Privacy Policy
Quick summary
We store your account, workspace, and billing info to run the service. We store the forms you create and the responses you collect so the product works. All customer data is hosted in Canada on Microsoft Azure. Data is encrypted in transit and at rest. We don't sell personal data, and we don't use your form contents or responses for ads or model training.
1) Who we are
AstroForms ("we", "us", "our") provides tools to create forms, collect responses, and manage submissions. Questions? Email support@astroforms.com.
2) What this policy covers
This policy explains what we collect, why we collect it, how we use and share it, and the choices you have.
3) The information we collect
a) You provide to us
- Account & workspace info – name, email, password (or OAuth identifier), workspace name, roles/permissions.
- Forms & configuration – the forms you build (questions, logic, settings), branding, and related metadata.
- Responses – submissions collected through your forms, including any files or fields your form asks for.
- Billing – subscription tier, invoices, and payment status (processed by our payment partner).
- Support – messages, attachments, and contact details you send us.
b) Collected automatically
- Usage & device data – app events, pages/actions used, timestamps, and crash/error logs.
- Approximate location (optional) – for form respondents, we may record city, state/province, and country inferred from IP address. We do not store exact addresses or precise GPS location. Form owners can disable location collection in form settings.
- Device type – for form respondents, we may record general device type (e.g., desktop/mobile/tablet) to help form owners understand completion trends.
- Cookies / local storage – to keep you signed in and remember preferences. See Cookies below.
4) How we use your information
- Provide and improve the service – create and publish forms, accept submissions, display results, and maintain reliability/performance.
- Customer support & security – troubleshoot issues; detect abuse, fraud, and unauthorized access.
- Payments – manage subscriptions, invoices, and receipts.
- Product communications – service updates, billing notices, and (if you opt in) feature tips.
- Legal – comply with law, enforce terms, and protect rights.
We do not sell personal information. We do not use your form contents or responses for ads or to train models.
5) Where we store and process data
Our production infrastructure and primary databases are located in Canada. We utilize Microsoft Azure's Canada Central (Toronto) and Canada East (Quebec City) regions to ensure data residency and redundancy within Canadian borders.
Data is encrypted in transit (TLS 1.2+) and at rest (e.g., AES-256). Access to production systems is restricted by role, logged, and audited. While our primary storage is in Canada, limited data (such as payment processing via Stripe or CDN delivery) may be processed globally by our service providers as described in Section 6.
6) Who we share data with (service providers)
We use trusted providers to run AstroForms. They only process data on our instructions and under contract:
- Microsoft Azure – hosting, databases, storage, logs.
- Authentication providers – Google / Microsoft OAuth (if you choose to sign in with them).
- Payments – Stripe (or equivalent) for card processing and invoicing.
- Email – transactional email (e.g., verification codes, receipts, service notices).
- Analytics/telemetry – aggregated usage and crash/error reporting.
We may disclose data if required by law, to protect users, or to defend our rights.
7) Forms, responses & customer content
We store forms you create and the responses submitted by respondents in order to provide AstroForms functionality (publishing forms, saving drafts, collecting submissions, viewing/exporting results, and related features).
We don't review your forms or responses unless you ask us to during a support case, there's a security/emergency risk, or we are legally required. Such access is limited, logged, and time-bounded.
Deletions – when you delete a form, submissions, or your account, we remove active copies promptly; residual copies may remain in backups for a limited period (see Retention).
8) Retention
- Account data – retained while your account is active.
- Forms & responses – retained until you delete them or close your account (or as otherwise configured by you).
- Backups – encrypted backups are cycled and typically expire within 30–90 days.
We may keep minimal records (e.g., invoices, security logs) as required by law.
9) Your choices & rights
- Access / export – request a copy of your data.
- Correction – update your profile details.
- Deletion – delete forms/responses or close your account.
- Opt-out – control email preferences (except essential service emails).
- Location capture controls – form owners can disable approximate respondent location capture in settings.
- Cookies – manage cookies in your browser or via our cookie settings (where available).
Residents of certain regions (e.g., EEA/UK, California) may have additional rights such as data portability and objection/restriction of processing. Contact us to exercise these rights.
10) Cookies
We use strictly necessary cookies (authentication, security), functional cookies (preferences), and limited analytics/performance cookies. You can control cookies via your browser. Blocking some cookies may affect how the site works.
11) Security
We apply layered security: encryption in transit/at rest, access controls, least-privilege roles, monitoring, and vulnerability management. No method is 100% secure; please use a strong password and keep your account details safe.
12) Children's privacy
AstroForms is not intended for children under 13 (or the age required by local law). We do not knowingly collect data from children.
13) International transfers
AstroForms is headquartered in and hosted in Canada. If you are accessing the service from outside Canada, please be aware that your information will be transferred to, stored, and processed in Canada.
For third-party sub-processors located outside Canada (e.g., payment processors), we ensure appropriate safeguards are in place (such as standard contractual clauses) to protect your data in accordance with applicable laws.
14) Changes to this policy
We may update this policy to reflect changes to our service or legal requirements. We'll update the "Last updated" date and, when changes are material, provide additional notice (e.g., email or in-app).
15) Contact us
Questions or requests: support@astroforms.com
AstroForms — Ontario, Canada