Use clear labels for every field so visitors understand what information to provide.
Keep forms as short as possible. Only request information that is needed to complete the service or request.
Use Markup, Basic HTML, or Advanced HTML or Text elements to add instructions between questions when visitors need extra context.
Use conditional logic to hide questions that are not relevant to every visitor.
Avoid collecting sensitive information. Do not request Social Security numbers, driver’s license numbers, passport numbers, passwords, medical information, bank account information, routing numbers, credit card numbers, or other sensitive data through Web Open webforms.
Test the form before publishing it. Submit a test response, confirm that required fields behave correctly, verify email notifications, and review the confirmation message.
Security Notice
Important Note:
To maintain compliance with data security requirements CiviPlus may, at any time and in its sole discretion, unpublish any form that solicits sensitive information with or without notice to you.
Information submitted through Web Open webforms is stored unencrypted. Web Open webforms may be used to collect PII, but should not be used to collect Sensitive PII, PHI, HIPAA-regulated data, or PCI data.
If you intend to collect sensitive information, contact your account manager to discuss CivicPlus’s secure form offerings.
File Upload Guidance
Use file upload elements carefully. When using file upload fields:
Limit accepted file types whenever possible.
Do not request files that contain sensitive information.
Use caution when opening files submitted by website visitors.