Privacy Policy
Last Updated: February 20, 2026
At FormBeep, we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your information when you use our form-to-WhatsApp notification service.
Our Core Privacy Principle: We believe in privacy by design. FormBeep temporarily stores form submission data only until you view it via WhatsApp, then permanently deletes it. We minimize data retention and never keep form values longer than necessary.
1. Information We Collect
1.1 Account Information
When you create a FormBeep account, we collect:
- Email address (via Clerk authentication)
- WhatsApp phone number (for receiving notifications)
- Website domains you authorize to use FormBeep
- Billing information (processed securely by Lemon Squeezy)
1.2 Form Submission Data
When someone submits a form on your website using FormBeep, we temporarily store:
- Form field values (names, emails, messages, etc.) — stored temporarily, deleted after viewing
- Timestamp of submission
- Domain where the form was submitted
- Field names (e.g., “name”, “email”, “message”)
- Delivery status (sent, delivered, failed)
- Message ID (for tracking delivery)
How form data is handled:
- Form submitted → data stored in encrypted database
- WhatsApp notification sent with “View Details” button
- You tap “View Details” → full form data sent to WhatsApp
- Form field values permanently deleted from our database after viewing
- Any unviewed form data is automatically deleted after 7 days
- Only metadata (timestamp, domain, field names, status) retained for 90 days
We do NOT store:
- IP addresses of form submitters
- User agent strings
- Form data after you’ve viewed it (permanently deleted)
2. How We Use Your Information
2.1 To Provide the Service
- Send form submission data to your WhatsApp number
- Verify that form submissions come from authorized domains
- Track message delivery status
- Enforce plan limits (message quota, domain limits)
2.2 To Improve the Service
- Monitor service performance and uptime
- Debug technical issues
- Analyze aggregate usage patterns (e.g., total messages sent per day)
2.3 For Billing
- Process payments via Lemon Squeezy
- Send invoices and receipts
- Manage subscription upgrades/downgrades
3. Data Storage and Security
3.1 Where We Store Data
- Account Data: Stored in Cloudflare D1 database (encrypted at rest)
- Form Submissions: Stored temporarily in Cloudflare D1 (encrypted), deleted after viewing
- Logs Metadata: Stored in Cloudflare D1 database
- Authentication: Managed by Clerk (SOC 2 Type II certified)
- Payments: Processed by Stripe (PCI DSS compliant)
3.2 Data Retention
- Account Data: Retained until you delete your account
- Form Submission Values: Stored temporarily until viewed via WhatsApp, then permanently deleted. Any unviewed form data older than 7 days is automatically purged.
- Logs Metadata: Retained for 90 days, then automatically deleted
3.3 Security Measures
- All data encrypted in transit (TLS 1.3)
- All data encrypted at rest
- API keys use cryptographically secure random generation
- Rate limiting to prevent abuse
- Origin validation to prevent unauthorized access
- Regular security audits
4. Third-Party Services
FormBeep integrates with the following third-party services:
4.1 Meta WhatsApp Business API
- Purpose: Deliver form notifications via WhatsApp
- Data Shared: WhatsApp phone number, message content
- Privacy Policy: WhatsApp Privacy Policy
4.2 Clerk
- Purpose: User authentication and account management
- Data Shared: Email address, authentication tokens
- Privacy Policy: Clerk Privacy Policy
4.3 Stripe
- Purpose: Payment processing and subscription management
- Data Shared: Email, billing information, subscription details
- Privacy Policy: Stripe Privacy Policy
4.4 Cloudflare
- Purpose: Hosting, CDN, and infrastructure
- Data Shared: All application data stored on Cloudflare infrastructure
- Privacy Policy: Cloudflare Privacy Policy
5. Your Rights
5.1 Access and Portability
You can access your account data at any time through the FormBeep dashboard. You can export your logs metadata in JSON format.
5.2 Deletion
You can delete your account at any time from the dashboard. Upon deletion:
- Your account data is immediately removed from our systems
- Your API key is revoked
- Any unviewed form submission data is permanently deleted
- Logs metadata is retained for 30 days (for security auditing), then permanently deleted
- Billing data is retained by Stripe per their retention policy
5.3 Correction
You can update your WhatsApp number, authorized domains, and other account settings at any time from the dashboard.
5.4 Objection and Restriction
You can object to data processing or request restrictions by contacting us at hello@formbeep.com.
6. GDPR Compliance (EU Users)
If you are located in the European Economic Area (EEA), you have additional rights under GDPR:
6.1 Legal Basis for Processing
- Contract Performance: Processing necessary to provide the service you signed up for
- Legitimate Interest: Improving service quality and preventing abuse
- Consent: For marketing communications (opt-in only)
6.2 Data Transfers
Your data may be transferred to and processed in the United States. We ensure adequate safeguards through:
- Standard Contractual Clauses (SCCs) with third-party providers
- Adherence to Privacy Shield principles where applicable
6.3 Data Protection Officer
For GDPR-related inquiries, contact our Data Protection Officer at: hello@formbeep.com
7. CCPA Compliance (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
7.1 Categories of Personal Information
We collect and process:
- Identifiers (email, WhatsApp number)
- Commercial information (subscription plan, usage data)
- Internet activity (logs metadata)
7.2 Sale of Personal Information
We do NOT sell your personal information. We never have and never will.
7.3 Your CCPA Rights
- Right to know what personal information we collect
- Right to delete your personal information
- Right to opt-out of sale (not applicable — we don’t sell data)
- Right to non-discrimination for exercising your rights
To exercise these rights, email hello@formbeep.com.
8. Children’s Privacy
FormBeep is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at hello@formbeep.com.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the “Last Updated” date at the top
- Notify you via email if changes are material
- Post a notice on our website
Your continued use of FormBeep after changes constitutes acceptance of the updated Privacy Policy.
10. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
- Email: hello@formbeep.com
- Support: hello@formbeep.com
- Website: https://formbeep.com