This Privacy Policy explains how 854 Labs LLC, an Indiana limited liability company operating html.contact (“html.contact”, “we”, “us”, or “our”), handles information when you use html.contact.
html.contact is a form backend. Customers create forms, whitelist source domains, verify recipient emails, receive submissions in a dashboard, optionally store one attachment, and send notification emails.
Roles
For form submissions, html.contact processes submission content on behalf of the customer who created the form. End users who submit forms should review the privacy policy of the website or organization operating that form.
For account registration, billing, support, security, abuse prevention, product analytics, legal compliance, and service administration, html.contact processes certain information for its own business and service-administration purposes.
Customers are responsible for deciding what their forms collect, providing their own notices and consents, and using html.contact lawfully.
Information We Collect
We may collect:
- Account information, such as email address, first name, and last name.
- Verified recipient emails linked to an account.
- Form configuration, allowed domains, form names, and routing settings.
- Form submission fields, such as names, emails, phone numbers, messages, and other fields chosen by the customer.
- One optional attachment per submission, if the customer form accepts file uploads.
- Source and security metadata, such as source host, source URL, user agent, approximate Cloudflare location signals when available, rate-limit signals, and IP-derived security signals.
- Email delivery and audit metadata, including recipient status, provider status, message IDs, and delivery lifecycle information when available.
- Billing, subscription, invoice, and usage metadata processed through Stripe.
- Product analytics events using internal unique IDs rather than email addresses.
- Support, privacy, legal, security, and trust correspondence.
We do not collect profile photos at launch.
Prohibited Data
html.contact is not intended for sensitive or regulated data. Do not use the service to collect or process:
- Health information or PHI.
- Payment card numbers.
- Social Security numbers, tax IDs, government IDs, or identity documents.
- Passwords, private keys, API keys, secrets, or credentials.
- Children’s data.
- GLBA, FERPA, HIPAA, PCI, or similar regulated workloads.
- Other highly sensitive personal data.
See the Acceptable Use Policy for more.
How We Use Information
We use information to:
- Provide, operate, secure, and improve html.contact.
- Receive, store, display, export, and route form submissions.
- Send notification, verification, billing, security, and support emails.
- Enforce allowed-domain checks, recipient verification, rate limits, spam screening, usage limits, and abuse controls.
- Provide account, billing, and customer support.
- Monitor reliability and product usage.
- Investigate abuse, security reports, legal requests, and policy violations.
- Comply with legal, accounting, tax, and operational obligations.
Product Analytics
We use PostHog for product analytics to understand usage patterns and improve the product. Public and authentication pages use cookieless analytics without PostHog browser storage or identified visitor profiles. Inside the signed-in app, analytics may use local browser storage and an internal unique user ID so we can understand product usage over time.
We do not use PostHog for advertising, cross-context behavioral advertising, email tracking, session replay, or form-submission inspection. Analytics events use internal unique IDs rather than email addresses, and our analytics helpers deny or redact sensitive properties such as emails, form keys, API keys, submitted fields, message bodies, Stripe payloads, cookies, passwords, submission IDs, and attachment IDs.
On public pages, we prefer analytics configurations that avoid non-essential persistent storage where feasible. Logged-in app analytics may use product analytics tied to internal unique IDs.
Cookies And Similar Technologies
html.contact may use necessary cookies and browser storage for login, sessions, security, preferences, dashboard operation, and first-party referral attribution for signup credits or promotions.
We do not use advertising cookies or cross-site advertising trackers.
html.contact is an endpoint service. It does not automatically embed cookies, trackers, scripts, or banners on customer websites. Customers are responsible for their own website notices, cookie disclosures, form labels, and consent requirements.
How We Share Information
We share information with service providers that help operate html.contact. These include infrastructure, billing, analytics, uptime/status, and email-alias providers. See Subprocessors.
We may also disclose information when needed to:
- Provide support or respond to a request.
- Process billing through Stripe.
- Send operational emails.
- Investigate abuse, security incidents, fraud, spam, or policy violations.
- Comply with law, legal process, or enforceable government requests.
- Protect html.contact, customers, end users, or the public.
- Transfer the service in connection with a merger, acquisition, financing, reorganization, or sale of assets.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising.
Storage And International Processing
html.contact is operated from the United States. Information may be processed in the United States and in other locations where our service providers operate.
The service is U.S.-first at launch. We do not claim EU data residency or broad enterprise EU/UK compliance coverage at launch. If your organization needs a DPA, email legal@html.contact.
Retention, Export, And Deletion
Submission persistence is a core product feature. We store submissions so customers can view, export, and manage them.
Customers can export forms and submissions through available product features. Account access, correction, export help, and deletion requests can be sent to support@html.contact. Privacy-specific questions can also be sent to privacy@html.contact.
Deletion may exclude limited records retained for security, abuse prevention, billing, tax, accounting, legal, audit, or compliance reasons.
We do not promise an automatic inactivity deletion policy at launch.
Security
We use technical and organizational measures designed to protect the service. See the Security page for details.
No internet service can guarantee perfect security. You are responsible for protecting your account, using strong passwords, keeping private API keys secret, and never placing hc_live_ keys in browser code.
Children
html.contact is not intended for children and must not be used to collect children’s data.
Your Choices And Requests
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of certain personal information. Send requests to support@html.contact. We may need to verify your identity or account ownership before acting on a request.
End users who submitted a form on a customer website should contact the website or organization operating that form first.
Changes
We may update this Privacy Policy from time to time. If changes are material, we will provide notice by email, in-app notice, or another reasonable method.
Contact
For privacy questions, email privacy@html.contact. For support, access, export, or deletion requests, email support@html.contact.
Written correspondence may be sent to:
854 Labs LLC
5534 Saint Joe Road
Fort Wayne, IN 46835
United States