Privacy Policy

Last updated: May 1, 2025

Overview

LazyForms ("the Service") is operated by DamnGoodTools. We respect your privacy and handle data responsibly. This policy explains what we collect, why, and how you can control it.

TL;DR:We collect the minimum data needed to operate the service. We don't sell your data. We don't run ads. We don't track you across the web.

What we collect

Account data

Your email address (used for login and notifications). That's it — no name, phone, or billing info required on the free tier.

Form submission data

Data submitted through your forms by your users. This includes whatever fields your form collects (names, emails, messages, etc.) plus metadata: submission timestamp and submitter IP address.

Usage data

Submission counts per form (for rate limiting and dashboard display). We don't use analytics trackers, cookies, or fingerprinting on our marketing site or dashboard.

How we use your data

  • Operate the Service — process form submissions, send email notifications, sync to Google Sheets, forward to webhooks
  • Account authentication — send OTP codes for login
  • Service communication — important updates about the Service (rare, no marketing spam)
  • Abuse prevention — IP addresses used for rate limiting and spam detection

What we don't do

  • Sell or share your data with advertisers
  • Use your submission data for AI training
  • Track you across websites
  • Use third-party analytics (no Google Analytics, no Mixpanel)
  • Set advertising or tracking cookies
  • Send marketing emails without consent

Data storage & security

Form submissions are stored in our PocketBase database hosted on secure infrastructure. Data is transmitted over HTTPS (TLS 1.3). Our form processing runs on Cloudflare Workers (edge network, encrypted at rest).

We retain submission data as long as your account is active. You can delete individual submissions or your entire account at any time.

Third-party services

We use the following third-party services to operate:

  • Cloudflare — CDN, Workers (form processing), Turnstile (spam protection), email delivery
  • PocketBase — database and authentication (self-hosted)
  • Google Sheets API — only when you enable Sheets integration; we access only the specific sheet you connect

These services have their own privacy policies. We don't share data beyond what's necessary to provide the features you enable.

Your rights (GDPR/CCPA)

You have the right to:

  • Access — view all data we store about you (available in the dashboard)
  • Export — download your submissions as CSV
  • Delete — delete submissions, forms, or your entire account
  • Rectify — correct inaccurate data
  • Object — opt out of any processing you disagree with

To exercise these rights, email support@lazyforms.com or use the self-service options in your dashboard.

Your responsibility as a form owner

When you use LazyForms to collect data from your users, you are the data controller. You're responsible for:

  • Having a privacy policy on your own site that discloses data collection
  • Obtaining appropriate consent from your users
  • Handling data subject requests from your own users
  • Complying with applicable data protection laws (GDPR, CCPA, etc.)

LazyForms acts as a data processor on your behalf.

Cookies

We use a single session cookie for authentication when you're logged into the dashboard. No tracking cookies, no third-party cookies, no cookie banner needed.

Children's privacy

LazyForms is not directed at children under 13. We don't knowingly collect data from children. If you believe a child has submitted data through your forms, it's your responsibility as the form owner to handle this appropriately.

Changes to this policy

We may update this policy. Significant changes will be communicated via email. Continued use after changes constitutes acceptance.

Contact

Privacy questions? Email support@lazyforms.com.