Legal

Privacy Policy

Last updated 23 August 2026

Who this covers

Quote It Right is a quoting and estimating tool for trades and makers, operated by [Legal entity name] [postal address]. This policy explains what we collect when you use the website and the application, why we collect it, who it is shared with, and what you can ask us to do with it.

It covers people who visit the site or hold an account. It also covers the clients of our users, who may receive a quote approval link without ever creating an account — the quote approval records section is the part that concerns them.

What we collect

Account information

Your email address, and your name and profile photo if you sign in with Google. Passwords for email sign-in are handled by Google Firebase Authentication and are never visible to us. You can also use the app as an anonymous guest, in which case we hold only a generated account identifier.

Business profile

Whatever you enter in settings: business name, phone number, address, website, logo image, default labour rate, margins, tax rate and quote expiry. This appears on the quotes you send, and you control which fields are shown.

Content you create

Projects and quotes, their line items and costs, templates, uploaded project photos, version history, and generated PDFs.

Information about your clients

Client records you enter — name, company, email, phone, address, website and notes. This is your data about your clients: we store and process it on your behalf so the product works, and we do not market to your clients or use their details for our own purposes. You are responsible for having a lawful basis to enter it.

Payment information

Subscription and quote payments are processed by Stripe. Card numbers never reach our servers — we store Stripe identifiers, subscription status, payment amounts and receipt links. If you connect a Stripe account to collect client payments, Stripe holds the payout and identity details required for that and we store only the connected account identifier and its status.

Usage data

We record product events — pages viewed, calculators used, quotes created, sign-ups and upgrades — with the page path and the referring URL. Anonymous visitors are identified by a randomly generated value stored in a first-party cookie; when you create an account, that value is linked to your account so activity from before sign-up connects to it.

We use no third-party analytics, advertising or tracking services. This data is first-party, stays in our own database, and is not sold, shared for advertising, or used to build profiles across other websites.

Email records

We log which transactional and lifecycle emails have been sent to you and when, so we don't send the same message twice.

Quote approval records

When one of our users sends a quote for approval, the recipient gets a link that opens the quote without an account. If they approve or reject it, we record an audit trail so the approval can be evidenced later:

  • the name they type as the approver, and whether they agreed to the terms
  • the date and time
  • their IP address and browser user-agent string
  • an approximate location (city and region) derived from that IP address by a third-party lookup service
  • precise GPS coordinates, only if their browser asks permission and they allow it — this is optional and declining it does not prevent approval

This record is visible to the user who sent the quote and is retained with that quote. It exists to demonstrate who approved what and when, and is not used for any other purpose.

Cookies and browser storage

We do not use advertising or cross-site tracking cookies. What we do store:

NameTypePurposeLifetime
qir_aidCookieA random identifier that links your visits together so we can measure how the product is used.2 years
qir-color-modeLocal storageRemembers whether you chose light or dark mode.Until cleared
qir-sidebarLocal storageRemembers whether you collapsed the sidebar.Until cleared
qir-signed-inLocal storageA flag noting you were signed in last time, so the correct page layout renders immediately.Until sign-out
Firebase authenticationLocal storageKeeps you signed in between visits. Set by Google Firebase.Until sign-out

You can clear these at any time in your browser settings. Clearing the authentication entry signs you out; clearing the others only resets preferences.

Why we use it

  • To provide the product — storing your quotes, sending them, and taking payment.
  • To operate your account, including subscriptions, trials and billing.
  • To send transactional email (quote approvals, payment confirmations) and product lifecycle email (welcome, trial reminders). You can opt out of the lifecycle messages; transactional messages are part of the service.
  • To understand which features are used and where people get stuck, so we can improve it.
  • To keep the service secure and to detect abuse.
  • To meet legal, tax and accounting obligations.

Where the law requires a lawful basis, ours is: performance of our contract with you (running the service), our legitimate interests (improving and securing the product), your consent (precise location on quote approval), and legal obligation (financial records).

Who we share it with

We do not sell personal information. We share it only with the service providers below, each acting on our instructions, and where required by law.

ProviderWhat it handles
Google FirebaseAuthentication, database, file storage for photos and logos.
StripeSubscription billing, quote payments and connected-account payouts.
ResendTransactional and lifecycle email delivery.
VercelWebsite and application hosting.
ip-api.comIP-to-city lookup, used once at the moment a quote is approved to record an approximate location.

If the business is sold or merged, personal information may transfer as part of that transaction; you would be told before it became subject to a different policy.

How long we keep it

  • Account and content — for as long as your account is open. Delete a project or client and it is removed; close your account and we delete your content.
  • Quote approval records — kept with the quote they belong to, because they are the evidence that the quote was approved.
  • Payment and invoice records — retained as long as tax and accounting rules require, which is typically several years and is usually longer than the account itself.
  • Usage events — retained in aggregate to understand long-term trends.

Your rights

Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, get a copy in a portable format, object to or restrict certain processing, and withdraw consent you previously gave. Residents of the EU and UK have these rights under the GDPR; residents of California and several other US states have comparable rights, including the right not to be discriminated against for exercising them.

Much of this you can do yourself: settings holds your profile, and projects and clients can be edited or deleted from the app. For anything else — including deleting your account entirely — email [privacy contact email] and we will respond within the time the applicable law allows.

If you are one of our users' clients and want your details removed, contact the business that sent you the quote; they control that record. If you cannot reach them, contact us and we will help.

Security

Access to your data requires authentication, and each account's records are isolated so one account cannot read another's. Traffic is encrypted in transit. Payment card data never touches our servers. Quote approval links carry a long random token and can be expired by the sender at any time.

No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulator where the law requires it.

International transfers

Our providers operate globally, so your information may be processed outside the country you live in, including in the United States. Where required, transfers rely on approved safeguards such as the European Commission's standard contractual clauses.

Children

This is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email [privacy contact email] and we will delete it.

Changes

We will update this page when our practices change, and the date at the top will change with it. If a change materially affects your rights, we will tell you directly rather than relying on you noticing.

Contact

Questions, requests or complaints: [privacy contact email] [postal address].

[Governing law / jurisdiction]. If you are in the EU or UK and are not satisfied with our response, you may complain to your local data protection authority.