1. Information We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information from third-party services.
Information you provide directly includes: your name and email address when you create an account; form designs and configurations you create; and any support communications you send to us.
Information collected automatically includes: IP address, browser type and version, operating system, pages visited, time spent on pages, and referral URLs. This is collected via server logs and privacy-respecting analytics.
Information from third parties includes: basic profile data (name, email, profile photo) provided by Google when you sign in with Google OAuth.
2. How We Use Your Information
We use the information we collect to:
• Provide, operate, and maintain the ReactForm platform.
• Create and manage your account and authenticate your identity.
• Process payments and manage your subscription (Pro plan).
• Send transactional emails such as password resets, billing receipts, and service notices.
• Respond to your support requests.
• Analyse usage patterns to improve and optimise the Service.
• Detect, prevent, and address security incidents and abuse.
We do not use your personal data for targeted advertising and we do not build advertising profiles.
3. Form Response Data
When respondents submit your forms, their responses are stored in your ReactForm account. You are the data controller for this information.
As the form owner, you are responsible for ensuring that your forms comply with applicable privacy laws in your jurisdiction — including providing appropriate privacy notices to your respondents and having a lawful basis for collecting their data.
ReactForm acts as a data processor for respondent data on your behalf. We process this data only to deliver the Service to you and do not use it for any independent purpose.
You can delete individual responses or all responses at any time from your form dashboard.
4. Data Storage & Security
Your data is stored on Google Cloud infrastructure via Firebase Firestore and Firebase Authentication. Google maintains industry-leading physical and logical security controls.
All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256.
Access to production data is restricted to authorised ReactForm personnel on a need-to-know basis.
While we take reasonable measures to protect your data, no method of transmission over the internet is 100% secure. We encourage you to use a strong, unique password and to enable security features where available.
6. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data to third parties.
We share data with the following categories of service providers solely to operate the platform:
• Firebase / Google Cloud — infrastructure, authentication, and database hosting.
• Payment processors — to process Pro plan subscription payments. We do not store your full card details.
• Email delivery services — to send transactional emails on our behalf.
All third-party providers are contractually bound to process your data only as instructed and to maintain appropriate security measures.
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of ReactForm, our users, or the public.
7. Data Retention
We retain your account data and form data for as long as your account is active.
If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain it for longer.
Anonymised, aggregated data that cannot reasonably be used to identify you may be retained indefinitely for product analytics.
Respondent data stored in your forms is retained until you delete it or until your account is deleted.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
• Access — the right to request a copy of the personal data we hold about you.
• Rectification — the right to ask us to correct inaccurate or incomplete data.
• Erasure — the right to request deletion of your personal data.
• Portability — the right to receive your data in a structured, machine-readable format.
• Objection — the right to object to certain processing activities.
• Restriction — the right to ask us to restrict processing in certain circumstances.
To exercise any of these rights, contact us at support@reactform.co. We will respond within 30 days.
9. Children's Privacy
ReactForm is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13.
If we become aware that we have collected personal information from a child under 13 without verifiable parental consent, we will take steps to delete that information promptly.
If you believe we may have collected information from a child under 13, please contact us at support@reactform.co.
10. International Data Transfers
ReactForm is operated from and your data is processed in data centres that may be located outside your country of residence.
If you are located in the European Economic Area (EEA), your data may be transferred to countries that the European Commission has determined provide an adequate level of protection, or we will implement appropriate safeguards such as standard contractual clauses.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons.
When we make material changes, we will update the effective date at the top of this page and notify you via email or a prominent notice within the platform.
We encourage you to review this Policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the revised Policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: support@reactform.co
We are committed to working with you to resolve any concerns about your privacy.
Have a privacy concern?
We take privacy seriously. Contact us and we'll respond within one business day.
Contact supportAlso see our Terms of Service
