log data — IP address, browser type, operating system, and timestamps, retained for security and abuse prevention.
- Cookie data — see Section 8.
Response data (processed for you)
When someone submits one of your forms, we process whatever your form asks for — which may include names, contact details, files, signatures, or payment details — purely to deliver the submission to you, sync it to your connected integrations, and store it until you delete it or your retention window expires.
How we use information
We use account and usage data to:
- Provide, operate, and secure the Service (authentication, backups, abuse prevention).
- Process payments and manage your subscription.
- Send transactional messages — receipts, security alerts, password resets, and critical product notices.
- Respond to support requests.
- Improve the product through aggregated, de-identified analytics (for example, "which field types are used most").
- Comply with legal obligations, such as tax and accounting rules.
We send product newsletters only with your consent, and every message includes a one-click unsubscribe. We do not sell personal data, and we do not share it with third parties for their own marketing.
We do not use response data to train machine-learning models. If you use the AI form assistant, your prompts are processed to generate your form and are not used to train models for other customers.
Legal bases (GDPR)
If you are in the EEA, UK, or Switzerland, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service | Performance of a contract (Art. 6(1)(b)) |
| Billing & tax records | Legal obligation (Art. 6(1)(c)) |
| Security, abuse prevention, product improvement | Legitimate interests (Art. 6(1)(f)) — keeping the Service safe and making it better |
| Marketing emails & non-essential cookies | Consent (Art. 6(1)(a)) — withdrawable at any time |
For response data, you are the controller and are responsible for your own legal basis. Our consent field type records timestamped consent with an audit trail to help you demonstrate it.
Data retention & deletion
Retention is a feature, not an afterthought:
- Response data — kept until you delete it, or automatically purged at the end of the retention window you configure per form (options from 24 hours to indefinite). Your plan sets the maximum: paid plans retain responses for as long as the subscription is active, and the Free plan retains them for 360 days, after which they and their uploaded files are removed by an automated sweep. Deleted responses are removed from production immediately and from encrypted backups within 30 days.
- Account data — kept while your account is active. When you delete your account, personal data is erased or anonymized within 30 days, except where law requires longer retention (for example, 7 years for tax records).
- Backups — encrypted, access-restricted, and cycled out within 30 days.
- Logs — security and access logs are retained for 12 months.
Your rights & how to exercise them
Depending on where you live, you may have the right to access, correct, export, restrict, or erase your personal data, to object to processing, to withdraw consent, and to lodge a complaint with your supervisory authority.
Account data: most rights are self-serve in Settings → Privacy (export, correct, delete). For anything else, email privacy@sureform.io. We respond within 30 days.
Response data: if you submitted a form built with SureForm and want to exercise your rights, please contact the form's owner directly — they are the controller. If you contact us, we will forward your request to them and assist as your processor. Workspace owners get one-click DSAR export and erasure tools in the responses inbox.
California residents: we do not “sell” or “share” personal information as defined by the CCPA/CPRA, and we honor Global Privacy Control signals.
Security
We protect data with encryption in transit (TLS 1.2+) and at rest (AES-256), hashed passwords, role-based access with least privilege, mandatory SSO and hardware-key 2FA for staff, continuous vulnerability management, and annual third-party penetration tests. File uploads are scanned and served from isolated storage. Payment fields never touch our servers — they go directly to Stripe or PayPal.
No method of transmission or storage is 100% secure. If a breach affects your personal data, we will notify you and the relevant authorities without undue delay and within the timeframes required by law.
Children
The Service is not directed at children under 16, and we do not knowingly collect their data as a controller. If you believe a child has created an account, contact us and we will delete it. Forms you build may be used in educational contexts; collecting data from minors through your forms is your responsibility as controller and must comply with applicable law (including COPPA where relevant).
Changes to this policy
We may update this policy as the product and the law evolve. If we make a material change, we will notify you by email and in-product at least 30 days before it takes effect. The "Last updated" date above always reflects the current version, and prior versions are available on request.
Contact us
Privacy questions, requests, or complaints:
- Email — privacy@sureform.io (Data Protection Officer)
- Post — Purple SaaS, LLC (DBA SureForm), Attn: Privacy, 30 N Gould St Ste R, Sheridan, WY 82801, USA
- EU representative — details available on request for Article 27 inquiries
If you are in the EEA/UK and believe we haven't resolved your concern, you have the right to complain to your local supervisory authority.