If you run an agency or a practice, you have probably had a form-abandonment tool pitched to you. The promise is appealing: recover the visitors who start filling out a contact form and leave before submitting. But if you have any instinct for privacy, a quieter question sits underneath the pitch — how, exactly, is it getting that data?
That question is the right one to ask, because the answer separates two very different kinds of software that look identical in a demo. One is honest lead recovery. The other is closer to a keylogger. Here is how to tell them apart — and the four questions that get you a straight answer from any vendor.
The two ends of the spectrum
At one end are session-replay and keystroke-logging tools. These record what a visitor does keystroke by keystroke, sometimes replaying the entire session like a video. They capture everything typed, including things a visitor entered and then deleted, and often everything in every field. This is the category that has drawn a wave of lawsuits under wiretapping statutes like California’s CIPA and Pennsylvania’s WESCA, on the argument that intercepting keystrokes without consent is unlawful interception.
At the other end is honest form-abandonment recovery. It reads a field’s completed value — the finished email address, the finished phone number — so a business can follow up on an inquiry the visitor was actively in the middle of sending. No keystroke stream. No session video. No capture of things typed and erased.
From the buyer’s chair these can be pitched with the same words: “we recover abandoned leads.” The difference is entirely in the mechanism, and the mechanism is where your legal and reputational exposure lives. So don’t evaluate the pitch. Evaluate the mechanism.
The four questions
Ask any form-abandonment vendor these four questions. A vendor operating honestly can answer all four plainly and immediately. A vendor who gets vague on any of them is telling you something.
1. Do you log keystrokes or record sessions?
The answer you want is a flat no. Reading a completed field value is a fundamentally different act from capturing every keystroke as it happens. Keystroke logging and session replay are the practices courts have been skeptical of; field-completion capture is not the same thing. If a vendor cannot clearly say they do neither, assume they do at least one.
2. Do you capture free-text fields?
This is the question that matters most for law firms and medical practices, and it is the one most vendors hope you do not ask. A contact form often includes a free-text box: “describe your legal matter,” “what symptoms are you experiencing,” “tell us about your situation.” The substance of an inquiry lives in that box — and it is exactly the data you least want captured, stored, and forwarded to a CRM or a Slack channel. An honest tool captures contact details only (name, email, phone) and never touches the free-text body. Ask directly. The answer should be that free-text is never captured.
3. Do you respect consent and geography?
Two parts. First: if a visitor is in the EU, UK, or Switzerland, are they captured at all? Under GDPR they should not be, by default. Second: if the site runs a consent platform like OneTrust, Cookiebot, or CookieYes, and the visitor declined tracking, does the tool honor that? An honest tool blocks EU/UK/Swiss visitors outright and stands down when a consent platform says no. A tool that fires on everyone regardless of location or consent is creating exposure that lands on you, the deployer — not the vendor.
4. Can a person opt out, and does it stick?
Anyone who was recovered should be able to say “stop,” and that request should suppress every future contact across every channel — email, SMS, and voice — permanently. Ask how opt-out is enforced and whether it persists. If the answer is hand-wavy, the do-not-contact list is probably not real infrastructure.
Why the mechanism is the customer’s problem, not just the vendor’s
Here is the part vendors rarely volunteer: when a form-abandonment tool creates legal exposure, the exposure usually lands on the business that deployed it, not the vendor who built it. If you are an agency putting this on a client’s site, that exposure runs through you to your client. Which is exactly why the honest answer to “how does it capture” is not a technicality — it is the whole decision. You are not just buying a feature. You are inheriting a mechanism.
How ReCapture answers the four questions
We built ReCapture to pass its own test, and we would rather show you than tell you. No keystroke logging and no session recording — we read completed contact fields only. No free-text capture — message boxes and “describe your situation” fields are never stored, transmitted, or forwarded anywhere. Passwords and sensitive fields (SSN, card numbers) are hard-excluded at the code level. EU, UK, and Swiss visitors are blocked entirely, and the tool honors OneTrust, Cookiebot, and CookieYes when present. Every recovered contact can opt out, and that opt-out is enforced across email, SMS, and voice, permanently.
All of it is laid out in plain language on our Privacy & Data page and in full detail on our Trust & Compliance page. For the communication side of compliance — TCPA, CAN-SPAM, GDPR, and HIPAA as they govern follow-up — we wrote a companion piece on the form-abandonment compliance problem.
We are a tool, not a law firm, and we will not tell you any vendor is “100% compliant” for every jurisdiction — anyone who does is overselling. What we will tell you is exactly how the software behaves, in writing, so you can make an informed call for yourself and your clients. That is the standard the whole category should be held to. Ask the four questions. Hold every vendor, including us, to the answers.
Want to see exactly what ReCapture captures and what it never touches? Read the Privacy & Data page, or get in touch with any question.
