Privacy Policy
Last updated: May 17, 2026
1. Introduction
Welcome to FormFlow. We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data when you visit our website or use our Webflow application and tell you about your privacy rights.
2. The Data We Collect About You
We collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data: includes first name, last name, username or similar identifier.
- Contact Data: includes email address.
- Financial Data: handled entirely by our payment processor (Stripe). We do not store your credit card details.
- Technical Data: includes internet protocol (IP) address, your login data, browser type and version.
3. Webflow Form Submissions
Crucial Notice: FormFlow acts primarily as a client-side logic enhancer. We DO NOT store, read, or intercept the text data your users submit through your Webflow forms. All standard form submissions are routed directly to Webflow's native servers or your configured third-party webhooks.
The only exception is if you explicitly use our "File Upload" or "Digital Signature" addons, in which case those specific files/images are temporarily processed and stored on our CDN (Supabase) to generate a URL link for your Webflow submission.
4. Third-Party Integration Credentials
When you connect third-party services (such as Mailchimp, HubSpot, or Klaviyo) through FormFlow, you may provide API keys or access tokens. These credentials are:
- Transmitted securely via HTTPS to our backend at formflowapp.com for integration testing and webhook delivery.
- Stored encrypted at rest in our database. They are never exposed in your published website markup or client-side code.
- Write-only — once saved, credentials are not returned in plaintext. The extension displays connection status only.
- Access-restricted — credentials are only accessible to authenticated site owners via Webflow's ID token verification.
You can disconnect integrations at any time, which will remove stored credentials from our systems.
5. Automatic Identity Verification
When the FormFlow Designer Extension loads inside Webflow Designer, it automatically verifies your identity using Webflow's short-lived ID token (webflow.getIdToken()). This sends your site ID and token to our server to confirm site ownership and load your integration settings. No additional personal data is collected during this process.
6. Data Retention & Deletion
Integration settings and credentials are retained for as long as the app is installed on your Webflow site. Upon uninstallation, all associated data is scheduled for deletion within 30 days. You may request immediate deletion by contacting us.
7. Contact Us
If you have any questions about this privacy policy or our privacy practices, please contact us at privacy@formflowapp.com.