Privacy Policy
Last updated: February 2026
FormFlo (“FormFlo”, “we”, “us”, “our”) is operated by Rishmathi Tech Ventures Pvt Ltd, with its registered office in Hyderabad, Telangana, India. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over it. By using FormFlo you agree to this policy.
1. Information we collect
- Account data — your name, work email, organization name, hashed password and role.
- Usage data — form metadata you build, records you submit, workflow approvals, audit logs, IP addresses and timestamps.
- Billing data — order details and payment status. Card / UPI / bank details are processed only by Zoho Payments; FormFlo never sees or stores them.
- Cookies — strictly an httpOnly session cookie issued at login. No third-party tracking or advertising cookies.
2. How we use your information
- To provide and operate the FormFlo service for your organization.
- To authenticate users, enforce RBAC and prevent abuse / brute-force attempts.
- To send transactional emails (invitations, password resets, approval notifications, billing receipts).
- To improve product reliability and add features. We do not sell your data — ever.
3. Data you must not store
FormFlo is a general-purpose low-code platform. You must not store sensitive information inside form fields or records, including but not limited to:
- Passwords, PINs, OTPs, security questions or any authentication secret;
- Full credit / debit card numbers, CVV, expiry, UPI PIN or net-banking credentials;
- Aadhaar, PAN, passport or any government ID numbers (unless explicitly required by a regulated workflow that you have separately compliance-certified);
- Medical records, biometric identifiers, or any data restricted by Indian DPDP Act / GDPR “special categories”.
If we detect such data we may quarantine the relevant records and notify you. Repeated violations may result in suspension under our Terms.
4. How we share data
We share only what is strictly required to run the service:
- MongoDB Atlas — encrypted at rest, used to store your tenant data.
- Zoho Payments — payment processing (PCI-DSS compliant).
- Zoho ZeptoMail — transactional email delivery (only for messages you trigger).
- Hosting infrastructure — cloud-based, with TLS for all traffic.
We do not transfer your data to any party for advertising or analytics.
5. Multi-tenancy & isolation
Every record, file and configuration is scoped to a single organization (tenant) via a strict org_id filter. Users from one tenant can never read or write data of another tenant.
6. Retention
We retain customer data for as long as your organization remains an active subscriber. On cancellation we retain data for 30 days (to allow re-activation) and then permanently delete it on request. Audit logs may be kept for up to 12 months to fulfil security / compliance obligations.
7. Your rights
Subject to the Digital Personal Data Protection Act, 2023 (India), you may request access, correction, deletion or export of your personal data. Org Admins can fulfil most of these requests directly through the FormFlo UI; for anything else, contact us at contact@rishmathi.com.
8. Security
- Passwords hashed with bcrypt; JWTs signed with HMAC-SHA256.
- API keys (ZeptoMail, Zoho Payments) are encrypted with a server-side secret before storage.
- TLS 1.2+ enforced for all client–server traffic.
- Login attempts are rate-limited per email and IP.
No system is 100% secure — please report vulnerabilities to contact@rishmathi.com responsibly.
9. Changes to this policy
We may update this policy from time to time. We will notify Org Admins by email on any material change. Continued use of FormFlo after the change constitutes acceptance.
10. Contact
Rishmathi Tech Ventures Pvt Ltd · Hyderabad, Telangana, India · contact@rishmathi.com