This page is maintained by All Web Forms to answer common privacy and security questions about allwebforms.com (the "Service"). It complements our Privacy Policy and Terms and Conditions. It is informational and is not a certification or independent audit.
1. Shared responsibility
Security is a shared responsibility. We secure the Service and the underlying platform. Customers are responsible for keeping account credentials safe, managing what data they collect through their forms, providing the appropriate legal basis to respondents, and configuring features such as required fields, file uploads, and integrations responsibly.
2. Data we process
- Account data — name, email, hashed password, billing details, audit metadata.
- Customer Content — forms you build and responses your respondents submit.
- Operational telemetry — IP, user agent, request metadata used for security, abuse prevention, and analytics.
3. Encryption
- In transit: all traffic to the Service is served over HTTPS / TLS 1.2 or higher.
- At rest: the managed database, storage, and backups encrypt data at rest using industry-standard AES-256.
- Secrets: API keys, OAuth tokens, and provider credentials are stored in a managed secret store and are not exposed to client-side code.
4. Access controls
- Row-level security (RLS) on every customer-facing table.
- Role-based access for admin tooling, with roles stored in a dedicated table.
- Authentication via secure password hashing, optional magic links, and OAuth providers.
- Internal access to production systems is restricted to a small number of authorised engineers and is gated by strong authentication.
5. Hosting and infrastructure
The Service runs on hardened, managed cloud infrastructure with a globally distributed CDN in front. Our database, authentication, storage, and edge functions are provided by an enterprise-grade backend platform with continuous monitoring and patching.
6. Backups and disaster recovery
The production database is backed up automatically by the managed platform. Deleted forms and submissions are purged from active systems immediately and from backups within 30 days. We regularly review recoverability of critical data.
7. Abuse, DDoS, and anti-bot protection
- Edge-level rate limiting on submission, auth, and admin endpoints.
- Bot and suspicious-visitor detection with administrator alerts.
- Per-IP throttling on sensitive flows such as sign-in and form submission.
- Optional CAPTCHA challenges that customers can enable on their forms.
8. Sub-processors
We work with a small number of vetted sub-processors to operate the Service:
- Managed cloud database, authentication, storage, and edge functions.
- Transactional email delivery.
- Payment processing for paid plans.
- Error monitoring and product analytics.
We do not sell personal data.
9. Data retention and deletion
- Account data is retained while your account is active.
- Form responses are retained according to your settings and plan limits.
- You can delete individual submissions, forms, or your entire account at any time from your account settings. Deleted data is purged from backups within 30 days.
10. International transfers
Where data is transferred outside your region, we rely on appropriate safeguards such as the Standard Contractual Clauses provided by our sub-processors.
11. Your rights
Depending on your jurisdiction you may have rights to access, correct, export, delete, or restrict processing of your personal data, and to object to or withdraw consent. To exercise these rights, email info@allwebforms.com. See our Privacy Policy for full details.
12. Incident response
We monitor the Service for security and availability incidents. If we confirm a security incident that affects your data, we will notify affected customers without undue delay and within the timeframes required by applicable law, together with the information needed to assess the impact.
13. Reporting a vulnerability
We welcome responsible disclosure. If you believe you have found a security vulnerability, email info@allwebforms.com with details and steps to reproduce. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.
14. Compliance posture
We design the Service with GDPR-style data protection principles in mind, including data-minimisation, purpose limitation, and user control over personal data. We do not claim formal certifications such as SOC 2, ISO 27001, or HIPAA compliance. If you require a signed data processing agreement (DPA), contact info@allwebforms.com.
15. Contact
Security questions: info@allwebforms.com
Privacy requests: info@allwebforms.com