Privacy statement

Last updated: 14 August 2026

This statement explains what personal data we process when you visit localform.dev or docs.localform.dev, when you buy or run LocalForm Pro, and when you email us - and what happens to the answers people fill into forms you build with LocalForm. It is written to meet Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).

1. Who we are

LocalForm is built and sold by XeWeb, which is the data controller for the processing described here.

XeWeb
Seraphin De Grootestraat 97, 2100 Deurne, Belgium
VAT number: BE 0672.654.319
Email: tim@xeweb.be

We are not required to appoint a Data Protection Officer, so questions about privacy go to the email address above. We answer requests within one month.

2. The short version

3. Visiting this website

localform.dev and docs.localform.dev are static sites served by Cloudflare, Inc. as our hosting provider. Like any web server, Cloudflare's infrastructure processes technical request data in order to deliver the pages and to defend against attacks and abuse:

Legal basis: our legitimate interest in delivering and securing the site (Article 6(1)(f) GDPR). We do not build profiles from this data, do not use it to identify individual visitors, and do not combine it with anything else.

We do not run our own analytics on this data and do not export it. It is held in Cloudflare's logs under their standard retention.

4. Cookies and tracking

We set no cookies and use no local storage, tracking pixels, session recording, A/B testing or advertising tags. Every asset on this site - stylesheets, images, the logo - is served from our own domain, so simply reading these pages does not send you to any third party.

Cloudflare may set strictly necessary security cookies when it needs to challenge traffic that looks abusive. Those cookies are exempt from the consent requirement because they exist purely to keep the site available.

Two places on this site link out: the checkout at Freemius and the plugin listing on WordPress.org. Once you follow those links, that site's own privacy policy applies.

5. Emailing us

If you email us - about support, a licence, an invoice or anything else - we process your email address, your name if you give it, and whatever you put in the message. We use it only to answer you and to keep a record of what was agreed.

Legal basis: performance of a contract where you are a customer (Article 6(1)(b) GDPR), and otherwise our legitimate interest in responding to people who contact us (Article 6(1)(f) GDPR).

Please do not send us form responses, exports or database dumps containing other people's personal data. If you need to share something for a support case, remove or redact the personal data first - we will ask you to if you don't.

6. Buying and running LocalForm Pro

The checkout

LocalForm Pro is sold through Freemius, which acts as the merchant of record and reseller. When you buy a licence you enter your details on Freemius' checkout, not ours. Freemius collects your name, email address, billing address, tax details and payment information, and processes the payment - we never see or store your card details. Freemius acts as an independent controller for that data; see the Freemius privacy policy.

From Freemius we receive the customer record connected to the licence: your name, email address, plan, licence key, purchase and renewal dates, and the sites the licence is activated on. We use it to deliver the product, provide support, handle renewals and refunds, and meet our bookkeeping obligations.

Legal basis: performance of the contract (Article 6(1)(b) GDPR) and our legal obligation to keep invoices (Article 6(1)(c) GDPR).

The licence check

Once installed, LocalForm Pro talks to Freemius to validate its licence and to fetch updates. That request carries your site URL, the licence key and the plugin version. It is the only outbound request LocalForm Pro makes on its own. Form submissions, uploaded files and your visitors' answers are never part of it.

7. The plugin itself, and forms you build

For the forms you publish on your own site, you are the data controller - not us. LocalForm is software that runs on your server. We have no access to your site, your database or your submissions, and we could not retrieve them if we wanted to. Your visitors' privacy notice, your legal basis for collecting their answers, and any request they make about their data are your responsibility.

What LocalForm stores on your site, so you can describe it accurately in your own privacy notice:

WhatWhereNotes
Form responses Your WordPress database (localform_submissions) The answers and the submission timestamp. No IP address and no user-agent string are stored with a submission.
Rate-limiting counter A WordPress transient Only a hash of the visitor's IP, and only for the length of the rate-limit window (one hour by default). The IP itself is never written down.
Duplicate-submission check A WordPress transient A hash of the submitted values, kept for a few minutes.
Webhook delivery logs Your WordPress database Contains the full payload that was sent, including the response data. Kept for 30 days, then deleted automatically.
Uploaded files (Pro) Your WordPress uploads directory Stays on your server until you delete it.

Things worth knowing when you write your own notice:

8. Who we share data with

We do not sell personal data and we do not share it for advertising. We use a small number of service providers:

ProviderRoleData involved
Cloudflare, Inc.Hosting and CDN for our websitesTechnical request data (see section 3)
FreemiusCheckout, payments, invoicing, licensing and updates for ProCustomer, billing and licence data (see section 6)
Proton AG (Switzerland)Our emailCorrespondence with you
AccountableBookkeeping and tax filingInvoice data

Beyond these, we disclose personal data only where the law requires it.

9. Transfers outside the EEA

Cloudflare is established in the United States and processes data there and in the other countries where its network runs. That transfer relies on the European Commission's Standard Contractual Clauses, together with the supplementary measures set out in Cloudflare's data processing addendum.

Freemius operates internationally; the entity that contracts with you is named on your invoice and in their data processing agreement. Where their processing takes place outside the EEA, it relies on the Standard Contractual Clauses or on an adequacy decision.

Our email is hosted by Proton in Switzerland, which the European Commission has recognised as providing an adequate level of data protection, so no additional safeguard is needed for that.

You can ask us for a copy of the safeguards that apply to any of these.

10. How long we keep data

DataRetention
Website request logsHeld by Cloudflare under their standard log retention; we keep no copy
Support and other correspondenceUp to 24 months after our last exchange, or longer where it documents an agreement
Customer and licence recordsFor as long as the licence is active, and then for the statutory bookkeeping period
Invoices and accounting records7 years, as required by Belgian tax law

11. Your rights

Under the GDPR you have the right to:

To exercise any of these, email tim@xeweb.be. We will answer within one month and may ask you to confirm your identity first. Exercising your rights is free; we charge nothing and it costs you nothing in service.

We take no automated decisions with legal or similarly significant effects, and we do no profiling.

If you think we have handled your data badly, you can complain to your national supervisory authority. In Belgium that is the Data Protection Authority, Drukpersstraat 35, 1000 Brussels - dataprotectionauthority.be. You may also complain to the authority where you live or work.

If your question is about a form you filled in on someone else's website, we cannot help: contact the site that published the form, because they hold your answers, not us.

12. Security

Our sites are served over HTTPS only. Access to customer and licence data is limited to the people who need it, protected by multi-factor authentication. We keep our software up to date and we deliberately hold as little personal data as we can - the cheapest way to keep data safe is not to have it.

13. Children

Our website and products are aimed at website owners and developers, not at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, email us and we will delete it.

14. Changes to this statement

We update this statement when our product or our providers change. The date at the top always reflects the current version. Material changes affecting existing customers will also be sent by email.