Privacy Policy
Your privacy is important to us. This policy explains how WebFormafy, operated by Sky Grid Developments LLC, collects, uses, shares, and protects your information.
Last updated: July 3, 2026
SkyGrid Project Privacy Notes
No Intentional Selling or Sharing
SkyGrid Developments does not intentionally sell, rent, or trade client/customer data. Data may pass through necessary providers such as hosting, email, analytics, payment, or integration services only when needed to run the system or complete requested work.
Portfolio and Gallery Examples
Public-facing completed work may be shown in galleries, examples, demos, or promotional material for SkyGrid and the client business unless a written agreement says otherwise. Private customer records, credentials, and sensitive operational details are not intended for portfolio use.
Client Review Still Matters
Clients should review their own privacy, refund, shipping, business, and compliance language before launch. SkyGrid can provide practical website copy, but legal and regulated business obligations should be reviewed by qualified professionals.
Your Privacy in 30 Seconds
What We Collect & How We Use It
Information We Collect
- Account: Name, email, password (hashed), and organization details when you register.
- Form Data: Data you collect via forms, menus, and auctions is stored securely and only accessible to you and authorized collaborators.
- Orders & Payments: Order details, tip amounts, and shipping info. We never store credit card numbers.
- Usage Analytics: Page views, form conversion rates, device info, field-level interaction patterns (e.g., which fields users click or focus on), and step-level drop-off analysis for multi-step forms.
- Auction Activity: Bids, watchlists, trust scores, and bidding history.
How We Use Your Information
- To provide and maintain the WebFormafy platform (forms, menus, auctions, organizations).
- To process orders, payments, and auction settlements.
- To generate analytics, A/B test results, and conversion insights for your forms.
- To send notifications — email, Slack, and in-app — about submissions, orders, bids, and account activity.
- To power AI features (form field suggestions, headline generation) via OpenAI.
- To comply with legal obligations.
Data Security
- In Transit: All data encrypted via HTTPS/TLS.
- At Rest: Sensitive tokens encrypted using .NET Data Protection API. Database protected with SQL Server TDE.
- Rate Limiting: API (100 req/min), form submissions (5/min per IP), webhooks (10/min per IP).
-
Security Headers: A strict Content-Security-Policy (nonce-based
script-srcwith'strict-dynamic', no'unsafe-inline', no'unsafe-eval'),X-Content-Type-Options: nosniff,Referrer-Policy: strict-origin-when-cross-origin,X-Frame-Options: SAMEORIGIN(relaxed only on opt-in embed pages), and a restrictivePermissions-Policyare enforced on all responses.
The deprecatedX-XSS-Protectionheader is intentionally not sent — modern browsers ignore it, and CSP is the current XSS defense. - CSRF Protection: Anti-forgery tokens on all state-changing operations.
- Audit Logging: Key user actions, authentication events, and security-relevant data access are logged.
Third-Party Services & Data Sharing
Payment Processors
We are designed so card numbers are handled by hosted third-party payment providers, not by WebFormafy servers. Our PCI scope depends on maintaining that hosted-field/redirect flow and completing the appropriate SAQ-A review for production deployments:
- Stripe — Checkout, subscriptions, Connect marketplace flows, and auction payment records. Privacy Policy
- PayPal — Checkout and subscription billing. Privacy Policy
- Square — Online checkout. Privacy Policy
- Google Pay — Mobile checkout. Privacy Notice
These providers receive only the payment and billing data necessary to process your transaction. WebFormafy may store order totals, processor transaction IDs, payout account IDs, and payment status metadata, but not card numbers or CVV values.
CRM & Integrations
When you choose to enable an integration, form submission data may be sent to:
- HubSpot — Contacts/leads from form submissions (OAuth 2.0). Privacy Policy
- Salesforce — Leads/contacts (OAuth 2.0). Privacy Policy
- Mailchimp — Email list subscribers (OAuth 2.0). Privacy Policy
- Google Sheets — Submission data appended to spreadsheets (OAuth 2.0). Privacy Policy
- Slack — Notification messages via webhooks. Privacy Policy
- Zapier / Webhooks — Data sent to your configured webhook endpoints with HMAC-signed payloads.
Integrations are opt-in only. You can disconnect any integration at any time, and all stored OAuth tokens are immediately cleared.
AI Services
- When you use the AI Form Designer, your form goal description and field context are sent to OpenAI to generate field suggestions, headlines, and CTAs.
- AI prompts are intended for form design context, not personal submission data. Do not enter names, emails, payment data, or sensitive customer content into AI prompts.
- OpenAI Privacy Policy
Infrastructure & Operations
- SendGrid — Transactional email delivery (account confirmations, notifications). Privacy Policy
- Azure / Cloud Hosting — Application hosting, database, and storage. Privacy Statement
- Application Insights — Performance monitoring and error tracking, configured for operational telemetry rather than intentional PII collection.
We do not sell, rent, or share your data with data brokers, advertisers, or any third parties not listed above.
Data Retention & Your Rights
Data Retention
- Form Submissions: Retained per your subscription tier limits. You can delete individual submissions or all data at any time.
- Audit Logs: Retained according to the configured audit retention policy, currently 365 days by default, then automatically purged.
- Webhook Logs: 30 days retention, then automatically purged.
- Analytics Data: Form views, field interaction data, step funnel events, and conversion data are retained while your account is active.
- Deleted Accounts: Account deletion removes or anonymizes active application data tied to your account, including forms, menus, auctions, orders, integrations, submissions, analytics, organizations, and messaging data, unless ownership transfer or legal retention requirements apply.
- Backups: Deleted personal data may remain in encrypted point-in-time backups until backup expiry. Backups are only restored for disaster recovery or legal obligations; if restored, erasure requests must be replayed before the system returns to service.
Your Rights
- Access: Download a Data Subject Access Request export from
/api/privacy/dsarwhile signed in. - Update: Edit your profile, organization, and form data at any time.
- Export: Download a full export of your personal data in machine-readable JSON format from your account settings.
- Delete: Delete your account and associated active application data from your account settings or the right-to-be-forgotten endpoint. This action is irreversible after completion; encrypted backup copies age out under the backup policy above.
- Disconnect Integrations: Revoke any connected CRM, payment, or notification integration at any time. Stored OAuth tokens are removed from active configuration.
To exercise any of these rights, visit your account settings or contact us at skygridobe@gmail.com.
Cookies & Tracking
Cookies We Use
- Authentication Cookies: Required. Used to keep you signed in and manage your session.
- Anti-Forgery Cookies: Required. Used for CSRF protection on all forms and API calls.
- Theme Preference: Optional. Stores your light/dark mode preference.
- Cookie Consent: Optional. Stores whether you accepted essential-only or all cookies.
We do not use third-party advertising cookies or social media tracking pixels. Visitors in the EU are shown a cookie consent banner before optional analytics preferences are recorded.
Analytics We Collect
- Form Analytics: Page views, submission rates, step-level drop-off points, and conversion funnels — tied to your forms, not to individual visitors' identities.
- Field Interaction Tracking: Which form fields users click, focus on, and interact with, aggregated by variant. This helps you identify high-engagement and problematic fields. No pixel-level mouse tracking or screen recording is performed.
- Device & Browser: Aggregate device type, browser, and screen size data for responsive design insights.
- Application Performance: Page load times and error rates via Application Insights (no PII).
You can control cookies via your browser settings. Disabling authentication cookies will prevent you from signing in.
Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or in-app notification. The "Last updated" date at the top of this page reflects the most recent revision.
Contact Us
If you have questions about this policy, your data, or want to exercise your rights, contact us:
Sky Grid Developments LLC
Email Support