Overview
Form Workflow Plus respects our customers' privacy, and keeping our customers' data protected at all times is our highest priority.
This security policy provides a high-level overview of the security practices put in place to achieve that objective.
Have questions or feedback? Feel free to reach out to us at contact@formworkflowplus.com
Infrastructure
us-central1). Google provides strong security measures to protect this infrastructure and is compliant with most certifications. You can read more about their practices here.
Authentication and access control
spreadsheets.currentonly, which limits access to the spreadsheet the add-on is opened in rather than your whole Drive.
Data isolation
Each customer account is provisioned with its own dedicated PostgreSQL schema. Application data belonging to one account is stored separately from every other account rather than sharing rows in common tables.
Data encryption
What we store — and what stays in your Google account
The content of your Google Forms, Google Sheets and Drive attachments stays in your own Google Workspace account. We never copy it out. The application data we hold is limited to your subscription details, the members you invite to your team, the IDs and names of the Forms and Sheets where the product is enabled, and the form responses needed to drive the approval workflow. This is described in full in our Privacy Policy.
Data retention and removal
Payment information
All payment processing is outsourced to Stripe, which is certified as a PCI Level 1 Service Provider. We don’t collect, store or transmit any card data and are therefore not subject to PCI obligations.
Logging
Our backend and add-on emit application and request logs to Google Cloud Logging, providing an audit trail of application activity.
Business continuity and disaster recovery
Our database provider takes automated backups of the managed PostgreSQL instance, and all backups are encrypted. Our services are deployed as immutable revisions, so a deployment can be rolled back to a previous known-good revision.
Sub-processors
We use a small, named set of sub-processors — Google, Supabase, Stripe and Hubspot — each engaged under a data processing agreement. The current list is maintained in our Privacy Policy.
Compliance
Responsible disclosure
We encourage everyone who practices responsible disclosure, and complies with our policies and terms of service, to report security issues to us. Please avoid automated testing and only perform security tests with your own data. Do not disclose any information regarding the vulnerabilities until we have fixed them. You can report vulnerabilities by contacting contact@formworkflowplus.com. Please include a proof of concept. We will respond as quickly as we can and will not take legal action against you if you have followed the rules above.