← All guides

Contact form without tracking and unnecessary IP storage

A contact form does not need analytics or a permanent visitor IP. What is necessary is the message data entered by the sender and appropriate protection against automated misuse.

Requirements

Access to form code or form settings as well as the relevant mail and server logs.

Only required fields

Only make the name mandatory if it is really needed for the purpose. An email address, subject and message are often sufficient for an answer. Do not store an IP address in the database together with the message as a “precautionary measure”.

Intercept spam locally first

A hidden honeypot field, a minimum fill time and server-side plausibility checks can intercept many bots without an external CAPTCHA. These procedures do not require permanent visitor identification.

Check logging separately

Even if the form code itself does not store an IP, web server, PHP error log, mail server, WAF or host can log the request. Control these levels separately and limit storage.

No unnecessary copies

When messages are delivered via email, do not also keep a second complete copy in the website database indefinitely. To prevent misuse, use data that is as short-lived and dedicated to a specific purpose as possible.

Test

Send a test message and check the database, mail delivery, browser requests and relevant logs.

Dismantling

If functions fail, only specifically reset the affected setting and then check again.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑