Skip to Help content

Review security and privacy

Understand EZFormz security and privacy

Outcome: Protect account and buyer data using practical controls and the current Privacy and Terms boundaries.

Use security as a shared responsibility

EZFormz provides account, permission, and privacy controls, but safe use also depends on what you publish, whom you authorize, and where you copy data. There is no useful promise that every account, device, integration, or public form is risk-free.

Start with 2FA, passkeys, and recovery methods. Keep devices updated, use a trusted password manager or authenticator, save recovery codes away from the enrolled device, and sign out of a shared browser when finished. Never send a login code, authenticator code, recovery code, passkey prompt, or setup secret to support or another user.

Normal account sign-in is passwordless. Email codes expire after 15 minutes; 2FA adds an authenticator or one-time recovery-code step; and passkeys use a domain-bound WebAuthn credential. Enter codes and approve passkeys only after starting from ezformz.net. A form password belongs to a buyer-facing form and is not an EZFormz account password.

Understand current service protections

The current service runs through Cloudflare Workers with D1 database and R2 object-storage bindings. Browser traffic uses HTTPS. Account session cookies are marked HttpOnly, Secure, and SameSite=Lax; passkey challenge cookies use the stricter SameSite=Strict setting. These controls reduce specific risks but do not make a compromised browser, email account, collaborator, or external destination safe.

Form passwords are SHA-256 hashed before storage. Order creation recalculates price and inventory state on the server rather than trusting browser totals, and sensitive authentication, upload, order, and integration routes apply rate limits or validation gates. API and OAuth credentials are checked for account, scope, and collaborator access instead of granting access solely because a form ID is known.

Public order submission also uses a hidden honeypot field to reject basic automated spam without showing a CAPTCHA in the normal checkout. It is one abuse control, not a guarantee that every unwanted or malicious submission will be stopped.

The Privacy Policy states that product cookies and browser storage are used for service functions rather than ad tracking and that personal information is not sold. The current public site does not use Google Analytics, Facebook Pixel, ad-retargeting scripts, or customer-data resale. The policy also lists the infrastructure, email, spreadsheet, and shipping providers that may process data for enabled features. Use the policy—not a Help summary—as the current privacy statement.

Limit who and what can access data

  • Publish only form text, payment destinations, wallet addresses, images, and links that buyers are meant to see. Review the public form while signed out before sharing it.
  • Give collaborators only the permissions needed for their work and remove access when it ends. A role that can view orders may expose buyer contact details, addresses, answers, payment evidence references, and seller notes.
  • Treat AI connections and API keys as account access. Under current form permissions, integrations may receive complete form configuration, payment instructions, Google Sheet URLs, product or variant costs, seller notes, buyer information, and order details.
  • Treat exports, spreadsheets, Airtable bases, tax-provider records, AI chats, downloaded proofs, and screenshots as additional copies. Restrict access at the destination and remove copies there separately when required.
  • Keep one-time order, edit, balance, recovery, invitation, and support-ticket links private. A person with a valid bearer link may be able to use the action or view the requester-facing record without your normal session.

Do not place API keys, provider credentials, private crypto keys or seed phrases, recovery codes, or one-time access links in form text, payment instructions, prompts, support tickets, or screenshots. A public wallet receiving address can be shared when needed; a private key or seed phrase cannot.

Understand privacy boundaries

Privacy explains how EZFormz handles and retains data, and Terms of Service describes the rules for using the service. These documents govern the service; a Help article is not a replacement for them.

Export and deletion controls apply to EZFormz-held account data as described in Manage account data and contact support. They do not reach copies already sent to a buyer, collaborator, spreadsheet, integration provider, AI provider, tax service, carrier, or local device. Use each destination's controls and retention process as well.

EZFormz does not process a seller's payment, hold funds, reverse a transfer, or guarantee that uploaded proof represents a settled payment. Sellers must verify payment through the selected payment service or public blockchain evidence and handle refunds through the service that moved the funds.

Report the right kind of problem

For a suspected account compromise, revoke affected Connected Apps and API keys, secure the account, and submit EZFormz technical support without including secrets. For payment fraud, impersonation, harassment, malicious forms, or other abuse, use Report an issue so the correct evidence and moderation workflow is used.

Unexpected 2FA, passkey, or account-email notices require prompt action. Keep control of any factor that still works, secure the account email and password manager, revoke exposed credentials, and preserve the notice without forwarding its private links or codes.