Privacy
Last updated: October 6, 2026
GRTforms (“the App”, “the Product”) is a hosted online forms product from GrtLabs Inc (“we”). You create a GRTforms account, build forms, publish public form URLs, and collect submissions. This policy describes what we collect, what we store, how we use it, and what we do not do. It follows the same section layout as the Runway privacy page on grtlabs.com, rewritten for GRTforms. It is not a review by a lawyer.
Information the App can access
When you sign up for GRTforms, you create a GRTforms account (email and credentials). That is different from apps that only use a third-party store OAuth install.
Depending on how you use the product, we handle:
- Account data. Email address and credentials (or credential hashes) used to sign up, log in, and manage your dashboard.
- Form definitions. The forms you create: field labels, types, layout (including column and width settings), validation rules you set, custom CSS you add, and publish/share settings (public slug, share/embed snippets).
- Submissions. Answers that respondents enter on your public forms at
/f/[slug]. Those answers can include whatever fields you configured (for example name, email, phone, or free text). We store submissions so you can view, edit, delete, filter by date, paginate, and export them to Excel (.xlsx) in the dashboard.
We do not claim to send notification emails, confirmation emails, or marketing messages from GRTforms today. Email delivery (including Mailgun) is not turned on as a live feature.
Information we store ourselves
Unlike apps that keep state only in process memory, GRTforms uses Postgres for persistence, hosted with the App on Railway.
We store:
- Account records needed for signup and login
- Form definitions and share/publish metadata
- Submissions entered by form respondents
Public forms collect whatever fields the form owner configures. For respondent data collected through a form you publish:
- You (the form owner) are the data controller for that respondent data.
- GrtLabs Inc is the processor / host that stores and displays that data so you can manage submissions in the product.
We do not place our own advertising cookies, pixels, or tags on third-party sites where you embed a form. The App and public forms run on forms.grtlabs.com. Session cookies or similar may be used for your logged-in dashboard. Railway and related infrastructure may process requests as part of hosting.
How we use it
We use this information to:
- Provide signup, login, and the dashboard
- Let you build, layout, theme (via custom CSS), publish, and share forms
- Accept and store submissions on public forms
- Show submission totals, pagination, date filters, view/edit/delete, and Excel (.xlsx) export
We do not use this information to advertise on our behalf to your form respondents, and we do not sell it.
Who else handles it
- Railway hosts the App and the Postgres database. Account, form, and submission data are stored and served through that host. Railway is a service provider for running the App, not a buyer of the data.
- If you embed a form (iframe or JS embed) on your own site, that site’s visitors load the form from forms.grtlabs.com; your site may have its own privacy practices separate from this policy.
We may also disclose information if a law, subpoena, or court order requires it, or to protect our rights. We do not sell personal information.
Your rights
If you are in the European Economic Area or the United Kingdom, you can ask us to access, correct, or delete personal information we hold about you. Email [email protected]. We process account and form data to provide the Product you signed up for. Form owners control what respondent fields they collect; we host that data as described above. The App is hosted in the United States.
If you are a California resident, you can ask what we collected, ask us to delete it, and ask us not to sell it. We do not sell personal information. Categories we hold typically include account contact details, form configuration, and submission content you or your respondents enter. The source is your GRTforms account and the public forms you publish. The purpose is operating the hosted forms product. To make a request, email [email protected] or use the GRTforms support page at https://grtlabs.com/apps/grtforms/support/. You can also call 713.714.6849.
Form owners who collect personal data from respondents should handle respondent requests according to their own obligations. We can help with account-level and hosting-related requests as described on the support page.
How long we keep it
We keep account data, form definitions, and submissions in Postgres while your account and forms remain active, so the dashboard and exports continue to work. If you delete a submission in the product, that submission is removed from the live store as the product implements delete. If you want an account closed or broader deletion, email [email protected] and we will work through what we can remove from our systems.
We do not claim a separate long-term archive beyond what the hosted Postgres database holds for the live product.
Changes
We may update this policy when the Product’s practices change. The date at the top is the latest version. The current page is https://grtlabs.com/apps/grtforms/privacy/.
Contact
GrtLabs Inc
Email: [email protected]
Phone: 713.714.6849
United States: 10101 Southwest Fwy #431, Houston, TX 77074
Canada: 163 Binder Twine Trail, Brampton, ON L6X 4V6
