Privacy policy
This policy explains what the Appal Contact Form Builder app stores, why, and how to get rid of it. We keep this deliberately short, because there is not much to say.
What we store
- Your forms. The fields, wording, styling and settings you build in the app.
- Submissions. Whatever a visitor types into one of your forms, plus any file they attach, so it can appear in your inbox and your CSV export.
- Context for each submission. The page it came from and the visitor's IP address, which help you spot spam. You can switch off IP recording in the app's settings.
- Emails we build. A copy of each notification and automatic reply, so you can see exactly what was sent.
- Your shop domain and an access token issued by Shopify, so the app can run inside your admin.
What we do not do
- We do not sell or rent anything we store.
- We do not use submissions to advertise to anyone.
- We do not read your customer records; the app only sees what a visitor types into your form.
Who else touches the data
- Railway hosts the app and its database.
- Amazon Web Services (SES) delivers notification emails.
- Shopify, because the app runs inside your admin.
Each of them only receives what is needed to do that job.
How long we keep it
Submissions stay until you delete them or uninstall the app. Uninstalling triggers Shopify's shop redaction webhook, and we then delete your forms, submissions, uploaded files and stored emails. You can also delete any single submission, or a whole form, from the app at any time.
Requests from shoppers
If a shopper asks you for their data or asks to be forgotten, Shopify sends us the request and we respond automatically: we locate submissions carrying that email address and, for a deletion request, remove them along with any files attached to them.
Contact
Write to support@appal.io and a person will answer.