Privacy statement
Last updated: 14 August 2026
This statement explains what personal data we process when you visit localform.dev or docs.localform.dev, when you buy or run LocalForm Pro, and when you email us - and what happens to the answers people fill into forms you build with LocalForm. It is written to meet Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).
1. Who we are
LocalForm is built and sold by XeWeb, which is the data controller for the processing described here.
XeWebSeraphin De Grootestraat 97, 2100 Deurne, Belgium
VAT number: BE 0672.654.319
Email: tim@xeweb.be
We are not required to appoint a Data Protection Officer, so questions about privacy go to the email address above. We answer requests within one month.
2. The short version
- This website sets no cookies, runs no analytics, and loads no fonts, scripts or images from anyone else's servers. There is nothing to consent to, which is why you see no cookie banner.
- The free LocalForm plugin makes no outbound request of its own. It sends us nothing - no telemetry, no usage statistics, no form data.
- Form responses never reach us. They are stored in the WordPress database of the site that collected them, and nowhere else.
- The only personal data we actually hold about you is what you email us, and what we receive from Freemius when you buy LocalForm Pro.
3. Visiting this website
localform.dev and docs.localform.dev are static sites served by Cloudflare, Inc. as our hosting provider. Like any web server, Cloudflare's infrastructure processes technical request data in order to deliver the pages and to defend against attacks and abuse:
- your IP address;
- the date and time of the request and the page or file requested;
- your browser's user-agent string and, if your browser sends one, the referring page;
- approximate country, derived from the IP address.
Legal basis: our legitimate interest in delivering and securing the site (Article 6(1)(f) GDPR). We do not build profiles from this data, do not use it to identify individual visitors, and do not combine it with anything else.
We do not run our own analytics on this data and do not export it. It is held in Cloudflare's logs under their standard retention.
4. Cookies and tracking
We set no cookies and use no local storage, tracking pixels, session recording, A/B testing or advertising tags. Every asset on this site - stylesheets, images, the logo - is served from our own domain, so simply reading these pages does not send you to any third party.
Cloudflare may set strictly necessary security cookies when it needs to challenge traffic that looks abusive. Those cookies are exempt from the consent requirement because they exist purely to keep the site available.
Two places on this site link out: the checkout at Freemius and the plugin listing on WordPress.org. Once you follow those links, that site's own privacy policy applies.
5. Emailing us
If you email us - about support, a licence, an invoice or anything else - we process your email address, your name if you give it, and whatever you put in the message. We use it only to answer you and to keep a record of what was agreed.
Legal basis: performance of a contract where you are a customer (Article 6(1)(b) GDPR), and otherwise our legitimate interest in responding to people who contact us (Article 6(1)(f) GDPR).
Please do not send us form responses, exports or database dumps containing other people's personal data. If you need to share something for a support case, remove or redact the personal data first - we will ask you to if you don't.
6. Buying and running LocalForm Pro
The checkout
LocalForm Pro is sold through Freemius, which acts as the merchant of record and reseller. When you buy a licence you enter your details on Freemius' checkout, not ours. Freemius collects your name, email address, billing address, tax details and payment information, and processes the payment - we never see or store your card details. Freemius acts as an independent controller for that data; see the Freemius privacy policy.
From Freemius we receive the customer record connected to the licence: your name, email address, plan, licence key, purchase and renewal dates, and the sites the licence is activated on. We use it to deliver the product, provide support, handle renewals and refunds, and meet our bookkeeping obligations.
Legal basis: performance of the contract (Article 6(1)(b) GDPR) and our legal obligation to keep invoices (Article 6(1)(c) GDPR).
The licence check
Once installed, LocalForm Pro talks to Freemius to validate its licence and to fetch updates. That request carries your site URL, the licence key and the plugin version. It is the only outbound request LocalForm Pro makes on its own. Form submissions, uploaded files and your visitors' answers are never part of it.
7. The plugin itself, and forms you build
For the forms you publish on your own site, you are the data controller - not us. LocalForm is software that runs on your server. We have no access to your site, your database or your submissions, and we could not retrieve them if we wanted to. Your visitors' privacy notice, your legal basis for collecting their answers, and any request they make about their data are your responsibility.
What LocalForm stores on your site, so you can describe it accurately in your own privacy notice:
| What | Where | Notes |
|---|---|---|
| Form responses | Your WordPress database (localform_submissions) |
The answers and the submission timestamp. No IP address and no user-agent string are stored with a submission. |
| Rate-limiting counter | A WordPress transient | Only a hash of the visitor's IP, and only for the length of the rate-limit window (one hour by default). The IP itself is never written down. |
| Duplicate-submission check | A WordPress transient | A hash of the submitted values, kept for a few minutes. |
| Webhook delivery logs | Your WordPress database | Contains the full payload that was sent, including the response data. Kept for 30 days, then deleted automatically. |
| Uploaded files (Pro) | Your WordPress uploads directory | Stays on your server until you delete it. |
Things worth knowing when you write your own notice:
- The plugin contains no analytics, no telemetry and no "phone home" of any kind, and fonts are served from your own domain.
- If you configure a webhook, every submission is sent to the URL you chose. That transfer is yours to document and to justify.
- If you use the MCP integration, an AI assistant you connect yourself can read and write forms on your site. What that assistant does with the data is governed by whoever provides it.
- You can export submissions to XLSX and delete individual responses or an entire form's responses from the admin, which is what you will use to answer access and erasure requests.
8. Who we share data with
We do not sell personal data and we do not share it for advertising. We use a small number of service providers:
| Provider | Role | Data involved |
|---|---|---|
| Cloudflare, Inc. | Hosting and CDN for our websites | Technical request data (see section 3) |
| Freemius | Checkout, payments, invoicing, licensing and updates for Pro | Customer, billing and licence data (see section 6) |
| Proton AG (Switzerland) | Our email | Correspondence with you |
| Accountable | Bookkeeping and tax filing | Invoice data |
Beyond these, we disclose personal data only where the law requires it.
9. Transfers outside the EEA
Cloudflare is established in the United States and processes data there and in the other countries where its network runs. That transfer relies on the European Commission's Standard Contractual Clauses, together with the supplementary measures set out in Cloudflare's data processing addendum.
Freemius operates internationally; the entity that contracts with you is named on your invoice and in their data processing agreement. Where their processing takes place outside the EEA, it relies on the Standard Contractual Clauses or on an adequacy decision.
Our email is hosted by Proton in Switzerland, which the European Commission has recognised as providing an adequate level of data protection, so no additional safeguard is needed for that.
You can ask us for a copy of the safeguards that apply to any of these.
10. How long we keep data
| Data | Retention |
|---|---|
| Website request logs | Held by Cloudflare under their standard log retention; we keep no copy |
| Support and other correspondence | Up to 24 months after our last exchange, or longer where it documents an agreement |
| Customer and licence records | For as long as the licence is active, and then for the statutory bookkeeping period |
| Invoices and accounting records | 7 years, as required by Belgian tax law |
11. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and get a copy of it;
- Rectify data that is wrong or incomplete;
- Erase your data, where we have no overriding obligation to keep it - invoices, for instance, we must keep;
- Restrict or object to processing based on our legitimate interests;
- Data portability for data you gave us, in a machine-readable format;
- Withdraw consent at any time, where processing was based on consent - which does not affect what was lawful before you withdrew it.
To exercise any of these, email tim@xeweb.be. We will answer within one month and may ask you to confirm your identity first. Exercising your rights is free; we charge nothing and it costs you nothing in service.
We take no automated decisions with legal or similarly significant effects, and we do no profiling.
If you think we have handled your data badly, you can complain to your national supervisory authority. In Belgium that is the Data Protection Authority, Drukpersstraat 35, 1000 Brussels - dataprotectionauthority.be. You may also complain to the authority where you live or work.
If your question is about a form you filled in on someone else's website, we cannot help: contact the site that published the form, because they hold your answers, not us.
12. Security
Our sites are served over HTTPS only. Access to customer and licence data is limited to the people who need it, protected by multi-factor authentication. We keep our software up to date and we deliberately hold as little personal data as we can - the cheapest way to keep data safe is not to have it.
13. Children
Our website and products are aimed at website owners and developers, not at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, email us and we will delete it.
14. Changes to this statement
We update this statement when our product or our providers change. The date at the top always reflects the current version. Material changes affecting existing customers will also be sent by email.