How SiteBackend works
How SiteBackend is organized, and what happens to a form submission or a customer testimonial from the moment it's sent until it reaches you.
This page explains how SiteBackend is organized, then follows a form submission and a testimonial from your visitor's browser to your dashboard.
Workspaces, sites, forms and testimonials
- A workspace holds everything for one business or client: sites, billing and teammates.
- A site is one website. It has its forms, contacts and testimonials. See sites.
- A form has a public endpoint,
https://api.sitebackend.com/forms/<id>, its own inbox, allowed origins, notification channels and settings. - A site's testimonials come in through its collect form and appear on your website through its widgets.
The life of a submission
- The request arrives. A browser posts the form to the endpoint, either as a regular form post or with
fetch. - The form and origin are checked. Paused forms and forms that don't exist are rejected. If the form has allowed origins, the request must come from one of them.
- Spam checks run, in order: the honeypot field, the rate limit (5 per minute per visitor, per form), the captcha if you enabled one, and the content filter. Honeypot and content-filter hits are stored in the Spam folder and the visitor sees a normal success page, so bots learn nothing.
- Your monthly limit is checked. Pro has no limit. On Free, submissions past the monthly limit are still saved, but hidden until you upgrade; they get no contact or notifications in step 5. See plans and limits.
- The submission is saved together with a contact for the sender's email, a notification for each of the form's channels, and the auto-reply to the sender if you turned it on (Pro), all in one step. Either everything is saved or nothing is.
- The visitor gets a response: a redirect to the thank-you page (or your own URL) for HTML forms, or JSON for
fetchrequests. - Notifications and the auto-reply go out in the background. If a channel is down, SiteBackend retries up to 8 times over about 22 hours.
The life of a testimonial
- The customer opens the collect form on your website. The form is loaded by SiteBackend's embed script inside a frame, so your site doesn't need any code of its own.
- They submit it. SiteBackend checks the honeypot and a rate limit of 3 per minute per visitor, validates the fields and checks the photo, if there is one.
- It's saved as Pending, or approved straight away if you turned on auto-approve for 4★ and up and the rating qualifies. Owners and admins get an email, unless you turned that off.
- You approve it in the site's Testimonials inbox. On the Free plan, up to 10 testimonials per site can be approved at a time.
- Your widgets show it within a few seconds. Widgets only get public details: name, role, company, photo, rating, text and date.
See collecting testimonials and testimonial widgets.
What gets stored for a submission?
The fields you send, the time, the page it came from (the Referer), the visitor's country when available, and their browser's user agent. IP addresses are never stored: SiteBackend keeps only a keyed hash, used for rate limiting.
For a testimonial, SiteBackend stores what the customer entered, their photo if they added one, and the same kind of keyed hash instead of their IP address. The collect form doesn't ask for an email address. If you add a testimonial by hand with the person's email, it's only visible in your dashboard.