Privacy Policy
Last updated: September 14, 2026 • Dedicated to safeguarding your business data and quotation confidentiality
1. Our Privacy Commitment
At QuoPact (“QuoPact,” “we,” “our,” or “us”), we recognize that commercial quotes contain sensitive, proprietary business intelligence—including strategic client lists, pricing formulas, scope definitions, and contact details. We are deeply committed to protecting the privacy, confidentiality, and security of both our registered business users and the prospective clients who view quotations published through our platform.
This Privacy Policy explains how information is collected, processed, and fortified when you utilize our website, software platform, and interactive quotation links.
2. Information We Collect
We collect only the minimum information necessary to provide reliable quotation publishing, tracking, and acceptance services:
When creating an account, we collect your business name, contact email address, securely hashed passwords, and optional business details (such as commercial contact telephone, business address, and uploaded branding logos).
Information entered into quotes, including project titles, customer/client names, line-item descriptions, deliverable breakdowns, quantities, unit prices, discount calculations, currency codes, payment terms, and project specifications.
When a recipient opens a public quote link, our system records the view timestamp, aggregate view counts, line-item adjustment feedback submitted by the client, and the authorized signatory name submitted upon formal digital quote acceptance.
Browser type, device classification, operating system, network IP address (processed strictly for connection routing and abuse prevention), and essential session cookies needed for secure login authentication.
3. How We Use Your Information
The information we collect is utilized strictly for direct operational purposes:
- Generating and hosting interactive, tamper-proof quotation links for your prospective clients.
- Providing you with real-time visibility into when clients open quotes, comment on deliverables, or approve proposals.
- Recording formal legal acceptance records, including client signer name and immutable acceptance timestamps.
- Authenticating authorized team members and enforcing business membership boundaries.
- Managing subscription billing cycles, tracking monthly quotation quotas, and preventing fraudulent abuse.
- Delivering vital system notices, security alerts, and customer support responses.
4. Enterprise Database Security Powered by Supabase
Your data is stored and protected using an enterprise-grade cloud database infrastructure hosted by Supabase, built upon an enterprise-hardened PostgreSQL architecture. We implement modern, defense-in-depth security standards to guarantee that your business records and client communications remain safe, isolated, and resilient:
- PostgreSQL Row-Level Security (RLS): Multi-tenant isolation is enforced directly at the database engine level. Every database query executed through our application is constrained by strict RLS policies tied to authenticated user IDs and business membership records. No business or user can access, query, or view quotations, client data, or metrics belonging to another account.
- Cryptographic Link Protection (HMAC SHA-256): Public quote links do not expose sequential identifiers or internal database UUIDs. QuoPact URLs utilize unpredictable, cryptographically derived tokens using HMAC SHA-256 hashes. Public quote records can only be resolved by presenting the valid opaque URL token, preventing enumeration or scraping attacks.
- End-to-End Encryption in Transit: All data transmitted between your browser, our application servers, and Supabase database endpoints is encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS).
- Storage Encryption at Rest: All database disks, persistent volume snapshots, and automated database backups are encrypted at rest using industry-standard AES-256 encryption keys.
- Credential Security: Authentication credentials and passwords are protected with salted cryptographic hashing algorithms. We never store, transmit, or have access to plaintext passwords.
- Infrastructure Compliance: Supabase maintains SOC 2 Type II compliance, ISO 27001 certification, high-availability replication, and adherence to European Union GDPR standards.
5. Payment Processing & Financial Security
All payment transactions for paid subscription tiers (such as Pro) are handled directly by PCI-DSS Level 1 certified third-party payment processors (such as Dodo Payments). QuoPact never collects, handles, or stores your credit card numbers, CVVs, or banking credentials on our servers. Financial transaction records are encrypted and retained solely by our payment partners in full accordance with international financial security standards.
6. We Never Sell or Monetize Your Data
We believe software should serve its users, not harvest them. We do NOT sell, rent, license, trade, or share your personal information, client contact lists, quotation pricing, or business records with third-party data brokers or advertising networks.Your client lists and proposals remain strictly your proprietary commercial property.
7. Cookies & Local Tracking Technologies
QuoPact employs a minimal, privacy-first approach to cookies and client-side storage:
- Strictly Necessary Authentication Cookies: Used to maintain secure, encrypted user login sessions across dashboard navigation.
- Quote Viewer Session Tokens: An ephemeral cookie (e.g.
qv_[token]) is stored on recipient devices solely to recognize return visits to a specific quotation link, preventing inflated view count statistics.
We do not use third-party behavioral advertising cookies, retargeting pixels, or cross-site tracking mechanisms.
8. Data Retention, Portability & Deletion
You retain complete control over your commercial records:
- Immediate Quote Deletion: When you delete a quote within your dashboard, the quote document, its historical versions, item records, and associated client feedback comments are permanently removed from our database.
- Account Deletion (“Right to be Forgotten”): You may request complete deletion of your account and business organization at any time. Upon processing, all corresponding database rows, membership records, and quote histories will be permanently purged.
9. Global Privacy Rights (GDPR, UK DPA & CCPA/CPRA)
Depending on your location, you may have specific statutory rights under data protection laws such as the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA):
- The right to access and obtain a copy of the personal data we hold about you.
- The right to rectify inaccurate or incomplete information.
- The right to request the erasure of your personal data.
- The right to object to or restrict certain processing activities.
- The right to data portability in a structured, machine-readable format.
- The right to non-discrimination for exercising your statutory privacy rights.
To exercise any of these rights, simply email our privacy team using the contact details below. We will respond promptly within statutory timeframes.
10. Children’s Privacy
QuoPact is designed solely for commercial business purposes and professional use. We do not knowingly collect, solicit, or maintain personal data from individuals under the age of 18. If we discover that personal information of a minor has been mistakenly collected, we will take immediate steps to delete the data from our databases.
11. Contact Our Privacy Team
If you have questions, concerns, or requests regarding this Privacy Policy or our security practices, please contact us at: