Zunoform

Privacy Policy

Last updated: July 22, 2026

Who we are

Zunoform (“we”, “us”) provides an online form builder at zunoform.com. This policy explains what data we collect, why, and the choices you have. It covers both account holders (“creators”) and people who fill out forms built with Zunoform (“respondents”).

Data we collect from creators

  • Account details: name, email address, password (stored as a salted hash), and profile image.
  • Content you create: forms, workspaces, themes, and settings.
  • Billing information: subscription status and plan, processed by our payment providers (Paddle / Lemon Squeezy / Stripe). We never see or store your card number.
  • Integration credentials you connect (e.g. Google Sheets, Slack, HubSpot): stored encrypted (AES-256-GCM) and used only to deliver your form responses where you asked.

Data we collect from respondents

  • The answers submitted through a form, delivered to the form's creator. The creator controls what is asked and how responses are used.
  • Technical metadata with each submission: IP address, browser user-agent, and completion time — used for spam protection and the creator's analytics.

For data submitted through a form, the creator is the data controller and Zunoform is a processor acting on their instructions.

How we use data

  • To provide, maintain, and improve the service.
  • To send transactional email (verification, password resets, response notifications you enable).
  • To prevent abuse, spam, and fraud.
  • To respond to support requests.

We do not sell personal data. We do not use form response content for advertising.

Service providers

We rely on a small set of subprocessors to run Zunoform: hosting infrastructure, Cloudflare (DNS, TLS, and content delivery), email delivery, payment processing (Paddle / Lemon Squeezy / Stripe), and Cloudflare R2 for file uploads. Each receives only what it needs to perform its function.

Cookies

We use first-party cookies for signing in (session cookies) and security. We do not run third-party advertising trackers.

Data retention & deletion

Your data is retained while your account is active. Creators can delete forms and responses at any time, which removes them from the live database. You can request full account deletion by contacting us; we will remove your data within 30 days, except where retention is required by law.

Security

All traffic is encrypted in transit (TLS). Passwords are hashed with bcrypt. Connected integration tokens are encrypted at rest. Access to production systems is restricted and protected with multi-factor authentication.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, email us at the address below. If you submitted data through someone else's form, contact that form's creator first — we will assist them in fulfilling your request.

Contact

Questions about this policy or your data: [email protected].

Changes

We may update this policy as the service evolves. Material changes will be announced by email or an in-app notice, and the date above always reflects the latest revision.