Legal

Privacy Policy

Last updated: 8 August 2026

1. Who we are

Formitor provides synthetic form monitoring for WordPress agencies. We submit test entries through the forms our customers connect, then verify whether the resulting notification email is actually delivered.

The controller of the personal data described here is the operator of Formitor. Contact us through the contact page for the registered entity details.

2. What we collect

  • Account data. The email address and authentication details of the person who signs up, plus any account name you set. Authentication is handled by Supabase Auth, including optional multi factor enrolment.
  • Site and form configuration. The site URLs, form identifiers, check schedules, alert recipients, and notification settings you add to your dashboard.
  • Monitoring results. Timestamps, pass or fail status, check duration, HTTP status, delivery and inbox placement outcomes, and the error detail needed to explain a failure.
  • Test entry content. The entries Formitor submits are synthetic values we generate and tag. They are not real visitor enquiries.
  • Mail log metadata. This is the one place real personal data appears. To verify that a site's outgoing mail is actually leaving, the Formitor plugin records the recipient address, subject line, timestamp and transport of mail your site sends. It does not record message bodies. This log lives on your own site, is visible to you in the plugin's Mail Log tab, and can be switched off in the plugin settings.
  • Security events. Failed authentications, rate limit trips and blocked requests, with the caller IP address, so an incident can be reconstructed.
  • Billing data. Handled by Stripe. We never receive or store your card number.

3. What we do not collect

Formitor is not designed to collect or store the genuine leads your clients receive. Test notifications are redirected to a monitoring inbox we control rather than to your real recipients, and tagged test submissions are cleaned up on the schedule below. The exception is the mail log described above, which records who mail was addressed to but never what it said.

4. How we use it

To run the checks you schedule, to confirm a failure before alerting on it, to send the alerts you configure, to render your dashboard and any status pages you publish, to bill your subscription, and to operate and secure the service. We do not use your data to train machine learning models.

5. AI features

Two features in the dashboard send text to a third party language model: the assistant chat, and the plain English explanation of a failing check. What is sent is the failure detail and the question you ask, not your account credentials or your mail log. Both are rate limited per user. If you would rather not use them, simply do not open them.

6. Seed mailboxes

Inbox placement monitoring reads a dedicated seed mailbox to determine which folder a test message landed in. We read the folder placement and remove the test message. We do not read, forward, or repurpose unrelated mail in that mailbox.

7. Where your data is processed

The Formitor database and application run in the United States, in the Supabase us-east-2 region. Monitoring checks are executed from servers in the United States and Europe. If you are in the United Kingdom or the European Economic Area, using Formitor means your account and monitoring data is transferred to the United States. Contact us before signing up if that transfer is a problem for your engagement.

8. Sub-processors

We use a small number of providers to operate the service. We do not sell personal data.

  • Supabase: database, authentication, file storage and serverless functions (United States).
  • Cloudflare: website and dashboard hosting, DNS, and part of the monitoring network.
  • Mailgun: outbound alert and transactional email (United States region).
  • Stripe: subscription billing and payment processing.
  • netcup and Advin Services: the virtual servers that run the monitoring checks.
  • Better Stack: uptime and heartbeat monitoring of our own infrastructure.

Error tracking is self hosted on our own infrastructure rather than sent to a third party.

9. How long we keep it

  • Check results: 90 days, then deleted automatically by a nightly job.
  • Uptime samples: 14 days at full resolution, then deleted. Hourly rollups are kept for longer history.
  • Test submissions on your site: 7 days by default, set by you in the plugin settings.
  • Account, site and form configuration: for as long as your account is open.
  • Security events: retained for incident investigation.

Deleting your account removes your sites, forms, results and configuration.

10. Your rights

You may request access to, correction of, export of, or deletion of your personal data, and you may object to or restrict certain processing. If you are in the United Kingdom or the European Economic Area you also have the right to complain to your local supervisory authority. We answer requests within 30 days.

11. Changes and contact

Material changes to this policy will be dated here. For any privacy question or to make a request, reach us through the contact page.