Privacy and security
A launch-safe checklist for a form that is about to go live.
- Use the same intended Google identity for sign-in and workspace service connections.
- Add only the exact published HTTPS hostnames that should use the workflow.
- Never collect payment-card data, passwords, credentials, private keys, or secrets in ordinary form fields.
- Use non-sensitive synthetic values for launch testing.
- Keep the workflow paused until its domain, destination, and setup code are correct.
- Use Stripe-hosted pages for payment details and invoices.
- Disconnect an unused Google service from Account > Google. Existing customer-owned Google files remain in Google.