Gravity Forms: Retention Policy and Mandatory Standards

Summary

This article explains the mandatory requirements that WordPress site owners and administrators must follow to keep their Gravity Forms secure and compliant.

Body

This article explains the mandatory requirements that WordPress site owners and administrators must follow to keep their Gravity Forms secure and compliant. 

 

In This Article:

 

Retention Policy

To lower security risks and boost site speed, ITS Digital Services sets a 90-day retention limit on all WordPress networks.

  • The system deletes all Gravity Forms entries and uploaded files after 90 days.
  • We will manually phase out entries and files uploaded before this policy started.
  • Once items hit the 90-day limit, the system removes them forever. You cannot get them back.

 

Form Configuration Standards

You must set up these options to secure forms, stop spam, prevent slow performance, and avoid breaking rules.

 

Add CAPTCHA

Add Google reCAPTCHA to every form.

Steps:

  1. Go to Forms > Settings > reCAPTCHA.
  2. Choose the reCAPTCHA type set up by ITS Digital Services.
  3. Save your settings.
  4. Open your form and add the CAPTCHA field.
  5. Save the form before you publish it.

 

Enable Honeypot

Turn on the built-in Honeypot anti-spam feature.

Steps:

  1. Edit your form.
  2. Go to Form Settings > Form Options.
  3. Check the box for Enable Anti-Spam Honeypot.
  4. Save the form.

 

Limit File Upload Fields 

Use file upload fields only when you truly need them.

If you must add a file upload field, follow these rules:

  • Limit file types (for example, .pdf, .jpg, .png).
  • Block unsafe file types (for example, .exe).
  • Set the maximum file size to under 5 MB.

 

Require Login for Internal or Uploaded Forms

Use the UNC Permission plugin to protect restricted forms with Onyen login.

Steps:

  1. Go to Plugins > UNC Permissions Plugin > Activate.
  2. Open the page with the Gravity Form.
  3. In the Onyen Restricted Content box, check Require Onyen Authentication.
  4. Test it: Log out (or use a private or incognito browser window) to make sure only logged-in users can access the form.

 

Data Handling Standards

These rules guide how you manage data to ensure security, reduce risks, and follow university policies.

 

Export Data Before the 90-day Deadline

Export any data you want to keep before the retention policy deletes it.

Steps:

  1. Go to Forms > Entries.
  2. Select the form you want to export.
  3. Click Export.
  4. Choose the fields you need and click Download Export File.
  5. Save the CSV file securely in an approved storage system, such as SharePoint or OneDrive.

 

Prohibit Sensitive Data

Do not collect sensitive data in Gravity Forms. 

Examples of prohibited data include:

  • Social Security numbers
  • Driver’s licenses or government IDs
  • Credit card or banking information
  • Health or medical records
  • Student transcripts, grades, or other personally identifiable information (PII). PII is data that can identify a person.

If someone submits sensitive data by mistake:

 

Collect Only Necessary Data

Limit your form to fields you truly need for your process.

Steps:

  • Review all fields before you publish.
  • Remove optional or unrelated questions.
  • Keep forms short to lower drop-off rates and reduce stored data.

 

Site Owner Responsibilities

Site owners must make sure their site and all collaborators (administrators, editors, contributors) follow these rules:

 

Follow Core Rules

  • Add CAPTCHA and Honeypot to every form.
  • Export entries before the 90-day deadline.
  • Monitor for sensitive data and report issues right away.
  • Avoid file uploads unless you truly need them.
  • Use approved tools (like Qualtrics, Teams, or SharePoint) for sensitive data.
  • Use the UNC Permissions plugin to require Onyen login for restricted forms.
  • Collect only the minimum data needed.
  • Check submissions often for misuse or errors.

 

Perform the Pre-Publication Checklist

Before you publish a form, confirm that you have:

  • Added CAPTCHA
  • Enabled Honeypot
  • Avoided or restricted file uploads
  • Excluded sensitive data fields
  • Set up a process to export data before 90 days
  • Restricted internal forms with the UNC Permissions plugin
  • Limited fields to only what you need

 

Perform the Pre-Retention Checklist

Before entries hit the 90-day limit, confirm that you have:

  • Reviewed entries for relevance
  • Exported and securely stored any needed data
  • Verified that no sensitive data remains in the system

 

Site Owner Attestation of Compliance

"By using Gravity Forms, I attest that:

  • As a site owner, I take responsibility for my site and all form managers (administrators, editors, and contributors).
  • I will not collect sensitive or regulated data through Gravity Forms.
  • I will ensure all administrators, editors, and contributors on my site follow this policy.
  • I understand that violations may lead to suspension or permanent removal from the WordPress network.
  • I will tell all collaborators about this policy and require them to follow it."

 


 

Details

Details

Article ID: 487
Created
Thu 10/2/25 1:05 PM
Modified
Mon 10/6/25 10:55 AM
Article Agent
The TDX agent acting as the primary point of contact for the article and is responsible for ensuring the content's accuracy on behalf of the group.