Legal

Privacy Policy

Last updated 26 August 2026

1. Who this covers

This policy explains how Quote Follow-Up handles personal data. We run a follow-up board for trade quotes: ingest, extract, owner confirm, follow-up send, customer reply drafts, and billing.

For your login, billing, and shop settings, we are the controller. For your customers' names, emails, phones, and job details on a quote, you are the controller. We process that data on your instructions so we can show the quote and send the follow-up you approve.

2. Data we collect about you (the owner)

  • Email, password hash (or Google account id), phone, company name, region, and your language preference (English, German, French, or Spanish)
  • Plan status, trial end, billing period, auto-renew flag, renewal date
  • Session cookies so you stay signed in
  • Forwarding address we issue for your shop
  • Sending channels we later enable for your shop: the SMS number assigned to your shop and your WhatsApp business line status
  • Accounting connection status for QuickBooks or Xero (encrypted tokens)
  • Gmail or Outlook mailbox tokens if you connect them, plus cadence, tone, and auto-send settings
  • Security audit events: who did what (for example settings changes, accounting connect or disconnect, admin reads), IP address, browser user-agent, and a short non-secret detail (provider name, cadence flags). We do not put tokens, passwords, or follow-up message text in that log

We do not store full card numbers. Checkout runs on Flutterwave. We keep the payment reference we need to mark the plan active or past due.

3. Data about people you quoted

When you CC the forwarding address, paste a quote, attach a PDF, connect Gmail, or connect QuickBooks or Xero, we may store:

  • Customer name, email, phone
  • Amount, currency, job description
  • Source (email, QuickBooks, Xero — Stripe when that ingest launches) and the provider's document id
  • Extracted fields and confidence, plus the raw text we used
  • Follow-up drafts, customer reply text, approved copy, send time, channel, and delivery errors
  • Accept-link status for a quote: viewed, signed, deposit paid or awaiting, if you use online acceptance
  • Consent ticks you recorded (email lawful basis now; the TCPA or WhatsApp permission you will attest before those channels send)

Do not send us quotes for people you are not allowed to follow up with. If a customer opts out (for example by replying STOP), we record that against their phone number so we can block further texts.

4. What we use it for

  • Create and secure your account
  • Build the quote, board, and inbox
  • Draft follow-ups and customer replies in your chosen language, then send the ones you approve (or auto-send if you turned that on)
  • Run invoice reminders for won jobs and host your accept link so customers can approve and pay a deposit through your own payment link
  • If enabled, text back a missed caller on your tracked number once, honoring opt-outs
  • Charge the plan you chose, pause sending if the trial ends or payment fails
  • Email you password resets and "draft ready" notices
  • Fix failures (duplicate ingest, expired accounting tokens, failed send)
  • Keep the service secure: abuse, disputed admin actions, and who changed shop settings

We do not sell personal data. We do not use customer quotes for advertising.

5. Processors

We use other companies to run the product:

  • Hosting and database for the app and job queue
  • Brevo — inbound quote mail and outbound follow-up email
  • NVIDIA or Anthropic — extract quote fields and draft copy
  • Intuit QuickBooks and Xero — if you connect them, to read sent quotes or invoices
  • Flutterwave — card checkout and subscriptions
  • Google — Google sign-in if you choose it, and Gmail sent-mail if you connect a mailbox

Not yet active: Microsoft (Outlook ingest), Infobip (SMS), Meta (WhatsApp), Twilio (missed-call text-back), and Stripe (quote ingest and deposit checkout paying into your own account). These are marked Coming soon in the product; when we switch one on, that provider will process only what the feature needs — for messaging, the recipient's number or WhatsApp id, the shop name as sender identity, and the message body. We will keep this notice current.

6. Legal bases (UK / EU)

Where UK GDPR or GDPR applies:

  • Contract — running your account, the board, and paid features
  • Consent — the lawful-basis tick on a UK/EU quote before email follow-up; TCPA or WhatsApp permission attestations when those channels launch; auto-renew only if you tick it at checkout
  • Legitimate interests — keeping the service secure (including IP and audit logs), preventing abuse, diagnosing failed sends

You confirm customer follow-up. We do not decide that a stranger should get a chase email.

7. United States

Text messaging is not enabled yet. When we switch SMS on, you will attest TCPA permission for a customer's number before any text, and we will store that attestation with the quote. If a customer replies STOP, we record it and block further texts to that number. Missed-call text-back, when enabled, will send at most one automated text per caller per cooldown window. We still need you not to upload customer data you should not have.

8. Cookies

We use cookies and similar storage only to keep you signed in (session token) and to remember display choices such as theme, your language preference, or which currency you pin on the board. We do not run advertising pixels on the app.

9. How long we keep it

Account and quote data stay while the shop is open. If you ask us to delete the account we remove the owner record, quotes, follow-ups, consents, and accounting tokens, except records we must keep for billing disputes or legal duty (for example a Flutterwave payment id).

Inbound mail and webhooks are stored so we can ignore duplicates. Failed jobs may keep an error string until the follow-up is resent or skipped. Security audit events are kept for 12 months, then deleted. We may keep those rows after an account close if we still need them for a security or billing dispute, and no longer than that 12-month window.

10. Your rights

You can access or correct shop details in Settings. To export or erase the account, email privacy@getquotefollowup.com. UK/EU owners can also object, restrict, or complain to a supervisory authority (ICO in the UK; your local DPA in the EEA).

If a customer of yours wants their data deleted, you are the controller. Tell us which quote and we will help remove it from the board.

11. Where data goes

The app, email, model, and payment providers may process data in the US, UK, EU, or other countries where those providers run. Quote text sent to a model leaves our database for that request. We do not put your quotes into a public training set of our own.

12. Children

The service is for adult trade owners. We do not knowingly take accounts from anyone under 18.

13. Changes

Material changes get a new date at the top of this page. The current version always lives at this URL.

14. Contact