Figment.so
BlogHow to usePricing

Squarespace Forms: Building Them and Where Submissions Go

A Squarespace form block sends every submission to your account email by default, and you can add Google Drive, Mailchimp, Zapier, or your site's own Contacts panel as extra places for that data to land. Google reCAPTCHA runs on every form block by default to filter spam, a file upload field can accept up to 5 files at 10 MB each, and how long a submission is stored depends on a setting most people never touch: whether the form has a required email field. Here's how it all works, sourced from Squarespace's own help center (checked September 2026).

What does a form block actually do by default?

Squarespace's own summary: "Use form blocks to collect important information from visitors. New form block submissions are sent to your email by default, but you can connect more storage options if needed" (Squarespace, "Form blocks"). Specifically, "the default storage option for form responses is the account email address of the site owner or contributor who added the form" — so out of the box, a form works with zero extra setup, but only one person's inbox sees the results unless you change that.

Squarespace recommends "a limit of 30 fields to keep your form manageable for visitors to complete," and notes the same number "is also the field limit for forms connected to Mailchimp." You can also add follow-up questions to dropdown, checkbox, radio, or survey fields, which only appear after a visitor picks a specific answer — useful for an intake form that branches based on an early response.

Where can submissions actually go besides my inbox?

Beyond the default email, Squarespace documents four additional storage destinations you connect from the block's Content tab under Additional Storage: "You can add Mailchimp, Google Drive, and Zapier as storage options for your submissions in addition to an email address," plus the site's own Contacts panel, which stores "form submitters and their details on your website" whenever the form has a required email field. You can connect more than one storage option at once — for example, an email address for immediate notification and Google Drive for a running spreadsheet record.

One plan-gated detail worth checking before you build around it: "Mailchimp and Zapier integrations in form blocks are available in the Core, Plus, Advanced, or some Legacy plans." If you're on Basic, verify current access on your own plan rather than assuming those two integrations are available.

A separate trap for anyone testing forms during a trial: "If your site is on a trial, you won't receive form submission emails unless the site owner is a Circle partner. To collect responses during your trial, connect to another storage option." A form can look like it's working during a trial while its email notifications are silently suppressed.

How do I get submissions out, and what's missing from the export?

Squarespace supports a direct CSV export from the block itself: "You can export submissions directly from the block to a .csv file. The .csv file includes all fields in the form, with one submission per row." The one specific gap: "Uploaded files aren't included in the export, but you can click direct links in the field to download those files" — so a file upload field's actual files need to be downloaded separately before you migrate or archive a form's history.

How long does Squarespace keep my form submissions?

This depends entirely on one setting: whether the form requires an email address. Squarespace states it plainly: "If your form includes a required email address field, the block stores any submissions until you delete the contact who submitted or delete the specific submission. If your form doesn't include a required email address field, the block stores each submission for 30 days." A quick anonymous feedback form without a required email field will quietly lose its own data after a month; a form with a required email field keeps everything until you delete it yourself.

What spam protection does a form block have?

Google reCAPTCHA runs by default. Squarespace's own description: "Google reCAPTCHA is an invisible tool that distinguishes humans from spambots. When a visitor fills out a form or newsletter signup, a reCAPTCHA logo may appear at the bottom of your site" (Squarespace, "Preventing form and newsletter block spam"). Squarespace states plainly that "Google reCAPTCHA is enabled by default and is required if you want visitors to upload files" (Squarespace, "Form blocks") — so disabling reCAPTCHA on a form removes the file upload field's availability, not just the spam filter.

There's a second, independent layer available: a confirmation email. "Another great way to prevent form spam is to select Squarespace or Mailchimp as your storage option. Both services send a confirmation email, which requires subscribers to confirm their subscription before they're added to a mailing list." That's specifically for the mailing-list signup path (when Email Signup is enabled on the form), not for every plain form submission.

If a submission does get through and looks suspicious, Squarespace's own guidance is direct: form emails always arrive "from a Squarespace email address, form-submission@squarespace.info," and "we'll never contact you through a form block on your site" — a useful line to remember if a fraudulent-looking submission claims to be from Squarespace itself.

What can a file upload field actually hold?

The file upload field is form-block-only — it's "only available in form blocks, not Add to cart forms or custom checkout forms" — and it needs reCAPTCHA turned on to appear at all. By default, visitors can upload:

  • Image: .png, .jpg, .tiff, .heic, .webp
  • Document: .docx, .doc, .pdf, .txt
  • Presentation: .pptx, .pdf
  • Video: .mp4, .avi, .avchd, .flv
  • Audio: .mp3, .wav, .aac, .mp4, .alac

You control which of those types are accepted and "how many files visitors can upload (up to 5)" per field, and "each uploaded file is limited to a size of 10 MB." Every file is scanned: "We scan all files for viruses before allowing the submission to be sent." Downloading an uploaded file works differently depending on where the submission is stored — a direct link in the Contacts panel or the notification email, or a URL you copy and paste when the storage option is Google Drive, Zapier, or Mailchimp — and Squarespace restricts who can do it: "Only site owners and administrators can download files, or contributors with both Email Campaigns Editor and Website Editor permissions." (Squarespace, "Form fields explained")

Can I use a Squarespace form for anything sensitive, like patient information?

No. Squarespace is explicit about this boundary: "Form blocks sent over SSL-enabled domains are encrypted, but they can't be used as part of a HIPAA-compliant solution. To collect secure patient information, we recommend Acuity Scheduling" instead. Encryption in transit isn't the same as a compliant intake system, and Squarespace draws that line itself rather than leaving it to guesswork. (Squarespace, "Form blocks")

What should I check before I rely on a form for something important?

  • Confirm which storage option actually receives a copy — the default email-only setup means only one inbox sees results unless you add Contacts, Google Drive, Mailchimp, or Zapier.
  • If the form matters for compliance or record-keeping, add a required email field so submissions persist indefinitely instead of expiring after 30 days.
  • Download any uploaded files separately before archiving or exporting a form's history — the CSV export leaves them out.
  • If you're testing on a trial site, don't assume a missing notification email means the form is broken; connect a non-email storage option to actually see test submissions.
  • Never route anything HIPAA-sensitive through a form block, regardless of SSL.

What happens to my forms if I move off Squarespace entirely?

That's a bigger question than storage settings, since the working form, its spam filtering, and its notification routing don't travel with an export the way the submission data does. Our guide to what happens to forms, bookings, and checkout during a migration covers the full replacement pattern across platforms, including Squarespace specifically, in more depth than fits here.

Where does Figment fit in?

Nowhere directly. Figment publishes a site from a Figma design through its Figma plugin; it has no form builder, submission storage, or spam-filtering system of its own. A Figment-published site that needs a working contact form would need to embed a separate, standalone form service, the same pattern anyone moving away from a builder's native form has to plan for regardless of which platform they're leaving.

Bottom line: Squarespace's form block is more capable than the default single-inbox setup suggests, but three details decide whether it fits a real workflow: the required-email-field setting controls whether submissions persist or expire in 30 days, reCAPTCHA being on is a prerequisite for file uploads rather than just a spam filter, and Mailchimp/Zapier storage is plan-gated. Check all three before you build something you're depending on.


Get the latest content from Figment. Subscribe today for Figma design guides and website building tips.


Figment.so

Contact

Twitter

Pricing

Privacy

Terms