Privacy in practical terms

Know what information moves through WebFormafy and why.

This policy explains how WebFormafy, operated by Sky Grid Developments LLC, collects, uses, discloses, protects, and retains information. It applies to account owners, their authorized team members, and people who interact with public forms, order pages, auctions, and workflows.

Last updated September 2, 2026

Start with the relationship

The right answer depends on how you use the platform.

These roles explain who makes the decisions about information and who can see it.

If you create an account

You choose the workflows, team access, payment paths, notifications, and integrations you enable. You can build and operate them yourself.

If you are a customer or visitor

The business that published the form or page decides what it asks for and why. That business can access the information you submit.

What WebFormafy does

WebFormafy stores and processes account and workflow information so the selected service can operate, remain secure, and be supported.

Where SkyGrid fits

SkyGrid implementation is optional. If an account owner hires SkyGrid, authorized project information may be reviewed to design, configure, migrate, launch, or support that account.

Follow the information

Collection should match the workflow the customer can see.

WebFormafy can connect several business steps, but connection does not mean every feature collects every category of information.

Customer action

A person submits a form, places an order, joins an auction, uploads a file, or responds to a review request.

Business record

The account owner and authorized collaborators receive the details needed to respond, fulfill, and keep an accurate record.

Selected service

A configured payment provider, email service, integration, or webhook receives only the information needed for that handoff.

Continued control

Account settings, exports, retention rules, access controls, and verified privacy requests govern what happens next.

What we collect and why

We collect the information needed to run the account and its chosen workflows.

Account and business information

  • Name, email address, password hash, profile details, and organization information.
  • Subscription, billing, support, consent, team membership, and account activity records.
  • Used to create the account, authenticate users, manage access, provide support, and administer the service.

Customer and workflow content

  • Answers, contact details, preferences, uploaded files, requests, reviews, orders, and fulfillment notes.
  • Auction records may include registrations, watchlists, bids, winning records, and trust or activity signals.
  • Used to provide the form, ordering, auction, workflow, notification, and collaboration features selected by the account owner.

Commercial information

  • Items, quantities, discounts, tips, tax, delivery or shipping details, totals, and payment status.
  • Provider account identifiers and transaction references used to connect and reconcile a configured payment path.
  • Card numbers and security codes are entered with the payment provider and are not stored by WebFormafy.

Usage and technical information

  • Page views, form progress, submissions, conversion events, field interactions, device and browser details, network information, and error context.
  • Used to operate and secure the service, diagnose failures, understand workflow performance, and improve usability.
  • We do not record screens or track individual mouse movements.
Product improvement boundary: we do not use raw customer submissions for unrelated advertising, data brokerage, or training general artificial intelligence models. We may use aggregated or deidentified information that is not reasonably linked to a person to understand and improve the service.

When information leaves WebFormafy

A disclosure should correspond to a provider, integration, or obligation you can identify.

We do not sell personal information. We disclose information in the following circumstances.

Account owners and teams

The account owner and authorized collaborators can access the customer and workflow records associated with their account.

Service providers

Hosting, storage, email, monitoring, security, and support providers process information under instructions that help us operate the service.

Features you enable

Payment providers, connected applications, and webhook destinations receive the information needed for the feature the account owner configured.

Legal and safety needs

We may disclose information when required by law or when reasonably necessary to protect rights, safety, the platform, or its users.

Business changes

Information may be transferred as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable notice and privacy obligations.

With your direction

We may disclose information when you ask us to, authorize it, or make information public through a feature you intentionally publish.

Providers and connected tools

What gets shared depends on what the account owner turns on.

Availability and the level of automated verification vary by provider and configuration.

Payments

Stripe is the primary hosted card and eligible wallet path. PayPal and Square may be available through configured checkout or handoff paths. Payment providers receive billing, order, fulfillment, tax, and transaction information needed for the selected flow.

Business integrations

Connected HubSpot, Salesforce, Mailchimp, Google Sheets, Slack, Zapier, or webhook destinations may receive customer and workflow fields selected for that connection. Disconnecting an integration removes its active credentials from WebFormafy, but it does not erase information already received by the outside provider.

Review the current provider categories

Artificial intelligence

If you intentionally use an artificial intelligence design feature, the goal and field context you enter may be sent to OpenAI to produce suggestions. Do not put customer submissions, payment details, or sensitive personal information into a design prompt.

OpenAI privacy

Infrastructure

Microsoft Azure supports application hosting, databases, and storage. Twilio SendGrid supports transactional email. Application Insights supports performance and error monitoring. Operational telemetry is minimized where practical, but identifiers or error context may be present.

Protection and retention

We use layered safeguards and keep different records for different reasons.

No service can promise absolute security. Our controls are designed to reduce risk and limit access.

How information is protected

  • Production traffic is protected with HTTPS and TLS.
  • Sensitive connection tokens are protected with the .NET Data Protection system.
  • Access controls, antiforgery protection, verified provider signatures, security headers, request limits, and audit records protect important actions.
  • Infrastructure providers apply their own database, storage, network, and backup safeguards.

How long information is kept

  • Account, workflow, submission, order, auction, and analytics information is generally kept while the account is active or until the account owner deletes it, subject to legal and operational needs.
  • Audit records are currently configured for 365 days by default.
  • Successful webhook records are removed after 30 days. Unresolved event payloads are redacted after 30 days, and limited failure metadata may remain for up to 90 days.
  • Deleted information may remain in protected backups until those backups expire. A restored backup must replay applicable deletion requests before normal service resumes.
Do not collect protected health information.

The generally available service is not offered with a business associate agreement through independent signup and must not be used for a workflow regulated by HIPAA. Encryption alone does not make a service HIPAA compliant. Read the HIPAA and Health Data notice before collecting health information.

Your choices and rights

You can review your account data and ask what happens to it.

Your rights vary by location. We may need to verify your identity, and a customer who submitted information to a business may need to contact that business first.

AccessRequest the personal information associated with your account.
CorrectUpdate profile, organization, and workflow information you control.
DeleteRequest deletion or anonymization of eligible active information. Financial, fraud, security, dispute, tax, ownership, and legal hold records may require review or continued retention.
DisconnectRemove active credentials for connected customer relationship, payment, and notification services.
Ask or appealContact us about a request, a decision, or information about categories, sources, purposes, and recipients where applicable law provides that right.

Cookies and measurement

We use essential browser storage and product measurement, not advertising trackers.

Browser privacy signals: because we do not currently sell personal information or share it for advertising across unrelated services, a Global Privacy Control signal does not change those practices. If our practices change, we will honor legally required opt out signals and update this policy.

Business responsibilities

Account owners remain responsible for the promises they make to their customers.

Sky Grid Developments LLC determines the purposes of processing for WebFormafy accounts, security, billing, support, and service operation. For customer content, the account owner generally decides what to collect and why, while WebFormafy processes that content to provide the configured service.

Before publishing

Ask only for information the workflow needs. Explain the purpose, provide any required notice, and review privacy, refund, shipping, payment, and industry obligations.

Before connecting

Confirm what each integration receives, who can access it, where it is retained, and whether the provider terms fit your use.

Before regulated use

Obtain any required data processing agreement, international transfer terms, consent, or professional review before regulated information enters the service.

Questions, requests, and policy changes

Ask us about your information in plain language.

We may revise this policy as the service or legal requirements change. We will update the date above and provide additional notice when a change is significant. For privacy questions or requests, contact Sky Grid Developments LLC.

Email Privacy Support