Privacy Policy
Last updated: September 29, 2026
1. Who this policy covers, and two different roles
This Privacy Policy explains how Graded Forms ("we," "us," "our") handles personal data through the Graded Forms service (the "Service"). It's important to understand that we act in two different roles, because different rules apply to each:
- As a data controller, for the account and billing information of the businesses and individuals who sign up for Graded Forms directly ("Customers," "you").
- As a data processor, for the data our Customers' own website visitors enter into forms tracked by our capture script. In that relationship, our Customer is the data controller responsible for their own visitors, and we process that data only on their instructions, as described in this policy and our Terms of Service.
If you are a website visitor whose partial form entry was captured by a business using Graded Forms, that business is who you should contact about your data — they control it. We're happy to help route such a request if you're not sure who to contact; see Section 9.
2. What data we collect
2.1 Customer account data
When you sign up for Graded Forms, we collect your email address (used for magic-link login and account communication), the sites you register, your alert and retention settings, and billing information. We never see or store your full card details — payment is handled entirely by Stripe, our payment processor; we only receive a customer and subscription reference from them.
2.2 Data captured from your website visitors (the capture script)
Our capture script (capture.js) is installed by Customers on their own websites. It reports a partial form fill only once a visitor enters a validly formatted email address and then leaves the page without submitting the form. When that happens, it sends:
- The email address the visitor typed in.
- Which other fields in the form were filled in — the field names only (e.g. "company" or "phone"), never the values typed into them.
- The total number of fields on the form, the form's identifier, and a timestamp.
- A randomly generated session token stored in the visitor's browser (via
sessionStorage), used only to avoid double-counting the same abandoned session — not to track the visitor elsewhere.
We do not collect passwords, payment details, browsing history, or any data from fields the visitor didn't fill in. We do not use this data for advertising, profiling, or any purpose beyond delivering it to the Customer who installed the script on their site.
2.3 The free abandonment audit script
Our separate, free audit script (audit.js) is deliberately built to collect zero personal data. It reports only two aggregate counters — how many times a form was started, and how many times one was abandoned — against an install code. It never sends an email address, a field name, a field value, or any visitor or session identifier.
3. How we use data
We use the data described above to:
- Operate the Service — display captured leads in a Customer's dashboard, send the real-time or monthly alerts a Customer has configured, and process billing.
- Maintain and improve the Service, including security and abuse prevention (for example, rate limiting).
- Communicate with Customers about their account, and respond to support requests.
4. Data retention
Captured leads are automatically and permanently deleted after a Customer-configured retention window (40 days by default, adjustable in account settings), unless a Customer has explicitly marked a lead as "converted," in which case it is kept until the Customer deletes it or their account. If a Customer deletes their account, their sites and all captured leads are deleted immediately and permanently.
5. Who we share data with
We don't sell personal data, and we don't share it for advertising purposes. We use a small number of service providers ("sub-processors") to run the Service, each of which processes data only as needed to provide their service to us:
- Supabase — database hosting and authentication.
- Stripe — payment processing and billing.
- Resend — delivery of transactional emails (login links, lead alerts, account notifications).
We may also disclose data if required by law, or to protect the rights, safety, or property of Graded Forms, our Customers, or others.
6. Cookies and similar technology
Our dashboard uses a session cookie, set by Supabase Auth, strictly to keep you logged in — it is not used for tracking or advertising. Our capture script uses sessionStorage (not a cookie) on the Customer's site solely to deduplicate repeated reports from the same abandoned session, as described in Section 2.2. The Graded Forms marketing site itself does not use analytics or advertising cookies.
7. Security
We apply reasonable technical and organizational measures to protect data, including encryption in transit (HTTPS), rate limiting on public endpoints, and strict separation between the credentials used to serve our marketing site and audit tool and those used to access account data. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.
8. International data transfers
Our sub-processors may process and store data in countries other than your own, including the United States. Where that happens, we rely on the safeguards those providers offer (such as Standard Contractual Clauses) for transfers out of the European Economic Area.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, or to object to or restrict our processing of it. Customers can exercise most of these rights directly from their account settings (data export, lead deletion, account deletion). For anything else, or if you're a website visitor whose data was captured by one of our Customers, contact us via our contact page and we'll either action your request or help direct it to the right Customer.
10. Children's privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16.
11. Changes to this policy
We may update this policy from time to time. If we make material changes, we'll update the "Last updated" date above and, where appropriate, notify Customers directly.
12. Contact us
Questions about this policy or how we handle data can be sent through our contact page.