Form Builder's Privacy Policy
We are committed to protecting your privacy
Privacy Policy
Your privacy is important to us. Learn how we collect, use, and protect your information.
Last updated: 16 June 2026
This Privacy Policy ("Policy") explains the information collection, use, and sharing practices of Shop Circle Holdings Ltd, One Kingdom Street, Paddington Central, London W2 6BD, United Kingdom ("we," "us," and "our") in connection with the Form Builder application ("Form Builder," the "App," or the "Services").
Shop Circle Holdings Ltd reserves the right to update this Privacy Policy from time to time. Your continued use of our Services after any such changes constitutes your acceptance of the revised Policy.
Form Builder has been designed to be used by merchants ("Store Owners") on the Shopify platform. Form Builder lets Store Owners build custom forms, collect submissions and file uploads, and route the resulting data to email, marketing, payment, automation, analytics, and support services. Unless otherwise stated, references to collecting, using, or disclosing personal information in this Policy describe actions taken by the Store Owner (as the data controller), carried out through the functionality of our application.
Before you use or submit any information through or in connection with the Services, please carefully review this Privacy Policy. By using any part of the Services, you understand that your information will be collected, used, and disclosed as outlined in this Privacy Policy.
Information We Collect
We collect information in multiple ways, including when you provide information directly to us, and when third parties or automated systems provide information to us.
Information You Provide Directly
Some areas of the Services may require you to submit information in order for you to benefit from the specified features (such as completing a form, uploading files, providing an e-signature, or making a payment) or to participate in a particular activity. You will be informed what information is required and what information is optional.
Information from Third-Party Sources
We may also obtain information from other sources, such as the Shopify platform, and combine that with information we collect about you. This includes shop, customer, content, theme, script-tag, and metafield data, as well as form-created customer records that merchants share with us through installing and using our application.
Information Automatically Collected
We automatically collect certain information when you visit the Services. This information includes your IP address, browser type, device type, operating system, referring URLs, and information about the usage of our Services, including information collected through cookies, pixel tags, and other tracking technologies.
We use Google Analytics for web analytics, and merchants may enable additional analytics and advertising integrations (such as Google Ads, Meta (Facebook) Pixel, and Microsoft Advertising) that collect and process data about the use of the Services and forms.
The specific categories of personal data we process through Form Builder include: contact information (name, email address, phone number); form submission data (any field values a respondent enters, including addresses, organization, and custom fields); uploaded content (files, images, and e-signatures submitted through forms); payment data (payment amount and tokenized card or PayPal payment details, plus optional customer name and email); marketing preferences (newsletter and email/SMS opt-ins, marketing-consent status); device and usage information (IP address, browser type, device info, session behaviour); location data (country, city, country code); app usage and form analytics (form views, interactions, submission and conversion events); cookie data (session ID, CSRF token, Shopify OAuth); and support request details. The specific categories collected depend on which Form Builder features and integrations the Store Owner enables.
Aggregate/De-Identified Information
We may aggregate and/or de-identify any information collected through the Services so that such information can no longer be linked to you or your device. We may use such information for any purpose, including without limitation for research and marketing purposes, and may also share such data with any third parties.
How We Use Your Information
We use the information we collect for the following purposes:
-
To provide, maintain, and improve the Services;
-
To communicate with you, including to respond to your comments, questions, and requests;
-
To monitor and analyse trends, usage, and activities in connection with our Services;
-
To detect, investigate, and prevent fraudulent transactions and other illegal activities;
-
To personalise and improve the Services and provide content or features that match your profile and interests;
-
For any other purpose for which the information was collected.
How We Share Your Information
We may share your information in the following situations:
-
With third-party vendors, consultants, and other service providers (our "subprocessors") who need access to such information to carry out work on our behalf;
-
In response to a request for information if we believe disclosure is in accordance with, or required by, any applicable law, regulation, or legal process;
-
If we believe your actions are inconsistent with our user agreements or policies, or to protect the rights, property, and safety of us or others;
-
In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company;
-
With your consent or at your direction.
Many of the integrations offered through Form Builder share data with third-party services only when a merchant explicitly enables and configures that integration. The categories of data shared, and whether any data is shared at all, therefore depend on the features each merchant turns on. See "Subprocessors" below for the list of third-party service providers we use.
Subprocessors
The following third-party service providers ("subprocessors") may process personal data in connection with Form Builder. Most marketing, automation, analytics, and payment subprocessors only receive data when a merchant explicitly enables and configures the relevant integration.
Providers that may process personal data
|
Provider |
Category |
Purpose / Data processed |
|
Shopify |
Core platform |
Hosts the app and stores merchant/store data. Reads and writes shop, customer, content, theme, script-tag, and metafield data; receives form-created customer records (name, email, phone, tags, metafields) and processes app lifecycle and GDPR webhooks. |
|
Amazon Web Services (AWS S3) |
File storage |
Stores files and images uploaded through forms, e-signatures, and generated submission/export archives (ZIP/CSV). May contain any personal data a respondent uploads or submits. |
|
Cloudinary |
Media/CDN |
Hosts and delivers form-related images and media assets used in form designs and templates. |
|
Stripe |
Payments |
Processes card payments collected through forms. Receives payment amount, card token, and optional customer details (name, email) to create charges and customer records. |
|
Braintree / PayPal |
Payments |
Alternative payment gateway for card and PayPal payments on forms. Receives payment nonce, amount, and customer details for transaction processing. |
|
Mailchimp |
Email marketing |
Syncs form respondents to merchant Mailchimp audiences. Receives email address, name, custom merge fields, tags, and marketing-consent status. |
|
Klaviyo |
Email & SMS marketing |
Creates/updates respondent profiles and subscribes them to merchant lists. Receives email, name, phone number, organization, and email/SMS consent. |
|
SparkPost |
Transactional email |
Delivers transactional emails (auto-responder confirmations, admin notifications). Processes recipient email addresses and message content. |
|
Ortto |
Customer data platform |
Receives merchant-level lifecycle/usage events (install, uninstall, plan change) and shop attributes for product analytics and marketing automation. |
|
Google Sheets / Google Drive |
Data export |
Exports form submissions to a merchant-connected Google Sheet. May contain any personal data captured in form responses. |
|
Zapier |
Automation |
Forwards form submission payloads to merchant-configured Zapier webhooks for downstream automation. May contain any personal data in the submission. |
|
Slack |
Notifications |
Sends form submission notifications to merchant Slack channels via webhook. May include respondent names, emails, and submitted field values. |
|
ZeroBounce |
Email validation |
Validates respondent email addresses for deliverability before a submission is accepted. Receives the submitted email address. |
|
Google reCAPTCHA |
Bot/spam protection |
Protects public forms from automated abuse. Google receives respondent device/usage signals and IP address for risk scoring. |
|
Google Fonts |
Typography |
Serves web fonts used in form rendering. Google may receive the respondent's IP address when fonts load. |
|
Google Analytics |
Analytics |
Tracks form views, interactions, and submission events when enabled by the merchant. Processes event name, category, action, label, form title, and page/referrer URL. |
|
Google Ads |
Advertising & conversion tracking |
Tracks form conversion events when enabled by the merchant. Processes conversion ID/label, event category/action/label, form title, and page/referrer URL. |
|
Meta (Facebook) Pixel |
Analytics & advertising |
Tracks form lead/conversion events when enabled by the merchant. Processes event type, form title/category, and event metadata. |
|
Microsoft Advertising (Bing Ads UET) |
Analytics & advertising |
Tracks form conversion events and advertising performance when enabled. Processes event/conversion metadata if configured. |
|
Freshdesk |
Support |
Creates support tickets from within the app. Receives merchant-submitted support request details. |
|
FreshChat |
Support chat |
In-app live chat widget; receives merchant user identifiers, email, and plan information. |
|
Tapfiliate |
Affiliate tracking |
Tracks affiliate referrals and commissions for app installs (merchant-level, not respondent data). |
Infrastructure & operational providers
These providers support the service and may incidentally store personal data, but are not respondent-facing integrations.
|
Provider |
Category |
Purpose |
|
Amazon Web Services (AWS) |
Hosting & infrastructure |
Hosts application servers, databases, file storage, backups, and supporting infrastructure services. |
|
Cloudflare |
CDN, security & performance |
Provides content delivery, caching, traffic routing, security, and DDoS protection services. |
|
New Relic |
Application monitoring |
Provides application performance monitoring, observability, and operational diagnostics. |
|
PostgreSQL |
Database |
Primary datastore for all app and form submission data. |
|
Redis |
Cache / queue backend |
Caching, rate limiting, and Sidekiq job queue storage. |
|
Sidekiq |
Background processing |
Runs asynchronous jobs for integrations, emails, and exports. |
|
Rollbar |
Error monitoring |
Captures application errors and exceptions for debugging (may incidentally include request data). |
|
App Manager (HulkApps) |
Billing / plan management |
Manages subscription plans, billing, and feature entitlements (merchant-level data). |
Third-Party Services and Websites
The Services may contain content from and hyperlinks to websites, locations, platforms, and services operated and owned by third parties. These third parties may use your information in ways that differ from this Privacy Policy. We encourage you to review the privacy policies of these third parties.
Online Analytics
We use third-party web analytics services (such as Google Analytics) on our Services to collect and analyse usage information through cookies and similar technologies. The information is used to analyse the use of the Services, including the frequency with which users visit various parts of the Services and what features they use. Merchants may also enable additional analytics and advertising integrations on their forms, as described in the "Subprocessors" section above.
EU and UK Data Subject Rights
If you are located in the European Economic Area ("EEA"), the United Kingdom and other regions with laws governing data collection and use that may differ from laws in the United States, please note that we may transfer information, including personal information, to a country and jurisdiction that does not have the same data protection laws as your jurisdiction. We may transfer your data to the United States, where some of our application infrastructure and subprocessors operate.
Where we transfer personal data outside the EEA or the United Kingdom, we ensure appropriate safeguards are in place, including EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and/or the UK International Data Transfer Addendum issued by the ICO under Section 119A of the Data Protection Act 2018.
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to:
-
Request access to your personal data
-
Request correction of your personal data
-
Request erasure of your personal data
-
Object to processing of your personal data
-
Request restriction of processing
-
Request transfer of your personal data
-
Right to withdraw consent
-
Right to lodge a complaint with a supervisory authority (in the UK, the Information Commissioner's Office (ICO); in the EU, the relevant national data protection authority)
If you wish to exercise any of these rights, please contact us at privacy@hulkapps.com.
Data Controller and Processor
For the purposes of applicable data protection law, the Store Owner (merchant) is the data controller in respect of the personal data of their customers and form respondents that is processed through Form Builder. Shop Circle Holdings Ltd acts as a data processor on behalf of the Store Owner. In relation to certain analytics, usage data, and account information, Shop Circle Holdings Ltd acts as an independent data controller.
Children's Privacy
Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal data, please contact us at privacy@hulkapps.com and we will take steps to delete such information.
Right to Complain
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with a supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO) at https://ico.org.uk. In the EU, you may contact your local data protection authority.
Security
We take steps to ensure that your information is treated securely and in accordance with this Privacy Policy. Unfortunately, no system is 100% secure, and we cannot ensure or warrant the security of any information you provide to us. To the fullest extent permitted by applicable law, we do not accept liability for unauthorised access, use, disclosure, or loss of personal information.
Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons. We encourage you to review this Policy periodically.
Governing Law
This Privacy Policy and any disputes arising out of or in connection with it shall be governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have non-exclusive jurisdiction.
Contact
For questions about this Privacy Policy, contact us at privacy@hulkapps.com.