Heartforms Privacy Policy
Effective October 2, 2026
Who we are
Heartforms (the form service and dashboard at forms.happyheartsoftware.com) is made and run by Happy Heart Software LLC, doing business as Happy Heart Software, based in Ohio, USA ("Happy Heart Software", "we", "us"). This policy covers Heartforms only.
Heartforms is used by two groups of people, and this policy covers both:
- Form owners: the people and businesses with a Heartforms account who create forms and receive the messages.
- People who fill in a form: anyone who sends a message, sign-up, RSVP or other answers through a form that uses Heartforms, whether it's on a Heartforms page or on the form owner's own website or app.
If you filled in a form
The form's owner decides what the form asks for and what they do with your answers. We store and deliver your answers for them, and don't use them for anything else. To see, change or delete what you sent, contact the form's owner first; if you can't reach them, email contact@happyheartsoftware.com and we'll help.
When you send a form, we keep:
- Your answers: everything you typed or chose in the form, such as your name, email address and message.
- Details about the message: when it was sent, the website or app it came from, its subject, and which of the owner's contacts it was meant for (if the form let you choose).
- Delivery records: whether the email to the owner, an optional confirmation email to you, and any other service the owner connected (see “Services involved”) received it.
If the form sends a confirmation email, it goes to the email address you entered, with a copy of your answers. To stop spam, we use a scrambled (one-way hashed) version of your IP address to count how many messages you send in a short time. It isn't stored with your answers, and the counts are deleted within about a day.
If you have a Heartforms account
We keep:
- Your account: your name, email address, team name and role, and when you last signed in. If you set a password, we store only a one-way hash of it, never the password itself.
- Sign in with Google: if you use it, Google tells us your email address and name, and confirms your email. We don't get your Google password or access to anything else in your Google account.
- Your team's forms and settings: each form's name, questions, page wording, access key, allowed websites, who gets its messages, confirmation-email wording and any webhook address.
- Your team's email addresses: the addresses that receive messages, and whether each one has been confirmed.
- Messages sent to your forms: as described above.
Everyone on your team can see and change the team's forms, messages and email addresses. People outside your team can't. Our administrators can see account and team details, and the number of messages each team receives, to run and support the service.
Cookies
The dashboard uses one cookie to keep you signed in for up to 30 days, and Sign in with Google uses a second cookie for about 10 minutes while you sign in. Both are needed for the service to work. Heartforms doesn't use advertising or analytics cookies, and form pages don't set cookies.
How we use information
- To save form messages and deliver them to the form's owner, and to send confirmation emails the owner turned on.
- To run accounts: signing in, confirming email addresses, invitations and password resets.
- To keep the service secure and free of spam and abuse.
We don't sell information, use it for advertising, or use form messages to train AI models.
Services involved
- Cloudflare runs Heartforms and stores its database. It may keep request logs, including IP addresses, for a few days for security and fixing problems.
- Resend sends Heartforms' emails: new-message notifications, confirmation emails, and account emails such as invitations and password resets.
- Google provides Sign in with Google (if you use it) and the typefaces on Heartforms pages. Your browser requests the fonts from Google, which receives your IP address and browser information.
- The form owner's own services: a form owner can connect a webhook, which sends each new message to another address they choose, such as a spreadsheet or automation tool. What happens there is up to the form owner and that service.
How long we keep it
- Form messages are kept until the form's owner deletes them, deletes the form or closes their account.
- Accounts are kept until they're closed.
- Sign-in sessions expire after 30 days. One-time links expire: email confirmations after 3 days, invitations after 7 days and password resets after 1 hour.
- Spam-protection counts are deleted within about a day.
Deleting your data
Form owners can delete any message, or a whole form and all its messages, from the dashboard at any time. To close an account and delete your team's data, email contact@happyheartsoftware.com. If you filled in a form and want your answers deleted, ask the form's owner, or email us and we'll help.
Security
Heartforms only works over encrypted connections (HTTPS). Passwords, sign-in sessions and one-time links are stored only as one-way hashes, and each team's data is kept separate from every other team's.
Children
Heartforms isn't directed to children under 13, and we don't knowingly collect their personal information. If you believe a child has sent us information, contact us and we'll delete it.
Your choices and rights
You can ask us what personal information we hold about you, and ask us to correct or delete it. Email contact@happyheartsoftware.com and we'll help. Depending on where you live, you may have additional rights, and we'll honor them.
Changes to this policy
If we change this policy, we'll post the new version here and update the date at the top. If a change affects information we already hold, we'll tell you in the app before it takes effect.
Contact us
Questions about your privacy? Email contact@happyheartsoftware.com.
← All privacy policies