Privacy overview
How PasaForm handles form data
This page explains the product behavior in plain language. It is not a substitute for the privacy notice configured by the workspace that owns a form.
For form submitters
What may be collected
The exact data depends on the form fields and workspace settings.
Form answers
Text, email, numbers, dates, selected options, checkbox answers, and calculated formula values.
Uploaded files
Files submitted through file fields, including original filename, type, size, and stored file reference.
Consent record
When privacy consent is enabled, PasaForm stores that consent was accepted, when it was accepted, and the checkbox label shown at the time.
Technical metadata
Submission time, IP address, user agent, and country, state, or city values when provided by request headers.
Location and IP data
PasaForm does not ask for browser GPS permission.
IP address is used for rate limiting, security review, and submission context. Country, state, and city are stored only when the deployment infrastructure provides those values in request headers. These values are approximate and may be missing, especially for VPNs, mobile networks, corporate networks, and privacy tools.
Who can access submissions
Users added to the workspace can access forms and submissions according to their workspace role.
Owners control workspace users, forms, submissions, branding, and workspace deletion.
Public visitors can submit published forms. They cannot browse workspace submissions or uploaded files.
Workspace owner responsibilities
PasaForm provides the tools, but the workspace must configure the right notice.
Privacy controls built into PasaForm
Required consent
Public forms can require submitters to accept the configured privacy notice before submission.
Workspace isolation
Forms, users, submissions, and files belong to a workspace boundary.
Role-based access
Roles control who can manage users, edit forms, delete forms, and view submissions.
No public raw paths
Uploaded files are served through authenticated routes instead of exposing raw storage paths.