Privacy Policy
Last updated: May 1, 2025
Overview
LazyForms ("the Service") is operated by DamnGoodTools. We respect your privacy and handle data responsibly. This policy explains what we collect, why, and how you can control it.
TL;DR:We collect the minimum data needed to operate the service. We don't sell your data. We don't run ads. We don't track you across the web.
What we collect
Account data
Your email address (used for login and notifications). That's it — no name, phone, or billing info required on the free tier.
Form submission data
Data submitted through your forms by your users. This includes whatever fields your form collects (names, emails, messages, etc.) plus metadata: submission timestamp and submitter IP address.
Usage data
Submission counts per form (for rate limiting and dashboard display). We don't use analytics trackers, cookies, or fingerprinting on our marketing site or dashboard.
How we use your data
- Operate the Service — process form submissions, send email notifications, sync to Google Sheets, forward to webhooks
- Account authentication — send OTP codes for login
- Service communication — important updates about the Service (rare, no marketing spam)
- Abuse prevention — IP addresses used for rate limiting and spam detection
What we don't do
- Sell or share your data with advertisers
- Use your submission data for AI training
- Track you across websites
- Use third-party analytics (no Google Analytics, no Mixpanel)
- Set advertising or tracking cookies
- Send marketing emails without consent
Data storage & security
Form submissions are stored in our PocketBase database hosted on secure infrastructure. Data is transmitted over HTTPS (TLS 1.3). Our form processing runs on Cloudflare Workers (edge network, encrypted at rest).
We retain submission data as long as your account is active. You can delete individual submissions or your entire account at any time.
Third-party services
We use the following third-party services to operate:
- Cloudflare — CDN, Workers (form processing), Turnstile (spam protection), email delivery
- PocketBase — database and authentication (self-hosted)
- Google Sheets API — only when you enable Sheets integration; we access only the specific sheet you connect
These services have their own privacy policies. We don't share data beyond what's necessary to provide the features you enable.
Your rights (GDPR/CCPA)
You have the right to:
- Access — view all data we store about you (available in the dashboard)
- Export — download your submissions as CSV
- Delete — delete submissions, forms, or your entire account
- Rectify — correct inaccurate data
- Object — opt out of any processing you disagree with
To exercise these rights, email support@lazyforms.com or use the self-service options in your dashboard.
Your responsibility as a form owner
When you use LazyForms to collect data from your users, you are the data controller. You're responsible for:
- Having a privacy policy on your own site that discloses data collection
- Obtaining appropriate consent from your users
- Handling data subject requests from your own users
- Complying with applicable data protection laws (GDPR, CCPA, etc.)
LazyForms acts as a data processor on your behalf.
Cookies
We use a single session cookie for authentication when you're logged into the dashboard. No tracking cookies, no third-party cookies, no cookie banner needed.
Children's privacy
LazyForms is not directed at children under 13. We don't knowingly collect data from children. If you believe a child has submitted data through your forms, it's your responsibility as the form owner to handle this appropriately.
Changes to this policy
We may update this policy. Significant changes will be communicated via email. Continued use after changes constitutes acceptance.
Contact
Privacy questions? Email support@lazyforms.com.