Privacy Policy

Draft — not yet reviewed. This document was prepared as a starting point and has not been reviewed by a lawyer. Do not rely on it, and do not publish it, until it has been.

Last updated: 31 August 2026

Our role

When a visitor submits a form on our customer's website, that customer decides what is collected and why. We act on their instructions to deliver it. Under the UK GDPR and EU GDPR, the customer is the controller and we are a processor.

Form submissions

We process the content of a submission only to deliver it by email. We do not store submission content after delivery: there is no submissions database and no message queue. Content is never written to our logs, and never included in error reports.

Delivery necessarily involves other providers — Cloudflare, Amazon Web Services, and the customer's own mail provider — each of which processes and retains data according to its own terms.

Operational records

For each request we record a request identifier, the form used, a timestamp, the outcome, and a coarse reason code. We do not record IP addresses; abuse controls use a keyed hash that rotates daily. These records are kept briefly and are used for troubleshooting, abuse handling, and capacity planning.

This website

These marketing pages set no analytics or advertising cookies.

Your rights

If you submitted a form on someone's website and want your information accessed, corrected, or erased, contact that website's operator — they hold the delivered email and are the controller. We can help them, but we do not hold a copy to act on.

Contact

support@submit-kit.com