Privacy Policy
Effective Date: February 11, 2026 | Last Updated: February 11, 2026
QuikForms, LLC ("QuikForms," "we," "us," or "our") is committed to protecting the privacy of all individuals who interact with our services. This Privacy Policy describes how we collect, use, disclose, and safeguard information in connection with our marketing website located at www.sfquikforms.com (the "Website") and our managed Salesforce application distributed via the Salesforce AppExchange (the "Service").
This Privacy Policy applies to three categories of individuals:
- Website Visitors -- individuals who visit www.sfquikforms.com;
- Customers -- Salesforce administrators and authorized users who install and configure the QuikForms managed package within their Salesforce organization ("Salesforce org"); and
- End-Users -- individuals who interact with or submit data through forms created by Customers using the QuikForms Service.
By accessing our Website or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Website or the Service.
1. Definitions and Roles
For the purposes of this Privacy Policy:
- Personal Data (or "Personal Information") means any information that relates to an identified or identifiable natural person, as defined under applicable data protection laws, including the EU General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA").
- Data Controller means the entity that determines the purposes and means of processing Personal Data.
- Data Processor (or "Service Provider") means the entity that processes Personal Data on behalf of a Data Controller.
Our Roles
| Context | QuikForms' Role | Explanation |
|---|---|---|
| Marketing Website (www.sfquikforms.com) | Data Controller | We determine why and how Personal Data collected through the Website is processed. |
| Form Submission Data (via the managed package) | Data Processor | We process form submission data solely on behalf of our Customers, who are the Data Controllers for their own form data. |
Customers are the Data Controllers for all data collected through forms built and deployed using the QuikForms Service. Customers are responsible for providing their own privacy notices to End-Users, obtaining necessary consents, and ensuring their use of the Service complies with applicable privacy laws.
2. Information We Collect
2.1 Information Collected Through the Website (www.sfquikforms.com)
When you visit the Website, we may collect the following information:
a. Google Fonts
The Website loads typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). When your browser requests these fonts, Google may receive your IP address and standard HTTP request headers. Google's handling of this data is governed by the Google Privacy Policy.
b. Web Server Logs
Our web servers automatically collect standard log information, which may include:
- IP address
- Date and time of access
- Pages requested
- HTTP status codes
- Referring URL
- Browser user agent string
Server logs are used for security monitoring, performance optimization, and troubleshooting.
2.2 Information Processed Through the Managed Package (Form Submissions)
The QuikForms managed package runs entirely within the Customer's Salesforce org. When End-Users interact with forms built using QuikForms, the following information may be collected and processed:
a. Form Field Values
All data submitted by End-Users through QuikForms forms (including but not limited to names, email addresses, phone numbers, and any other fields configured by the Customer) is stored directly in the Customer's Salesforce org. QuikForms does not have access to, transmit, or store this data on its own infrastructure.
b. File Uploads
End-Users may upload files through QuikForms forms (up to 9 MB per file). Uploaded files are stored as Salesforce Attachments or ContentDocument records in the Customer's Salesforce org. QuikForms does not retain copies of uploaded files.
c. Cloudflare Turnstile CAPTCHA
QuikForms uses Cloudflare Turnstile for bot verification and spam prevention. Cloudflare may collect certain information as part of this verification process, including IP address and browser characteristics. Cloudflare's handling of this data is governed by the Cloudflare Privacy Policy.
d. Analytics Data (Aggregate and Pseudonymized)
QuikForms collects the following analytics information to provide Customers with form performance insights:
- IP Address Hash: The End-User's IP address is hashed using SHA-256 with a daily rotating salt. The raw IP address is not stored by default.
- Device Category: Desktop, Mobile, or Tablet (derived client-side from screen dimensions).
- Browser Type: Chrome, Safari, Firefox, Edge, or Other (derived client-side from the user agent string).
- Referrer Domain: The hostname of the referring website only (the full URL path and query parameters are not recorded).
- Timestamps: The date and time of form views and submissions.
e. Optional: Raw IP Address and User Agent String
Customers may optionally enable the Log_User_Browser_Info__c setting on a per-form basis. This setting is disabled by default. The Customer, as Data Controller, is responsible for providing appropriate notice to End-Users before enabling this feature.
f. Exception Logs
For error monitoring and debugging, QuikForms may log technical error information in the Customer's Salesforce org. These logs are accessible only to authorized Salesforce administrators.
3. How We Use Information
3.1 Website Data (Data Controller)
We use information collected through the Website for the following purposes:
- Website Analytics: To understand visitor behavior, improve content and user experience, and measure marketing effectiveness.
- Security and Fraud Prevention: To detect and prevent unauthorized access, abuse, and security incidents.
- Infrastructure Operations: To maintain, monitor, and optimize the performance of the Website.
- Legal Compliance: To comply with applicable laws and respond to legal requests.
3.2 Managed Package Data (Data Processor)
As a Data Processor, we process form submission data and related analytics data solely on behalf of and under the instructions of our Customers. We do not use form submission data for our own marketing, advertising, profiling, or any purpose other than providing the Service to our Customers.
4. Legal Bases for Processing (GDPR)
For individuals in the European Economic Area ("EEA"), the United Kingdom ("UK"), and Switzerland, we rely on the following legal bases under the GDPR:
| Processing Activity | Legal Basis |
|---|---|
| Web server logs | Legitimate interests (Art. 6(1)(f)) -- to ensure security and proper functioning of the Website. |
| Google Fonts requests | Legitimate interests (Art. 6(1)(f)) -- to render the Website with proper typography. |
| Form submission processing (as Data Processor) | Performance of a contract (Art. 6(1)(b)) with our Customer. |
| CAPTCHA verification | Legitimate interests (Art. 6(1)(f)) -- to prevent spam and fraudulent submissions. |
| Analytics data (IP hash, device, browser, referrer) | Legitimate interests (Art. 6(1)(f)) -- to provide Customers with aggregate performance analytics. |
| Optional raw IP/user agent logging | As determined by the Customer-Controller. |
5. Information Sharing and Disclosure
We do not sell, rent, or trade Personal Data.
We may share information in the following limited circumstances:
5.1 Third-Party Service Providers
- Cloudflare, Inc. -- CAPTCHA verification tokens are transmitted to Cloudflare for bot detection.
- Google LLC -- Font requests are served by Google Fonts.
- Salesforce, Inc. -- The Service operates on the Salesforce platform. All form submission data resides within the Customer's Salesforce org.
5.2 Legal Requirements
We may disclose information if required to do so by law or in the good-faith belief that such disclosure is necessary to comply with a legal obligation, protect our rights, or prevent fraud.
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, Personal Data may be transferred as part of the transaction. We will provide notice before Personal Data becomes subject to a different privacy policy.
6. Third-Party Service Providers
Cloudflare, Inc.
- Purpose: Bot verification and spam prevention via Cloudflare Turnstile.
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
Google LLC
- Purpose: Typography rendering via Google Fonts.
- Privacy Policy: https://policies.google.com/privacy
Salesforce, Inc.
- Purpose: Cloud platform on which the QuikForms managed package operates.
- Privacy Policy: https://www.salesforce.com/company/privacy/
7. Data Storage, Location, and Security
7.1 Website Data
We implement commercially reasonable administrative, technical, and physical security measures to protect information collected through the Website.
7.2 Managed Package Data
The QuikForms managed package is installed and runs entirely within the Customer's Salesforce org. QuikForms does not operate its own servers, databases, or data stores for form submission data.
7.3 Security Measures Within the Managed Package
- IP Address Hashing: SHA-256 hashing with a daily rotating salt.
- Rate Limiting: Automated rate limiting protects against submission abuse.
- Origin Verification: Configurable referrer validation.
- CAPTCHA Verification: Cloudflare Turnstile integration.
- Honeypot Fields: Hidden form fields to detect automated bot submissions.
- Salesforce Platform Security: Enterprise-grade encryption at rest and in transit.
8. Data Retention
8.1 Website Data
- Web Server Logs: Retained for 90 days and then automatically deleted.
8.2 Managed Package Data
- Form Submission Data: Retained in the Customer's Salesforce org as determined by the Customer's own data retention policies.
- Analytics Rollup Records: Retained for 365 days by default. Customers may configure a different retention period.
- Exception Logs: Automatically cleaned up based on configurable retention settings.
8.3 Cloudflare Turnstile Data
CAPTCHA verification tokens are ephemeral and are not stored by QuikForms after the verification response is received.
9. Your Privacy Rights
Depending on your jurisdiction and applicable law, you may have the following rights with respect to your Personal Data:
- Right of Access: Request confirmation of whether we process your Personal Data and obtain a copy.
- Right to Rectification: Request correction of inaccurate Personal Data.
- Right to Erasure: Request deletion of your Personal Data, subject to certain exceptions.
- Right to Restriction of Processing: Request that we limit our processing.
- Right to Data Portability: Receive your Personal Data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing.
- Right to Non-Discrimination: Not receive discriminatory treatment for exercising your rights.
How to Exercise Your Rights
Website Visitors: Contact us at [email protected].
End-Users (form submitters): Direct your privacy requests to the organization whose form you submitted, as they are the Data Controller.
Customers: You maintain direct access to and control over all data within your Salesforce org.
10. GDPR -- Additional Provisions for EEA, UK, and Swiss Individuals
10.1 Data Controller Contact
QuikForms, LLC
Email: [email protected]
10.2 Data Processing Agreements
Customers located in the EEA, UK, or Switzerland may request a Data Processing Agreement ("DPA") by contacting [email protected].
10.3 Data Protection Officer
Given the nature and scale of our processing activities, QuikForms has not appointed a Data Protection Officer. For privacy-related inquiries, please contact us at [email protected].
10.4 Supervisory Authority
If you are located in the EEA or UK, you have the right to lodge a complaint with your local data protection supervisory authority.
10.5 Automated Decision-Making
QuikForms does not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.
11. CCPA/CPRA -- Additional Provisions for California Residents
11.1 Sale and Sharing of Personal Information
QuikForms does not sell Personal Information as defined under the CCPA/CPRA. QuikForms does not share Personal Information for cross-context behavioral advertising purposes.
11.2 California Privacy Rights
- Right to Know: Request disclosure of categories and specific pieces of Personal Information collected.
- Right to Delete: Request deletion of Personal Information collected.
- Right to Correct: Request correction of inaccurate Personal Information.
- Right to Opt Out of Sale/Sharing: Although we do not sell or share, you may submit a request.
- Right to Non-Discrimination: We will not discriminate for exercising your rights.
11.3 Exercising Your Rights
To exercise your rights under the CCPA/CPRA, please contact us at [email protected].
12. Children's Privacy
The Website and the Service are not directed at children under the age of 16. We do not knowingly collect Personal Data from children. If you believe that your child has provided Personal Data to us, please contact us at [email protected], and we will take steps to delete such information.
13. International Data Transfers
13.1 Website Data
Data collected through the Website may be transferred to and processed in the United States and other countries where our hosting providers operate facilities. We rely on Standard Contractual Clauses ("SCCs") and other legally recognized transfer mechanisms.
13.2 Managed Package Data
Form submission data is stored in the Customer's Salesforce org. The geographic location is determined by the Customer's Salesforce instance and data residency configuration. QuikForms does not independently transfer this data across borders.
14. Do Not Track Signals
Some web browsers transmit "Do Not Track" ("DNT") signals. We currently do not respond to DNT browser signals on the Website. For more information about DNT, visit https://allaboutdnt.com/.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this Privacy Policy and post a notice on the Website. Your continued use of the Website or Service after any changes constitutes your acceptance of the updated Privacy Policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
QuikForms, LLC
Email: [email protected]
Privacy: [email protected]
Website: www.sfquikforms.com
Appendix A: Data Processing Summary for Customers
| Data Element | Stored Where | By Default | Retention |
|---|---|---|---|
| Form field values | Customer's Salesforce org | Yes | Per Customer policy |
| File uploads (up to 9 MB) | Customer's Salesforce org | Yes (when used) | Per Customer policy |
| IP address (SHA-256 hash) | Customer's Salesforce org | Yes | 365 days (configurable) |
| Device category / Browser type | Customer's Salesforce org | Yes | 365 days (configurable) |
| Referrer domain | Customer's Salesforce org | Yes | 365 days (configurable) |
| Raw IP address | Customer's Salesforce org | No (opt-in) | Per Customer policy |
| Cloudflare Turnstile token | Transmitted to Cloudflare | N/A | Ephemeral |
| Exception logs | Customer's Salesforce org | Yes (on error) | Configurable |
QuikForms, LLC is organized under the laws of the State of Oregon.