Privacy policy
Last updated: July 2026
QuoteBuild is quoting, estimating, and job-management software for UK builders and trade businesses. This policy explains the information we use to run the service, support accounts, process payments, and improve the product.
1. Information We Collect
We collect information you provide when you create an account, use QuoteBuild, subscribe, or contact us. This can include:
- Name and contact data
- Business details required for quoting and invoicing
- Jobs, estimates, quotes, invoices, photos, uploaded plans, takeoff measurements, and related job records
- Redacted old quotes submitted through an invited prospect quote-rebuild link, together with the email address that received the link
- Payment and subscription information processed through Stripe
- Support messages and product usage information
2. How We Use Your Information
We use this information to:
- Maintain your account and provide the service
- Create quotes, invoices, job records, and related documents
- Process subscriptions, payments, and billing messages
- Send technical notices, updates, and support messages
- Respond to your comments, questions, and requests
- Review an invited prospect's redacted old quote, prepare quote-rebuild findings, and return those findings to the associated email address
- Understand product usage and launch funnel performance where analytics are accepted
3. Service providers
QuoteBuild uses providers to run the service, including Supabase for database, authentication, and private file storage; Stripe for payments; Vercel for hosting and request processing; Google Workspace/Gmail and Resend for email; PostHog and Google Analytics 4 for optional product analytics; and Sentry for privacy-filtered crash and performance diagnostics when configured.
4. Prospect quote-rebuild uploads
If we email you a one-time quote-rebuild link, the upload request is associated with the email address that received that link. We use the association to review the submitted quote for the requested rebuild and scope findings, manage the request, and return the result by email. It is not a public document-sharing service.
Vercel processes the page and upload request. Supabase stores the upload request record and file in a private, access-restricted bucket. Google Workspace/Gmail or Resend may process the invitation, replies, and delivered findings. Optional product analytics is suppressed on the upload page.
Before uploading, you are responsible for removing client names, addresses, contact details, and any other personal information that is not needed for the rebuild. Do not upload a file if you are not authorised to share it or cannot redact it appropriately.
JPG and PNG files are decoded and re-created without embedded metadata before storage. PDF intake is disabled unless the operator malware-scanning workflow is explicitly marked ready. When enabled, PDFs are kept private and quarantined until the local ClamAV process records a clean scan; scanner absence or errors leave the PDF quarantined. Scanning reduces risk but cannot guarantee a file is safe. There is no public download route for prospect uploads.
The private file and its associated upload record are targeted for automated deletion 30 days after the upload link is created. A protected daily cleanup retries storage or metadata deletions that do not complete successfully.
5. Cookies and analytics
Essential storage is used for login, security, preferences, and core service operation. QuoteBuild also records two minimal operational events—first quote created and checkout started—without page URLs, referrers, marketing attribution, payment card details, or raw quote content. Wider optional analytics only runs after you accept it. Read the cookie policy.
In the iPhone app, optional PostHog analytics is off by default and can be changed in Settings. Mobile analytics does not include job names, client details, addresses, notes, financial amounts, photos, or credentials. The app may keep a user-specific offline copy of essential job details and queued notes or spend updates on the device; this local data is cleared when the user logs out or changes account.
5A. Plan Takeoff drawings
Plan Takeoff drawings are stored in private Supabase storage and are available only inside the authenticated job that owns them. Drawings, measurement geometry, supplier workings, and takeoff notes are internal estimating records and are not included in client quote packs.
Supported images are decoded and re-created without embedded metadata. PDF, JPG, and PNG files are checked for type, size, and readable structure before use. Plan Takeoff remains a manual estimating aid and does not automatically interpret construction scope.
Drawings are retained with the job until you delete the drawing, job, or account. Storage deletion is attempted immediately and queued for protected retry if the storage provider does not complete it.
6. Retention and deletion
Product data is kept while your account is active. If a paid account is cancelled, the current default is to keep product data for one month after the paid period ends or delete it sooner on request where legally and operationally possible. Some billing, accounting, security, support, or dispute records may need to be kept longer.
7. Your rights
You can contact us to ask about access, correction, export, deletion, or restriction of your personal data. We may need to verify the request before acting on it.
8. Security
We use service-provider security controls, access controls, and product safeguards to protect account and job data. No system is perfect, so please contact us quickly if you think your account or data has been exposed.
9. Contact us
If you have questions or comments about this Privacy Policy, please contact us at hello@quotebuild.co.uk.