Privacy Policy

Last updated: 24 August 2026

This Privacy Policy describes how your personal information is collected, used, and shared when you visit sureforms.com, when you use the SureForms plugin on a site we operate, and when you install the SureForms plugin on a site of your own.

When a form built with SureForms appears on someone else’s website, that website’s owner decides what data their forms collect and is responsible for their own privacy policy. This policy covers our own sites, and it covers the specific points where our own services sit in the data path on a site you run. Those points are described under Using SureForms On Your Own Website below.

Who We Are

We are Brainstorm Force US LLC. You can find more information about us, including our full address, on our company website.

Contact for all privacy matters: [email protected]

What Personal Information We Collect

When you visit our website, we automatically collect information about your device, including your web browser type, IP address, and time zone. As you browse the Site, we also collect information about the individual web pages or products you view, what websites or search terms referred you to the Site, and how you interact with the Site.

Cookies and Similar Technologies

Cookies are small data files placed on your device, often including an anonymous unique identifier. We use cookies and similar technologies (such as pixels and tags) across our sites for the following purposes:

  • Essential — required for core site functionality, including security, load balancing, and making a form work as you expect
  • Functional — remember your preferences and settings
  • Analytics — help us understand how visitors use our sites and test improvements to site design
  • Marketing — used for advertising measurement and remarketing

Our consent system is configured to prevent non-essential analytics and marketing technologies from running until the required consent has been provided. Functional technologies are handled according to their purpose and the applicable consent requirements. You can change your preferences at any time by clicking Cookie Preferences in the footer.

We honor the Global Privacy Control (GPC) signal where required by law. If your browser or extension sends a GPC signal, we treat it as a valid request to opt out of the sale or sharing of your personal information.

A list of the cookies and tracking technologies our scanner detects on this site is available on our Cookie Policy page, linked from the cookie preference banner. That list is updated when the scanner detects a change. A scanner sees what loads on the pages it visits, so a technology that appears only on a page it has not yet scanned may not be listed straight away.

Retention: Records of your cookie consent choices are retained for up to 365 days, or less if manually cleared sooner, so we can demonstrate compliance with applicable consent requirements and honor your prior preferences on return visits.

Cookies We Set Ourselves

These are set by the SureForms plugin. They exist to make a form work and are not used for advertising or analytics.

CookiePurposeHow long it lastsCategory
srfm_partial_resume_<form id>Lets you return to a partly completed form and carry on where you left off7 daysEssential to the save-and-resume feature. Set only on forms where that feature is switched on, because the feature cannot work without it. If you do not want it, complete the form in one sitting or contact us and we will take your submission by email
srfm_pro_custom_app_user_session_idIdentifies your session while you are signed in to a SureForms-built application on this siteUntil you close your browserEssential

Third-party services loaded on pages carrying a form may set their own cookies once they run. In practice this means Stripe (__stripe_mid, __stripe_sid) on a page that takes a payment, and Google reCAPTCHA (_GRECAPTCHA), hCaptcha, or Cloudflare Turnstile on a page protected against spam. Those cookies are set by those companies under their own privacy policies. Because they appear only on pages carrying a payment or a captcha, they may not be listed by our scanner until such a page is scanned. See the tables further down this page.

Forms You Submit On Our Site

When you submit a form on our Site, we store the answers you gave. Alongside those answers we may also record technical details about the submission, so we can tell genuine submissions from spam and troubleshoot problems.

  • The name of your browser and the operating system or device you used
  • The address of the page the form was submitted from
  • Your IP address, where IP logging is switched on for that form

Separately from the record we store, a copy of your IP address may be included in the notification email a form sends to us, or in a hidden field on the form, where the form has been set up to include it. This can happen whether or not IP logging is switched on for that form. Notification emails are retained with the rest of our email records.

If a form accepts file attachments, the files you upload are stored with your submission. Where the form is connected to an external storage service, a copy of the file is also sent to that service, see Where Your Form Submissions Go below.

If a form offers a save and resume option, or saves your progress as you type, we also store the partial answers you have entered so far along with your IP address, so the entry can be matched back to you when you return.

We use your IP address for a short anti-abuse check on each submission. For that check the address is converted using a one-way hashing process, and the original address used for that check is discarded within one minute. The hash is not stored with the form submission.

Comments

When you leave comments on the site, we collect the data shown in the comments form, along with your IP address and browser user-agent string, to help with spam detection.

An anonymized string created from your email address (a hash) may be shared with the Gravatar service to check if you are using it. Gravatar’s privacy policy is available here. After your comment is approved, your profile picture is visible to the public alongside your comment.

Contact Forms

Information submitted through contact forms on our Site is sent to our self-hosted support desk.

We may collect information submitted through contact forms, including (but not limited to) your first and last name and email address. We use it to answer you and to manage your request, and it is stored in our self-hosted CRM for that purpose. Submitting a contact form does not add you to our marketing list. We only send you marketing email if you separately opt in, as described under Newsletter Emails below.

Support

To help with our products, we may ask for temporary access to your website, either your live site or a staging copy, whichever you prefer, such as an admin login or FTP/database credentials. We may also ask you to share a license key, name, or email address.

Troubleshooting typically takes place directly on your site itself, and in these cases we do not transfer, export, or store your site’s data on our own servers. We recommend a staging copy where practical, but understand this is not always feasible for every customer.

In some cases, particularly for more complex issues, we may create a copy of your website on our own servers to investigate the problem. Once the issue is resolved, we delete these copies from our systems.

Information submitted through support forms is managed through our self-hosted support portal.

A few important points about access shared with our support team:

  • We use any access you provide strictly for debugging your specific issue
  • We do not copy site data to our own systems, except where you authorize us to create a temporary troubleshooting copy as described above, which we delete once the issue is resolved
  • We do not share your access or your data with anyone outside the company, other than the service providers listed in this policy that host and operate our support systems
  • Where you are able to share a staging site rather than a live one, and to keep a working backup of anything shared with us, we recommend doing so

Retention: Where troubleshooting happens on your site directly rather than on data transferred to us, there is no site-data copy for us to retain, and you are responsible for rotating or revoking any login, FTP, or database credentials you shared with us once your issue is resolved. We have no further use for them once the support ticket closes. Where we have created a copy of your site on our own servers for investigation, we delete that copy once the issue is resolved.

We retain support ticket records, including any screenshots, logs, or other materials shared as part of a ticket, for 3 years from the date the ticket is closed. We do this so we can refer back to how a past issue was resolved if it recurs, and to analyze recurring issues internally to improve our products and reduce future support volume.

If your site contains your own customers’ or visitors’ personal data (for example, order or form submissions) that we may view while troubleshooting on your site, we access that data only as necessary to resolve your issue and do not retain or use it beyond that purpose. You remain responsible for your own compliance obligations toward your site’s visitors and customers.

Purchase

If you purchase products or services from us, our payment gateway provider may require your credit card and billing information to process the transaction. Credit card details are not stored by us on any internal or external database accessible to us.

We use payment providers that state they maintain applicable PCI DSS compliance for their payment services. PCI DSS is administered by the PCI Security Standards Council.

When you make or attempt a purchase, we verify your card through a payment gateway and collect information including your name, billing address, shipping address, payment information, email address, and phone number.

Where a payment is taken through a form on our Site, the payment is processed by Stripe or PayPal. To help those providers detect fraudulent transactions, the record they create for your payment includes your IP address. In Stripe’s case the address is stored on the customer record they hold and is retained under their own retention rules. Payment requests to Stripe are routed through a service we operate at api.sureforms.com, which passes the request on to Stripe and does not retain your card details.

Retention: Billing and transaction records are retained for as long as your account or license remains active, including to support plan renewals. Because we are subject to tax, accounting, and audit-related legal obligations, financial records are retained for the period required by applicable law even after account deactivation or a data deletion request. This is a standard, legally recognized exception to deletion rights, not a workaround, and applies specifically to financial and transaction records rather than personal information generally.

Information We Receive When You Set Up the Plugin

When you complete the SureForms setup wizard on your website, the plugin sends us your email address, first name, last name, and the domain of the site you are setting up. We receive this at metrics.brainstormforce.com.

We use it to help you get started with the product and to send you service messages about the plugin, such as setup guidance, security notices, and important product changes. Setting up the plugin does not sign you up for marketing email. Product announcements and offers are sent only if you separately opt in, as described under Newsletter Emails below.

This is separate from the optional usage information described in the next section, and separate again from license activation. Unlike that information, it identifies you personally.

Retention: These records are retained for as long as we have a relationship with you, and you can ask us to delete them at any time by writing to [email protected]. Opting out of our emails does not by itself delete the record; tell us if you want both.

Information About Your Website and Server Configuration

When you use our WordPress products, and only if you have opted in to usage tracking, we may receive website and technical usage information about your site, including (but not limited to) whether SSL is installed, Curl/PHP/MySQL versions, PHP ini settings, server software, WordPress version and language, timezone, whether the site is a Multisite installation, debug settings, site URL, active plugins and theme, and BSF Updater version.

Most of this describes software and server configuration rather than a person. Some of it, such as your site URL, can be connected to you or to your account, so we do not treat this information as categorically non-personal and we handle it under this policy.

This is switched off unless you turn it on, and you can turn it off again at any time. Learn more here.

We collect it to develop better, more compatible software and serve our customers more effectively.

License Keys

A license key is required to validate your purchase and unlock benefits like automatic updates, developer support, and extra resources. When you activate a license key, we receive your website URL, name, and email address, and we keep records of every website URL where the key has been activated.

Retention: License activation records are retained while the license is active, and afterwards for the period reasonably necessary for account history, support, fraud prevention, tax and accounting obligations, and dispute handling.

Using SureForms On Your Own Website

When you run SureForms on a site of your own, you decide what your forms collect, and you are responsible for the privacy policy shown to your visitors. Most of what the plugin does stays on your server. There are three points where information reaches us, and they are ours to disclose:

  • Payments. If you take payments with Stripe through a SureForms form, the payment request is routed through a service we operate at api.sureforms.com before it reaches Stripe. Your visitor’s payment details pass through our infrastructure in transit. We do not retain card details.
  • Google Sheets and Google Drive. Authorization for these two connections is brokered through api.sureforms.com, so our infrastructure sits in the authorization path between your site and Google.
  • Setup. The setup wizard sends us your own name, email address, and site domain, as described under Information We Receive When You Set Up the Plugin above. This is about you as our customer, not about your visitors.

Two further points are worth knowing even though the data does not reach us. The plugin’s email summary includes a typeface loaded from Google Fonts, which means the recipient’s email application contacts Google when the message is opened. And several features of the plugin contact third parties directly from your server — geolocation, spam-check verification, and payment providers, as described in Information We Send To Third Parties From Our Servers below. Those transfers happen from your site to those companies. They are not visible to us, and a cookie banner cannot stop them, so they belong in your own privacy policy.

Third-Party Services Loaded On Our Pages

Some pages on our Site load files from other companies. When your browser fetches one of those files, that company receives your IP address and basic details about your browser. The services below load only on pages that use the feature they belong to. A form that uses no captcha, no custom font, no payment, and no address autocomplete loads none of them.

ServiceWhy it loadsWhen it loadsHow we treat it
Google reCAPTCHA (Google LLC)Spam and abuse protection for formsOn pages with a reCAPTCHA-protected formLoads with the page, for fraud and abuse prevention. See the note below if you would rather not be assessed this way
hCaptcha (Intuition Machines, Inc.)Spam and abuse protection for formsOn pages with an hCaptcha-protected formLoads with the page, for fraud and abuse prevention
Cloudflare Turnstile (Cloudflare, Inc.)Spam and abuse protection for formsOn pages with a Turnstile-protected formLoads with the page, for fraud and abuse prevention
Stripe.js (Stripe, Inc.)Collects card details securely and screens for fraudOn pages with a form that takes a paymentLoads with the page, to take a payment you have chosen to make
Google Maps and Places (Google LLC)Suggests and completes addresses as you typeOn pages with a form using address autocompleteLoads with the page, to run the address field you are filling in
Google Fonts (Google LLC)Supplies a Google-hosted typeface where a page or a form is set up to use oneOnly on those pages. The typefaces our own theme uses are served from our own servers, not from GoogleLoads with the page. We treat the typeface as part of presenting the page, not as tracking

None of these is used by us for advertising, analytics, or profiling. That is why they sit outside our marketing and analytics categories. Whether a particular technology can load before you answer the cookie banner depends on the technology, the purpose it serves, and the rules that apply where you are, rather than only on how we use it. We review them on that basis, and where consent is required for one of them we will place it behind the banner and update this policy and our cookie list before doing so. The cookies these companies set once they run are described under Cookies We Set Ourselves above.

Google reCAPTCHA in particular analyzes how you interact with the page in order to score whether you are a real visitor. If you would rather not be assessed this way, please contact us at [email protected] and we will accept your submission by email instead.

Information We Send To Third Parties From Our Servers

Separately from the files your browser loads, our servers send a small amount of information to other companies while handling your visit or your submission. Because this happens on our side, it is not something your browser settings or a cookie banner can control.

  • Country lookup. To pre-select the right country on a phone number field, or to apply country-based limits on who may submit a form, we send your IP address to a geolocation provider, ipapi.co, operated by Kloudend, Inc., and receive back a two-letter country code. We keep the answer in a short-lived cache, keyed to a one-way hash of your IP address, so we do not have to ask again.
  • Spam checks. When you submit a protected form, the token generated by reCAPTCHA, hCaptcha, or Turnstile is sent to that provider to be verified, together with your IP address.
  • Payments. Payment details you enter are sent to Stripe or PayPal to take the payment, as described under Purchase above.

Who We Share Your Data With

We do not sell or trade your personal information for money.

Some of our advertising and analytics tools involve sharing personal information with third parties for cross-context behavioral advertising, as that term is defined under California law, meaning those partners may use information about your activity on our sites to show you relevant ads elsewhere. This sharing only happens for the categories marked below, and only after you have provided consent through our cookie preference banner, or is subject to your California opt-out rights described further down.

CategoryService (domain detectedWhat they receivePurposeSale / Share / Service Provider
Tag managementGoogle Tag Manager (googletagmanager.com)IP address, browser and device information, page URLLoads and manages our other scripts and tags, and reads your consent status to decide which may runService provider, not sold or shared. See the note below on how tags behave before you answer the banner
Advertising / conversion measurementGoogle Ads and DoubleClick (googleads.g.doubleclick.net, ad.doubleclick.net, stats.g.doubleclick.net, www.google.com, www.google.fi)Page views, device and browser identifiers, cookiesAd performance measurement, remarketing, targeted advertisingShared for cross-context behavioral advertising
Advertising / conversion measurementMeta Pixel (connect.facebook.net, www.facebook.com)Page views, device and browser identifiers, cookies, and only where you have consented, hashed contact information via Meta’s Advanced MatchingAd performance measurement, remarketing, targeted advertisingShared for cross-context behavioral advertising
Website analyticsGoogle Analytics (region1.analytics.google.com)Page views, device and browser identifiers, cookiesUnderstand site usage. GA4 data may also build Google Ads audiences via Ads LinkingShared for cross-context behavioral advertising
Performance analyticsCloudflare Web Analytics, served through our own domainIP address, request metadata, page URL, and page timing informationMeasure how quickly our pages load. It sets no advertising or analytics cookie and is not linked to advertising audiencesService provider, not sold or shared. Loads with the page
SEO and backlink analyticsAhrefs (analytics.ahrefs.com)Page views, referrer, device informationMeasure organic search performanceService provider, not sold or shared
On-site experimentationSigmize (api.sigmize.com)Browsing behavior, page interactions, assigned test variantA/B testing to improve user experienceService provider, not sold or shared
AI chat supportPowerful Docs (app.powerfuldocs.com, phstaging.bsf.io)Chat messages, name, email if provided during the conversationAI-powered chat assistance, loads after you provide consentService provider, not sold or shared
Video embedsYouTube (www.youtube.com, youtu.be)Page views, device and browser identifiers, standard platform cookiesDisplay embedded video content, loads after you provide consentShared, loads after consent
Payments and checkoutSureCart (js.surecart.com), Stripe, PayPalBilling and payment details, IP addressTake and process payments and manage your licenseService provider, not sold or shared
Google Fonts (fonts.googleapis.com)Serve a Google-hosted typeface on the pages that request oneIP address, browser informationOur own theme typefaces are self-hosted, so this appears only where a page or form uses a Google-hosted fontService provider, not sold or shared
Image optimization CDNShortPixel (cdn.shortpixel.ai)IP address, request metadataServe optimized images. Classed as essential and loads before you answer the banner, because pages would not render correctly without itService provider, not sold or shared
WordPress core servicesWordPress.org (s.w.org)Basic request metadataCore WordPress functionality such as emoji support and update checksService provider, not sold or shared
Content delivery and securityCloudflareIP address, request metadataSite performance, security, and email address obfuscationService provider, not sold or shared
Email deliveryAmazon SESEmail addressTransactional and marketing email, sent from our serversService provider, not sold or shared
Profile picturesAutomattic Inc. (Gravatar)Hashed email addressShow a profile picture next to a comment, on pages that have commentsService provider, not sold or shared
Affiliate attributionAffiliateWP cross-domain trackerReferral and click identifiersTrack and pay affiliate referralsService provider, not sold or shared

How we classify these recipients: the last column reflects the written agreement and data-processing terms we have in place with each provider, and the way we have configured the service. It is our assessment rather than a guarantee about a provider’s own practices, and we review it when we add a provider or change a configuration.

How tags behave before you answer the banner: our consent tool controls when advertising and analytics tags may run. Depending on the page and the rules that apply where you are, either our tag container is not loaded at all until you answer the banner, or it loads with Google Consent Mode signalling that consent has not been given, which lets it read your choice while sending no identifiers and setting no advertising or analytics cookies. In either case, no advertising or analytics cookie is set, and no identifier is sent to Meta or to Google Ads, until you have consented to marketing. Meta’s Advanced Matching, which lets Meta match hashed contact information to a Meta account for better ad targeting, is active only for visitors who have consented to marketing cookies.

Cross-BSF-product tracking: Because Brainstorm Force operates multiple distinctly branded product sites (SureForms, Astra, Spectra, ConvertPro, and others), each site runs its own independent cookie consent tool. Your consent choice on one BSF site does not carry over to another. When you visit any BSF-operated site, you will see that site’s own cookie banner, and that site applies its own consent configuration, so technologies that require consent run according to the choice you make there. If you want to opt out across multiple BSF properties, you will need to do so on each site individually.

Where Your Form Submissions Go

If you submit a form on our Site, your answers, and any files you attached, may additionally be delivered to a service we have connected to that form. Where a connection is active, that provider receives the field values the form is set up to send it, which normally includes your name, email address, and any other contact details you entered, and processes them under its own privacy policy.

We send form data to a connected service only where that integration has been configured for the form. We do not provide those submissions to those services for our own targeted-advertising purposes, and each provider processes the data under its own terms and the configuration selected. If you would like to know exactly which services a particular form sends data to, write to us at [email protected].

Some of the integrations available in SureForms deliver submissions to another plugin running on this same server, for example our own self-hosted CRM. Where that is the case, your submission does not leave our infrastructure and no third party receives it.

Authorization for our Google Sheets and Google Drive connections is handled through a service we operate at api.sureforms.com.

How Long We Keep Your Data

We keep personal information only for as long as we need it for the purpose we collected it, or for as long as the law requires. In practice:

  • Form submissions, including any files attached to them, are retained according to the retention setting configured for the relevant form. Where automatic deletion is enabled, the configured schedule controls when the entry and any attached files are removed.
  • Partially completed forms are kept for up to 7 days so you can resume them, then removed.
  • Country-lookup results are cached for up to 24 hours against a one-way hash of your IP address.
  • Anti-abuse hashes of your IP address are discarded within one minute.
  • Cookie consent records are kept for up to 365 days.
  • Support ticket records are kept for 3 years from the date the ticket is closed.
  • Setup and license records are kept for as long as we have a relationship with you, and afterwards for the period our tax and accounting obligations require.
  • Purchase and license records are kept for as long as you hold a license with us, and afterwards for the period our tax and accounting obligations require.
  • Copies of submissions delivered to a connected service, and any IP address included in a payment record, are retained by that provider under its own rules rather than ours.

You can ask us to delete your data sooner. See What Rights You Have Over Your Data below.

Where Your Data Is Processed

We are based in the United States, and several of the providers listed above process data in the United States and other countries. Where personal information is transferred out of the European Economic Area, the United Kingdom, or India, the safeguard we rely on depends on the destination and on the region the data came from:

  • From the EEA: an adequacy decision where one covers the destination, the European Commission’s Standard Contractual Clauses, or the EU-US Data Privacy Framework where the recipient is certified under it.
  • From the United Kingdom: the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework where the recipient is certified under it. EU Standard Contractual Clauses on their own do not cover a UK restricted transfer, which is why the Addendum or the IDTA is used.
  • From India: contractual safeguards with the recipient, and transfers are made consistent with the restrictions applying under the Digital Personal Data Protection Act, 2023 and the rules made under it.

You may ask us at [email protected] for details of the safeguards applying to a particular transfer, including any of the form integrations named above.

California Privacy Rights

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  • Right to know what personal information we collect, use, disclose, and if applicable sell or share, and to request a copy of it
  • Right to delete personal information we have collected from you, subject to certain exceptions
  • Right to correct inaccurate personal information we maintain about you
  • Right to opt out of the sale or sharing of your personal information. Based on the categorization above, this means opting out of the advertising and conversion-measurement tools (Meta Pixel, Google Ads, DoubleClick, and Google Analytics) that involve cross-context behavioral advertising. We do not treat the other recipients listed in this policy, including the form integrations under Where Your Form Submissions Go, as sales or shares of personal information: each is engaged under a written agreement that limits their use of personal information to providing their service to us
  • Right to limit the use and disclosure of sensitive personal information, where applicable
  • Right to non-discrimination for exercising any of the above rights

To opt out of the sale or sharing of your personal information, click Do Not Sell or Share My Personal Information or Cookie Preferences in the site footer. We also honor Global Privacy Control (GPC) signals as a valid opt-out request. We action opt-out requests as soon as feasible, and no later than 15 business days from receipt.

To exercise your other rights, contact us at [email protected]. We will verify your request and respond within 45 days, as required by law, with a possible 45-day extension for complex requests, in which case we will notify you of the extension and the reason.

You may also designate an authorized agent to make a request on your behalf, subject to our ability to verify the agent’s authority to act for you.

Your Rights Under India’s Digital Personal Data Protection Act (DPDP)

If you are located in India, you have the following rights as a Data Principal under the Digital Personal Data Protection Act, 2023:

  • Right to access a summary of the personal data we hold about you and how we process it
  • Right to correction and erasure of your personal data
  • Right to grievance redressal, as described below
  • Right to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity
  • Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before your withdrawal

We do not knowingly collect personal data from individuals under the age of 18 without verifiable parental consent, consistent with the DPDP Act’s requirements for children’s data.

Grievance Officer: Mohit Sharma, [email protected]

If you have a grievance regarding how we handle your personal data, you may contact our Grievance Officer at the address above, or write to us at [email protected] and ask for your message to be passed to the Grievance Officer. Either route starts the same process.

As our own service commitment, we aim to acknowledge your grievance within 72 hours of receipt, including a reference number and expected resolution timeline, and to resolve most grievances within 30 days and in any event within 90 days. These are timelines we set for ourselves rather than statutory deadlines. The Digital Personal Data Protection Rules, 2025 come into force in phases, with several provisions taking effect later than the date of this policy, and we will update this section as those provisions apply to us.

How Secure Is My Information

We maintain technical and organizational measures appropriate to the risk, in order to protect your personal information from being inappropriately lost, misused, accessed, disclosed, altered, or destroyed. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Card information, when provided, is encrypted in transit using TLS (also known as SSL).

What Rights You Have Over Your Data

To exercise the privacy rights available to you, including access, correction, deletion, objection, restriction, or withdrawal of consent, contact us at [email protected]. Some requests are subject to legal exceptions, and some processing must continue for legal, security, accounting, contractual, or other permitted purposes.

You can also request information about the source of your personal data if it was not provided directly by you, or how long it will be retained. You have the right to request deletion of data no longer needed for its original purpose, or to cease its processing. Certain records, such as financial and transaction records, may be retained even after a deletion request, where retention is required by applicable tax, accounting, or audit obligations, consistent with the recognized legal exceptions to the right of deletion. You can request we stop using your data for direct marketing purposes, and you may withdraw consent at any time by clicking unsubscribe in our emails.

Legal basis for processing (EEA and UK visitors): Depending on the purpose, we process your data based on your consent (for example, non-essential cookies and marketing communications), the necessity of processing to perform our contract with you (for example, fulfilling a purchase, or delivering your submission to a service you asked us to send it to), our legitimate interests (for example, improving our services, spam prevention, and fraud prevention), or compliance with a legal obligation.

If you believe we have not complied with applicable data protection laws, you have the right to lodge a complaint with your local data protection authority. Within technical limits, we will provide your personal data to you or your data protection authority upon request.

If we cannot provide requested data within a reasonable timeframe, we will let you know when it will be available. If we deny a request, we will explain why.

Children’s Online Privacy Protection Act Compliance

We do not knowingly collect personal information from children under the age of 13. If we determine we have collected personal information from a child under 13, we will take reasonable measures to remove it from our systems. If you are under 13, please do not submit personal information through the Site, service, or Software.

Third-Party Links

We may include or offer third-party products or services on our website. These third-party sites have separate, independent privacy policies, and we hold no liability or responsibility for their content or activities.

Affiliate Disclosure

Some third-party links on our store may be affiliate links. We earn a referral fee when you buy services from companies we recommend. We only recommend products we believe add value to our customers. If you purchase after clicking an affiliate link, we receive a commission.

These affiliate commissions help us generate free content on our blog and free courses on SkillJet.

Affiliate tracking cookies are subject to the same consent preferences described in the Cookies section above.

Remarketing and Targeted Advertising

We work with third parties including Google Ads, Google Analytics, and Meta (Facebook) to provide targeted advertisements or marketing communications that may interest you, based on your browsing activity on our sites. This may include cross-context behavioral advertising as defined under California law. For more on how targeted advertising works, see the Network Advertising Initiative’s educational page.

You can opt out of targeted advertising through Facebook or Google directly, or by clicking Cookie Preferences in the site footer, which applies to the advertising partners listed in this policy.

Newsletter Emails

We send product announcements, software updates, and special offers by email. You will receive these only if you ask for them, by signing up to our newsletter or by ticking the marketing option on a form, and you can stop them at any time using the unsubscribe link in every email.

Buying, downloading, or installing one of our products does not by itself sign you up for marketing email.

Marketing email is separate from the service email we need to send you about a purchase, a license, a security notice, or a support ticket. Unsubscribing from marketing does not stop those.

If you are in the EEA or the UK, we will only send you marketing email where you have given consent, and we will never make that consent a condition of buying or using our products.

Will This Privacy Policy Ever Change

We may update this Policy to keep pace with changes in our Site, Software, Services, business, and applicable laws. When we do, we will post the updated Policy here and change the date at the top. Where a change is significant, we will take reasonable steps to tell you about it. Where a change means we need your consent for something new, we will ask for that consent rather than treat your continued use of our products as agreement.

Contact Us

For questions about our privacy practices or to make a complaint, contact us by email at [email protected] or by mail:

Brainstorm Force US LLC, 2093 Philadelphia Pike #3090, Claymont, DE 19703, United States

If you are in India and want to raise a grievance under the DPDP Act, you can write to our Grievance Officer, Mohit Sharma at [email protected], or use [email protected] and we will route it.

Start Creating Beautiful Forms Easily with SureForms Today

Start with AI-generated forms and customize them to your needs.
SureForms makes form creation a breeze.

Trusted by Thousands of Businesses
Start for Free. No Credit Card Required
24/7 World Class Support Team
Scroll to Top