Privacy Policy
Last updated: October 3, 2026
At InfiForm ("we," "us," or "our"), accessible via infiform.com, we are committed to safeguarding your privacy and protecting the personal information entrusted to us. This Privacy Policy details the types of personal data we collect, why we collect it, how it is stored and secured, and your legal rights regarding your information.
This policy applies to all visitors to our website, registered account holders ("Form Creators"), and individuals who submit information through forms hosted on our platform ("Form Respondents").
1. Overview & Distinct Data Roles
InfiForm operates as a dual-role platform under global privacy frameworks (including the European Union General Data Protection Regulation / GDPR and the California Consumer Privacy Act / CCPA/CPRA):
- InfiForm as a Data Controller: When you register for an account, subscribe to our plans, navigate our marketing website, or communicate directly with our support team, InfiForm acts as the Data Controller of your account information.
- InfiForm as a Data Processor / Service Provider: When Form Creators build and distribute forms, surveys, or quizzes using InfiForm, the Form Creator acts as the Data Controller of any information submitted by end users. InfiForm processes and stores that response data strictly on behalf of and according to the instructions of the Form Creator.
If you are a Form Respondent with questions about how your submission is handled, we recommend reaching out directly to the organization or individual who provided the form link, as they control your submission data.
2. Information We Collect
A. Information From Form Creators (Account Holders)
When you sign up and manage forms on InfiForm, we collect:
- Account Credentials: Full name, email address, password hash, or third-party authentication tokens (e.g., Google or GitHub OAuth).
- Workspace & Team Information: Organization names, workspace identifiers, team member email invitations, and assigned role permissions (Owner, Admin, Member).
- Billing Information: Payment card details, billing address, and transaction history. All payment card transactions are tokenized and processed directly by our PCI-DSS Level 1 certified payment processor (Stripe); InfiForm never stores raw credit card numbers on its servers.
- Form Configuration & Assets: Questions, conditional logic rules, theme preferences, vector background choices, typography settings, custom domains, and uploaded brand assets.
B. Information From Form Respondents (End Users)
When you complete and submit a form hosted on InfiForm:
- Form Responses: Any text, email address, phone number, physical address, file upload, multiple-choice selection, rating, score, or other data input field requested by the Form Creator.
- Submission Metadata: The timestamp of submission, completion time, browser user agent, referring URL, and IP address (used solely for security verification, DDoS mitigation, and spam prevention).
C. Automatically Collected Technical Data
When browsing our website or interacting with our web applications:
- Device & Browser Information: Device type, operating system version, browser vendor, screen resolution, and language preferences.
- Log Data: Server logs containing IP addresses, request paths, timestamps, HTTP status codes, and referral sources.
- Cookies & Local Storage: Session identifiers, authentication tokens, and UI preferences (such as light or dark theme mode).
3. How We Use Your Information
We process personal information only for legitimate operational and business purposes, including:
- Service Provision: Hosting, rendering, and delivering high-performance conversational forms, surveys, and quizzes.
- AI-Powered Generation: Generating form layouts, question sets, and custom themes when prompted by creators using our AI Form Builder. Form generation prompts are processed ephemerally and are never used to train public machine learning foundation models.
- Analytics & Reporting: Providing creators with submission metrics, conversion rates, and completion time reports.
- Communication: Sending essential transactional emails, password resets, team invitations, submission notifications, and billing invoices.
- Security & Integrity: Detecting and preventing malicious activities, spam submissions, phishing attacks, credential stuffing, and platform abuse.
- Legal Compliance: Complying with applicable laws, tax obligations, subpoena requests, and regulatory audits.
4. 100% Data Ownership & Non-Sale Commitment
- You Own Your Data: Form Creators retain 100% ownership and copyright over their form questions, logos, and collected response data.
- We Never Sell Data: InfiForm does not sell, rent, monetize, or broker personal information, creator information, or respondent data to third-party data brokers or advertisers.
- No Advertising Trackers: We do not inject third-party ad network tracking scripts or behavioral ad pixels into forms you publish.
5. Security & Infrastructure Standards
We implement modern, enterprise-grade technical and organizational safeguards designed to protect personal data:
- Encryption in Transit: All traffic to and from InfiForm web applications and published forms is encrypted via Transport Layer Security (TLS 1.3 / HTTPS).
- Encryption at Rest: All databases, database backups, and uploaded attachments are encrypted at rest using industry-standard AES-256 encryption.
- Isolated Multi-Tenant Architecture: Customer data is segmented logically using tenant and workspace identifiers with row-level security constraints to ensure data separation.
- Soft-Delete Safeguards: Critical resources (forms, workspaces, and team access) employ soft-delete protocols with strict access revocation to protect against accidental data loss.
- Cloud Infrastructure: Our production database is hosted on Neon (managed PostgreSQL) with automated backups, high availability, and secure network firewalls.
6. Subprocessors & Third-Party Service Providers
To operate our platform efficiently, we partner with vetted third-party service providers ("Subprocessors") who meet stringent data privacy standards:
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel | Edge hosting, application routing & serverless compute | United States / Global Edge |
| Neon Inc. | Serverless PostgreSQL database hosting and storage | United States (AWS) |
| Cloudflare, Inc. | Cloudflare R2 object storage and global CDN for form file uploads | Global Edge / United States |
| Stripe, Inc. | PCI-compliant payment processing, invoices & billing | United States / Global |
| Resend | Transactional email delivery (invites, verification) | United States |
| OpenAI / Replicate | AI model inference for on-demand form generation | United States |
All Subprocessors are bound by strict Data Processing Agreements (DPAs) requiring adherence to equivalent data protection and security standards.
7. Data Retention & Deletion
- Account Data: Maintained for as long as your account remains active. If you delete your account, your workspaces and associated personal details will be scheduled for permanent purging from production databases within thirty (30) days.
- Form Responses: Form Creators can export (CSV/JSON) or delete individual submissions or entire form response sets at any time directly through the Form Studio. Once deleted by the creator, responses are removed from active tables immediately.
- Log Files: Operational server logs are automatically rotated and retained for security audit purposes for a maximum of ninety (90) days before automatic expiration.
8. Your Legal Rights (GDPR & Global Standards)
Depending on your country or state of residence (including the European Economic Area, United Kingdom, and Switzerland), you may exercise the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data when no longer needed for lawful purposes.
- Right to Data Portability: Receive your data in a structured, commonly used, and machine-readable format.
- Right to Restrict Processing: Request restriction of processing under certain legal conditions.
- Right to Object: Object to processing based on legitimate business interests.
Note for Form Respondents: If you submitted information into an InfiForm created by an organization or individual, please direct your data rights request directly to the form owner (the Data Controller). We will gladly assist form creators in fulfilling valid data subject requests.
9. California Privacy Rights (CCPA / CPRA)
Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California residents have specific statutory rights:
- The right to know what personal information is collected, disclosed, or shared.
- The right to delete personal information collected from you.
- The right to correct inaccurate personal information.
- The right to non-discrimination for exercising your privacy rights.
- "Do Not Sell or Share My Personal Information": As stated above, InfiForm does not sell or share personal information with third parties for cross-context behavioral advertising.
To exercise these rights, submit a request to privacy@infiform.com.
10. Cookies & Tracking Technologies
We use essential cookies strictly necessary to provide authentication, session security, and user preferences. We do not use third-party cross-site advertising cookies. You can manage or disable cookies via your browser settings, though doing so may affect the functionality of the InfiForm Studio application. For detailed information, please review our Cookie Policy.
11. Children's Privacy
InfiForm is not directed to individuals under the age of 13 (or under 16 in certain jurisdictions). We do not knowingly collect personal data from children. If we become aware that an account has been created by a child under the minimum age, we will immediately take steps to terminate the account and purge associated data.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect enhancements to our features, changes in legal requirements, or operational updates. When significant changes occur, we will update the "Last updated" date at the top of this policy and notify registered creators via email or an in-app banner.
13. Contact Us
If you have questions, comments, or concerns regarding this Privacy Policy or our data protection practices, please contact our team:
- Email: privacy@infiform.com
- Support Inquiries: support@infiform.com
- Website: https://infiform.com