Privacy Policy

ExForms Privacy Policy

Last Updated: January 17, 2026


This Privacy Policy describes how ExForms ("Company," "we," "us," or "our") collects, uses, and protects information when you use our services, including the ExForms Office Add-in and integrations with third-party services such as QuickBooks Online.


1. Information We Collect

1.1 Account Information

When you create an ExForms account, we collect:

Information Purpose
Email Address Account identification, communications, password recovery
Full Name Account personalization, support communications
Company Name Multi-tenant account organization
Subscription Details Service provisioning, billing

1.2 Integration Connection Data

When you connect third-party services (QuickBooks, Toggl, etc.):

Information Purpose Retention
OAuth Access Tokens Authenticate API requests to connected services Until you disconnect; stored encrypted in Azure Key Vault
OAuth Refresh Tokens Maintain continuous access without re-authorization Until you disconnect; stored encrypted
Workspace/Company IDs Identify which account to sync with Duration of connection
Connection Metadata Connection status, last sync time, error states Duration of connection

1.3 Usage Data

We automatically collect:

  • Sync Operation Logs: What types of data were synced, record counts, success/failure status
  • Error Logs: Technical details when errors occur (for troubleshooting)
  • Feature Usage: Which features you use (aggregate analytics)
  • Performance Metrics: Response times, processing durations

1.4 Transient Data (NOT Stored)

The following data is processed but NOT permanently stored:

  • Excel Data: Cell values, table data you send for synchronization
  • QuickBooks Business Data: Customer records, invoices, items, etc.
  • Document Content: PDF, Word, PowerPoint files processed for form filling

This data is:

  • Transmitted securely (TLS 1.2+)
  • Processed in memory on our servers
  • Immediately sent to the destination (QuickBooks, generated documents)
  • Never written to persistent storage

2. How We Use Your Information

2.1 Service Provision

We use your information to:

  • Authenticate you to ExForms and connected services
  • Process data synchronization requests
  • Generate filled documents (PDF, Word, PowerPoint)
  • Maintain your connections and configurations

2.2 Service Improvement

We use aggregated, anonymized data to:

  • Improve application performance
  • Identify and fix bugs
  • Develop new features
  • Optimize user experience

2.3 Communications

We may contact you for:

  • Service announcements and updates
  • Security alerts
  • Support responses
  • Billing and subscription matters

We do NOT sell your contact information or send marketing emails from third parties.

We may use or disclose information when required by:

  • Law enforcement requests with valid legal process
  • Court orders or subpoenas
  • Protection of our legal rights
  • Prevention of fraud or security threats

3. Information Sharing

3.1 Third-Party Services

When you connect integrations, we share data with those services:

Service Data Shared Purpose
QuickBooks Online (Intuit) Your Excel data mapped to QuickBooks fields Create/update QuickBooks records as you configured
Toggl Track Your Excel data mapped to Toggl fields Create/update Toggl records as you configured
Microsoft Authentication tokens via Office.js Enable Excel Add-in functionality

3.2 Service Providers

We use trusted service providers:

Provider Service Data Access
Microsoft Azure Cloud hosting, Key Vault Infrastructure provider; encrypted data only
DigitalOcean Cloud hosting Infrastructure provider; encrypted data only
FastSpring Direct payment processing Billing information only

3.3 We Do NOT Sell Your Data

We do not sell, rent, or trade your personal information or business data to third parties.


4. Data Security

4.1 Encryption

Data State Protection
In Transit TLS 1.2+ (HTTPS) for all connections
At Rest (Credentials) AES-256 encryption, Azure Key Vault with HSM
At Rest (Templates) AES-256 envelope encryption
Processing Isolated containers, memory-only processing

4.2 Access Controls

  • Role-based access control (RBAC) for our systems
  • OAuth 2.0 for third-party service authentication
  • No shared passwords; unique credentials per service

4.3 Infrastructure Security

  • SOC 2 Type II compliant cloud providers
  • Regular security audits
  • Automated vulnerability scanning
  • Container isolation for all processing

4.4 Incident Response

In the event of a security incident:

  • We will notify affected users within 72 hours
  • We will provide details of what data may have been affected
  • We will describe remediation steps taken

5. Data Retention

5.1 Retention Periods

Data Type Retention Period
Account Information Until account deletion + 30 days
OAuth Tokens Until you disconnect the integration
Connection Configurations Until you delete the connection
Sync Operation Logs 90 days
Error Logs 30 days
Transient Business Data Not retained (processed and discarded)

5.2 Account Deletion

When you delete your account:

  • Account data is marked for deletion immediately
  • All OAuth tokens are revoked and deleted
  • All configurations are deleted
  • Backup retention: 30 days maximum, then permanently deleted

6. Your Rights

6.1 Access and Portability

You have the right to:

  • Access your account information
  • Export your configuration data
  • Receive a copy of data we hold about you

6.2 Correction

You can update your account information at any time through:

  • The MyAccount portal
  • Contacting support

6.3 Deletion

You can request deletion of your data by:

  • Deleting your account through MyAccount
  • Contacting [email protected]
  • Disconnecting specific integrations

6.4 Disconnect Integrations

You can revoke our access to connected services at any time:

  • Through the ExForms Destinations settings
  • Through the connected service's settings (e.g., QuickBooks Connected Apps)

6.5 Opt-Out

You can opt out of:

  • Marketing communications (via unsubscribe link)
  • Analytics tracking (contact support)

7. Cookies and Tracking

7.1 Cookies We Use

Cookie Type Purpose Duration
Session Maintain login state Session
Preferences Remember your settings 1 year
Analytics Aggregate usage statistics 1 year

7.2 Do Not Track

We respect Do Not Track (DNT) browser signals for analytics cookies.


8. Children's Privacy

ExForms is not intended for use by children under 16. We do not knowingly collect information from children. If we discover we have collected information from a child, we will delete it promptly.


9. International Data Transfers

9.1 Data Location

Your data may be processed in:

  • United States (primary data centers)
  • European Union (for EU customers, where applicable)

9.2 Transfer Safeguards

For international transfers, we use:

  • Standard Contractual Clauses (SCCs)
  • Data processing agreements with all providers
  • Encryption of all data in transit and at rest

10. QuickBooks Integration Specific

10.1 Intuit Data Practices

When you use the QuickBooks integration:

  • Intuit's Privacy Policy also applies to your QuickBooks data
  • We access only the QuickBooks data necessary for your configured sync operations
  • We do not store copies of your QuickBooks business data

10.2 Disconnecting QuickBooks

To stop our access to QuickBooks:

  1. From ExForms: Go to Destinations → QuickBooks → Disconnect
  2. From QuickBooks: Go to Settings → Manage Apps → ExForms → Disconnect

When disconnected:

  • We immediately delete your QuickBooks OAuth tokens
  • We delete your QuickBooks connection configuration
  • We cannot access your QuickBooks data

11. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes:

  • We will update the "Last Updated" date
  • We will notify you via email for significant changes
  • Continued use after changes constitutes acceptance

12. Refund Policy

We want you to be satisfied with ExForms. If you are not completely satisfied with your purchase, we offer a straightforward refund policy.

12.1 Refund Window

Subscription Type Refund Period
Monthly Subscriptions 14 days from purchase date
Annual Subscriptions 14 days from purchase date
Upgrades 14 days from upgrade date

12.2 How to Request a Refund

To request a refund:

  1. Email: Send a refund request to [email protected]
  2. Subject Line: "Refund Request - [Your Email/Order ID]"
  3. Include: Your account email and reason for the refund (optional but helpful)

12.3 Refund Processing

  • Refunds are typically processed within 5-10 business days
  • Refunds are issued to the original payment method
  • Upon refund, your subscription will be cancelled and access to premium features will end

12.4 Exceptions

Refunds may not be available for:

  • Requests made after the 14-day refund window
  • Accounts that have been suspended for Terms of Service violations
  • Repeated refund requests (more than one refund per customer)

12.5 Payment Processor

Direct web payments and refunds are processed securely through FastSpring (fastspring.com), our authorized payment processor. FastSpring handles direct billing, taxes, and refund transactions on our behalf. Microsoft marketplace purchases are billed and refunded by Microsoft under Microsoft marketplace terms.


13. Contact Us

For privacy-related questions, requests, or technical support:

ExForms
Operated by: SC Evaldo Apps SRL
Address: Bd. Nicolae Iorga 59A, Bl. F1, Sc. A, Iași, 700214, Romania
Email: [email protected]
Website: exceltoforms.com

To Exercise Your Privacy Rights
Email: [email protected]
Subject: "Privacy Request - [Your Request Type]"

Refund Requests
Email: [email protected]
Subject: "Refund Request - [Your Email/Order ID]"


14. Additional Information for Specific Regions

14.1 European Union (GDPR)

If you are in the EU:

  • Legal Basis: We process data based on contract performance, legitimate interests, and consent
  • Data Controller: ExForms is the data controller for account data
  • Data Processor: ExForms is a data processor for your business data
  • DPO: Contact [email protected]
  • Supervisory Authority: You have the right to lodge a complaint with your local supervisory authority

14.2 California (CCPA)

If you are a California resident:

  • Right to Know: Request what data we collect and how we use it
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: We do not sell personal information
  • Non-Discrimination: We will not discriminate against you for exercising your rights

© 2026 ExForms. All rights reserved.