Privacy Policy
Last updated: 18 July 2026
This policy explains what Form to CMS collects, why, and what happens to it. It's written by the person who built the system, not adapted from a template farm. The operator is Henry Kirkness, trading as Studio Henry, England, United Kingdom.
1.The two hats we wear
For your account and workspace data (your email, billing, settings, usage) we are the data controller — we decide how it's processed and answer for it.
For your submitters' data (the names, emails and content people put in your forms) we are a data processor acting on your instructions. You're the controller; your privacy notice should tell your submitters what happens to their entries.
2.What we collect as controller
- Account: your email address and name (magic-link sign-in — we never see or store a password), workspace membership and roles.
- Billing: handled by Stripe. Card details go directly to Stripe; we never see or store them. We keep your Stripe customer id, plan and subscription status.
- Usage & diagnostics: server logs (IP, user agent, timing) kept short-term for security and debugging. There are no advertising trackers, and currently no analytics cookies at all — the only cookie is your sign-in session.
- Support: emails you send us, kept so we have context next time.
3.What we process on your behalf
Submissions: submitter name and email, the content of their entry, screening results, moderation decisions and the audit trail, plus payment/refund references for paid listings (the payment itself lives in your Stripe account). We use this data to run the pipeline you configured — screening, queueing, publishing, refunding — and for nothing else. We do not sell it, and we do not use it to train AI models.
4.Who else touches the data (subprocessors)
The service runs on a small set of providers:
| Provider | Purpose | Region |
|---|---|---|
| Vercel | Application hosting and edge network | EU/US |
| Neon | Postgres database (submissions, accounts) | EU (Frankfurt) |
| Stripe | Subscription billing; listing payments on your connected account | EU/US |
| Resend | Transactional email (magic links, invitations, notices) | EU/US |
We'll update this table before adding a provider that touches personal data. A signed DPA is available on request.
5.Retention and deletion
- Submissions marked as spam are deleted after 30 days.
- Everything else lives as long as your workspace does. Deleting your workspace (or your account, if it's the workspace's last) cascades: sites, collections, submissions and audit trails go with it.
- Backups can hold residual copies for up to 30 days after deletion, then they're gone too.
- We keep invoices and records the law requires us to keep (UK tax rules: six years).
6.Cookies
One cookie: your session, so you stay signed in. No advertising cookies, no third-party trackers. If we ever add product analytics, it will be cookieless-by-default and this policy will say so first.
7.Security
All traffic is encrypted in transit; data is encrypted at rest by our providers. Plugin tokens and pairing codes are stored as SHA-256 hashes — the raw secret is shown exactly once. Access to production data is limited to the operator. If a breach affects your data we'll tell you without undue delay, and the ICO where required.
8.Your rights
Under UK GDPR you can ask for access, correction, deletion, portability, or restriction of your personal data, and object to processing. Email henry@kirkness.com and we'll respond within a month. If you're unhappy with how we handle it, you can complain to the ICO (ico.org.uk). If you're a submitter to someone else's site, contact that site's owner first — they control your data; we'll help them honour your request.
9.International transfers
Primary data storage is in the EU (Neon, Frankfurt). Where a provider processes data in the US, transfers rest on the UK–US Data Bridge or standard contractual clauses.
10.Changes
If this policy changes materially we'll email account holders before the change takes effect. The date at the top always reflects the current version. See also the Terms of Service.