Privacy
PostForm receives form submissions on behalf of the people who run websites, stores them, and emails them on. That means most of the personal data we hold was not given to us by the person it describes. It was typed into somebody else's contact form. This page says what we do with it and how to get it removed.
If you filled in a form and ended up here
We are the company that delivered your message to the site owner. We are not the site owner, and we do not act on your message. We hold what you typed into the form, the email address you gave if you gave one, and the IP address the submission came from.
We delete all of it automatically after 30 days. We also take a nightly encrypted backup of the database, kept for a further 30 days, so a deleted submission can persist in a backup for that much longer before it ages out. We do not restore backups to bring deleted data back. If you want it gone sooner, email privacy@postform.dev from the address you used, or tell us the site and roughly when you submitted, and we will delete it and confirm. You do not need an account and there is no form to fill in.
You should also contact the site owner: they received a copy by email and their copy is theirs, not ours. We can only delete our own.
What we store
| Data | Why | Kept for |
|---|---|---|
| Submission contents | To deliver them to the site owner and let them re-read them in the dashboard | 30 days |
| Submitter email address | Used as the Reply-To so the site owner can answer | 30 days |
| Submitter IP address | Rate limiting and abuse investigation. This is the only thing we hold on our own account rather than the site owner's | 30 days |
| Account email and password | To let a customer log in | Until the account is deleted |
| Endpoint request log (IP, key, outcome) | So a customer can tell a broken form from a quiet one | 30 days |
We do not use cookies for analytics or advertising. The only cookie we set is the session cookie that keeps a logged-in customer logged in.
Our role
For submission contents we are a processor: the site owner decides what to collect and why, and we act on their instructions. Our data processing agreement sets out those terms and forms part of our contract with every customer.
For IP addresses, account details and error reports we are a controller: nobody asked us to collect those, we do it to keep the service working and to stop it being abused. The lawful basis is legitimate interest.
Who else sees it
These are the only third parties involved, and none of them sell data:
| Provider | What for | Where |
|---|---|---|
| Supabase | Postgres database and authentication | EU/US, per project region |
| Resend | Outbound email delivery | US |
| Vercel | Application hosting and edge network | Global |
| Sentry | Error reporting (identifiers only, never submission content) | US/EU |
| GitHub | Encrypted nightly database backups | US |
Error reports carry identifiers only (an access key, a submission id) and never submission contents. That is enforced in code, not by policy.
Your rights
Access, correction, deletion, restriction, objection and portability. Email privacy@postform.dev and we will answer within 30 days. If we are the processor rather than the controller we will tell you who the controller is so you can go to them as well. You can also complain to your data protection authority.
If you run a form that posts to PostForm
You need to say so in your own privacy notice. Your submitters are giving their data to you; the fact that it travels through and rests with a processor is something you have to disclose, and we cannot do it for you because they never see this page. Name PostForm as a processor, say the data is held for 30 days, and link here.
Changes
If we add a sub-processor or change a retention window we will update this page and email account holders before it takes effect.
Last updated 2026-08-04.