Privacy Notice

Last updated August 19, 2026

This notice is for SnipForm, operated by Silver Apple Studios LTD (doing business as SnipForm), a company registered in England at 22 Wenlock Road, London N1 7TA, United Kingdom. It covers snipform.io, app.snipform.io, and the SnipForm services. Privacy questions and requests: [email protected].

We built SnipForm cookieless and privacy-first, and this notice is written to match how the product actually works. The technical detail lives on our compliance page; this document is the formal version.

1. Two roles: whose data, whose responsibility

If you visited a website that uses SnipForm (for analytics, forms, or landing pages), the owner of that website is the data controller of anything collected there - POPIA calls them the responsible party. We process that data only on their instructions, as their processor (POPIA: operator). For questions or requests about data a website collected about you, contact that website's owner; if you contact us instead, we will point your request to them and assist them in honouring it.

If you hold a SnipForm account or visit our own sites, we are the controller of your data, and the rest of this notice describes that processing.

2. What we collect as a controller

  • Account data: name, email address, password (stored hashed), team membership, and the settings you configure.
  • Billing data: handled by Stripe. Card numbers never touch our servers; we hold subscription state and invoice records.
  • Security and usage logs: sign-ins and dashboard activity on your account, kept to protect it.
  • Communications: messages you send us, and the transactional email we send you.
  • Our own site analytics: snipform.io runs our own Signals tracker in its default cookieless configuration - nothing is stored on your device, no IP address is stored, and visits cannot be linked across days or sites. Section 3 explains the mechanism.

3. How Signals tracking works

Signals uses no cookies, no localStorage, and stores nothing on the visitor's device. Sessions are derived server-side by hashing request characteristics with a secret salt that is unique to each website and rotates every 24 hours; the raw inputs, including the IP address, are discarded immediately. No IP address is stored on any analytics record, and form spam checks keep only a one-way hash of the IP, never the IP itself. Linking a visitor across days, or across websites, is cryptographically impossible.

Personal data enters the platform only where a visitor submits a form or a website identifies a visitor deliberately (for example after a login on their own site). That data belongs to the website owner, who controls it and can delete it at every level - individual submission, contact, form, property, or entire account.

4. Legal bases (GDPR / UK GDPR)

  • Contract: operating your account and providing the services you signed up for.
  • Legitimate interests: securing the platform, preventing abuse and spam, measuring our own site with cookieless analytics, and improving the product.
  • Legal obligation: retaining billing and tax records.
  • Consent: anything optional we ask you for explicitly; you can withdraw it at any time.

5. Who we share data with

We do not sell personal data and we do not share it for advertising. Data is shared only with the sub-processors that run the platform:

Provider Role Location Data involved
Google Cloud Platform Hosting & storage EU (europe-west1, Belgium) All application data
Elastic Cloud Analytics storage EU (GCP europe-west1) Session & event data
Cloudflare Network, CDN & geolocation Global edge Request routing; supplies geo lookups at the edge
Stripe Payments EU / US Billing details (card data never touches SnipForm)
Zoho ZeptoMail Transactional email EU Notification emails
Sentry Error monitoring EU (Germany) Diagnostic data
Anthropic AI report insights (paid tiers) US Aggregate metrics only - never visitor-level data
Slack, Zapier & customer webhooks Optional automations As configured Only the data account holders choose to route there

Account holders can also connect their own integrations (Slack, Zapier, webhooks, ad platforms, Shopify); what flows there is chosen and controlled by them. We may disclose data where the law requires it.

6. Where data lives, and international transfers

All primary infrastructure runs in the European Union (Google Cloud europe-west1, Belgium), with analytics storage, error monitoring, and email also in EU regions. SnipForm's operating company is UK-registered; the UK and EU recognise each other's data protection regimes as adequate. Where a sub-processor processes data in the United States (Stripe, Anthropic), transfers rely on recognised safeguards such as the EU-US Data Privacy Framework and standard contractual clauses. For South African data subjects, processing in the EU takes place under a legal regime that upholds protections substantially similar to POPIA's conditions for lawful processing (section 72).

7. Retention and deletion

Data is retained for the life of the account it belongs to and is removed by deletion: deleting a submission, contact, form, or property deletes its data, and deleting an account cascades through everything it owns, with a pre-delete audit shown before confirmation. Deleting a contact destroys every identifying field and scrubs related event records. Billing records are kept as long as tax law requires. Residual copies in encrypted backups age out with the backup cycle.

8. Security

All traffic is encrypted in transit (HTTPS with HSTS). Storage is encrypted at rest by our cloud providers. API access is scoped per token, passwords are hashed, and payment card data is handled entirely by Stripe. No system is perfectly secure, but we treat minimising what we store - no cookies, no raw IPs - as the first layer of security.

9. Your rights

Depending on where you live, you have rights to access, correct, delete, restrict, or receive a copy of your personal data, to object to certain processing, and to withdraw consent. Account holders can exercise most of these directly in the dashboard (including full account deletion and a data request page); anyone can email [email protected]. We respond within the timelines your law sets (one month under GDPR/UK GDPR and POPIA; 45 days under the CCPA). You also have the right to complain to your supervisory authority - the ICO in the UK, or your local data protection authority in the EU/EEA.

South Africa (POPIA)

For data we control, South African data subjects have the POPIA rights of access, correction, and deletion, and may object to processing or lodge a complaint with the Information Regulator (inforegulator.org.za). For data collected by a website that uses SnipForm, that website's owner is the responsible party and we act as their operator: we process only with their authorisation, treat the data as confidential, and notify them promptly if unauthorised access is suspected. Direct marketing rules (POPIA section 69) apply to the responsible party doing the marketing.

California and other US states

We do not sell personal information and do not share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months. California residents may request access, deletion, or correction as described above, and will not be discriminated against for exercising their rights. For our customers, we operate as a service provider under the CCPA/CPRA and the comprehensive privacy laws of other US states.

10. Cookies

Our marketing site uses no cookies - its analytics run on our own cookieless tracker. The app (app.snipform.io) sets only strictly necessary first-party cookies to keep you signed in and protect against request forgery; there are no third-party advertising or analytics cookies anywhere. That is why there is no cookie banner: there is nothing to consent to.

11. Browser privacy signals

We do not currently respond to Do-Not-Track or Global Privacy Control signals. Because we do not sell or share personal data for advertising, there is no sale or sharing for such signals to opt you out of; our default tracking is already the most private configuration we can offer.

12. Children

SnipForm is a business tool and is not directed at children under 16. We do not knowingly collect their data; if you believe a child has provided us personal data, contact us and we will delete it.

13. Changes to this notice

When this notice changes, the date at the top changes with it, and material changes are announced to account holders by email or in the dashboard.

14. Contact

Silver Apple Studios LTD (t/a SnipForm), 22 Wenlock Road, London N1 7TA, United Kingdom ยท [email protected]. For data processing agreements or security questionnaires, get in touch.