Skip to main content
Every form on a deployed Hiveku site is captured automatically — contact forms, quote requests, newsletter footers, popups. There is nothing to wire up: the first time a form receives a submission, it appears in your project under Analytics → Forms, and each new lead can notify your team by email or Slack, create a CRM contact, and trigger workflows. If some of your site’s forms are not leads (a sign-in screen, an app’s own pages), you choose what is captured: see Choose which forms Hiveku captures.

Where submissions live

Open your project, click Analytics in the sidebar, then the Forms sub-tab. You’ll see:
  • Each form on your site as its own record, with a running submission count. Forms register themselves automatically the first time they receive a submission.
  • The Submissions panel — every captured lead, newest first, with the fields the visitor filled in.

Work the inbox

The Submissions panel is built to be triaged like an email inbox:
  • Search across everything a visitor typed, plus form names.
  • Filter by status (New, Read, Responded, Spam, Archived), by form, by Has email, or by In CRM.
  • Bulk actions — select submissions and choose Mark as spam, Not spam, Archive, or Delete.
Delete removes a submission from your list but keeps the underlying analytics event, so your form conversion numbers stay accurate. It does not delete a CRM contact the submission may have already created. An Undo link appears for 10 seconds after deleting.

Choose who gets notified

Click Notifications in the Forms tab.
1

Set project-wide recipients

Under Send every submission to, enter up to 10 comma-separated email addresses. These apply to every form on the project unless a form overrides them.
2

Add a Slack webhook (optional)

Paste a hooks.slack.com webhook URL. Submissions post to Slack alongside the email — it does not replace it.
3

Override per form

Each form in the Per form list can have its own recipients, and its own Notifying / Muted toggle. Muting a form stops the email only — the submission is still captured and still appears in the tab. To stop capturing a form, see Choose which forms Hiveku captures.

Choose which forms Hiveku captures

By default Hiveku captures every form on your deployed site. That suits a marketing site, where almost every form is an enquiry. It does not suit a web app: sign-in screens, password resets, admin pages and the details your own users type into the app are not leads, and capturing them turns each one into a CRM contact, a notification email, a workflow run and possibly an ad conversion. Open your project, click Analytics, then Forms, then Capture. Every setting there applies from the next submission, with nothing to deploy.
Capture settings only apply to forms Hiveku captures automatically on your deployed site. Hosted Hiveku forms, and forms your site sends to a workflow’s webhook address, are never affected.

The capture switch

Capture is on by default. Switched off, Hiveku captures no form on the site automatically. The switch overrides every other setting on this page, including markup in your site’s code.

Site type: Marketing site or Web app

  • Marketing site (the default): every form is captured except the ones you exclude.
  • Web app: only the forms you choose are captured, meaning forms set to Always, forms on pages an include path rule matches, and forms marked data-hiveku-capture="on" in your site’s code. Everything else is skipped.
Choose Web app for anything with a sign-in, a customer portal, admin screens, or pages where your users enter their own information. Before you switch, set your real lead forms (contact, quote, demo request) to Always so they keep arriving.

Skip sign-in and password forms

On by default. Hiveku skips a submission that carries only sign-in details (an email address or username, a password, a code) and nothing that reads as a name, phone number, company or message, when it:
  • comes from a sign-in, sign-out or password page: an address ending in /login, /log-in, /signin, /sign-in, /wp-login, /logout, /log-out, /signout, /sign-out, /forgot-password, /reset-password or /password-reset (a file extension such as .php makes no difference), or any address with auth or password as a whole part of it, such as /auth/callback or /users/password/new;
  • is sent to a sign-in address; or
  • includes a password field.
This setting never skips a signup form that asks for a name.

Path rules

A path rule excludes or includes every form on the pages it matches. A site can have up to 50.
  • Rules start with /. Capital letters, a trailing slash and anything after ? are ignored.
  • A rule matches the page the form was on, not the address the form sends its data to.
  • Not allowed: /* or * on their own (use the capture switch or the Web app site type instead), **, full web addresses, ?, # and spaces.
  • When several rules match a page, the most specific one wins, so you can exclude /portal/* and still include /portal/contact. When an exclude and an include are equally specific, the exclude wins.
Before a path rule or a site type change is saved, the panel shows which forms it would start or stop capturing, counted from your recent submissions. Check that none of your lead forms is on the list of forms it would stop capturing.

Always, Never or Default for one form

Each form in the Capture list has its own setting:
  • Always: captured, even on a Web app site, on a page a path rule excludes, or when it looks like a sign-in form. Only the capture switch and data-hiveku-capture="off" in your code override it.
  • Never: not captured.
  • Default: follows the site type, Skip sign-in and password forms and your path rules.
A form’s own setting beats the sign-in setting and every path rule. Up to 200 forms can have one.

Why a form is or is not captured

Each form in the Capture list shows its status and the reason. Mixed means some of its submissions are captured and some are not, for example the same form on several pages when a path rule excludes only some of them. When settings disagree, the most specific wins, in this order: the capture switch, then markup in your site’s code, then the form’s own setting, then Skip sign-in and password forms, then the most specific path rule, then the site type. If none of them applies, the form is captured.

Opt a form in or out in code

A developer can mark a form in your site’s code:
data-hiveku-capture="off" is honoured by every Hiveku script on the page, including Hiveku Analytics. Use it for search boxes, filters and anything else that is not a lead. data-hiveku-capture="on" is how a web app keeps its real lead forms. The markup beats a form’s own setting and every path rule; only the capture switch overrides it. A form with no <form> element that your code sends with window.hivekuCaptureForm(fields, name) counts as opted in, so it is captured on a Web app site too. Markup arrives with your site’s next deploy. On pages that also run Hiveku Analytics, allow up to a day for visitors’ browsers to pick up the updated analytics script.

When changes take effect

  • New submissions: immediately, with no deploy.
  • Analytics reports: within about a minute.
  • Ad conversions: conversions waiting to be sent for a form you just excluded are held back automatically. Conversions already sent to an ad platform stay there.
  • Submissions captured before the change: they stay until you erase them.
Changing capture settings needs Edit permission on website projects.

Erase submissions captured by mistake

Changing a setting does not remove what was already captured. Erase permanently removes the captured submissions your current settings exclude, so change the setting first, then erase. To erase one form’s submissions, set that form to Never (or exclude its pages), then use Erase. Erase removes:
  • the automatically captured submissions your current settings exclude, including any you had marked as spam or deleted from the list;
  • the files visitors uploaded with them;
  • the form notes on your CRM contacts;
  • ad conversions still waiting to be sent for them;
  • the submitted details kept in your workflows’ run history;
  • CRM contacts that exist only because of those submissions. A contact with any other history (a deal, an email, another form) is kept.
Erase cannot undo:
  • notification emails already sent;
  • conversions already sent to an ad platform (Meta does not allow deleting them);
  • visitors Hiveku Analytics already identified from these forms;
  • changes these submissions made to contacts that existed before them;
  • the copy of each submission kept with your site’s analytics.
Erase starts with a preview: how many submissions it would remove from each form, how many contacts it would erase and how many it keeps, and what it cannot undo. Nothing is removed until you confirm. Large sets are erased in batches; when more remain, run Erase again. If the same submission also reached Hiveku through a hosted form or one of your workflows’ webhooks, it is left alone. Erasing needs Delete permission on both website projects and CRM contacts.
Erasing is permanent. There is no undo and no restore.

Muting a form is not the same as not capturing it

Muting a form under Notifications stops the email only. A muted form is still captured: it still creates CRM contacts, runs your workflows and can send ad conversions. To stop that, use the Capture settings above.

Spam protection

Form spam protection has two layers: built-in scoring that is always on, and optional Google reCAPTCHA you can switch on per site.

Built-in scoring (always on)

Every captured submission is checked for bot fingerprints at the moment it arrives — things like a filled honeypot field, a form submitted faster than a human can type, bursts of submissions from one source, link-only message bodies, and disposable email domains. Analytics and ad-pixel beacons that disguise themselves as form submissions are caught too. Submissions that score as spam are filed under the Spam filter in the Submissions panel. A spam-filed submission is never emailed to you, never added to your CRM, and never triggers a workflow — but it is also never deleted. If a genuine lead lands there, select it and click Not spam: it returns to your inbox and the notification email is delivered within a few minutes.

Google reCAPTCHA (optional)

For sites getting hit harder, add invisible reCAPTCHA scoring on top:
1

Turn it on

Go to Hosting → Integrations in your project and toggle Form spam protection on. The setting is per environment, so enable it for the environment you care about — usually production.
2

Pick a sensitivity

  • Lenient — only certain spam is filed. Right for a high-value, low-volume form where a missed lead is expensive.
  • Balanced — recommended for most forms. The default.
  • Strict — files borderline submissions too. For a form that is actively being hammered.
3

Deploy

The protection attaches at build time, so click Deploy after enabling it.
There are no keys to create and no Google account needed — it runs on Hiveku’s platform configuration. It is invisible to visitors: no checkbox, no puzzle, and Google is not contacted at all until a visitor focuses a form field.
Nothing is ever deleted by spam protection at any sensitivity. Filed submissions stay under the Spam filter and are one click from restored.

Escalate a single hammered form

If one specific form keeps attracting bots, you can require a visible “I am not a robot” checkbox on just that form: open Forms → Notifications, find the form in the Per form list, and tick Require a visible “I am not a robot” checkbox on this form.
The visible checkbox adds friction for real visitors and blocks submission until it is ticked. Use it only on a form that keeps getting hit, and leave the rest of your forms on invisible scoring. It requires Form spam protection to be switched on under Hosting.

File uploads

Any form on a deployed site can accept files (resumes, photos, PDFs, quote attachments) with no extra setup. The files are stored by Hiveku and travel with the submission.

Add a file field

Put a named file input inside the form, exactly like any other field:
That is all. There is no upload endpoint to build, no storage to provision and nothing to configure. The same works for a multi-file input (multiple) and for the starter template’s FileUpload component. If you build sites with the Hiveku coding agent or the Claude Code plugin, they already know this rule.

What visitors see

When a visitor picks a file, it uploads in the background with a plain status line under the input (“Uploading resume.pdf 42%”, then “resume.pdf ready”). The submit button waits until every file has finished, and the form then submits as usual. An upload that fails never blocks the lead: the submission still arrives, without that file.

Limits

The file type is taken from the extension and verified against the file’s contents before anything is stored. Under Forms → Notifications → Uploads you can switch uploads off for a project, narrow the accepted types, raise or lower the size limit and change the retention period.

Where the files appear

  • Analytics → Forms: each submission lists its files with size and a Download link.
  • Notification email: the files arrive as real attachments, up to 5 files or 25 MB per email. Larger sets are listed by name with a link to the Forms tab.
  • CRM contact: an Attachments section on the contact, plus document links on the form activity card in the contact’s timeline.
  • Workflows: the form-submitted trigger exposes {{trigger.attachments}} (name, size, type and a download link valid for 24 hours), and the Send Email node has an Attach form files toggle.

Retention and removal

Files are kept for one year by default (adjustable between 30 days and one year per project). Deleting a submission removes its files after 7 days; deleting a project or an account removes them with it. A file that has been removed shows as Expired in the Forms tab, or as Removed: malware detected when the scanner flagged it.

Opting out of uploads

To keep Hiveku from uploading files from a particular form or input, add data-hiveku-uploads="off" to the <form> or to the <input>. The submission is still captured; only the file handling is skipped. To stop Hiveku capturing a form at all, use data-hiveku-capture="off" instead: see Opt a form in or out in code.

Malware scanning

Every uploaded file is scanned for malware after it lands. A file becomes downloadable once its scan is clean, usually within a few minutes; until then the Forms tab and the CRM show Scanning for malware, and the notification email waits up to 10 minutes for the verdict before going out without the file (it stays downloadable from the Forms tab afterwards). A file the scanner could not read (for example a password-protected document) is delivered with a Could not be scanned note. A file the scanner flags is removed immediately and shown as Removed: malware detected; nothing is delivered.
A clean scan is not a guarantee. Treat a downloaded attachment the way you would treat any email attachment from a stranger.

Duplicate prevention

One physical submission produces exactly one lead. A single form submit can be observed more than once — by the page script and by your site’s backend, for example — and repeat submits of identical content within a few minutes are common. Hiveku links these captures together automatically, so you see one row in the Submissions panel, receive one notification email, and get one CRM contact. URL variations of the same page (like a trailing slash) count as the same form, not two separate records.

Troubleshooting

Open the Submissions panel, set the status filter to Spam, select the submission, and click Not spam. It moves back to your inbox and the notification email is delivered within about 5 minutes. If it happens repeatedly on the same form, switch the sensitivity to Lenient under Hosting → Integrations.
reCAPTCHA is not configured on your deployment. Built-in scoring still runs regardless. Contact support if you expected the toggle to be available.
Switch the sensitivity to Strict under Hosting → Integrations, and add the visible checkbox to the specific form being targeted (see above). Remember to Deploy after changing the Hosting toggle — the protection attaches at build time.
Check three things in Forms → Notifications: that recipients are set (if none are, submissions fall back to the address shown in the hint), that the form isn’t Muted in the Per form list, and that the submission didn’t land under the Spam filter. If no submission arrived at all, check that the form is still captured under Forms → Capture.
Open Analytics → Forms → Capture and find the form. Its status and reason show whether a capture setting now skips it: the capture switch, a path rule, the Web app site type, Skip sign-in and password forms, or the form set to Never. Set the form to Always to capture it again from its next submission.
Your site is probably a web app on the Marketing site default. Set your real lead forms to Always, switch the site type to Web app (or exclude the app’s pages with a path rule), then use Erase to remove what was already captured.
Check that uploads are switched on under Forms → Notifications → Uploads, that the file type and size are within the limits above, and that the form or input does not carry data-hiveku-uploads="off". A site that submits the form from code while an upload is still running sends the lead without the file; let the visitor press the submit button instead.

What’s Next?

Leads to CRM

Auto-create tagged CRM contacts from form submissions

AI Form Response

Send an instant AI-drafted reply to every new lead

Track Analytics

See the traffic behind your form conversions

CRM Contacts

Manage the pipeline your leads flow into