Privacy Policy
Last Updated: July 24, 2026
1. Overview
Welcome to DataForm ("we," "our," or "us"). DataForm is a SaaS form builder platform designed to help users create custom online forms, collect form submissions, and stream visitor responses directly into their connected Google Sheets.
Your privacy and data security are fundamental to our mission. This Privacy Policy outlines what information we collect, how we process and protect it, and your rights regarding your data when using our service at https://dataform.app or any associated domains.
2. Information We Collect
We collect information only as necessary to provide, maintain, and secure our form building and Google Sheets integration service:
- Account Information: When you register an account, we collect basic details such as your full name, email address, and authentication credentials managed securely via Firebase Authentication.
- Form Configurations: We store form structures, custom field definitions, labels, and form settings configured by you in our database.
- Google OAuth Integration Tokens: When you connect your Google Account to stream form submissions to Google Sheets, we receive Google OAuth access and refresh tokens along with your connected Google email.
- Technical & Log Data: We automatically log standard HTTP request metadata (IP address, browser type, timestamp) for security monitoring, rate limiting, and spam protection.
3. Google User Data & Limited Use Disclosure
DataForm's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Requested Scopes: We request access to
https://www.googleapis.com/auth/spreadsheets(to append form response rows to your chosen worksheet) andhttps://www.googleapis.com/auth/drive.readonly(to allow you to select target Google Sheets from your Drive). - No Data Mining: We do not read, scan, or analyze data in your Google Sheets for marketing, advertising, or profiling purposes.
- No Selling of Google Data: We will never sell, transfer, or disclose your Google user data to third parties.
4. Zero Payload Storage Policy
DataForm employs a Direct Stream Architecture for form responses. When a visitor submits a published form, our API validates the payload and instantly streams the response directly to your connected Google Sheet via Google Sheets API.
Raw form submission payloads are not permanently stored in our Firestore databases. This ensures that sensitive respondent data remains strictly inside your own Google Account environment.
5. Data Security & Encryption
We implement industry-standard technical and organizational security measures to protect your account and credentials:
- AES-256 Encryption: All Google OAuth tokens are encrypted server-side using AES-256 encryption before storage and are never exposed to browser localStorage or client-side JavaScript.
- HTTPS/TLS Transmission: All data in transit is encrypted using TLS 1.3/1.2 protocols.
- Strict Authorization Rules: Firebase Security Rules enforce owner-only access to user profiles and form settings.
6. Your Rights & Data Control
You maintain full ownership and control over your data at all times:
- Disconnect Integration: You can disconnect your Google Account at any time from the Integrations tab, which revokes and deletes stored OAuth tokens immediately.
- Delete Forms: Deleting a form removes all associated form configurations from DataForm instantly.
- Google Account Permissions: You can revoke DataForm access at any time via your Google Security Settings.
7. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our security practices, please contact us:
DataForm Privacy & Legal Team
Email: codebysohaib@gmail.com
Website: https://dataform.codebysohaib.dev
