Privacy overview

How PasaForm handles form data

This page explains the product behavior in plain language. It is not a substitute for the privacy notice configured by the workspace that owns a form.

For form submitters

Before submitting a public form, review the privacy notice shown on that form. That notice should explain the purpose of collection, how the workspace will use your information, and who to contact for privacy requests.

What may be collected

The exact data depends on the form fields and workspace settings.

Form answers

Text, email, numbers, dates, selected options, checkbox answers, and calculated formula values.

Uploaded files

Files submitted through file fields, including original filename, type, size, and stored file reference.

Consent record

When privacy consent is enabled, PasaForm stores that consent was accepted, when it was accepted, and the checkbox label shown at the time.

Technical metadata

Submission time, IP address, user agent, and country, state, or city values when provided by request headers.

Location and IP data

PasaForm does not ask for browser GPS permission.

IP address is used for rate limiting, security review, and submission context. Country, state, and city are stored only when the deployment infrastructure provides those values in request headers. These values are approximate and may be missing, especially for VPNs, mobile networks, corporate networks, and privacy tools.

Who can access submissions

Workspace members

Users added to the workspace can access forms and submissions according to their workspace role.

Workspace owners

Owners control workspace users, forms, submissions, branding, and workspace deletion.

Public visitors

Public visitors can submit published forms. They cannot browse workspace submissions or uploaded files.

Workspace owner responsibilities

PasaForm provides the tools, but the workspace must configure the right notice.

Keep form fields limited to what is needed for the stated purpose.
Review the Privacy tab before publishing each form.
Name the workspace contact or process for privacy requests when appropriate.
Limit workspace membership to people who need access.
Export and share submissions only through approved operational channels.
Delete forms or workspaces deliberately because deletion is intended to be permanent.

Privacy controls built into PasaForm

Required consent

Public forms can require submitters to accept the configured privacy notice before submission.

Workspace isolation

Forms, users, submissions, and files belong to a workspace boundary.

Role-based access

Roles control who can manage users, edit forms, delete forms, and view submissions.

No public raw paths

Uploaded files are served through authenticated routes instead of exposing raw storage paths.

Need help with a specific form?

Contact the workspace or organization that published the form. For PasaForm product support, email hello@pasaform.app. You can also read the FAQs.