This Privacy Policy explains how personal data is handled when you use HornetForms. We have tried to keep it short and in plain English. Where a word is in bold the first time it appears, it has the meaning given there.
1. Who we are#
HornetForms is operated by PhraseMine LLC, a Delaware limited liability company, with its registered address at 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA ("PhraseMine", "we", "us").
In this policy, the "Service" means the HornetForms app at https://forms.hornetforms.com (including custom domains that our customers connect to it) and our website at https://hornetforms.com.
- Contact for privacy matters (and anything else): info@hornetforms.com
- Data protection officer: we have not appointed a data protection officer.
- EU and UK representative: we have not appointed an EU or UK representative; contact us at info@hornetforms.com.
2. Scope#
This policy covers:
- Account holders: people who create an account to build forms, work together in workspaces or use the API ("users").
- Website visitors: people who visit hornetforms.com or our own pages in the app (sign-in, sign-up, dashboard).
- Respondents: people who view or fill in forms published on the Service, to the extent we process their data ourselves (see section 3).
3. Our role: controller and processor#
Forms are created and published by our users ("form owners"). For the content of a form and the responses it collects, the form owner decides what is collected and why. The form owner is the controller, and we process responses on the form owner's behalf as a processor (or "service provider"), under our Data Processing Addendum.
If you responded to a form, please contact the form owner first about your response (access, correction, deletion). The form owner's contact details and privacy notice should be shown on or linked from the form. We help form owners answer such requests, and we forward requests we receive to the form owner where we can identify them.
We are the controller for account data, for our website, for the security and operational data described below, and for the forms we run ourselves (for example our waitlist form).
4. What we process#
4.1 Account data#
- Name, email address, password (stored only as a salted hash), email verification status, workspace memberships and roles, and invitations you send or receive.
- Sign-in sessions: a session record with the IP address and browser user agent of the device you signed in from, kept until the session expires or you sign out.
- Security records: short-lived rate-limit counters keyed by IP address and action for sign-in, sign-up and similar actions; one-time links and codes sent by email (stored hashed where possible).
- API keys you create (the secret part is stored only as a hash; a public identifier and the last four characters are kept in clear) and an audit log of API actions in your workspaces (action, resource, time and a hashed IP address), kept for 180 days.
4.2 Content created by users#
- Forms, their questions, logic, translations, designs, themes, uploaded images (logos, covers, social images), templates, folders and draft history. Automatic draft snapshots are deleted after 90 days.
- Integrations you configure: webhook endpoints (their signing secrets are stored encrypted), notification email settings and, for custom domains, the domain names.
4.3 Form responses (processed for form owners)#
- Answers to the form's questions, including any personal data the form asks for, and files uploaded by respondents.
- Response metadata: submission and start time, duration, the browser user agent, the referring page address as reported by the browser, UTM campaign parameters (
utm_source,utm_medium,utm_campaign,utm_term,utm_content) stored as they appear in the link (they may contain personal data if whoever created the link put it there), whether the form was embedded, and the language shown. - IP hash: a keyed hash of the respondent's IP address, used to limit abuse (rate limiting, duplicate submissions). The raw IP address is not stored with the response.
- One response per person: if the form owner turns this on, a keyed hash of the identifying answer (for example an email address) is stored to prevent duplicate responses. If email verification is turned on, a hashed email address and a code are stored; codes expire after 10 minutes and the records are deleted after 24 hours.
- Partial responses: if the form owner turns on saving progress, unfinished answers are stored so the respondent can resume. Untouched partial responses are deleted after 30 days.
- Edit history: when a form owner edits a response, the previous answers are kept as revisions (at most 100 per response). Deleting a response also deletes its edit history and its uploaded files.
- Form owners can export responses (CSV and Excel), receive them in email notifications, send them to their own webhooks or read them through the API.
4.4 Form analytics (Insights)#
The Service records cookieless statistics about form visits for form owners: the visit day and time, progress through the form, completion, duration, the referring site name only (no page path or query), UTM source, medium and campaign, coarse device type, browser family, operating system and language. Unique visitors are counted with a hash of the IP address network and user agent combined with a random salt that changes every day; old salts are deleted, after which the hashes can no longer be linked to anyone. No cookies or similar identifiers are used for this. Raw visit records are deleted after 90 days; daily totals are kept for the life of the form.
4.5 Tracking tools added by form owners#
Form owners can add Google Analytics 4, Google Tag Manager or the Meta Pixel to their own full-page forms. These tools never load in embedded forms, and Google Tag Manager only runs on a form owner's verified custom domain. When a form owner adds one, the script loads from Google or Meta in the respondent's browser and that provider processes data under its own terms.
Form owners can switch on a consent banner, in which case these scripts do not load until the respondent accepts. If the form owner does not switch it on, the scripts load when the form opens, and the form owner is responsible for any consent the law requires. Browsers that send a Global Privacy Control signal never load these scripts. We do not use these tools on our own pages.
4.6 Other third-party content on forms#
- Bot protection: forms whose owner turned on spam protection load Cloudflare Turnstile, which processes browser and device signals to tell people from bots. Turnstile is not used on our sign-in or sign-up pages.
- Embedded content: when a form owner embeds a video, map or scheduling widget (for example YouTube, loaded from the privacy-enhanced domain
youtube-nocookie.com, Vimeo, Loom, Calendly or Google Maps), that content loads from the provider, which processes the respondent's data under its own terms.
4.7 Emails#
We send emails through Resend (sending region: EU, Ireland): account emails (verification, password reset, sign-in links, invitations, account deletion), notifications to form owners about new responses (which can include answers), confirmation emails to respondents when the form owner turns them on, email verification codes, and service notices (for example about a disabled webhook). Resend receives the recipient's address and the email content.
4.8 AI features#
When a user asks the Service to generate or translate a form, the user's instructions and the relevant form content are sent to OpenRouter and the model provider it routes the request to (by default OpenAI), together with a pseudonymous hash of the user's account id, which the provider uses to detect abuse. We store only usage metadata (time, model, token counts and any error code), not the prompt or the result outside the form itself. Respondents' answers are never sent to AI providers.
4.9 Cookies and browser storage#
- Cookies in the app: we use only cookies the Service needs to work: sign-in session cookies for account holders, and a time-zone preference cookie in the dashboard. We do not use analytics or advertising cookies on our own pages.
- Browser storage on public forms (local or session storage; nothing is sent to us unless noted): a resume token for saving progress (the server stores only its hash), the unlock token of a password-protected form for the current tab, a "you already responded" marker when the form owner limits responses per browser, and the respondent's choice in the consent banner.
- Tracking tools added by form owners (section 4.5) may set their own cookies.
Our Cookies page has more detail.
4.10 Server logs and error reports#
- Logs: our servers log technical events (errors, background job results, request status and timing for the API). Logs do not contain form answers, request bodies, raw IP addresses, email addresses, passwords or tokens. Logs are stored on our servers in Germany, rotated automatically and kept for up to 30 days.
- Error reports: when an error occurs, a technical report (error type and message, code location, the route pattern or job queue and the software version) is sent to Sentry (Functional Software, Inc., US data region). Email addresses, IP addresses, tokens, query strings and long secret-like values are removed before sending, and no user, request body, cookie or answer data is included.
4.11 Backups#
We back up the database and uploaded files every night. Backups contain all the data described in this section, including sign-in session records. They are kept on our server and, encrypted before they leave the server, with a separate storage provider (Cloudflare R2) that cannot read them. Our hosting provider also keeps whole-server backups. Backups are access-controlled and rotate automatically; see section 6 for how long they are kept.
4.12 Website visitors (hornetforms.com)#
- Analytics: hornetforms.com uses Cloudflare Web Analytics, which counts page views without cookies and without building profiles of visitors. We see only totals (for example pages viewed, referring sites, countries and browsers).
- Hosting: the website is delivered by Cloudflare, whose servers process your IP address and request details to deliver pages and protect the site against attacks.
- Contacting us: if you email us, we receive your email address and whatever you write, and use it to reply.
- Waitlist: while sign-ups are by invitation only, you can join our waitlist through a form hosted on HornetForms. We use what you enter (for example your name and email address) to invite you when a place is available and to tell you about the launch.
- Live demo: if you open a demo or waitlist form on our website, it loads from the HornetForms app and is handled as described in sections 4.3 to 4.6.
5. Purposes and legal bases#
The legal bases below are those of the EU and UK General Data Protection Regulation (GDPR).
| Purpose | Data | Legal basis |
|---|---|---|
| Providing accounts, workspaces, forms and integrations | 4.1, 4.2, 4.7, 4.8 | Contract (Art. 6(1)(b)) |
| Hosting and processing responses for form owners | 4.3 to 4.6 | Processing on the form owner's instructions (Art. 28); the form owner needs its own legal basis |
| Security, abuse and spam prevention, rate limiting | IP hashes, session records, rate-limit counters, bot protection, logs | Legitimate interests (Art. 6(1)(f)) in keeping the Service and its users safe |
| Keeping the Service running and fixing errors | Logs, error reports | Legitimate interests (Art. 6(1)(f)) |
| Backups and disaster recovery | 4.11 | Legitimate interests (Art. 6(1)(f)) |
| Service emails | 4.7 | Contract; legitimate interests |
| Website analytics and delivery | 4.12 | Legitimate interests (Art. 6(1)(f)) in running and improving our website |
| Answering your messages | 4.12 | Legitimate interests (Art. 6(1)(f)); contract where your message is about your account |
| Waitlist | 4.12 | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Complying with the law and defending legal claims | Any data needed for the purpose | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
6. How long we keep data#
| Data | How long we keep it |
|---|---|
| Account data and content | Until you delete your account or the workspace. Deleted forms stay in the trash for 30 days, then are deleted with their responses and files. |
| Responses | Until the form owner deletes them, the form is deleted, or the form's automatic deletion setting removes them (configurable per form, 1 to 3,650 days) |
| Unfinished (partial) responses | 30 days after the last change |
| Abandoned file uploads | 24 hours (at most 7 days) |
| Raw visit records (Insights) | 90 days; daily totals for the life of the form |
| Email verification records | 24 hours |
| Webhook delivery log | Payloads 30 days, delivery records 90 days |
| API audit log | 180 days |
| Draft snapshots | 90 days |
| Sign-in sessions | Until they expire or you sign out |
| Server logs | Up to 30 days |
| Error reports | For the retention period of our Sentry plan, no longer than 90 days |
| Database and upload backups | 14 days, on our server and off-site (the three most recent backups are always kept) |
| Whole-server backups by our hosting provider | 7 daily backups |
| Emails you send us | As long as needed to deal with your message and any follow-up |
| Waitlist entries | Until we have invited you and the waitlist is closed, or until you ask us to remove you |
Because whole-server backups can contain our most recent database backups, data you delete can remain in backups for up to about three weeks before it is gone for good. Backups are never used for anything other than restoring the Service.
7. Recipients and sub-processors#
We share personal data only with service providers that process it for us under data processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Servers, database, uploaded files, server backups | Germany |
| Cloudflare, Inc. | Bot protection (Turnstile), encrypted off-site backups (R2), DNS; hosting and cookieless analytics for hornetforms.com | United States and global network |
| Resend, Inc. | Sending emails | EU (Ireland) sending region; company in the United States |
| OpenRouter, Inc. and OpenAI, L.L.C. | AI form generation and translation | United States |
| Functional Software, Inc. (Sentry) | Error reports | United States |
The full, current list with more detail is on our Sub-processors page.
Form owners decide where their responses go next (their email inbox, webhooks, exports, API clients and tracking tools they add). Those recipients are the form owner's responsibility.
We may disclose personal data where the law requires it, for example in response to a valid court order, and to protect the rights, safety and property of our users, the public or PhraseMine. Where the law allows, we will tell the affected customer first. If PhraseMine is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of that transaction, and this policy will continue to apply to it.
8. International transfers#
The Service's data (database, uploaded files and backups on our server) is stored in Germany, in the European Union. PhraseMine is a US company, and some of our service providers are based in the United States (see section 7). When personal data from the European Economic Area, the United Kingdom or Switzerland is accessed from or transferred to a country without an adequacy decision, we protect it with:
- the EU Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914;
- for UK data, the UK International Data Transfer Addendum to those clauses, and for Swiss data, the clauses as adapted for Swiss law; and
- where applicable, the recipient's certification under the EU-U.S. Data Privacy Framework (and its UK extension and Swiss framework).
You can ask us for a copy of the relevant safeguards at info@hornetforms.com.
9. Your rights#
Depending on where you live, you may have the right to access, correct or delete your personal data, to restrict or object to its processing, to data portability, and to withdraw consent at any time (without affecting processing before you withdrew it). If you are in the EU, EEA, UK or Switzerland, you also have the right to complain to the data protection supervisory authority in the country where you live or work, or where you think the law was broken (in the UK, the Information Commissioner's Office).
- Account holders can download a copy of their account data and delete their account at any time on the Profile page (
/profile). Deleting your account removes your account data; your personal workspace and workspaces where you are the only member are deleted with their forms and responses. If you are the only owner of a shared workspace, transfer ownership or delete it first. - Respondents: please contact the form owner (see section 3). A form owner can delete individual responses; deleting a response also deletes its uploaded files and its edit history.
- Waitlist: email us and we will remove you.
- For anything else, email info@hornetforms.com. We will answer within one month and may need to verify your identity first.
10. US state privacy rights#
If you live in California or another US state with a consumer privacy law, and that law applies to us, you have the right to:
- know what personal information we collect, use and disclose (sections 4 to 7 describe this);
- access and get a copy of your personal information;
- correct inaccurate personal information;
- delete your personal information; and
- not be discriminated against for using these rights.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information to infer characteristics about you.
To make a request, email info@hornetforms.com. We will verify your request by matching it with information we already hold (for example by asking you to confirm from your account's email address). You can use an authorised agent; we may ask the agent for proof that you authorised it. If we decline your request, you can appeal by replying to our answer with "Appeal" in the subject line, and we will respond within the time the law requires.
If you responded to a form, the form owner is the business responsible for your response; please contact them first.
11. Security#
We protect personal data with HTTPS for all connections, passwords, tokens and IP addresses stored only as hashes, encrypted secrets (for example webhook signing secrets), role-based access to workspaces, rate limiting and bot protection, hardened servers that receive security updates automatically, restricted administrative access, and encrypted off-site backups that we test by restoring them. The Service is hosted in ISO 27001-certified data centres in Germany.
No system is perfectly secure. If a personal data breach affects you, we will notify you, our customers and the authorities where the law requires.
12. Children#
The Service is not directed to children under 16, and you must be at least 16 to create an account. We do not knowingly collect personal information from children under 13 (as defined by the US Children's Online Privacy Protection Act, COPPA). If we learn that we have, we will delete it. If you believe a child has given us personal information, please contact us.
Form owners who use the Service to collect data from children are responsible for obtaining any parental consent the law requires, including under COPPA.
13. Changes to this policy#
We may update this policy from time to time. We will post the new version on this page with a new "last updated" date and, for material changes, tell account holders by email or in the Service before the change takes effect.
14. Contact#
PhraseMine LLC, 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA
Email: info@hornetforms.com
Related documents: Terms of Service, Data Processing Addendum, Sub-processors, Cookies.