Skip to content

Privacy Policy

Last updated: 19 August 2026

This Privacy Policy explains how Qanform (“Qanform”, “we”, “us”) handles personal data when you use https://qanform.com and related services. It is written to be publicly readable without an account, including for Google’s OAuth verification of our Google Sheets integration.

1. Who we are

Qanform is a visual form builder and submissions database at https://qanform.com. Contact: support@qanform.com.

2. Data we collect

Account data: name, email address, password hash (we never store your password in plaintext), email verification status, and session cookies needed to keep you signed in.

Workspace data: workspaces, projects, forms, form schemas, translations, styles, and settings you create.

Submission data: answers sent through your published forms, including file uploads you choose to collect. Form respondents typically do not need a Qanform account.

Usage and diagnostics: timestamps, approximate IP used for rate limiting and security, and application error reports. We use Sentry to capture technical errors. We configure Sentry to avoid sending passwords, session cookies, and OAuth tokens.

3. How we use data

We use this data to provide the product: host your forms, store and export submissions, send transactional email (verification, password reset, email change), enforce access control, prevent abuse, and fix outages.

We do not sell personal data. We do not use personal data or Google user data for advertising, credit scoring, or unrelated profiling.

4. Google user data (Limited Use)

If you connect Google, Qanform requests access to Google Sheets and read-only Google Drive access so you can pick an existing spreadsheet (or create one) and so we can append or update rows when a form is submitted.

We access: OAuth tokens for your Google account; the list of spreadsheets needed for the picker; spreadsheet titles, IDs, and sheet names you select; and cell values we write or read in those selected sheets to deliver submissions. We do not use Drive access to scrape unrelated personal files, photos, or documents.

Google OAuth tokens are encrypted at rest and are never returned to the browser or included in API responses. You can disconnect Google from the form integrations screen. You can also revoke Qanform in your Google Account permissions.

Qanform's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not allow humans to read Google user data unless: you ask us to for support with your consent; it is required for security, legal compliance, or investigating abuse; or it is aggregated data that cannot identify a person. We do not transfer Google user data to third parties except to provide the feature you requested (for example, writing to the Google spreadsheet you chose) or as required by law.

5. Notion

If you connect Notion, we store encrypted OAuth tokens and write submission fields to the Notion database you select. You can disconnect Notion in the product. We do not use Notion data for advertising.

6. Email

We send transactional email (account verification, password reset, email change) through our email provider. We do not send marketing campaigns from this product today.

7. Cookies

We use a secure, HTTP-only session cookie to keep you signed in on qanform.com. We do not use third-party advertising cookies.

8. Storage and processors

Application data is stored in our hosted database. Uploaded files are stored in private object storage and streamed through our API. Email is sent by our transactional email provider. Optional destinations (Google Sheets, Notion) receive only the mapped submission fields you configure. Error monitoring is provided by Sentry.

9. Retention and deletion

We keep account and workspace data while your account is active. Submissions stay until you delete them or your workspace data is removed. To request deletion of your account and associated data, email support@qanform.com. We may retain limited records if required for security or law.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Email support@qanform.com. Form respondents should contact the form owner first; we process respondent data on behalf of the workspace that published the form.

11. Children

Qanform is not directed at children under 16. Do not create an account or submit personal data if you are under 16.

12. International transfers

We may process data in the regions where our hosting providers operate. By using Qanform you understand that your data may be processed outside your country, with safeguards our providers apply.

13. Changes

We may update this policy. The “Last updated” date will change. Material changes that affect Google user data will remain consistent with Google’s Limited Use rules.

Terms of Service · Refund Policy · support@qanform.com