Skip to content

PostTo vs Basin

The Basin alternative built for European data residency

Basin is a solid form backend with a loyal following. PostTo covers the same core job — point your form's action at an endpoint, get submissions in your inbox — and adds the things that matter when data protection is part of your requirements list.

PostTo is hosted in Europe, encrypts every submission field at rest on every plan, and offers an HMAC-signed server-side mode that no mainstream form backend provides. Switching is a one-attribute change.

Free plan, no credit card required.

PostTo vs Basin at a glance

PostTo Basin
Hosting & data residency Europe — submission data stays within European borders United States
Encryption at rest AES-256 on every plan, including Free Not offered as a plan feature
HMAC-signed incoming submissions Yes — timestamp + body signed with HMAC-SHA256, replay-protected No — they sign outgoing webhook payloads, not the incoming submission
Spam filtering First-party baseline on all plans; optional AI classification, opt-in per endpoint Built-in filtering (captcha, AI, honeypot, domain/country rules)
Spam-flagged submissions Held for review — release with one click, never silently dropped Held in a spam tab for review, with a "not spam" release option
What counts against your quota Only emails actually delivered — blocked spam is free Same — spam submissions are excluded from your monthly limit
Webhooks HMAC-signed webhook fan-out Available on paid plans
Free plan 50 submissions/month, no credit card Yes, with limits

Comparison reflects publicly available information at the time of writing. Check Basin's site for their current features and pricing.

Why developers switch

Data residency you can point to

Hosted in Europe, operated by a European company, no transatlantic transfer for baseline operation. When a client's DPO asks where contact-form data lives, the answer is one sentence.

Security on the free plan too

AES-256 encryption at rest applies to every submission on every plan. The HMAC-signed API mode protects server-side integrations against replay attacks and forged payloads.

Spam handling with a paper trail

Baseline filtering is fully first-party — no data leaves PostTo. Optional AI classification is off by default and opt-in per endpoint, and anything flagged is held for your review rather than discarded.

Migrating from Basin

The whole migration is a change to your form's action="" attribute.

  1. 1

    Create a free PostTo account and add an endpoint — you'll get an endpoint URL immediately.

  2. 2

    Replace the Basin URL in your form's action="" attribute with your PostTo endpoint URL.

  3. 3

    Deploy. Field names stay as they are — PostTo accepts arbitrary fields and maps subject, message, name, and email via per-endpoint field mapping.

Frequently asked questions

How do I migrate from Basin?
Swap the URL in your form's action attribute for your PostTo endpoint URL and deploy. No SDK, no JavaScript, no markup changes — PostTo accepts arbitrary field names.
Will my form's design or markup change?
No. PostTo never injects widgets, iframes, or styling. Your form, your HTML, your field names.
Does PostTo have a free plan?
Yes — 50 submissions per month, no credit card required. It is a real free tier with the full dashboard, spam filtering, and CSV export.
Where is my submission data stored?
In Europe, encrypted at rest with AES-256. Retention is configurable per endpoint with automatic purging, plus manual per-submission purge for erasure requests.

Ready to try the Basin alternative?

Create an endpoint, point your form at it, and see your first submission in the dashboard — all on the free plan.

Try PostTo free