Privacy Policy
Last updated: July 11, 2026
This policy covers two separate scopes: (1) how GriffinForms handles data on this website (griffinforms.com), and (2) how the GriffinForms plugin handles data on your WordPress site. These are distinct — please read the section relevant to you.
Part 1 — This website (griffinforms.com)
Who we are
GriffinForms is a WordPress form builder plugin developed and maintained as an independent product. This website is our marketing and documentation site.
Data we collect on this site
- Basic analytics (page views, referrers) collected in aggregate.
- Form submissions you send us (e.g., contact forms) including the fields you provide and your IP address for abuse prevention.
- Server logs (IP address, user agent) used for security and troubleshooting.
We do not sell or share this data for advertising. It is used only to improve GriffinForms, respond to inquiries, and secure this service.
Cookies and tracking
- Essential cookies for site functionality (e.g., session management).
- Analytics cookies to understand aggregate usage. No cross-site advertising trackers.
Data retention
Contact submissions sent to us are retained only as long as needed to respond and maintain records of interactions. Server logs are rotated regularly.
Third-party processors
We may use standard infrastructure providers (hosting, CDN, email delivery, analytics) to operate this site. These providers act as processors and do not use your data for their own purposes.
Your rights
If you have submitted data to us through this site and wish to access or delete it, contact us using the address at the bottom of this page.
Part 2 — The GriffinForms plugin
Your site, your data
The GriffinForms plugin runs entirely on your own WordPress installation. As the site owner, you are the data controller for all form submissions collected through GriffinForms on your site. Configure consent, retention, and disclosure according to your own policies and applicable regulations.
- Form submissions are stored in your WordPress database unless you disable storage.
- Optional integrations (payments, email, spam protection) send data to the provider you select, only when configured by you.
- Logs and error reports remain on your site. We do not receive them unless you choose to share them with support.
- We do not collect or receive your site’s form submission data. GriffinForms does not send submission data to griffinforms.com.
Deactivation feedback
If you deactivate the GriffinForms plugin, you may optionally tell us why. This is the one case where the plugin sends data to GriffinForms, and only if you choose to submit feedback — selecting Skip & Deactivate sends nothing.
- What is sent, if you submit feedback: the reason you select, any optional comment you write, your site name and URL, and your plugin, WordPress, and PHP versions.
- Your administrator email address is included only if you tick the option to be contacted about your feedback. Otherwise no personal contact information is sent.
- Where it goes: the data is transmitted over HTTPS to GriffinForms-owned infrastructure (hosted on Cloudflare) and used to improve the plugin. Operator notifications are delivered through the Brevo transactional email service. If you consent to be contacted, your feedback is also raised as a support request in our Zoho Desk helpdesk so we can follow up with you.
- This is separate from your form submission data, which is never sent to GriffinForms (see above).
Third-party integrations on your site
Optional integrations you enable (e.g., Stripe, Mailgun, hCaptcha, Google Sheets) will process data according to their own privacy policies. Review those policies before enabling any integration.
Google API and Google Sheets integration
GriffinForms Pro includes an optional Google Sheets integration. When enabled by a site administrator, it uses Google OAuth 2.0 to connect a Google account and write form submission data to a Google Sheet owned by that account. This section documents how this integration interacts with Google user data in accordance with the Google API Services User Data Policy.
Data accessed
When the Google Sheets integration is connected, GriffinForms requests the OAuth scope https://www.googleapis.com/auth/drive.file. This scope grants access only to Google Drive files that GriffinForms itself creates, or files that the site administrator explicitly selects from their Google Drive using the built-in file picker. GriffinForms does not have access to any other files in the connected Google account. GriffinForms also reads the account’s email address and profile picture (from the stored token) solely to display the connected account in the plugin settings.
Data usage
GriffinForms uses the granted access exclusively to write form submission data to Google Sheets on behalf of the site administrator who initiated the OAuth connection. Depending on the spreadsheet mode configured in the integration settings:
- Auto mode: GriffinForms creates a new spreadsheet in the connected Google account the first time a submission is received for that form.
- Existing mode: the site administrator selects an existing spreadsheet from their Google Drive using a built-in file picker; GriffinForms then has access to that specific file only.
In both modes, GriffinForms only appends new submission rows and adds column headers as needed. It does not read, analyse, modify, or delete spreadsheet content beyond what it has written. This access is used solely on behalf of the site administrator — not on behalf of end users who submit forms. Google user data is never used for advertising, profiling, AI or ML model training, or any purpose other than writing form submission data to the administrator’s designated spreadsheet.
Data sharing
Google user data obtained through this integration is not shared with GriffinForms, its developers, or any third party. OAuth tokens are stored exclusively in the WordPress database of the site where the plugin is installed. Form submission rows are written directly from the WordPress site to the connected Google account’s spreadsheet.
During the OAuth connection flow, the browser is briefly redirected through griffinforms.com/oauth/google-sheets, which serves as a registered redirect URI to relay the authorisation code back to the WordPress site. This relay does not log, store, or retain any token data, authorisation codes, or user information.
Data storage and protection
OAuth tokens (access token and refresh token) are stored in the wp_options table of the WordPress site where GriffinForms Pro is installed. Their security is governed by the security practices of that WordPress installation. GriffinForms does not transmit, copy, or back up these tokens to any external server. Access tokens may be cached briefly in memory during a request cycle and are never written to logs or external storage. All communication between GriffinForms and Google APIs, and between the browser and the OAuth relay endpoint at griffinforms.com/oauth/google-sheets, occurs exclusively over HTTPS/TLS. Access to stored tokens is restricted to the WordPress installation itself; they are not exposed via any public-facing endpoint.
Data retention and deletion
OAuth tokens are retained for as long as the Google Sheets integration remains connected. A site administrator can disconnect the integration at any time from the GriffinForms settings, which permanently deletes all stored tokens from the WordPress database. Upon disconnection GriffinForms immediately loses all access to the connected Google account. Administrators can also revoke access independently from myaccount.google.com/permissions. Submission data already written to a Google Sheet is not affected by disconnection and remains under the account owner’s control in Google Sheets.
Limited Use
GriffinForms’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
Questions about this policy? Reach out at .