Appearance
Privacy Policy
Last updated: 2026-08-24
This Privacy Policy explains how Menelabs O.E. ("BootForm", "we", "us") collects, uses, and protects information in connection with the BootForm service (bootform.com, app.bootform.com, api.bootform.com, and related subdomains).
Two kinds of data this policy covers
BootForm is a form-backend service: developers ("Customers", "you") point an HTML <form> at a BootForm endpoint, and BootForm accepts, stores, and delivers whatever the Customer's own form collects from their own site's visitors ("End Users"). This creates two distinct roles that matter for how each category of data is handled:
- Customer data — your account: email, name, authentication method, billing details, workspace and form configuration. Here, BootForm is the data controller — we decide why and how this data is processed, and this policy governs it directly.
- Form submission data — whatever an End User submits through a Customer's form. Here, the Customer is the data controller (they decide what their form asks for and what they do with the answers) and BootForm acts as a data processor, storing and delivering that data on the Customer's behalf and instructions. If you submitted a form built on BootForm and have a question about how your information is used, the right place to start is the website or organization whose form you filled in — they control that data, not us.
Information we collect
Account data (Customers)
- Identity: email address, optional display name.
- Authentication: a bcrypt password hash (never your plaintext password), or, if you sign in via GitHub/Google/Microsoft, the profile information that provider shares (email, name, avatar URL) with your authorization.
- Billing: plan tier, billing cycle, and usage — actual payment card details are handled entirely by our payment processor (Paddle, see below); we never see or store your card number.
- Configuration: forms, workspaces, notification destinations, API keys (stored hashed), team members you invite, and the settings you configure for each.
- Security/audit data: sign-in timestamps and IP addresses, for fraud prevention and account security (e.g. detecting suspicious login activity).
Form submission data (on behalf of Customers)
- Whatever fields a Customer's form collects — entirely defined by the Customer, not BootForm.
- The submitting visitor's IP address, used for spam/abuse prevention and rate limiting.
- Any file attachment a Customer's form is configured to accept.
What we don't collect
BootForm's own applications (the marketing site, dashboard, and admin panel) use no third-party analytics or advertising trackers, and no tracking cookies. The dashboard stores your session token in your browser's local storage, not a cookie. We don't buy, sell, or rent personal data to anyone.
How we use information
- To provide the service: accept submissions, apply your spam-protection settings, and deliver submissions to the destinations you've configured (email via our transactional email provider, and/or Discord, Slack, Telegram, or a webhook URL you've set up).
- To operate your account: authentication, billing, plan enforcement, quota notifications.
- To communicate with you: transactional emails only (sign-in links, password resets, email verification, team invites, quota warnings). We do not send marketing or newsletter email today.
- To secure the service: detect and prevent abuse, fraud, and spam.
- To provide support when you contact us.
Who we share data with
We use a small number of subprocessors to run BootForm. None of them are permitted to use your data for their own purposes.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Microsoft Azure | Hosting — database, file storage, message queues, compute (currently in the United States, East US region) | Account data, form submission data |
| Twilio SendGrid | Transactional email delivery | Email address, email content |
| Paddle.com Market Limited | Payment processing and billing (Merchant of Record) | Billing/plan data; card details are handled entirely by Paddle |
| GitHub / Google / Microsoft | OAuth sign-in, only if you choose to use it | Email, name, avatar (only what that provider shares with your authorization) |
| Discord / Slack / Telegram / a webhook URL you configure | Delivering form submissions where a Customer has chosen to send them | Form submission data, per the Customer's own configuration |
Because Menelabs O.E. is based in the EU and our infrastructure provider (Microsoft Azure) is currently US-based, personal data may be transferred outside the EU/EEA. Microsoft is certified under, and BootForm relies on, the safeguards Microsoft provides for such transfers (including Standard Contractual Clauses). We do not currently offer EU-region-only data residency — if that matters for your use case, contact us before relying on BootForm for regulated data.
Data retention
Form submissions are retained according to the Customer's plan, then automatically and permanently deleted:
| Plan | Retention |
|---|---|
| Free | 7 days |
| Starter | 30 days |
| Pro | 1 year |
| Business | Unlimited by default, configurable |
Account data is retained for as long as the account is active.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing.
- Individual submissions: delete any submission directly from the BootForm dashboard at any time.
- An entire form (and every submission it holds): delete the form directly from the dashboard — this removes all of its submissions too.
- Export: download your form's submissions as CSV or JSON directly from the dashboard.
- Your account: to close your account and request deletion of your account data, email support@bootform.com. We'll confirm once it's done.
- An End User's data: if you submitted a form built on BootForm and want that data deleted or corrected, contact the website/organization that owns the form — they're the data controller and can act on the request directly (including via the dashboard tools above). If you're unable to reach them, contact us and we'll assist where we reasonably can.
Cookies
BootForm's marketing site, dashboard, and admin panel do not use tracking or advertising cookies. The dashboard and admin apps authenticate using a token stored in your browser's local storage, not a cookie.
Children's privacy
BootForm is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we'll delete it.
Security
We use industry-standard practices to protect data in transit (TLS) and at rest, including hashed passwords (bcrypt) and hashed API keys/webhook secrets. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.
Changes to this policy
We may update this policy as the service changes. Material changes will be reflected by updating the "Last updated" date above; continued use of BootForm after a change means you accept the updated policy.
Contact
Questions about this policy, or a request relating to your data: support@bootform.com.
Menelabs O.E.