Privacy Policy

Effective Date: August 14, 2026 | Version 2.0

At QuoteNest, we respect your privacy and are committed to protecting the personal data of both our users (service operators) and their respective customers (clients). This Privacy Policy explains how we collect, process, share, and protect information when you use our website, dashboard, and services.

1. Information We Collect

We collect information that you directly provide to us, as well as metadata gathered automatically during service operation.

Categories of Data We Process:

  • Account Credentials: Owner name, business name, password hashes, and email address used for authorization and security via Supabase Auth.
  • Customer / Client Records: Client names, phone numbers, and job addresses entered by you to generate estimates, dispatch invoices, or schedule reminders.
  • WhatsApp Messaging Log: Metadata (timestamps, delivery statuses) regarding WhatsApp messages sent via the Meta Cloud API. We do not store the specific message payloads permanently once delivered.
  • Transaction and Subscription Information: Subscription status, trial end-dates, and billing logs. Payments are processed by Lemon Squeezy, our Merchant of Record. We do not collect or store your payment card numbers.
  • AI Processing Inputs: Job descriptions, square footage, room counts, and service types submitted to generate AI-powered quotes via Google Gemini.
  • Analytics & Usage Data: Pages visited, features used, clicks, session duration, device type, browser, IP address, and referral source — collected via PostHog.
  • Error & Diagnostic Data: Application error logs, stack traces, and performance metrics collected via Sentry for debugging and reliability.
  • Email Communications: Email address used for transactional emails (onboarding sequences, billing receipts) dispatched via Resend.

2. Purpose of Processing & Legal Basis

We process data to deliver the core service features under standard contract performance:

  • Account Delivery: To register accounts, authenticate access, and maintain session persistence.
  • AI Estimation: To run calculations and generate professional PDF/text quotes for your clients based on job inputs (sqft, rooms, service type).
  • Automated Reminders: To deliver scheduled rebooking reminders via WhatsApp (Meta API integration) as requested by you.
  • Billing & Fraud Prevention: To verify subscription status and block spam registrations (e.g. temporary/disposable emails).

3. Data Sharing and Third-Party Subprocessors

We do not sell, rent, or trade your data. To perform our services, we share data with the following trusted subprocessors, all of which comply with standard security and privacy regulations:

Partner / SubprocessorRole / ServiceData Handled
Supabase Inc.Cloud Database & AuthenticationUser credentials, client records, quote details
Lemon Squeezy LLCMerchant of Record & PaymentsBilling records, subscription details, plan states
Meta Platforms Inc.WhatsApp Cloud API GatewayClient phone numbers, business name parameters
Google LLC (Gemini AI)AI Quote Generation EngineJob inputs (rooms, sqft, service type), business name
PostHog Inc.Product Analytics & Session TrackingPage views, feature usage, IP addresses, browser cookies
Functional Software Inc. (Sentry)Error Monitoring & Crash ReportingStack traces, session metadata, IP addresses
Vercel Inc.Application Hosting & CDNAll HTTP requests, IP addresses, edge function logs
Cloudflare Inc.Encrypted Database Backup Storage (R2)Full encrypted database snapshots
Resend Inc.Transactional Email DeliveryUser email addresses, onboarding email content
Upstash Inc.Rate Limiting Infrastructure (Redis)IP addresses, request frequency counters

4. Security, Encryption & Data Residency

We apply bank-grade security protocols to prevent unauthorized access, alteration, or disclosure:

  • In-Transit Security: All connections are encrypted via SSL/TLS (HTTPS) using modern cryptographic standards.
  • At-Rest Encryption: Database records are encrypted at rest using Advanced Encryption Standard (AES-256) on Supabase infrastructure.
  • Security Auditing: Session security and access controls are refreshed using modern server-side JSON Web Token (JWT) verification.

5. Cookies & Session Management

QuoteNest uses essential session cookies (via Supabase Auth) for secure login persistence. We also use analytics cookies (via PostHog) to track feature usage and improve our product, and functional cookies (via Lemon Squeezy) for affiliate tracking on our marketing site. You can disable non-essential cookies in your browser settings. For full details on our cookie practices, please read our Cookie Policy.

6. AI-Generated Content & Data Processing

  • QuoteNest uses Google's Gemini AI models to generate professional cleaning estimates and quotes.
  • Job inputs (room counts, square footage, service type, add-ons) and business name are sent to Google's API.
  • Google's Gemini API does NOT retain or train on user-submitted data per their Cloud API Terms.
  • AI outputs are suggestions only; users bear full responsibility for reviewing and confirming accuracy before sending quotes to clients.
  • QuoteNest does not use client personal data (names, phone numbers, addresses) as AI model inputs.

7. Data Retention & Deletion

  • Active accounts: Data retained for the duration of the subscription.
  • Cancelled accounts: Profile and client data retained for 30 days after cancellation, then permanently deleted.
  • Backups: Encrypted database backups stored on Cloudflare R2 are automatically rotated and purged after 90 days.
  • Users can request immediate, permanent deletion of all data by emailing support@getquotenest.com or via the Settings page.

8. International Data Transfers

  • QuoteNest's infrastructure is hosted primarily in the United States (Vercel, Supabase, PostHog).
  • If you access the service from outside the US (including the EU/EEA), your data may be transferred to and processed in the US.
  • We rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable to ensure adequate protection for cross-border transfers.

9. Data Breach Notification

  • In the event of a data breach affecting personal data, QuoteNest will notify affected users within 72 hours via email.
  • Where required by law (e.g., GDPR), we will also notify the relevant supervisory authority.
  • Our incident response process includes immediate containment, forensic investigation, and remediation.

10. Data Controller vs. Data Processor

Under international privacy frameworks (including GDPR, CCPA, and CPRA), QuoteNest acts solely as a Data Processor when handling the personal information of your clients (e.g., their names and phone numbers). You, the QuoteNest registered user, are the Data Controller. You are solely responsible for ensuring you have obtained explicit, verifiable consent from your clients before uploading their data to our servers or sending them communications via our Meta WhatsApp API integration.

11. Your Rights (GDPR & CCPA Compliance)

Regardless of your residency, QuoteNest provides all users with control over their data. You have the right to:

  • Access the personal information we hold about you.
  • Rectify or correct any inaccurate client or profile information.
  • Request the permanent deletion of your account and all associated client data (right to be forgotten) from the Settings menu.
  • Cancel subscriptions instantly to prevent future billing.
  • California Residents (CCPA/CPRA): We do not sell, share, or rent your personal information to third parties for monetary or other valuable consideration. You have the right to request access to, deletion of, and correction of your personal data. To exercise these rights, email support@getquotenest.com.

12. Children's Privacy

Our services are intended strictly for business operators and professionals. We do not knowingly collect or solicit personal information from anyone under the age of 13.

13. Updates to this Policy

We may update this Privacy Policy from time to time to reflect changes in our legal obligations or services. Any updates will be posted on this page with an updated "Effective Date" at the top. We recommend checking back regularly to stay informed.

Data Processing Agreement (DPA) Addendum

This addendum serves as the formal Data Processing Agreement (DPA) between you (the Data Controller) and QuoteNest (the Data Processor). By using QuoteNest to manage your business, you agree to these terms regarding the processing of your clients' data in accordance with global privacy laws (including GDPR and CCPA).

Authorized Sub-Processors

To provide our 30-second quoting infrastructure, QuoteNest utilizes the following secure, enterprise-grade third-party sub-processors. All data in transit is TLS encrypted.

  • Vercel (Frontend Hosting & Infrastructure Edge Network)
  • Supabase (Database, Authentication, & AES-256 Encrypted Storage)
  • Meta / WhatsApp Cloud API (Encrypted Message Delivery)
  • Google Gemini API (AI Context Parsing - strict zero data retention policy)
  • Resend (Transactional Emails)
  • Upstash (Redis Rate Limiting)
  • PostHog (Aggregated Product Analytics)

QuoteNest remains strictly responsible for the compliance of our sub-processors and contractually ensures they adhere to GDPR and CCPA equivalent security standards. We will notify users prior to adding any new sub-processors that handle personal data.