Terms of service

Rules for using FormTo's website, dashboard, API, and hosted form endpoints.

Last updated: April 6, 2026

Agreement

By accessing or using FormTo's websites, applications, APIs, and related services (the "Services"), you agree to these Terms of service ("Terms"). If you use the Services on behalf of an organization, you represent that you have authority to bind that organization. If you do not agree, do not use the Services.

Definitions

In these Terms, the following words have the meanings set out below:

  • "Services"— FormTo's hosted form endpoints, web dashboard, API, webhook delivery, email notifications, export features, and all related functionality described on our website or in-product.
  • "Customer"(also "you", "your") — the individual or legal entity that registers an Account and uses the Services, including free and paid plan users.
  • "End User" — any natural person who submits data through an HTML form, script, or other client that the Customer has configured to post to FormTo-hosted endpoints.
  • "Submission Data" — the payload (field names, values, and associated metadata such as timestamps and IP address) received when an End User submits a form.
  • "Content" — form configurations, custom redirect URLs, webhook settings, email templates, and any other data or materials the Customer uploads or configures within the Services.
  • "API" — the programmatic interfaces provided by FormTo, accessible via HTTPS, used to manage forms, retrieve submissions, and interact with other product features.
  • "Account" — the registered account created by a Customer to access the Services, associated with a verified email address.
  • "FormTo"(also "we", "us", "our") — the operator of the FormTo platform, a business registered in Poland.

Description of the Services

FormTo provides hosted endpoints that accept form submissions, a dashboard to manage forms and view submissions, notifications (including email), webhooks, exports, and related features described on our website and in-product. We may modify, add, or discontinue features with reasonable notice where practicable.

Eligibility

To create an Account and use the Services you must: (a) be at least 18 years of age, or have reached the age of legal majority in your jurisdiction, whichever is higher; (b) have the legal capacity to enter into binding contracts; and (c) if acting on behalf of a legal entity, have authority to bind that entity to these Terms.

The Services may be used for both commercial and non-commercial purposes, subject to plan limits and these Terms. We reserve the right to refuse service to anyone at our discretion, consistent with applicable law.

Accounts

You must provide accurate registration information and keep credentials secure. You are responsible for activity under your account. Notify us promptly at contact@formto.dev if you suspect unauthorized access. Authentication may be provided by a third party (e.g. Clerk); their terms may also apply.

Acceptable use

You agree not to:

  • Violate applicable law or infringe others' rights.
  • Use the Services to send spam, phishing, malware, or deceptive content, or to harvest data without proper authority.
  • Attempt to probe, scan, or test vulnerability of our systems without authorization, or bypass rate limits or security measures.
  • Misuse API keys or share them in public code, client-side bundles, or repositories. API keys are for server-side or otherwise secure use only.
  • Use the Services in a way that materially harms other customers, end users, or our infrastructure.

We may suspend or terminate access for violations. See also our Security & reliability overview.

Free plan limits

The Free plan is subject to hard limits on monthly submissions (currently 50). Forms are unlimited on all plans. These limits are presented in the app and on our Pricing page and may change with reasonable notice.

Customers who approach or exceed Free plan limits may experience throttling, queuing of incoming submissions, or temporary suspension of the affected form endpoint without prior individual notice. We will not delete Submission Data solely due to quota overrun, but incoming submissions beyond the monthly cap may be rejected. Upgrading to a paid plan immediately restores full capacity.

Form submissions and your end users

You control how forms are embedded and what data you collect from end users. You are responsible for lawful collection, notices, consents, and rights requests toward your end users. You represent that you have a lawful basis to send submission data to FormTo for processing. We process such data to provide the Services as described in our Privacy policy.

API and integration terms

Access to the API is subject to rate limits described in the API documentation and may vary by plan. We reserve the right to throttle or temporarily block requests that exceed these limits or that we reasonably believe threaten service stability.

We may release new API versions and deprecate older ones. We will provide a minimum of 90 days' notice before removing or breaking-changing a stable API endpoint, except where immediate action is required for security or legal reasons. No SLA (Service Level Agreement) is provided on the Free tier; SLA commitments are stated explicitly on the plan description where applicable.

API keys issued under the Professional plan or higher are credentials that grant programmatic access to your Account data. You are solely responsible for safeguarding API keys. Do not embed API keys in client-side code, public repositories, or any environment where they may be exposed to third parties.

Fees and payment

Paid plans, taxes, and billing cycles are presented at checkout or in the app. Payments are processed by a third-party processor (Polar.sh). Unless stated otherwise, fees are non-refundable except as required by law or our refund policy below. You authorize us and our payment partners to charge your payment method for applicable fees. Downgrades or cancellations take effect at the end of the current billing period unless otherwise specified.

Refund policy

Free tier: No charges apply; no refunds are applicable.

Paid plan cancellation: If you cancel a paid subscription, your plan remains active until the end of the current paid billing period, after which your account reverts to the Free tier. We do not provide pro-rata refunds for unused time within a billing period unless required by applicable law (including mandatory consumer protection rights described below).

Billing errors: If we charge you incorrectly (e.g. due to a technical error), we will promptly refund the excess amount once the error is confirmed. To report a billing discrepancy, contact us at contact@formto.dev with your Account email and a description of the issue.

Consumer withdrawal right (EU / Poland)

If you are a consumer (a natural person acting outside of trade or professional activity) residing in the European Union or another jurisdiction that implements EU Directive 2011/83/EU on consumer rights, including under Polish law (Ustawa z dnia 30 maja 2014 r. o prawach konsumenta), you have the right to withdraw from a distance contract within 14 calendar days from the date of purchase, without giving reasons.

However, by proceeding with the purchase and requesting immediate activation of a paid plan, you expressly acknowledge and agree that the Services begin immediately upon purchase and that you lose your right of withdrawal once the service has been fully performed, in accordance with Art. 38(1)(a) of Directive 2011/83/EU and Art. 38 pkt 1 of the Polish Consumer Rights Act. If the service has not yet been fully performed, you remain entitled to a proportional refund for the unperformed portion.

To exercise a withdrawal right (where applicable), notify us at contact@formto.dev before the 14-day period expires. A plain-language statement of your intention to withdraw is sufficient; you do not need to use a specific form.

Data processing — controller and processor

In the context of Submission Data (data submitted by End Users through Customer-configured forms):

  • The Customer is the data controller — you determine the purposes and means of processing End Users' personal data.
  • FormTo is the data processor— we process Submission Data solely on the Customer's instructions and as necessary to provide the Services.

The parties agree that this section, together with the Privacy policy, constitutes a Data Processing Agreement ("DPA") addendum in satisfaction of the requirements of Article 28 of Regulation (EU) 2016/679 (GDPR). FormTo will: (a) process Submission Data only on documented instructions from the Customer; (b) ensure that persons authorized to process such data are bound by confidentiality; (c) implement appropriate technical and organizational security measures; (d) assist the Customer with data subject rights requests insofar as possible given the nature of the processing; (e) delete or return Submission Data upon termination of the Services as elected by the Customer; and (f) provide information necessary to demonstrate compliance with Article 28 obligations.

For Customer's own Account data (email, profile, billing information), FormTo acts as an independent controller and processes such data as described in our Privacy policy.

Subprocessors

FormTo engages the following categories of subprocessors to deliver the Services. By accepting these Terms, you grant general authorization for FormTo to use subprocessors:

  • Clerk — authentication and identity management
  • Polar.sh — subscription and billing management
  • Supabase — database, file storage, and serverless functions (EU Frankfurt)
  • Netlify / Railway / Vercel — hosting and infrastructure
  • Resend — transactional email delivery

FormTo maintains an up-to-date list of subprocessors and will notify Customers of any addition or replacement of subprocessors with at least 14 days' prior notice via email or in-app notification. If a Customer has a reasonable, documented objection to a new subprocessor on data protection grounds, they may raise the objection with us before the change takes effect.

Security obligations

FormTo's obligations

FormTo commits to: (a) encrypting Submission Data in transit using TLS; (b) implementing access controls so that only authorized personnel access Customer data on a need-to-know basis; (c) maintaining an incident response process; and (d) providing a non-legal summary of our security measures on our Security & reliability page.

Customer's obligations

You are responsible for: (a) keeping Account credentials and API keys confidential; (b) not embedding server-side API keys in client-side code or public repositories; (c) ensuring that End Users are informed about data collection through your forms; and (d) promptly notifying us if you become aware of unauthorized access to your Account or API keys.

Data breach notification

In the event that FormTo becomes aware of a personal data breach affecting Submission Data processed on behalf of a Customer, we will notify the affected Customer(s) within 72 hours of becoming aware, in accordance with Article 33 of the GDPR. The notification will include, to the extent available: a description of the nature of the breach; categories and approximate numbers of individuals affected; likely consequences; and measures taken or proposed to address the breach.

The Customer, as controller, bears responsibility for notifying the relevant supervisory authority (e.g. UODO in Poland) and, where required, affected End Users, in accordance with applicable data protection law.

Service levels and support

We aim for reliable operation. Specific uptime commitments may apply only where expressly stated for your plan (e.g. SLA references on pricing). General status information may appear on our Status page. Support channels and response expectations depend on your plan.

Intellectual property

We retain all rights in the Services, branding, and documentation. You retain rights in your content (including form configurations and submission data you control). You grant us a limited license to host, process, transmit, and display your content solely to provide and improve the Services.

Disclaimers

THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED OR ERROR FREE.

Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT WILL FORMTO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR EXEMPLARY DAMAGES, OR LOSS OF PROFITS, DATA, OR GOODWILL, ARISING FROM OR RELATED TO THESE TERMS OR THE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY. OUR AGGREGATE LIABILITY FOR CLAIMS ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICES IN ANY TWELVE-MONTH PERIOD IS LIMITED TO THE GREATER OF (A) THE AMOUNTS YOU PAID US FOR THE SERVICES IN THAT PERIOD OR (B) ONE HUNDRED US DOLLARS (USD $100), EXCEPT WHERE LIABILITY CANNOT BE LIMITED UNDER MANDATORY LAW (SUCH AS DEATH OR PERSONAL INJURY CAUSED BY NEGLIGENCE, OR STATUTORY CONSUMER RIGHTS).

Indemnity

You will defend and indemnify us and our affiliates, officers, and employees against third-party claims, damages, and costs (including reasonable attorneys' fees) arising from your use of the Services, your content, your forms and end-user relationships, or your breach of these Terms, except to the extent caused by our willful misconduct.

Force majeure

Neither party will be liable for any delay or failure in performance resulting from causes beyond that party's reasonable control, including but not limited to: acts of God, natural disasters, epidemic or pandemic, war, terrorism, riot, civil unrest, government action or regulation, court orders, labor disputes, power failures, internet outages, or failures of third-party infrastructure or services (including cloud providers, DNS providers, or authentication services). The affected party will notify the other promptly and take reasonable steps to mitigate the impact.

Termination

You may stop using the Services at any time. We may suspend or terminate access for breach, risk, legal obligation, or extended inactivity as permitted by law. Upon termination, your right to use the Services ceases. Provisions that by nature should survive (including disclaimers, limitations, indemnity, and governing law) will survive.

Assignment

You may not assign, transfer, or delegate these Terms or any rights or obligations hereunder without our prior written consent. Any purported assignment in violation of this section is null and void.

FormTo may assign or transfer these Terms, in whole or in part, in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of our assets, provided that the acquiring entity assumes all obligations under these Terms. We will provide reasonable notice to Customers of any such assignment.

Severability

If any provision of these Terms is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction, that provision will be limited or eliminated to the minimum extent necessary so that the remainder of these Terms continues in full force and effect without being impaired or invalidated.

Notices

Official legal notices to FormTo (e.g. breach of contract, data protection requests) must be sent by email to contact@formto.dev with a subject line clearly indicating the nature of the notice. We will acknowledge receipt by email; notices are deemed received upon our written acknowledgment.

Notices from FormTo to you will be sent to the email address registered to your Account. You are responsible for keeping your registered email address current. Notices are deemed received 24 hours after the email is sent (unless we receive a delivery failure notification).

Governing law and disputes

These Terms are governed by the laws of Poland, without regard to conflict-of-law rules, subject to mandatory consumer protections in your country of residence if you are a consumer. Courts located in Poland shall have exclusive jurisdiction for disputes arising from these Terms, except where mandatory law grants you the right to bring claims in your home courts.

Enterprise and custom terms

Enterprise customers may execute a separate agreement that supersedes conflicting provisions in these Terms. Contact contact@formto.dev for enterprise inquiries.

Entire agreement

These Terms, together with our Privacy policy and Cookie notice, constitute the entire agreement between you and FormTo with respect to the Services and supersede all prior and contemporaneous agreements, representations, and understandings, whether written or oral, relating to the same subject matter. In the event of a conflict between these Terms and any separate written agreement executed by both parties, the terms of the separate written agreement shall prevail.

Changes

We may update these Terms. We will post the new version on this page and update the "Last updated" date. If a change is material, we will provide reasonable notice (e.g. email or in-app). Continued use after the effective date constitutes acceptance of the revised Terms, except where stricter consent is required by law.

Contact

Legal or contractual questions: contact@formto.dev.

Privacy · Cookies · Home