Skip to content
Part one

Privacy Policy#

Formly is run by [[ LEGAL ENTITY NAME ]], company number [[ COMPANY NUMBER ]], registered at [[ REGISTERED ADDRESS ]]. Where this policy says “we”, that is who it means.

Who this is for#

Two different people end up in Formly’s database, and they are owed different things.

  • You, the business owner. You made an account, you pay us, and the page is yours. Your data is between you and us.
  • The person who fills in your page. They have never heard of Formly. They filled in a form on your page because they want you to ring them back. As far as they are concerned this is your business’s form, and their details are yours to hold and answer.

We handle that second set of data because you asked us to, on your instructions, and we do not use it for anything of our own. The exact legal label for that arrangement — and the contract terms that have to sit behind it — is [[ CONTROLLER OR PROCESSOR — LAWYER TO CONFIRM ]].

What we collect#

Only what the product needs to work. There is no advertising business here, so there is nothing to be gained by collecting more.

  • Your account. An email address and a password. Sign-in runs on Supabase, which stores the password hashed — it never reaches us in a readable form, and we cannot look it up or tell you what it is.
  • Your payment. Card details go straight to Stripe and are held by Stripe. Formly never sees or stores a card number. What comes back to us is a customer reference and whether the subscription is active.
  • What you tell the assistant. The description of your business you type into the chat, and anything you say while editing. We use it to write and redraft your page.
  • Your page. The words, images, colours, fonts and form fields that make up the page we publish for you.
  • Form submissions. Whatever your form asks for — usually a name, a phone number, and a sentence about the job.
  • Ordinary technical logs. IP address, browser, timestamps, error traces. The boring exhaust of running a web service, kept so we can fix things when they break.

People who fill in your pages#

When someone completes the form on your page, three things happen, and nothing else happens.

  • The submission is stored against your page so you can see it.
  • It is emailed to you, through Resend, straight away. Only completed forms — a half-filled one is never sent anywhere.
  • If you have set a webhook, the same submission is posted to the URL you gave us.

Formly never contacts your customers. We do not email them, market to them, profile them, sell their details, or add them to anything. Following up is yours, and it stays yours.

About webhooks. A webhook is a URL you choose and paste in yourself. Once a submission has been posted to it, that data is in a system we have nothing to do with — your CRM, Zapier, Make, whatever sits at the other end. What happens to it there is governed by that service’s terms and yours, not by this policy.

You are also the one deciding what your form asks for. If you add a field, you are the one who has to have a reason to ask for it and a lawful way to hold the answer. The categories we will not let a Formly page collect are [[ RESTRICTED DATA CATEGORIES ]].

Who else handles it#

Formly is a small product built on other people’s infrastructure. These are the companies that touch data in the ordinary running of it. We do not sell data to anyone, and none of these are advertising arrangements.

Supabase
Accounts, sign-in, and the database your pages and submissions live in.
Stripe
Payments and subscriptions. Stripe holds the card details; we hold a reference to a Stripe customer.
Anthropic
The model that writes and designs your page. It receives the description of your business you type into the chat. It is never sent a form submission.
Resend
Transactional email — lead notifications to you, and account email like a password reset.
Hosting
[[ HOSTING PROVIDER ]], serving from [[ HOSTING REGION ]].
Analytics
[[ ANALYTICS TOOL — IF ANY ]]. If the answer is none, this row should say none and mean it.
Your webhook
Only if you set one, and only the completed submissions from your own pages.

We may also have to hand something over if the law requires it. If that ever happens and we are allowed to tell you, we will.

Where data crosses a border between these services, the mechanism that is supposed to make that lawful is [[ INTERNATIONAL TRANSFER MECHANISM ]].

Cookies and tracking#

Signing in sets a session cookie. Without it, the browser forgets who you are on the next click, so there is no version of a logged-in product that does without one.

Beyond that, the full list of cookies and third-party scripts on this site and on the pages Formly generates is [[ COOKIE INVENTORY — CONFIRM BEFORE LAUNCH ]]. That needs to be checked against the real build rather than written from memory, and whether a consent banner is required follows from the answer.

How long we keep things#

Every number in this section is a decision with legal consequences, so every number here is still blank.

  • Form submissions: [[ LEAD RETENTION PERIOD ]]
  • Your account and pages after you cancel: [[ ACCOUNT RETENTION AFTER CANCELLING ]]
  • Server and error logs: [[ SERVER LOG RETENTION ]]
  • Backups, which lag behind deletions everywhere: [[ BACKUP RETENTION ]]

Billing records normally have to be kept for longer than anything else, for tax reasons, whatever the rest of this section ends up saying.

Security#

What we can say plainly: traffic is served over HTTPS, passwords are hashed by Supabase rather than held by us, and card numbers never reach our systems because Stripe takes them directly.

What we are not going to say: that we are certified, audited, or compliant with any particular standard. We are not. If that changes, this paragraph will name the standard and the date, and until it does you should assume nothing beyond the sentence above.

If something does go wrong and data is exposed, we will tell the people affected within [[ BREACH NOTIFICATION WINDOW ]], and we will say what actually happened rather than the shortest true sentence available.

Your choices#

Depending on where you live, you may have rights over the data an organisation holds about you — to see it, correct it, get a copy, or have it deleted. The exact rights, who they apply to, and how to use them are [[ DATA RIGHTS AND HOW TO USE THEM ]].

Two things do not need a legal framework to be true. You can delete a page whenever you like. And if someone who filled in one of your forms asks you to delete their details, tell us and we will remove them from your page’s records — though if a webhook already sent a copy onward, only you can clear it from the system at the other end.

Questions about any of this go to [[ PRIVACY CONTACT EMAIL ]]. If a formal data protection contact is required, that is [[ DATA PROTECTION CONTACT ]], and the representative for people in the EU or UK is [[ EU / UK REPRESENTATIVE — IF NEEDED ]]. There is no minimum age written into this product yet; that decision is [[ MINIMUM AGE ]].

Changes, and who to ask#

If this policy changes in a way that matters, we will email account holders and change the date at the top. Small corrections get the date change only.

Anything else: [[ PRIVACY CONTACT EMAIL ]].

Part two

Terms of Service#

The deal in one line: you pay first, we build and host a branded page with a working form in it, and either of us can walk away.

The agreement#

These terms are between you and [[ LEGAL ENTITY NAME ]]. Making an account means you accept them. If you are agreeing on behalf of a company, you are confirming you are allowed to.

What you are buying is a service, not software you own. We are not transferring the platform to you, and you are not licensing our code. The page we produce for you is a different matter, and that is covered further down.

Your account#

One account, one business, one person responsible for it. Keep the password to yourself — anything done from a signed-in session is treated as done by you, and we cannot tell the difference. If you think someone else is in your account, email [[ SUPPORT CONTACT EMAIL ]] and we will lock it.

Give us an email address you actually read. It is where lead alerts go, and it is the only way we have of reaching you.

Plans, payment, cancelling#

Two plans, both billed monthly through Stripe.

  • Starter — $15 a month. One live page.
  • Growth — $30 a month. Up to five live pages, which works out at about $6 a page.

Leads are unlimited on both. You are paying for pages, not for the people who fill them in.

Payment comes first, and there is no free trial. You pay before you get access. There is no countdown running against a card you forgot about, and nothing to cancel before a deadline. You can cancel any time from your account, and you keep what you have paid for until the end of the month you have already paid for.

Refunds are [[ REFUND POLICY ]]. If we ever change what a plan costs, existing subscribers get [[ PRICE CHANGE NOTICE PERIOD ]] of warning first, and cancelling instead is always a fair answer.

If a payment stops#

Your link keeps loading. It shows a plain message saying the page is not available right now — never a dead 404 that makes it look as though your business has closed. Pay again and the real page is back on the very next visit, with nothing to republish and nothing to rebuild.

Your pages and your leads are not deleted the moment a card fails. How long they are held is the retention question above: [[ ACCOUNT RETENTION AFTER CANCELLING ]].

Your content and acceptable use#

Your business name, your logo, your photographs, your words and your leads are yours. You give us permission to store, host and display them for the purpose of running your page — that is all the permission is for, it lasts as long as your account does, and we do not use your content to advertise Formly without asking you first.

In return, you are responsible for what goes on the page. That means:

  • You have the right to use the images, names and claims you put on it.
  • What it says about your business is true — the qualifications, the licences, the guarantees, the years in the trade.
  • It is not being used for anything illegal, deceptive, or built to impersonate somebody else.
  • It is not being used to send unsolicited messages, or to collect details from people under a pretext.
  • You do not attack, overload, scrape or reverse-engineer the service, or resell it as though it were your own product.

If a page breaks these rules, we can take it down. Where there is time to ask first, we will, and the notice you get before a suspension is [[ NOTICE PERIOD BEFORE SUSPENSION ]].

What Formly writes for you#

You describe your business and Formly writes a draft — a headline, a subheadline, value propositions, steps, some common questions, and a form. It is a starting point produced by a model from what you told it. You review it before anything goes live, and if it is not right you can describe the business again and have it written again. An editor for the words and the design is not part of the service yet.

Check it before you publish. A model can write a confident sentence that is not true of your business: a guarantee you do not offer, an area you do not cover, a qualification you do not hold. Once it is on your page it is your claim, so read the draft the way a customer would.

We do not claim ownership of the text and layout generated for your page. Two businesses that describe themselves similarly may well end up with similar pages, and neither of you is doing anything wrong when that happens.

Availability and support#

We are not going to print an uptime figure we have no history to back. Formly is new. Things will occasionally break, and when they do we will fix them and say what happened. Any commitment we make about uptime is [[ UPTIME COMMITMENT — IF ANY ]], and about how fast support answers, [[ SUPPORT RESPONSE COMMITMENT — IF ANY ]]. If those stay blank, it is because we have not earned the right to fill them in.

Maintenance happens. So do changes: features get added, and occasionally something gets removed. If we remove something you are relying on, we will tell you before we do it.

Ending the agreement#

You can cancel any time, for any reason, without a phone call. Your pages stop being served at the end of the period you have paid for.

We can end it too, if a page breaks the rules above, if payment fails and stays failed, or if we shut the service down. If we are the ones ending it and you have not done anything wrong, you get a refund of the unused part of the month and enough notice to take a copy of your leads.

This is the part of a contract most likely to matter and the part we are least qualified to draft, so almost all of it is still open.

  • The limit on what we can be liable for: [[ LIABILITY CAP ]]
  • The law that governs these terms: [[ GOVERNING LAW ]]
  • Where a dispute gets decided: [[ COURTS OR ARBITRATION ]]

What we can say without a lawyer: Formly builds and hosts a page. We do not promise it will win you work, and we are not party to whatever you agree with the people who contact you through it. That relationship is entirely yours.

Nothing in the finished version of this section should try to exclude liability that the law does not allow to be excluded.

Changes, and who to ask#

If these terms change materially, subscribers get [[ TERMS CHANGE NOTICE PERIOD ]] of notice by email, and cancelling before the change takes effect is always an option.

Anything you want to ask about the above: [[ SUPPORT CONTACT EMAIL ]].

Before launch

Placeholders to fill#

Every red block on this page, collected in one list so none of them can quietly survive into a published version.

32 blanks, none of which we can fill in ourselves

Who we are

[[ LEGAL ENTITY NAME ]][[ COMPANY NUMBER ]][[ REGISTERED ADDRESS ]][[ EFFECTIVE DATE ]][[ LAST UPDATED ]]

Who to contact

[[ PRIVACY CONTACT EMAIL ]][[ SUPPORT CONTACT EMAIL ]][[ DATA PROTECTION CONTACT ]][[ EU / UK REPRESENTATIVE — IF NEEDED ]]

How the data is handled

[[ CONTROLLER OR PROCESSOR — LAWYER TO CONFIRM ]][[ HOSTING PROVIDER ]][[ HOSTING REGION ]][[ ANALYTICS TOOL — IF ANY ]][[ COOKIE INVENTORY — CONFIRM BEFORE LAUNCH ]][[ INTERNATIONAL TRANSFER MECHANISM ]][[ RESTRICTED DATA CATEGORIES ]]

How long, and what happens if it goes wrong

[[ LEAD RETENTION PERIOD ]][[ ACCOUNT RETENTION AFTER CANCELLING ]][[ SERVER LOG RETENTION ]][[ BACKUP RETENTION ]][[ BREACH NOTIFICATION WINDOW ]][[ DATA RIGHTS AND HOW TO USE THEM ]][[ MINIMUM AGE ]]

Money, promises and the law

[[ REFUND POLICY ]][[ PRICE CHANGE NOTICE PERIOD ]][[ UPTIME COMMITMENT — IF ANY ]][[ SUPPORT RESPONSE COMMITMENT — IF ANY ]][[ NOTICE PERIOD BEFORE SUSPENSION ]][[ LIABILITY CAP ]][[ GOVERNING LAW ]][[ COURTS OR ARBITRATION ]][[ TERMS CHANGE NOTICE PERIOD ]]

One more thing for whoever picks this up. The two documents above describe a product that is partly built. Before this goes live, the descriptions need checking against what actually ships — particularly the cookie list, the list of companies that touch data, and anything in the terms that describes a feature.