Skip to main content

Web form lead capture

Your Leads board is the sales pipeline — prospects from first enquiry to won. Until now every lead had to be typed in by hand. The web form gives you a front door for inbound work: a public, embeddable enquiry form that you put on your own website, and every submission lands on the Leads board automatically in the New column, tagged as a web enquiry.

Each VCR gets one form with its own secret key. The form is branded with your logo and company name, you choose which fields appear, and built-in spam protection keeps the junk out.

Open the web form settings​

  1. Go to Sales in the sidebar, then Leads in the switcher.
  2. Click Web form in the top-right (next to New lead). You need Sales access to see it.
  3. The Lead capture web form dialog opens. The first time you open it, your form is created automatically with a fresh key.

Turn the form on​

At the top of the dialog is the Form is live switch:

  • On — the form accepts submissions.
  • Off — visitors who open the form see a short "not accepting enquiries right now" message instead of the fields. Nothing is lost; turn it back on at any time.

Just under the switch you'll see your running totals: how many submissions you've received, how many were blocked as spam, and when the last one arrived.

Share or embed the form​

The Share & embed section gives you two ways to publish the form:

  • Direct link — a …/f/<your-key> URL you can email, put behind a "Get a quote" button, or share on social media. Use Copy to copy it, or Open to preview it in a new tab.
  • Embed snippet (iframe) — paste this HTML into your website to show the form inline on a page. Copy snippet copies it ready to paste.
<iframe
src="https://portal.clevercam.co.za/f/lf_xxxxxxxxxxxxxxxx"
title="Request a callback"
style="width:100%;max-width:480px;height:640px;border:0;"
loading="lazy"
></iframe>

Regenerate the key​

Regenerate key issues a brand-new key and invalidates the old link and embed immediately. Only do this if a key has leaked or is being abused — afterwards you must replace the snippet everywhere you've embedded it.

Customise the form content​

The Form content section controls what visitors see:

FieldWhat it does
TitleThe heading at the top of the form, e.g. "Request a callback".
Intro textAn optional line under the title.
Submit button labelThe text on the button, e.g. "Send enquiry".
Redirect URL after submitOptional. If set, visitors are sent to this page after a successful submit (e.g. your own thank-you page) instead of seeing the thank-you message.
Thank-you messageShown after a successful submit when no redirect URL is set.

Choose the fields​

The Fields section lists the five fields the form can collect. For each one you can:

  • Show — tick to include the field on the form.
  • Edit the label the visitor sees.
  • Required — tick to make the field mandatory before the form can be sent.
FieldWhere it lands on the lead
Your nameLead contact name
EmailLead contact email
PhoneLead contact phone
CompanyLead company
How can we help?Lead notes

The company (or, if blank, the contact name) becomes the lead's name on the board. Reset to default restores the standard five-field set.

Routing & protection​

The Routing & protection section decides what happens to each submission and keeps bots out:

  • Lead source label — the text stamped onto the lead's source (defaults to website), so you can tell web leads apart in reports.
  • Assign to sales rep — optionally pre-assign every web lead to one of the sales-role members on People. Leave on Assign later to leave new leads unowned.
  • Max submissions / hour per visitor — a per-visitor rate limit. Submissions over the limit are refused with a "try again later" message.
  • Min seconds to fill (anti-bot) — submissions completed faster than this are treated as suspicious.

Every submission also passes through a hidden honeypot field that real visitors never see.

Suspected bots get a human check, not a silent bin​

When a submission trips the honeypot or the fill-time check, the enquiry is not discarded. The form shows a quick human check instead — a simple question like "Quick check — what is 4 + 6?" — and the enquiry is sent the moment the visitor answers it. This protects real people who trip the checks by accident (browser autofill can complete a form in under a second), while bots that never answer are dropped as before. Each triggered check is counted in your "blocked as spam" total.

Two more things make false positives rare:

  • Signed-in staff are always trusted. If you open the form in a browser where you're signed in to CleverOps (e.g. testing your own form), the spam checks are skipped entirely.
  • Every submission attempt is logged with its outcome — including which check triggered — so an administrator can always see why a specific enquiry was challenged.
POPIA

Visitor IP addresses are never stored in the clear — only a salted hash is kept, purely to power the rate limit.

What happens when someone submits​

  1. The visitor fills in the form and clicks the submit button.
  2. A new lead is created on your Leads board in the New column, with a Web chip so you can spot inbound enquiries at a glance.
  3. The Leads page header shows a "N new web enquiries waiting" note while any web leads sit in New.
  4. From there it's an ordinary lead — drag it through the pipeline, add an estimated value, link a quote, or convert it to a customer when you win the deal.

Open the Web form dialog any time to see your submission and spam totals.

Deploying the endpoint​

The form posts to a public Supabase edge function (lead-web-form) backed by the lead_web_forms table (migrations 20260629g_lead_web_forms.sql and 20260701i_lead_web_form_challenge.sql). Before the form will accept live submissions, an administrator must apply those migrations and deploy the function with JWT verification disabled so third-party sites can post to it:

supabase functions deploy lead-web-form --no-verify-jwt

The committed supabase/config.toml already sets verify_jwt = false for this function.

Permissions​

Configuring the form and reading its submission stats requires Sales access (the same permission as managing leads). The public form itself needs no sign-in — that's the point.