Effective July 17, 2026

Privacy Policy

This policy explains what personal data SharaForms handles, why we handle it, who controls that data, and what choices are available to account holders, workspace members, site visitors, and form respondents.

Applies to
Visitors, customers, workspace members, and respondents
Core role
Platform provider and processor for customer-managed form data
Primary contact

1. Scope and Data Roles

This Privacy Policy applies to the SharaForms website, hosted application, public forms, APIs, templates, documentation, and related customer support interactions. It covers personal data we collect directly from you, data generated by use of the service, and data customers ask us to process on their behalf.

SharaForms acts in different privacy roles depending on the relationship. For account registration, billing, support, marketing site analytics, and platform security, SharaForms generally acts as the controller of that personal data. For form submission data collected by our customers through forms they create, SharaForms generally acts as a processor or service provider and the customer that published the form is the controller responsible for the underlying collection and use.

2. Information We Collect

The data we collect depends on how you interact with SharaForms. Some information is provided directly by you, some is generated automatically when you use the service, and some may be received from connected integrations or payment providers.

  • Account and workspace information such as name, email address, login credentials, workspace profile details, role assignments, and preferences.
  • Billing and transaction information such as billing contact details, subscription status, invoices, tax information, and limited payment metadata from processors. We do not store full card numbers issued by payment processors.
  • Product usage data such as login events, browser and device information, IP address, audit activity, feature usage, and diagnostic logs used for reliability and abuse prevention.
  • Form and submission data such as form fields, uploaded files, generated documents, automation settings, and response content submitted by respondents to customer-owned forms.
  • Support and communication records such as emails, feedback, sales conversations, bug reports, and onboarding notes.

3. How We Use Personal Data

We use personal data to provide and operate SharaForms, maintain security, authenticate users, process transactions, answer support requests, improve product performance, and communicate important service information. We also use limited site and product analytics to understand adoption and maintain usability where permitted by your preferences and applicable law.

Where required by law, we rely on appropriate legal bases such as performance of a contract, legitimate interests, consent, and compliance with legal obligations. Customers remain responsible for determining their own legal basis for the personal data they collect through forms they publish using SharaForms.

4. Cookies, Tracking, and Analytics

SharaForms uses cookies and similar technologies to keep the service secure, remember session state, store preference choices, measure traffic, and improve product performance. Some cookies are strictly necessary for authentication, fraud prevention, and the core functionality of the application.

Where non-essential analytics or similar tools are used, you can manage those preferences through the consent tools made available on the site or in the product. Blocking some cookies may affect the functionality or convenience of certain parts of the service.

5. Sharing and Disclosures

We do not sell personal data in the ordinary meaning of that term. We may share information with service providers and partners only where reasonably necessary to operate the platform, deliver support, secure the service, process payments, or perform customer-requested integrations.

  • Infrastructure, hosting, storage, monitoring, and backup providers.
  • Payment processors, invoicing tools, and accounting or tax service providers.
  • Support, communications, and scheduling providers used to answer requests or deliver service messages.
  • Third-party integrations enabled by the customer, such as automation, messaging, CRM, or productivity tools, according to the customer's configuration.
  • Regulators, courts, law enforcement, or other parties where disclosure is required to comply with law, protect rights, investigate abuse, or prevent harm.

6. Security and Retention

We use administrative, technical, and organizational measures intended to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. These measures include access controls, logging, credential protections, product security features, and operational monitoring. No system can be guaranteed to be perfectly secure, and customers are also responsible for securing their own accounts, endpoints, integrations, and downstream workflows.

We retain personal data for as long as reasonably necessary to provide the service, honor customer instructions, comply with legal and tax obligations, resolve disputes, enforce agreements, and maintain security or backup continuity. Retention periods vary depending on the type of data, the plan or feature in use, and the deletion actions taken by the customer or user.

7. International Transfers

SharaForms and its service providers may process data in countries other than the country where you live or where the customer that owns a form is established. When international transfers occur, we take reasonable steps to use appropriate contractual, technical, or organizational safeguards where required by applicable law.

8. Your Rights and Choices

Depending on your location and the laws that apply to you, you may have rights to access, correct, delete, object to, restrict, or export certain personal data, and to withdraw consent where processing relies on consent. You may also have the right to lodge a complaint with a supervisory authority.

If you are a respondent who submitted a form to one of our customers, the fastest route is usually to contact the organization named on that form, because it controls the form and decides what data is collected. If we receive a respondent request that relates to customer-controlled form data, we may direct the request to that customer or ask for more information so the request can be handled correctly.

9. Customer Responsibilities

Customers are responsible for the forms they publish, the notices and consents they provide to respondents, the legal basis they rely on, the instructions they give to SharaForms, and the integrations or exports they enable. Customers must make sure that their collection and use of data through SharaForms complies with the privacy, employment, health, consumer, sector-specific, and international laws that apply to their activities.

10. Children's Data

SharaForms is not directed to children, and we do not knowingly collect personal data from children in violation of applicable law. If you believe a child has provided personal data through the service without proper authorization, contact us and we will investigate and take appropriate action.

11. Changes to This Policy and Contact Information

We may update this Privacy Policy from time to time to reflect product changes, legal developments, or operational updates. The current version will be posted on this page with its effective date. If a change materially affects how we handle personal data, we may also provide additional notice through the product, by email, or through other reasonable means.

Questions, requests, or concerns about this policy can be sent to [email protected] or raised through the support options available inside the product and our Help Center.

Your privacy controls
  • Account holders can access, export, or delete their account data from product settings when those tools are available.
  • Cookie and analytics preferences can be managed from the consent banner on the public site and inside the app experience where shown.
  • Requests about a specific form response should usually be sent to the organization that published the form, because that organization decides what data is collected and why.
Contact us

For privacy requests or questions about this policy, contact us at [email protected] or use our Help Center.