Privacy Policy
ExForms Privacy Policy
Last Updated: January 17, 2026
This Privacy Policy describes how ExForms ("Company," "we," "us," or "our") collects, uses, and protects information when you use our services, including the ExForms Office Add-in and integrations with third-party services such as QuickBooks Online.
1. Information We Collect
1.1 Account Information
When you create an ExForms account, we collect:
| Information | Purpose |
|---|---|
| Email Address | Account identification, communications, password recovery |
| Full Name | Account personalization, support communications |
| Company Name | Multi-tenant account organization |
| Subscription Details | Service provisioning, billing |
1.2 Integration Connection Data
When you connect third-party services (QuickBooks, Toggl, etc.):
| Information | Purpose | Retention |
|---|---|---|
| OAuth Access Tokens | Authenticate API requests to connected services | Until you disconnect; stored encrypted in Azure Key Vault |
| OAuth Refresh Tokens | Maintain continuous access without re-authorization | Until you disconnect; stored encrypted |
| Workspace/Company IDs | Identify which account to sync with | Duration of connection |
| Connection Metadata | Connection status, last sync time, error states | Duration of connection |
1.3 Usage Data
We automatically collect:
- Sync Operation Logs: What types of data were synced, record counts, success/failure status
- Error Logs: Technical details when errors occur (for troubleshooting)
- Feature Usage: Which features you use (aggregate analytics)
- Performance Metrics: Response times, processing durations
1.4 Transient Data (NOT Stored)
The following data is processed but NOT permanently stored:
- Excel Data: Cell values, table data you send for synchronization
- QuickBooks Business Data: Customer records, invoices, items, etc.
- Document Content: PDF, Word, PowerPoint files processed for form filling
This data is:
- Transmitted securely (TLS 1.2+)
- Processed in memory on our servers
- Immediately sent to the destination (QuickBooks, generated documents)
- Never written to persistent storage
2. How We Use Your Information
2.1 Service Provision
We use your information to:
- Authenticate you to ExForms and connected services
- Process data synchronization requests
- Generate filled documents (PDF, Word, PowerPoint)
- Maintain your connections and configurations
2.2 Service Improvement
We use aggregated, anonymized data to:
- Improve application performance
- Identify and fix bugs
- Develop new features
- Optimize user experience
2.3 Communications
We may contact you for:
- Service announcements and updates
- Security alerts
- Support responses
- Billing and subscription matters
We do NOT sell your contact information or send marketing emails from third parties.
2.4 Legal Compliance
We may use or disclose information when required by:
- Law enforcement requests with valid legal process
- Court orders or subpoenas
- Protection of our legal rights
- Prevention of fraud or security threats
3. Information Sharing
3.1 Third-Party Services
When you connect integrations, we share data with those services:
| Service | Data Shared | Purpose |
|---|---|---|
| QuickBooks Online (Intuit) | Your Excel data mapped to QuickBooks fields | Create/update QuickBooks records as you configured |
| Toggl Track | Your Excel data mapped to Toggl fields | Create/update Toggl records as you configured |
| Microsoft | Authentication tokens via Office.js | Enable Excel Add-in functionality |
3.2 Service Providers
We use trusted service providers:
| Provider | Service | Data Access |
|---|---|---|
| Microsoft Azure | Cloud hosting, Key Vault | Infrastructure provider; encrypted data only |
| DigitalOcean | Cloud hosting | Infrastructure provider; encrypted data only |
| FastSpring | Direct payment processing | Billing information only |
3.3 We Do NOT Sell Your Data
We do not sell, rent, or trade your personal information or business data to third parties.
4. Data Security
4.1 Encryption
| Data State | Protection |
|---|---|
| In Transit | TLS 1.2+ (HTTPS) for all connections |
| At Rest (Credentials) | AES-256 encryption, Azure Key Vault with HSM |
| At Rest (Templates) | AES-256 envelope encryption |
| Processing | Isolated containers, memory-only processing |
4.2 Access Controls
- Role-based access control (RBAC) for our systems
- OAuth 2.0 for third-party service authentication
- No shared passwords; unique credentials per service
4.3 Infrastructure Security
- SOC 2 Type II compliant cloud providers
- Regular security audits
- Automated vulnerability scanning
- Container isolation for all processing
4.4 Incident Response
In the event of a security incident:
- We will notify affected users within 72 hours
- We will provide details of what data may have been affected
- We will describe remediation steps taken
5. Data Retention
5.1 Retention Periods
| Data Type | Retention Period |
|---|---|
| Account Information | Until account deletion + 30 days |
| OAuth Tokens | Until you disconnect the integration |
| Connection Configurations | Until you delete the connection |
| Sync Operation Logs | 90 days |
| Error Logs | 30 days |
| Transient Business Data | Not retained (processed and discarded) |
5.2 Account Deletion
When you delete your account:
- Account data is marked for deletion immediately
- All OAuth tokens are revoked and deleted
- All configurations are deleted
- Backup retention: 30 days maximum, then permanently deleted
6. Your Rights
6.1 Access and Portability
You have the right to:
- Access your account information
- Export your configuration data
- Receive a copy of data we hold about you
6.2 Correction
You can update your account information at any time through:
- The MyAccount portal
- Contacting support
6.3 Deletion
You can request deletion of your data by:
- Deleting your account through MyAccount
- Contacting [email protected]
- Disconnecting specific integrations
6.4 Disconnect Integrations
You can revoke our access to connected services at any time:
- Through the ExForms Destinations settings
- Through the connected service's settings (e.g., QuickBooks Connected Apps)
6.5 Opt-Out
You can opt out of:
- Marketing communications (via unsubscribe link)
- Analytics tracking (contact support)
7. Cookies and Tracking
7.1 Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Session | Maintain login state | Session |
| Preferences | Remember your settings | 1 year |
| Analytics | Aggregate usage statistics | 1 year |
7.2 Do Not Track
We respect Do Not Track (DNT) browser signals for analytics cookies.
8. Children's Privacy
ExForms is not intended for use by children under 16. We do not knowingly collect information from children. If we discover we have collected information from a child, we will delete it promptly.
9. International Data Transfers
9.1 Data Location
Your data may be processed in:
- United States (primary data centers)
- European Union (for EU customers, where applicable)
9.2 Transfer Safeguards
For international transfers, we use:
- Standard Contractual Clauses (SCCs)
- Data processing agreements with all providers
- Encryption of all data in transit and at rest
10. QuickBooks Integration Specific
10.1 Intuit Data Practices
When you use the QuickBooks integration:
- Intuit's Privacy Policy also applies to your QuickBooks data
- We access only the QuickBooks data necessary for your configured sync operations
- We do not store copies of your QuickBooks business data
10.2 Disconnecting QuickBooks
To stop our access to QuickBooks:
- From ExForms: Go to Destinations → QuickBooks → Disconnect
- From QuickBooks: Go to Settings → Manage Apps → ExForms → Disconnect
When disconnected:
- We immediately delete your QuickBooks OAuth tokens
- We delete your QuickBooks connection configuration
- We cannot access your QuickBooks data
11. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes:
- We will update the "Last Updated" date
- We will notify you via email for significant changes
- Continued use after changes constitutes acceptance
12. Refund Policy
We want you to be satisfied with ExForms. If you are not completely satisfied with your purchase, we offer a straightforward refund policy.
12.1 Refund Window
| Subscription Type | Refund Period |
|---|---|
| Monthly Subscriptions | 14 days from purchase date |
| Annual Subscriptions | 14 days from purchase date |
| Upgrades | 14 days from upgrade date |
12.2 How to Request a Refund
To request a refund:
- Email: Send a refund request to [email protected]
- Subject Line: "Refund Request - [Your Email/Order ID]"
- Include: Your account email and reason for the refund (optional but helpful)
12.3 Refund Processing
- Refunds are typically processed within 5-10 business days
- Refunds are issued to the original payment method
- Upon refund, your subscription will be cancelled and access to premium features will end
12.4 Exceptions
Refunds may not be available for:
- Requests made after the 14-day refund window
- Accounts that have been suspended for Terms of Service violations
- Repeated refund requests (more than one refund per customer)
12.5 Payment Processor
Direct web payments and refunds are processed securely through FastSpring (fastspring.com), our authorized payment processor. FastSpring handles direct billing, taxes, and refund transactions on our behalf. Microsoft marketplace purchases are billed and refunded by Microsoft under Microsoft marketplace terms.
13. Contact Us
For privacy-related questions, requests, or technical support:
ExForms
Operated by: SC Evaldo Apps SRL
Address: Bd. Nicolae Iorga 59A, Bl. F1, Sc. A, Iași, 700214, Romania
Email: [email protected]
Website: exceltoforms.com
To Exercise Your Privacy Rights
Email: [email protected]
Subject: "Privacy Request - [Your Request Type]"
Refund Requests
Email: [email protected]
Subject: "Refund Request - [Your Email/Order ID]"
14. Additional Information for Specific Regions
14.1 European Union (GDPR)
If you are in the EU:
- Legal Basis: We process data based on contract performance, legitimate interests, and consent
- Data Controller: ExForms is the data controller for account data
- Data Processor: ExForms is a data processor for your business data
- DPO: Contact [email protected]
- Supervisory Authority: You have the right to lodge a complaint with your local supervisory authority
14.2 California (CCPA)
If you are a California resident:
- Right to Know: Request what data we collect and how we use it
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: We do not sell personal information
- Non-Discrimination: We will not discriminate against you for exercising your rights
© 2026 ExForms. All rights reserved.