<!-- Public document guidance. No visitor answers or order data. -->
Canonical: https://formzdocs.com/privacy
Markdown: https://formzdocs.com/privacy.md

<a id="customer-main"></a>

[Home](/index.md) Privacy Policy

Formz policies & support

# Privacy Policy

How your browser drafts, orders, payment information and optional analytics are handled, and how to make a privacy request.

Effective  October 5, 2026

## On this page

- [Who handles your information](#who-handles-your-information)
- [Browser drafts, previews and free tools](#browser-drafts-and-free-tools)
- [Orders and private download links](#orders-and-private-links)
- [Payments, receipts and support](#payments-receipts-and-support)
- [Providers and sharing](#providers-and-sharing)
- [Cookies and preferences](#cookies-and-preferences)
- [Why we use information](#why-we-use-information)
- [Retention and deletion](#retention)
- [Your controls and privacy requests](#your-privacy-requests)
- [Security and policy updates](#security-and-policy-updates)

[Read the help center](/help.md)

Unsaved entries stay in your browser tab. Continuing to checkout sends the information needed to prepare your order to our service. Card details go to Stripe. Optional analytics depends on a fresh versioned choice.

<a id="who-handles-your-information"></a>

## Who handles your information

Formz is a document-generation service offered by DevCreate Studio LLC. Our public business name is Formz Docs.

This policy covers Formz’s website and document service. We decide how the information needed to run Formz is used. Contact [hello@formzdocs.com](mailto:hello@formzdocs.com) for a privacy question or request; our support mailing address is on the [Contact page](/contact.md). Providers also explain their own processing in the policies linked below.

<a id="browser-drafts-and-free-tools"></a>

## Browser drafts, previews and free tools

Form entries and previews are held in your browser tab while you work. Closing or reloading the tab clears unsaved entries. Saving a draft is optional and stores its answers in this browser’s local storage on this device. A saved draft stays until you clear it or remove the browser’s site data; anyone with access to that browser may be able to restore it.

The seven free tools process their inputs and files in browser memory. They do not send those values or PDF files to the order service, save them as customer drafts, or place them in page URLs. Downloaded PDFs and CSV files remain wherever you save them.

<a id="orders-and-private-links"></a>

## Orders and private download links

When you continue to checkout, the order service receives the form answers and payroll information needed to validate the order and generate its PDF. These may include names, addresses, taxpayer identifiers, employer details, pay periods, amounts and elections, depending on the chosen document. It stores an order snapshot, generated PDF, quote and payment/recovery records. We use these to provide the document, restore authorized access and resolve order or billing problems.

Your order ID and private access token are kept in session storage for this browser tab. Answers are restored from the authenticated service, not embedded in public pages or analytics. A receipt link carries the access token in its URL fragment; the app consumes and removes that fragment when it restores access. Treat the original link as confidential and do not share it with someone who should not see the order.

Only enter information that you have authority to use. Tax and payroll records can be sensitive. Formz does not independently check whose records they are, whether an identifier was issued, or whether income is authentic.

<a id="payments-receipts-and-support"></a>

## Payments, receipts and support

Stripe receives the card and billing information you enter on its hosted payment page. Formz does not collect card numbers in the editor or store a full card number. Stripe provides payment/session references, status and the checkout contact details needed to reconcile the order and send its receipt.

After confirmed live payment, Resend sends a receipt and private recovery link to the checkout email. The filled PDF and form answers are not attached to the receipt. We retain the delivery-processing records needed for retries and support. These messages are order communications, not a Formz account or marketing subscription.

If you contact support, we receive your email, order reference and whatever details you choose to send. Keep taxpayer numbers, completed documents, card details and access links out of ordinary email. We use the message to answer the request and investigate the relevant order.

<a id="providers-and-sharing"></a>

## Providers and sharing

We use service providers for hosting, private document storage, payment processing, receipt delivery and optional analytics. We share information needed for those functions, rather than publishing your filled document. Their processing may also be subject to their own legal obligations and privacy terms.

- [Cloudflare](https://www.cloudflare.com/privacypolicy/) hosts the website and order service and stores order records and PDFs in private infrastructure. Network providers can process technical request information such as IP addresses and browser/request details.
- [Stripe](https://stripe.com/privacy) processes payments and provides order payment status and checkout contact information.
- [Resend](https://resend.com/legal/privacy-policy) delivers transactional receipts and recovery links.
- [Google](https://policies.google.com/privacy) provides optional analytics for public pages after you allow it.

<a id="cookies-and-preferences"></a>

## Cookies and preferences

The site uses browser storage for the theme you choose, an optional saved draft, the current tab’s order access and your analytics preference. Theme and analytics choices stay until changed or site data is removed; saved drafts remain until cleared, and session order access belongs to the current tab. The analytics preference records only your choice and its policy version, with no identifier or timestamp in that preference. These support the requested features; refusing optional analytics does not prevent document preparation or purchase.

Google Analytics and first-party journey measurement are optional. They are not initialized until you allow the current analytics scope. An older public-page-only preference does not authorize the expanded scope. You can decline it or withdraw your choice using “Cookie settings” in the footer. Withdrawal stops future optional Formz analytics collection in this browser and requests first-party revocation as described below; it does not retract information already sent to Google. Browser controls can also remove cookies and site storage, but clearing site data may remove drafts, theme choices, preferences or saved order access.

With permission, Google may set _ga and _ga_HJJ03RBCPW cookies to distinguish browsers and maintain session information. Google describes a default expiry of two years; actual lifetime can differ with provider settings, browser limits, repeat visits or removal. See [Google’s cookie explanation](https://support.google.com/analytics/answer/11397207).

Google Analytics runs on public pages only after you accept analytics cookies. You can reject analytics or change your choice through Cookie settings in the footer. Accepted page-view events use canonical public URLs and titles with standard browser/device details. Query strings, fragments, private workspace pages, form answers, tool inputs/files and order access details are excluded from those events. Referrers are limited to a known public Formz page or another site’s origin. Google signals and advertising personalization are disabled. Version 1 preferences require a fresh choice. If you accept the version 2 preference, optional first-party measurement connects registered public entry pages/campaigns, form selection, first user edit, validated review and valid tool results to checkout, confirmed payment and the first authorized PDF response. A separate random journey capability stays in tab session storage and expires after 24 hours. No answers, field names, files, arbitrary campaign text, full referrers or order access tokens enter these events. Withdrawal clears local journey state immediately and asks the server to revoke its optional milestones and attribution; when offline, only the measurement token and retry-expiry timestamp remain for retry, bounded to the 24-hour journey lifetime plus seven days, so server erasure is confirmed only after acknowledgment. Optional journey records, including private-order attribution and outbox journey references, expire after 30 days; aggregate funnel buckets remain for 12 months. Minimal confirmed sales counts, document quantity and quote totals remain separately for order/accounting operations, including when analytics is rejected. They do not contain the withdrawn journey/campaign association. These first-party reports cover opted-in journeys and newly observed sales, not all visitors or complete purchase history.

We do not use session replay, visitor-entered values or completed documents in analytics.

<a id="why-we-use-information"></a>

## Why we use information

We use the order information you provide to perform the requested preparation, purchase and delivery, handle support and refunds, protect the service and reconcile payments. Where a legal basis is required, the purchase/requested service is the basis for necessary order processing; legal obligations and legitimate interests can apply to payment records, security and dispute handling. Optional analytics relies on your permission.

We do not sell your tax/payroll entries or filled PDFs, use them for advertising, or use them to determine eligibility or verify income. We may disclose necessary records when required by law or to investigate abuse and protect the service. Providers may process information in countries other than where you live; their linked policies explain their processing and applicable transfer protections.

<a id="retention"></a>

## Retention and deletion

An order that is never paid is deleted automatically 14 days after it was created, together with its answers and generated PDF; this waits only while a delayed payment is still pending. A paid or refunded order, with its answers, PDF, payment references and receipt-processing record, is deleted automatically 90 days after payment. After deletion the order page and recovery link stop working, and only a marker that the order expired remains. These periods allow download recovery, support, refunds and payment reconciliation. An order created before this schedule began is scheduled the next time it is opened; stored PDFs are also removed by a storage rule after 120 days. Stripe and our email provider keep their own records under their policies. There is no self-service order-deletion button; ask us if you want an order removed sooner.

Service error logs record error types, code locations, status codes and order IDs. They do not contain form answers, files, email addresses or access links, and our hosting provider keeps them for a limited period.

Optional journey records, including private-order attribution and outbox journey references, are automatically cleaned after 30 days; anonymous aggregate funnel buckets after 12 months. A journey is eligible for optional attribution for 24 hours. Withdrawal removes its optional milestones and attribution after server acknowledgment, and the journey reference stored beside an order is removed at that order’s next daily check; a pending capability-only revocation retry can last up to that journey lifetime plus seven days. Minimal confirmed-sales counts, document quantities, quote totals and deduplication records remain separately for order/accounting operations under the retention criteria above, including when analytics is rejected. They do not retain withdrawn or expired journey attribution.

Clearing an editor or saved browser draft does not delete a server order, a downloaded file or provider records. You can ask us to review access, retention or deletion by emailing [hello@formzdocs.com](mailto:hello@formzdocs.com) with an order ID and the nature of your request. We verify the request and review what can be deleted or must be retained. We do not promise immediate deletion from every backup or provider system; applicable legal requirements and provider obligations may limit deletion.

<a id="your-privacy-requests"></a>

## Your controls and privacy requests

Use Clear in the editor for the current form and Clear saved draft for the device copy. Use Cookie settings to change optional analytics. Keep your order link private and remove downloaded files from your device when you no longer need them.

Depending on the law that applies, you may request access, correction, deletion, restriction, portability or object to certain processing. You may also withdraw analytics permission and contact the relevant privacy authority. Email [hello@formzdocs.com](mailto:hello@formzdocs.com) and tell us what you need. Include an order ID when relevant; do not send taxpayer numbers, cards or private links.

We may need proportionate verification before releasing or changing private information. We will explain any information needed and respond as required by applicable law. A privacy request is handled by support; it is not an automatic deletion or PDF-correction action. Withdrawing analytics does not cancel your order.

<a id="security-and-policy-updates"></a>

## Security and policy updates

The site uses HTTPS, private storage and order-specific access controls. These reduce exposure but cannot guarantee that every system, email account or device is secure. Keep downloaded documents, saved drafts and recovery links protected. Notify support if you think someone else has obtained access to your order.

We may update this policy as the service changes. The effective date identifies the current version; changes to optional processing should be reflected in the relevant choices. Check this page when deciding what information to provide.

## A question about your order?

Email [hello@formzdocs.com](mailto:hello@formzdocs.com) with an order ID and a short description. Leave sensitive form answers and private links out of the message.

[Terms of Service](/terms.md)[Refunds & cancellation](/refunds.md)[Privacy Policy](/privacy.md)[Contact Formz](/contact.md)
