Formwell privacy policy
Formwell stores what shoppers type into the forms a merchant builds with it — which can include names, email addresses and messages, depending on the fields the merchant chose — and emails each submission to the address the merchant set. Everything lives in the app's own database.
Effective · Questions: hello@sproutcart.co
Who is responsible
Formwell is a Shopify app built and operated by SproutCart, an independent Shopify developer. A merchant installs it on their store; the merchant's own privacy policy also applies to their customers. For anything on this page, write to hello@sproutcart.co.
Formwell is in development and is not yet offered for install on the Shopify App Store. This page describes what the app's code does today.
What the app stores
- Every value a shopper enters into a form. What that includes depends on the fields the merchant adds; the default form asks for a name, an email address and a message. From: Shoppers who submit a form on the storefront. Why: So the merchant can read and answer the submission.
- The email address from the form's first email field, stored separately. From: The same submission. Why: So a customer redaction request can find the submission.
- The Shopify customer ID of the shopper — only when they were logged in to a customer account. From: Shopify's signed app proxy request. Why: So a customer redaction request can find the submission.
- The notification email address the merchant sets for each form. From: The merchant, in the app's admin. Why: To send each new submission there.
- The store's domain, its offline access token, its name, its forms and its settings (admin language and two preferences). From: Shopify, at install, and the merchant in the app's admin. Why: To run the app for that store.
What it does not store
- No IP addresses and no browser details.
- No file uploads — forms cannot accept files.
- No order or payment data.
- Nothing the app stores is sent to an AI service.
Where it is stored
In the app's own database, on the server that runs the app. The production hosting provider has not been chosen yet, because the app is not yet offered for install; it will be named here before it is.
Services that see the data
- Shopify — The platform the app runs on, and the proxy every form request passes through. What it sees: Everything listed above.
- Inngest — Runs the app's background jobs, such as sending the notification email. What it sees: The submission's ID and the store's domain, not its contents. Inngest keeps its own event history under its own retention, outside the app's database.
- An email delivery service (SMTP) — Sends each submission to the form's notification address, one welcome email to the merchant at install, and the reply to a customer data request, sent to the store's own email address. What it sees: Every value in the submission; the store's contact email address and name; for a data request, everything listed above that is stored for that customer.
The app does not sell, rent or trade any of this data, and does not use it for advertising. It is not shared with anyone beyond the services above.
When it is deleted
- The merchant uninstalls the app: Every form, every submission, the access token, the store's name and its billing record are deleted immediately.
- Shopify sends shop/redact, 48 hours after uninstall: The same deletion runs again, so nothing that arrived in between survives. The store's settings row (the admin language and two preferences) goes with it.
- Shopify sends customers/redact for a customer: Every submission whose stored email address matches the customer's, or that was made while logged in as that customer, is deleted. A guest who typed a different email address is not found by this match.
- Otherwise: Nothing expires on a timer. There is no delete button in the admin yet; to remove a single submission sooner, write to us.
Customer data requests
When Shopify sends a customers/data_request, the app collects every submission matched to the customer (by email address or logged-in customer ID), with its answers, and emails it to the store's own email address in Shopify, for the merchant to pass on to the customer. If it cannot reach the store (the app was uninstalled), it sends nothing.
Changes to this policy
When what the app stores or who sees it changes, this page changes with it and the effective date above moves.
Contact
hello@sproutcart.co. For help using the app, see the Formwell support page.