MyForms24/7 logo
MyForms24/7

Privacy Policy

Last updated: May 16, 2026

1. Who We Are

MyForms24/7 (“we,” “us,” or “our”) is an online platform that provides digital form templates, e-signature services, document management, and related business tools. Our website is located at myforms247.com. For any privacy-related questions, contact us at [email protected].

2. Information We Collect

We collect information in two ways:

Information you provide directly

  • Account details: name, email address, and password
  • Form submissions: any data entered into forms you complete (e.g., W-4, I-9, evaluations)
  • Payment information: processed securely by Stripe — we never store card numbers
  • Contact inquiries: name, email, and message content from our contact form
  • E-signatures: name, email, IP address, and timestamp recorded at the time of signing

Information collected automatically

  • Log data: IP address, browser type, pages visited, and referring URL
  • Cookies: essential session cookies for authentication (see Section 7 below)

3. How We Use Your Information

We use your data for the following purposes:

  • Provide our services — process form submissions, generate PDFs, deliver e-signatures, and manage your employer portal
  • Account management — authenticate your login, manage your subscription, and display your dashboard
  • Communication — send transactional emails (submission confirmations, signing requests, password resets) and respond to support inquiries
  • Payment processing — process purchases and subscriptions through Stripe
  • Security & compliance — detect and prevent fraud, enforce our terms, and maintain audit trails for e-signatures

4. Lawful Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or another jurisdiction that requires a lawful basis for data processing, we rely on the following:

  • Contractual necessity — processing required to provide the services you signed up for (account management, form processing, e-signatures)
  • Consent — where you have given explicit consent, such as accepting cookies or opting in to notifications
  • Legitimate interest — for security measures, fraud prevention, and improving our services, balanced against your privacy rights
  • Legal obligation — where we are required by law to retain certain records (e.g., tax-related documents, e-signature audit trails)

5. Data Sharing & Third-Party Services

We do not sell your personal data. We share data only with the following categories of service providers, who process it on our behalf under strict data protection agreements:

  • Stripe — payment processing (Stripe Privacy Policy)
  • Amazon Web Services (AWS) — cloud hosting, file storage, and database infrastructure
  • SendGrid — transactional email delivery

We may also disclose data if required by law, regulation, or legal process.

6. Data Retention

We retain your data only as long as necessary for the purposes outlined in this policy:

  • Account data — retained as long as your account is active. If you request deletion, we remove your data within 30 days.
  • Form submissions & documents — retained according to your plan (e.g., 30-day auto-delete for Basic plans, longer for higher tiers). Employers may download and retain their own copies.
  • E-signature records — retained for at least 7 years to meet legal compliance requirements for electronic signatures.
  • Payment records — retained as required by tax and financial regulations.
  • Contact form messages — retained for up to 12 months, then deleted.

7. Cookies

A cookie is a small text file stored on your device when you visit a website. We use cookies as follows:

Essential cookies (strictly necessary)

These cookies are required for the site to function and cannot be disabled:

CookiePurposeDuration
next-auth.session-tokenKeeps you logged inSession / 30 days
next-auth.csrf-tokenPrevents cross-site request forgerySession
next-auth.callback-urlRemembers where to redirect after loginSession

Preference cookies

CookiePurposeDuration
myforms247_cookie_consentStores your cookie preferencePersistent (localStorage)

Third-party & tracking cookies

We do not use any third-party analytics, advertising, or tracking cookies. If this changes in the future, we will update this policy and request your consent before any tracking cookies are set.

Managing cookies

You can manage or delete cookies through your browser settings. Note that disabling essential cookies will prevent you from logging in. Most browsers let you:

  • View what cookies are stored
  • Delete individual or all cookies
  • Block cookies from specific or all sites

8. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS) and at rest
  • Secure cloud infrastructure hosted on AWS
  • Password hashing using bcrypt
  • Role-based access controls
  • Regular security reviews

No system is 100% secure. If you become aware of a security issue, please contact us immediately at [email protected].

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure (“Right to be Forgotten”) — request deletion of your personal data
  • Restriction — request that we limit how we use your data
  • Portability — request your data in a portable, machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

10. International Data Transfers

Our servers and service providers are located in the United States. If you are accessing our services from outside the US, your data will be transferred to and processed in the US. We ensure appropriate safeguards are in place, including data processing agreements with our service providers.

11. Children's Privacy

Our services are not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by posting the updated policy on this page with a new “Last updated” date. Your continued use of our services after any changes constitutes acceptance of the updated policy.

13. Contact Us

For any questions about this Privacy Policy or our data practices, contact us at:

MyForms24/7
Email: [email protected]