Privacy

PostForm receives form submissions on behalf of the people who run websites, stores them, and emails them on. That means most of the personal data we hold was not given to us by the person it describes. It was typed into somebody else's contact form. This page says what we do with it and how to get it removed.

If you filled in a form and ended up here

We are the company that delivered your message to the site owner. We are not the site owner, and we do not act on your message. We hold what you typed into the form, the email address you gave if you gave one, and the IP address the submission came from.

We delete all of it automatically after 30 days. We also take a nightly encrypted backup of the database, kept for a further 30 days, so a deleted submission can persist in a backup for that much longer before it ages out. We do not restore backups to bring deleted data back. If you want it gone sooner, email privacy@postform.dev from the address you used, or tell us the site and roughly when you submitted, and we will delete it and confirm. You do not need an account and there is no form to fill in.

You should also contact the site owner: they received a copy by email and their copy is theirs, not ours. We can only delete our own.

What we store

DataWhyKept for
Submission contentsTo deliver them to the site owner and let them re-read them in the dashboard30 days
Submitter email addressUsed as the Reply-To so the site owner can answer30 days
Submitter IP addressRate limiting and abuse investigation. This is the only thing we hold on our own account rather than the site owner's30 days
Account email and passwordTo let a customer log inUntil the account is deleted
Endpoint request log (IP, key, outcome)So a customer can tell a broken form from a quiet one30 days

We do not use cookies for analytics or advertising. The only cookie we set is the session cookie that keeps a logged-in customer logged in.

Our role

For submission contents we are a processor: the site owner decides what to collect and why, and we act on their instructions. Our data processing agreement sets out those terms and forms part of our contract with every customer.

For IP addresses, account details and error reports we are a controller: nobody asked us to collect those, we do it to keep the service working and to stop it being abused. The lawful basis is legitimate interest.

Who else sees it

These are the only third parties involved, and none of them sell data:

ProviderWhat forWhere
SupabasePostgres database and authenticationEU/US, per project region
ResendOutbound email deliveryUS
VercelApplication hosting and edge networkGlobal
SentryError reporting (identifiers only, never submission content)US/EU
GitHubEncrypted nightly database backupsUS

Error reports carry identifiers only (an access key, a submission id) and never submission contents. That is enforced in code, not by policy.

Your rights

Access, correction, deletion, restriction, objection and portability. Email privacy@postform.dev and we will answer within 30 days. If we are the processor rather than the controller we will tell you who the controller is so you can go to them as well. You can also complain to your data protection authority.

If you run a form that posts to PostForm

You need to say so in your own privacy notice. Your submitters are giving their data to you; the fact that it travels through and rests with a processor is something you have to disclose, and we cannot do it for you because they never see this page. Name PostForm as a processor, say the data is held for 30 days, and link here.

Changes

If we add a sub-processor or change a retention window we will update this page and email account holders before it takes effect.

Last updated 2026-08-04.