Legal

Privacy Policy

Last updated: February 6, 2026

Overview

FormDrop ("we", "us", "our") operates the formdrop.dev website and form processing service. This Privacy Policy explains how we collect, use, and protect information when you use our service.

We are committed to being a privacy-first form backend. We collect only what is necessary to provide the service and never sell your data.

Information We Collect

Account Information

When you create an account, we collect your email address and password (stored securely via Supabase Auth). We use this to authenticate you and send service-related communications.

Form Submission Data

When someone submits a form through your endpoint, we collect:

  • The form field data submitted by the visitor
  • The submitter's IP address (for rate limiting and spam protection)
  • The submitter's user agent string
  • The referring page URL
  • A timestamp of the submission

This data is stored in your account and is accessible only to you. We do not access, analyze, or share the contents of form submissions.

Payment Information

If you upgrade to a paid plan, payment processing is handled entirely by Stripe. We do not store your credit card number. We receive only a Stripe customer ID and subscription status to manage your account.

Usage Data

We track aggregate usage metrics (submission counts per month) to enforce plan limits. We use Plausible Analytics, a privacy-friendly, cookie-free analytics tool, to understand site usage. No personal data is collected by our analytics.

How We Use Your Information

  • To provide and maintain the FormDrop service
  • To send email notifications when forms are submitted
  • To enforce rate limits and prevent spam/abuse
  • To manage billing and plan limits
  • To communicate service updates or issues

Data Storage & Security

All data is stored in Supabase (backed by PostgreSQL) with row-level security enabled. Data is encrypted in transit (TLS) and at rest. Our application is hosted on Vercel. We use industry-standard security practices to protect your data.

Data Sharing

We do not sell, rent, or share your personal data or form submission data with third parties, except:

  • Service providers — Supabase (database), Vercel (hosting), Stripe (payments), and Resend (email delivery) process data on our behalf to provide the service.
  • Legal requirements — We may disclose information if required by law, regulation, or legal process.

Data Retention

Your form submissions are retained as long as your account is active. If you delete a form, its submissions are permanently deleted. If you delete your account, all associated data is removed.

Your Rights

You can access, export, or delete your form data at any time through the dashboard. To delete your account entirely, contact us at the email below.

Cookies

We use only essential cookies required for authentication (session tokens) on the FormDrop dashboard. We do not use advertising or tracking cookies. Our analytics (Plausible) are fully cookie-free. Importantly, your form endpoints set zero cookies on your visitors.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date.

Contact

If you have questions about this Privacy Policy, contact us at support@formdrop.dev.