Privacy Policy
Last updated: May 23, 2026
Who we are
Userforms is a customer-feedback intake and analysis platform operated by Userforms Inc. You can reach us at privacy@userforms.com for any privacy question.
What this policy covers
This policy explains what personal data Userforms collects when you use our website at userforms.com and our application at app.userforms.com, how we use it, who we share it with, and what choices you have. It applies to account holders and to anyone whose feedback is imported into a Userforms organization by an account holder.
Data we collect
- Account data: your name, email address, and password hash when you sign up. If you sign in with Google, we receive your Google account ID, email, and basic profile info via the
userinfo.emailanduserinfo.profilescopes. - Organization data: the organizations you create, their members, and the integrations they connect.
- Feedback content: the reviews, survey responses, and other customer messages your team imports into Userforms — including data fetched via the Google Business Profile API (see the next section).
- Usage data: request logs, error traces, and feature-usage telemetry, retained for up to 90 days to debug and harden the product.
How Userforms uses Google user data
Userforms' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When an organization owner connects a Google account to Userforms, we request the https://www.googleapis.com/auth/business.manage OAuth scope. This is the only scope Google offers for reading Business Profile reviews; there is no read-only variant. With it, we do the following:
- Why we access it. To read the reviews on Google Business Profile locations the connecting organization manages, so we can import and analyse them inside Userforms. We never write back to your Google Business Profile — no replies, no edits, no posts.
- What we store. The OAuth access token, refresh token, the connected account's Google user ID and email, and the reviews we fetch (text, author display name as published on Google, star rating, and timestamps). Access and refresh tokens are encrypted at rest with AES-256-GCM.
- Where it's stored. In our managed Postgres database (Supabase, EU region). Encryption keys are held outside the database in our hosting provider's secret manager.
- Who can access it. Only members of the organization that connected the Google account. Userforms employees do not read review content except (a) when you explicitly ask us to look at specific data for a support ticket, (b) for security investigations such as abuse detection, or (c) where required by law.
- Limited Use compliance. We do not transfer data obtained through the Google APIs to third parties, use it for advertising, retargeting or credit-worthiness, sell it, or use it for AI/ML model training — including personalised AI features.
- Retention. Reviews are stored until the owning organization deletes them or disconnects the Google account. Tokens are deleted immediately on disconnect, and we also call Google's revocation endpoint so the authorization disappears from your Google account permissions list.
- Revoking access. You can disconnect from within Userforms at any time on the Integrations page of your organization. You can also revoke Userforms directly on Google at myaccount.google.com/permissions.
How we use the rest of your data
- To operate Userforms and provide the features you use.
- To analyse feedback content into themes, sentiment, and summaries inside your organization's dashboard.
- To debug errors, monitor abuse, and harden the platform against attack.
- To send transactional emails (password reset, billing receipts, important security notices). We do not send marketing email without a separate opt-in.
Who we share data with
We share data only with the service providers we depend on:
- Vercel — application hosting.
- Supabase — Postgres database.
- Resend — transactional email delivery.
- Stripe — billing and payment processing.
- OpenAI / Anthropic — LLM inference for the theme-analysis pipeline. Feedback content sent to these providers is processed under their zero-retention configurations; data obtained through Google APIs is not used for any model training and is only sent for inference under the same zero-retention setup.
Each of these processors is bound by data-processing terms that limit them to providing services to us. We do not sell personal data, and we do not share it with advertising platforms or data brokers.
Security
We store secrets and OAuth tokens encrypted at rest. Database connections are TLS-only. Production access is restricted to a small number of named employees with multi-factor authentication. Audit logs are retained for 1 year.
Your rights
You can export, correct, or delete your account and your organization's data from inside Userforms, or by emailing privacy@userforms.com. Depending on where you live, you may have additional rights under the GDPR or CCPA — we'll honour any verified request consistent with those laws.
Children
Userforms is not directed to children under 13 and we do not knowingly collect personal data from them.
Changes to this policy
We'll update the "Last updated" date above and, for material changes, notify account holders by email at least 14 days before the change takes effect.
Contact
Email privacy@userforms.com with any privacy question or request. You can also find general contact information on our contact page.