hform/legal

Privacy policy

Last updated 2026-08-16 · hform.com is run by an independent maker in Sweden. Questions or requests: the contact form.

You can wear three hats on hform. Here's what we know about you in each one.

1 · You're visiting the site

We use self-hosted, cookieless analytics (Umami, running on our own server in Sweden) to count visits. It stores no cookies and builds no personal profiles. There are no ads and no third-party trackers. That's the whole list.

2 · You run forms with us

We store: your email address, your forms, and the messages they receive. We email you sign-in links, message notifications and service notices — no marketing without asking you first. Signing in sets one session cookie so you stay signed in; it identifies your session and nothing else. We never sell data. Payment details (when paid plans arrive) will be handled by Stripe — card numbers never touch our servers.

3 · You filled in someone's form

The form's owner decides what their form asks; we store what you send on their behalf — legally, they are the controller and we are the processor (see the data processing agreement). Alongside your answers we keep an anonymized fingerprint of your IP address (a one-way hash we can't reverse — used only against abuse), your browser type and the referring page. Bot protection (Cloudflare Turnstile) may process technical signals about your browser to tell you apart from a robot. Want your submission deleted? Ask the form's owner, or contact us.

Where your data lives

On our own server in Stockholm, Sweden — inside the EU. Emails are delivered via Postmark (USA) under EU standard contractual clauses.

How long we keep things

Your rights (GDPR)

You can see, correct, export and delete your data. Export is built in (CSV in your dashboard). For everything else, one message is enough — no forms to fill in about forms.

Changes

If this policy changes in a way that matters, we'll say so here and note the date above.