Information We Collect
We collect account and workspace information such as name, business name, email address, phone number, website domains, industry, timezone, login credentials, and settings. When a visitor uses an embedded Preapproved 1-2-3 form, we collect the submitted name, email address, phone number, page source, and configured context such as vehicle, property, stock, VIN, or page-type details. We also collect operational data including IP address, browser metadata, event identifiers, analytics events, delivery attempts, audit logs, and error logs. If paid billing is enabled through Stripe, Stripe may collect billing, payment, tax, fraud-prevention, and customer information needed to process payments.
How We Use Information
We use information to provide the service, create and secure accounts, authorize embedded forms on approved domains, capture and store leads, deliver lead notifications, show analytics, troubleshoot delivery issues, prevent abuse, maintain audit records, communicate about the service, and support billing or account administration when applicable.
Parties We Disclose Information To
We disclose information to the business account that configured the form, authorized account viewers, platform administrators, service providers that help operate hosting, logging, email or CRM delivery, security, analytics, and payment processing, including Stripe when Stripe billing is active. We may also disclose information when required by law, to enforce our rights, to protect users or the service, or as part of a business transfer such as a merger, acquisition, or asset sale.
Method Of Disclosure
Information may be disclosed through the customer dashboard, admin tools, secure application databases, encrypted HTTPS requests, email or CRM delivery payloads configured by the account, server logs, support communications, and payment-processing interfaces. We do not sell personal information.
Security Practices
We use safeguards designed to protect information, including password hashing, CSRF protection, session controls, tenant-scoped queries, authorized-domain checks for embedded forms, opaque expiring form-session tokens, prepared database statements, restricted storage paths, audit logging, and HTTPS-ready deployment helpers. No system can be guaranteed perfectly secure, so users should protect their credentials and promptly report suspected unauthorized access.
Retention And Choices
We retain account, lead, analytics, delivery, and audit information for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, and maintain security. Account owners may request help accessing, correcting, or deleting information, subject to operational, legal, and security requirements.
Contact
Questions about this Privacy Policy can be directed through the Contact page.