Privacy Policy

Last updated 12 August 2026

Our role

EasyForms (“we”, “the app”) is a Shopify application that lets a merchant publish forms on their storefront and manage the responses.

For data submitted through those forms, the merchant is the data controller and we act as a data processor on their behalf. We process that data only to provide the service, and never for our own purposes. For account data about the merchant themselves, we act as controller.

Merchant data

When a merchant installs the app, Shopify provides us with:

  • Store domain (for example example.myshopify.com)
  • Store name and the store owner’s email address
  • An access token, used to call the Shopify API on the store’s behalf
  • The subscription plan the store is on

We also store the forms, settings, styling and notification preferences the merchant configures inside the app.

Shopper data

The merchant decides which fields their form contains, so the personal data collected is under their control. A form can collect any of the following, and we store whatever is submitted:

DataSource
Form answers — which may include name, email address, phone number, company, postal address, free-text messages and signaturesEntered by the shopper
Uploaded files, such as screenshots, photos or documentsAttached by the shopper
IP address, browser user agent, referring URL and the page the form was submitted fromRecorded automatically, for spam prevention and rate limiting
Number of times a form was openedCounted anonymously. No identifier is stored with a view

Uploaded files are stored in the merchant’s own Shopify Files library, not on our servers. They are served from Shopify’s CDN.

We do not use cookies for advertising, run third-party trackers on the storefront, or sell or rent personal data to anyone.

Why we process it

  • To deliver the service — storing submissions so the merchant can read and act on them
  • To notify the merchant — sending an email when a new submission arrives, if they have enabled it
  • To create customer records — where the merchant has enabled it, a Shopify customer may be created or updated from a submission
  • To prevent abuse — IP address and user agent are used for rate limiting, honeypot checks and optional reCAPTCHA verification
  • To provide analytics — counts of form opens and submissions, shown only to the merchant

Sub-processors

We share data with these providers only as needed to run the service:

ProviderPurposeData involved
Shopify Inc.Hosting the store, storing uploaded files, customer recordsSubmissions data, uploaded files, customer details
ResendSending notification emails to the merchantRecipient address and the contents of the notification
DigitalOceanApplication and database hostingAll data described above
Google (reCAPTCHA)Spam prevention — only if the merchant enables itData collected by reCAPTCHA under Google’s own policy

We may disclose data where required by law, or to protect our rights or the safety of others.

Retention

  • Submissions and customer records are kept until the merchant deletes them, or until the app is uninstalled
  • When a merchant uninstalls, their data is erased within 48 hours, on receipt of Shopify’s shop redaction request
  • Deleting a form deletes its submissions
  • Notification emails queued for delivery are removed after sending

Your rights

If you are a shopper

The merchant whose store you submitted the form to is responsible for your data. Contact them to access, correct or delete it. When they act on such a request through Shopify, we erase the relevant records — including any files you uploaded — automatically.

If you are a merchant

You can export or delete data from within the app at any time, and uninstalling erases everything we hold for your store. You may also contact us directly using the details below.

We support Shopify’s mandatory privacy webhooks: customers/data_request, customers/redact and shop/redact. Each is implemented and acts on the data, rather than merely acknowledging the request.

Security

  • All traffic is served over HTTPS
  • Requests from a storefront are verified using Shopify’s signature, so data cannot be read or written by an unauthenticated caller
  • Every database query is scoped to the store that owns the record
  • Uploaded files are validated by both file type and extension, and size-limited
  • Access tokens and API credentials are stored as environment configuration, never in source control

No system is perfectly secure. If you believe you have found a vulnerability, please contact us before disclosing it publicly.

International transfers

Our servers are located in the United States. If you access the service from elsewhere, your data will be transferred to and processed there.

Contact

Questions about this policy, or a request relating to your data: support@devconsole.co

We may update this policy as the app changes. Material changes will be reflected in the “last updated” date above.