QuikForms Legal

Policies, agreements, and legal information for QuikForms.

Privacy Policy

Effective Date: February 11, 2026 | Last Updated: February 11, 2026

QuikForms, LLC ("QuikForms," "we," "us," or "our") is committed to protecting the privacy of all individuals who interact with our services. This Privacy Policy describes how we collect, use, disclose, and safeguard information in connection with our marketing website located at www.sfquikforms.com (the "Website") and our managed Salesforce application distributed via the Salesforce AppExchange (the "Service").

This Privacy Policy applies to three categories of individuals:

  1. Website Visitors -- individuals who visit www.sfquikforms.com;
  2. Customers -- Salesforce administrators and authorized users who install and configure the QuikForms managed package within their Salesforce organization ("Salesforce org"); and
  3. End-Users -- individuals who interact with or submit data through forms created by Customers using the QuikForms Service.

By accessing our Website or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Website or the Service.

1. Definitions and Roles

For the purposes of this Privacy Policy:

  • Personal Data (or "Personal Information") means any information that relates to an identified or identifiable natural person, as defined under applicable data protection laws, including the EU General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA").
  • Data Controller means the entity that determines the purposes and means of processing Personal Data.
  • Data Processor (or "Service Provider") means the entity that processes Personal Data on behalf of a Data Controller.

Our Roles

Context QuikForms' Role Explanation
Marketing Website (www.sfquikforms.com) Data Controller We determine why and how Personal Data collected through the Website is processed.
Form Submission Data (via the managed package) Data Processor We process form submission data solely on behalf of our Customers, who are the Data Controllers for their own form data.

Customers are the Data Controllers for all data collected through forms built and deployed using the QuikForms Service. Customers are responsible for providing their own privacy notices to End-Users, obtaining necessary consents, and ensuring their use of the Service complies with applicable privacy laws.

2. Information We Collect

2.1 Information Collected Through the Website (www.sfquikforms.com)

When you visit the Website, we may collect the following information:

a. Google Fonts

The Website loads typefaces from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). When your browser requests these fonts, Google may receive your IP address and standard HTTP request headers. Google's handling of this data is governed by the Google Privacy Policy.

b. Web Server Logs

Our web servers automatically collect standard log information, which may include:

  • IP address
  • Date and time of access
  • Pages requested
  • HTTP status codes
  • Referring URL
  • Browser user agent string

Server logs are used for security monitoring, performance optimization, and troubleshooting.

2.2 Information Processed Through the Managed Package (Form Submissions)

The QuikForms managed package runs entirely within the Customer's Salesforce org. When End-Users interact with forms built using QuikForms, the following information may be collected and processed:

a. Form Field Values

All data submitted by End-Users through QuikForms forms (including but not limited to names, email addresses, phone numbers, and any other fields configured by the Customer) is stored directly in the Customer's Salesforce org. QuikForms does not have access to, transmit, or store this data on its own infrastructure.

b. File Uploads

End-Users may upload files through QuikForms forms (up to 9 MB per file). Uploaded files are stored as Salesforce Attachments or ContentDocument records in the Customer's Salesforce org. QuikForms does not retain copies of uploaded files.

c. Cloudflare Turnstile CAPTCHA

QuikForms uses Cloudflare Turnstile for bot verification and spam prevention. Cloudflare may collect certain information as part of this verification process, including IP address and browser characteristics. Cloudflare's handling of this data is governed by the Cloudflare Privacy Policy.

d. Analytics Data (Aggregate and Pseudonymized)

QuikForms collects the following analytics information to provide Customers with form performance insights:

  • IP Address Hash: The End-User's IP address is hashed using SHA-256 with a daily rotating salt. The raw IP address is not stored by default.
  • Device Category: Desktop, Mobile, or Tablet (derived client-side from screen dimensions).
  • Browser Type: Chrome, Safari, Firefox, Edge, or Other (derived client-side from the user agent string).
  • Referrer Domain: The hostname of the referring website only (the full URL path and query parameters are not recorded).
  • Timestamps: The date and time of form views and submissions.

e. Optional: Raw IP Address and User Agent String

Customers may optionally enable the Log_User_Browser_Info__c setting on a per-form basis. This setting is disabled by default. The Customer, as Data Controller, is responsible for providing appropriate notice to End-Users before enabling this feature.

f. Exception Logs

For error monitoring and debugging, QuikForms may log technical error information in the Customer's Salesforce org. These logs are accessible only to authorized Salesforce administrators.

3. How We Use Information

3.1 Website Data (Data Controller)

We use information collected through the Website for the following purposes:

  • Website Analytics: To understand visitor behavior, improve content and user experience, and measure marketing effectiveness.
  • Security and Fraud Prevention: To detect and prevent unauthorized access, abuse, and security incidents.
  • Infrastructure Operations: To maintain, monitor, and optimize the performance of the Website.
  • Legal Compliance: To comply with applicable laws and respond to legal requests.

3.2 Managed Package Data (Data Processor)

As a Data Processor, we process form submission data and related analytics data solely on behalf of and under the instructions of our Customers. We do not use form submission data for our own marketing, advertising, profiling, or any purpose other than providing the Service to our Customers.

For individuals in the European Economic Area ("EEA"), the United Kingdom ("UK"), and Switzerland, we rely on the following legal bases under the GDPR:

Processing Activity Legal Basis
Web server logs Legitimate interests (Art. 6(1)(f)) -- to ensure security and proper functioning of the Website.
Google Fonts requests Legitimate interests (Art. 6(1)(f)) -- to render the Website with proper typography.
Form submission processing (as Data Processor) Performance of a contract (Art. 6(1)(b)) with our Customer.
CAPTCHA verification Legitimate interests (Art. 6(1)(f)) -- to prevent spam and fraudulent submissions.
Analytics data (IP hash, device, browser, referrer) Legitimate interests (Art. 6(1)(f)) -- to provide Customers with aggregate performance analytics.
Optional raw IP/user agent logging As determined by the Customer-Controller.

5. Information Sharing and Disclosure

We do not sell, rent, or trade Personal Data.

We may share information in the following limited circumstances:

5.1 Third-Party Service Providers

  • Cloudflare, Inc. -- CAPTCHA verification tokens are transmitted to Cloudflare for bot detection.
  • Google LLC -- Font requests are served by Google Fonts.
  • Salesforce, Inc. -- The Service operates on the Salesforce platform. All form submission data resides within the Customer's Salesforce org.

5.2 Legal Requirements

We may disclose information if required to do so by law or in the good-faith belief that such disclosure is necessary to comply with a legal obligation, protect our rights, or prevent fraud.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, Personal Data may be transferred as part of the transaction. We will provide notice before Personal Data becomes subject to a different privacy policy.

6. Third-Party Service Providers

Cloudflare, Inc.

Google LLC

Salesforce, Inc.

7. Data Storage, Location, and Security

7.1 Website Data

We implement commercially reasonable administrative, technical, and physical security measures to protect information collected through the Website.

7.2 Managed Package Data

The QuikForms managed package is installed and runs entirely within the Customer's Salesforce org. QuikForms does not operate its own servers, databases, or data stores for form submission data.

7.3 Security Measures Within the Managed Package

  • IP Address Hashing: SHA-256 hashing with a daily rotating salt.
  • Rate Limiting: Automated rate limiting protects against submission abuse.
  • Origin Verification: Configurable referrer validation.
  • CAPTCHA Verification: Cloudflare Turnstile integration.
  • Honeypot Fields: Hidden form fields to detect automated bot submissions.
  • Salesforce Platform Security: Enterprise-grade encryption at rest and in transit.

8. Data Retention

8.1 Website Data

  • Web Server Logs: Retained for 90 days and then automatically deleted.

8.2 Managed Package Data

  • Form Submission Data: Retained in the Customer's Salesforce org as determined by the Customer's own data retention policies.
  • Analytics Rollup Records: Retained for 365 days by default. Customers may configure a different retention period.
  • Exception Logs: Automatically cleaned up based on configurable retention settings.

8.3 Cloudflare Turnstile Data

CAPTCHA verification tokens are ephemeral and are not stored by QuikForms after the verification response is received.

9. Your Privacy Rights

Depending on your jurisdiction and applicable law, you may have the following rights with respect to your Personal Data:

  • Right of Access: Request confirmation of whether we process your Personal Data and obtain a copy.
  • Right to Rectification: Request correction of inaccurate Personal Data.
  • Right to Erasure: Request deletion of your Personal Data, subject to certain exceptions.
  • Right to Restriction of Processing: Request that we limit our processing.
  • Right to Data Portability: Receive your Personal Data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing.
  • Right to Non-Discrimination: Not receive discriminatory treatment for exercising your rights.

How to Exercise Your Rights

Website Visitors: Contact us at [email protected].

End-Users (form submitters): Direct your privacy requests to the organization whose form you submitted, as they are the Data Controller.

Customers: You maintain direct access to and control over all data within your Salesforce org.

10. GDPR -- Additional Provisions for EEA, UK, and Swiss Individuals

10.1 Data Controller Contact

QuikForms, LLC
Email: [email protected]

10.2 Data Processing Agreements

Customers located in the EEA, UK, or Switzerland may request a Data Processing Agreement ("DPA") by contacting [email protected].

10.3 Data Protection Officer

Given the nature and scale of our processing activities, QuikForms has not appointed a Data Protection Officer. For privacy-related inquiries, please contact us at [email protected].

10.4 Supervisory Authority

If you are located in the EEA or UK, you have the right to lodge a complaint with your local data protection supervisory authority.

10.5 Automated Decision-Making

QuikForms does not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects individuals.

11. CCPA/CPRA -- Additional Provisions for California Residents

11.1 Sale and Sharing of Personal Information

QuikForms does not sell Personal Information as defined under the CCPA/CPRA. QuikForms does not share Personal Information for cross-context behavioral advertising purposes.

11.2 California Privacy Rights

  • Right to Know: Request disclosure of categories and specific pieces of Personal Information collected.
  • Right to Delete: Request deletion of Personal Information collected.
  • Right to Correct: Request correction of inaccurate Personal Information.
  • Right to Opt Out of Sale/Sharing: Although we do not sell or share, you may submit a request.
  • Right to Non-Discrimination: We will not discriminate for exercising your rights.

11.3 Exercising Your Rights

To exercise your rights under the CCPA/CPRA, please contact us at [email protected].

12. Children's Privacy

The Website and the Service are not directed at children under the age of 16. We do not knowingly collect Personal Data from children. If you believe that your child has provided Personal Data to us, please contact us at [email protected], and we will take steps to delete such information.

13. International Data Transfers

13.1 Website Data

Data collected through the Website may be transferred to and processed in the United States and other countries where our hosting providers operate facilities. We rely on Standard Contractual Clauses ("SCCs") and other legally recognized transfer mechanisms.

13.2 Managed Package Data

Form submission data is stored in the Customer's Salesforce org. The geographic location is determined by the Customer's Salesforce instance and data residency configuration. QuikForms does not independently transfer this data across borders.

14. Do Not Track Signals

Some web browsers transmit "Do Not Track" ("DNT") signals. We currently do not respond to DNT browser signals on the Website. For more information about DNT, visit https://allaboutdnt.com/.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this Privacy Policy and post a notice on the Website. Your continued use of the Website or Service after any changes constitutes your acceptance of the updated Privacy Policy.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

QuikForms, LLC
Email: [email protected]
Privacy: [email protected]
Website: www.sfquikforms.com

Appendix A: Data Processing Summary for Customers

Data Element Stored Where By Default Retention
Form field values Customer's Salesforce org Yes Per Customer policy
File uploads (up to 9 MB) Customer's Salesforce org Yes (when used) Per Customer policy
IP address (SHA-256 hash) Customer's Salesforce org Yes 365 days (configurable)
Device category / Browser type Customer's Salesforce org Yes 365 days (configurable)
Referrer domain Customer's Salesforce org Yes 365 days (configurable)
Raw IP address Customer's Salesforce org No (opt-in) Per Customer policy
Cloudflare Turnstile token Transmitted to Cloudflare N/A Ephemeral
Exception logs Customer's Salesforce org Yes (on error) Configurable

QuikForms, LLC is organized under the laws of the State of Oregon.