Effective Owner activation required · OWNER_ACTIVATION_REQUIRED

Privacy

Renvoro Forms is supplied by Demo owner placeholder under the privacy requirements of Owner counsel to supply. This notice describes how the configured service handles information.

Information handled

We process form fields submitted through configured endpoints, endpoint names and origins, account email, delivery state, support requests, billing records, evaluation requests, and minimal operational events. Source network addresses are converted to keyed hashes for abuse controls; raw addresses are not intentionally stored by the application.

Two further records belong to an account rather than to an enquiry. A delivery domain you ask Renvoro Forms to verify is stored as the domain name, whether its DNS record was found, and when a resolver last answered; the challenge value is derived on demand and is never stored. A Renvoro Account account also has an entitlement record holding the platform's account reference, the tier it granted, and when that grant was last confirmed. Renvoro Forms receives no name, delivery address, or payment detail from the platform.

Analytics

Product events use a random session-only identifier. Allowed properties are limited to plan, acquisition source, and result band. Analytics must not contain names, email addresses, form values, or full page URLs.

Purpose

Data is used to capture enquiries, provide references, show account history, enforce limits, prevent abuse, evaluate the service, and respond to support and privacy requests. When outbound email is enabled, the same data is used to attempt delivery and retry failures.

Protection and retention

Submission contents and account destinations are encrypted with AES-GCM before storage. Receipt tokens are stored as keyed hashes plus encrypted copies used to return the same receipt after a safe retry; source identities are stored as keyed hashes. Configured paid retention is 30, 90, or 365 days by plan. Homepage demo records stop being available after 24 hours. Analytics, support, provider, and backup retention follow the owner-configured operating and legal policies. Account deletion keeps a keyed-hash tombstone to block data resurrection. Its encrypted account-email copy exists only while deletion is pending and is blanked when finalization completes.

Product limits

Do not submit payment-card, health, government identifier, password, or other regulated or highly sensitive data. File uploads and arbitrary webhooks are disabled.

Processors and disclosure

The service uses the hosting, database, billing, and transactional-email processors selected by its operator. Processor names, data locations, and cross-border terms must match the owner-approved provider schedule. Application data is not sold.

Your controls

Signed-in account owners can export or delete account data from the workspace. If an authorized provider or billing operation is active, deletion remains pending and new account writes stay blocked until safe finalization. An unknown provider outcome requires reconciliation rather than unsafe timed erasure. Form senders should contact the agency that collected their enquiry. Privacy requests can be sent to privacy@demo.invalid; security or breach reports can be sent to security@demo.invalid.

Return to Renvoro Forms