Privacy Policy
Last updated: July 2026
1. Who we are
NBForms ("we", "us", or "our") is a form backend service that lets you collect HTML form submissions without managing a server. This policy explains what personal data we collect, how we use it, and your rights regarding it.
2. Data we collect
We collect only what is necessary to provide the service:
- Account data — your email address, name, and (optionally) a password hash when you register.
- Submission data — the field values submitted through forms you create. You control what fields your forms ask for.
- Payment data — transaction records (amount, date, credit balance). We do not store raw card details; payments are processed by our payment provider.
- Usage data — which pages you visit, when you log in, and which API routes are called. This is stored in server logs and used to diagnose errors.
- Contact messages — if you contact us via the contact form, we store your name, email, and message.
3. How we use your data
We use your data exclusively to operate and improve NBForms:
- Delivering the service — storing and displaying your form submissions, sending email notifications, processing payments.
- Authentication — verifying your identity when you log in.
- Transactional email — sending verification codes, password reset links, and team invitations.
- Support — responding to contact messages and support tickets.
- Security — detecting abuse, enforcing rate limits, and blocking spam submissions.
4. Third-party services
We use a small set of third-party processors to run NBForms:
- MongoDB Atlas — database hosting. Your account data and submission data are stored here.
- Brevo (Sendinblue) — transactional email delivery (verification codes, notifications, invitations).
- Payment processor — handles credit purchases. We receive only the transaction outcome; no card data touches our servers.
- Google Tag Manager, Google Analytics, and Google Ads — website analytics and conversion tracking on nbforms.com, loaded only if you accept analytics/advertising cookies in the cookie banner. See section 7 below.
- Integrations you configure (Slack, Google Sheets, Telegram, etc.) — submission data is forwarded to these services only when you explicitly set up an integration.
5. Data retention
We retain your account data and submissions for as long as your account is active. If you delete a form, its submissions are permanently deleted. If you close your account, all your data is deleted within 30 days.
Server logs are retained for 30 days and then purged.
6. Your rights
You have the right to access, correct, or delete your personal data at any time. You can export or delete your submissions from the dashboard. To close your account and remove all data, contact us at the address below.
If you are located in the EU or EEA, you have additional rights under the GDPR, including the right to data portability and the right to lodge a complaint with your local supervisory authority.
7. Cookies
We use one strictly-necessary cookie: an HTTP-only session cookie that keeps you logged in. This cookie is always active and does not require consent, since the service cannot function without it.
On nbforms.com (not on hosted form pages published by our customers), we also use Google Tag Manager to run Google Analytics and Google Ads conversion tracking. These set analytics and advertising cookies and are only loaded after you accept them in the cookie banner shown on your first visit — before that, they remain switched off via Google Consent Mode. You can accept, decline, or change your choice at any time using "Cookie Preferences" in the footer.
See Google's own privacy policy (policies.google.com/privacy) for how it handles data collected through Analytics and Ads.
8. Children
NBForms is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has submitted data through our service, please contact us and we will delete it.
9. Changes to this policy
If we make material changes to this policy, we will notify you by email or by posting a notice in the dashboard before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Questions about this policy? Contact us.